{
   "data": [
      {
         "Links": [
            {
               "Title": "Vulnerabilities in Open Source C2 Frameworks",
               "Link": "https://blog.includesecurity.com/2024/09/vulnerabilities-in-open-source-c2-frameworks/"
            }
         ],
         "Authors": ["Laurence Tennant"],
         "Programs": ["Bishop Fox (Sliver)", "Havoc", "Ninja C2", "SHAD0W", "Covenant"],
         "Bugs": ["RCE", "OS command injection", "Authentication bypass", "Arbitrary file download", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-09-18",
         "AddedDate": "2024-09-24"
      },
      {
         "Links": [
            {
               "Title": "[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package",
               "Link": "https://medium.com/@p0lyxena/2-500-bug-bounty-write-up-remote-code-execution-rce-via-unclaimed-node-package-6b9108d10643"
            }
         ],
         "Authors": ["Fuleki Ioan"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Dependency confusion"],
         "Bounty": "2,500",
         "PublicationDate": "2024-09-18",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Data Theft in Salesforce: Manipulating Public Links",
               "Link": "https://www.varonis.com/blog/manipulating-salesforce-public-links"
            }
         ],
         "Authors": ["Nitay Bachrach"],
         "Programs": ["Salesforce"],
         "Bugs": ["SOQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-09-16",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Attacking PowerShell CLIXML Deserialization",
               "Link": "https://www.truesec.com/hub/blog/attacking-powershell-clixml-deserialization"
            }
         ],
         "Authors": ["Alexander Andersson"],
         "Programs": ["Microsoft"],
         "Bugs": ["Insecure deserialization", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-09-13",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Logic Flaw: I Can Block You from Accessing Your Own Account",
               "Link": "https://medium.com/@hashimamin/logic-flaw-i-can-block-you-from-accessing-your-own-account-63fc2a88bb72"
            }
         ],
         "Authors": ["Hashim Amin"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2024-09-13",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Escalating From Reader To Contributor In Azure API Management",
               "Link": "https://binarysecurity.no/posts/2024/09/apim-privilege-escalation"
            }
         ],
         "Authors": ["Christian Håland"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-09-13",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS",
               "Link": "https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b"
            }
         ],
         "Authors": ["Mikko Kenttälä (@Turmio_)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["RCE", "Arbitrary file write", "Arbitrary file delete", "TCC bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-09-13",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Interesting Story of an Account Takeover Vulnerability",
               "Link": "https://medium.com/@deepanshudev369/interesting-story-of-an-account-takeover-vulnerability-140a45a058a3"
            }
         ],
         "Authors": ["Deepanshu (@golu_369)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Host header injection"],
         "Bounty": "2,000",
         "PublicationDate": "2024-09-12",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Microsoft Windows MSI Installer - Repair to SYSTEM - A detailed journey",
               "Link": "https://sec-consult.com/blog/detail/msi-installer-repair-to-system-a-detailed-journey/"
            }
         ],
         "Authors": ["Michael Baer"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-09-12",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI",
               "Link": "https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/"
            }
         ],
         "Authors": ["watchTowr (@watchtowrcyber)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "TLD hacking"],
         "Bounty": "-",
         "PublicationDate": "2024-09-11",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Directory Traversal, SQL Injection and Server-Side Request Forgery",
               "Link": "https://research.aurainfosec.io/disclosure/sagecrm2/"
            }
         ],
         "Authors": ["Chris McCurley (@chrisrmccurley)"],
         "Programs": ["Sage"],
         "Bugs": ["Path traversal", "SQL injection", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-09-10",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Getting code execution on Veeam through CVE-2023-27532",
               "Link": "https://blog.scrt.ch/2024/09/10/getting-code-execution-on-veeam-through-cve-2023-27532/"
            }
         ],
         "Authors": ["Alain Mowat (@plopz0r)"],
         "Programs": ["Veeam"],
         "Bugs": ["RCE", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-09-10",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Hijacking SQL Server Credentials using Agent Jobs for Domain Privilege Escalation ",
               "Link": "https://www.netspi.com/blog/technical-blog/network-pentesting/hijacking-sql-server-credentials-with-agent-jobs-for-domain-privilege-escalation/"
            }
         ],
         "Authors": ["Scott Sutherland"],
         "Programs": ["-"],
         "Bugs": ["Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-09-10",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "When Certificates Fail: A Story of Bypassed MFA in Remote Access",
               "Link": "https://edermi.github.io/post/2024/mfa_bypass_mtls/"
            }
         ],
         "Authors": ["Michael Eder (@michael_eder_)"],
         "Programs": ["-"],
         "Bugs": ["2FA / MFA bypass", "Citrix"],
         "Bounty": "-",
         "PublicationDate": "2024-09-09",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Self-XSS to ATO via Site Features",
               "Link": "https://script.hashnode.dev/self-xss-to-ato-via-site-features"
            }
         ],
         "Authors": ["Hossein Shourabi (@hoseinshurabi)"],
         "Programs": ["-"],
         "Bugs": ["Self-XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-09-08",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-45195: Apache OFBiz Unauthenticated Remote Code Execution (Fixed)",
               "Link": "https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/"
            }
         ],
         "Authors": ["Ryan Emmons"],
         "Programs": ["Apache OFBiz"],
         "Bugs": ["RCE", "Forced browsing", "Broken authorization"],
         "Bounty": "-",
         "PublicationDate": "2024-09-05",
         "AddedDate": "2024-09-24"
      },
      {
         "Links": [
            {
               "Title": "How 100% Manual Hacking (Without Even Kali And Burp) Led To 2 Medium Vulnerabilities On YesWeHack",
               "Link": "https://medium.com/@manan_sanghvi/how-100-manual-hacking-without-even-kali-and-burp-led-to-2-medium-vulnerabilities-on-yeswehack-bbda00fcd84e"
            }
         ],
         "Authors": ["Manan Sanghvi (@An____Anonymous)"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-09-05",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Unmasking Harmful Content in a Medical Chatbot: A Red Team Perspective",
               "Link": "https://www.synack.com/blog/unmasking-harmful-content-in-a-medical-chatbot-a-red-team-perspective/"
            }
         ],
         "Authors": ["William Wallace (@phyr3wall)"],
         "Programs": ["-"],
         "Bugs": ["AI", "LLM Jailbreak", "Chatbot"],
         "Bounty": "-",
         "PublicationDate": "2024-09-05",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "SSTI in Bug Bounty Program: The Time I Played with Handlebars and Broke Stuff",
               "Link": "https://medium.com/@ali.zamini/ssti-in-bug-bounty-program-the-time-i-played-with-handlebars-and-broke-stuff-7dc1f9834a3d"
            }
         ],
         "Authors": ["Ali Zamini"],
         "Programs": ["-"],
         "Bugs": ["SSTI"],
         "Bounty": "-",
         "PublicationDate": "2024-09-05",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Spip Preauth RCE 2024: Part 2, A Big Upload",
               "Link": "https://thinkloveshare.com/hacking/spip_preauth_rce_2024_part_2_a_big_upload/"
            }
         ],
         "Authors": ["Laluka (@TheLaluka)"],
         "Programs": ["SPIP"],
         "Bugs": ["RCE", "File upload", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-09-04",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Revival Hijack – PyPI hijack technique exploited in the wild, puts 22K packages at risk",
               "Link": "https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/"
            }
         ],
         "Authors": ["Andrey Polkovnichenko", "Brian Moussalli"],
         "Programs": ["PyPI"],
         "Bugs": ["CI/CD", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2024-09-04",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Zomatoooo! IDOR in Saved Payments",
               "Link": "https://prateeksrivastavaa.medium.com/zomatoooo-idor-in-saved-payments-f8c014879741"
            }
         ],
         "Authors": ["Prateek Srivastava"],
         "Programs": ["Zomato"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-09-04",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "P3 (Medium) : How I Gain Access To NASA's Internal Workspace?!",
               "Link": "https://medium.com/@srishavinkumar/p3-medium-how-i-gain-access-to-nasas-internal-workspace-d0896fee563c"
            }
         ],
         "Authors": ["Sri Shavin Kumar"],
         "Programs": ["NASA"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-09-03",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities",
               "Link": "https://www.sonarsource.com/blog/basic-http-authentication-risk-uncovering-pyspider-vulnerabilities/"
            }
         ],
         "Authors": ["Yaniv Nizry (@YNizry)"],
         "Programs": ["pyspider"],
         "Bugs": ["Reflected XSS", "CSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-09-02",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "Ghost In The Ppl Part 1: Byovdll",
               "Link": "https://blog.scrt.ch/2024/08/09/ghost-in-the-ppl-part-1-byovdll/"
            },
            {
               "Title": "Part 2: From Byovdll To Arbitrary Code Execution In Lsass",
               "Link": "https://blog.scrt.ch/2024/08/15/ghost-in-the-ppl-part-2-from-byovdll-to-arbitrary-code-execution-in-lsass/"
            },
            {
               "Title": "Ghost in the PPL Part 3: LSASS Memory Dump",
               "Link": "https://blog.scrt.ch/2024/09/02/ghost-in-the-ppl-part-3-lsass-memory-dump/"
            }
         ],
         "Authors": ["Clément Labro (@itm4n)"],
         "Programs": ["-"],
         "Bugs": ["Use-After-Free", "Memory corruption", "LSA Protection bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-09-02",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "IIS welcome page to source code review to LFI!",
               "Link": "https://medium.com/@omarahmed_13016/iis-welcome-page-to-source-code-review-to-lfi-23ec581049f5"
            }
         ],
         "Authors": ["Omar Ahmed (@spaceboy2O)"],
         "Programs": ["-"],
         "Bugs": ["LFI", "Blind SSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-09-01",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN",
               "Link": "https://sudhanshur705.medium.com/bypassing-csp-via-url-parser-confusions-xss-on-netlifys-image-cdn-755a27065fd9"
            }
         ],
         "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
         "Programs": ["Netlify"],
         "Bugs": ["XSS", "CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-09-01",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "A Story About How I Found XSS in ASUS",
               "Link": "https://infosecwriteups.com/a-story-about-how-i-found-xss-in-asus-cb233ce3bb9c"
            }
         ],
         "Authors": ["Karthikeyan.V (@karthithehacker)"],
         "Programs": ["Asus"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-09-01",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "How I Got $250 For My Second Bug on HackerOne",
               "Link": "https://medium.com/@likithteki76/how-i-got-250-for-my-second-bug-in-hackerone-35c75cbd84bd"
            }
         ],
         "Authors": ["Likith Teki"],
         "Programs": ["-"],
         "Bugs": ["OAuth", "Session expiration issue"],
         "Bounty": "250",
         "PublicationDate": "2024-09-01",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "The Hunt for XXE to LFI: How I Uncovered CVE-2019–9670 in a Bug Bounty Program",
               "Link": "https://infosecwriteups.com/the-hunt-for-xxe-to-lfi-how-i-uncovered-cve-2019-9670-in-a-bug-bounty-program-5668e4afa806"
            }
         ],
         "Authors": ["Karthikeyan.V (@karthithehacker)"],
         "Programs": ["-"],
         "Bugs": ["XXE", "LFI", "Components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2024-08-31",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "Breaking Down Barriers: Exploiting Pre-Auth SQL Injection In WhatsUp Gold - CVE-2024-6670",
               "Link": "https://summoning.team/blog/progress-whatsup-gold-sqli-cve-2024-6670/"
            }
         ],
         "Authors": ["Sina Kheirkhah (@SinSinology)"],
         "Programs": ["Progress (WhatsUp Gold)"],
         "Bugs": ["SQL injection", "Reverse engineering", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-30",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways",
               "Link": "https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html"
            }
         ],
         "Authors": ["hyper (@hyprdude)"],
         "Programs": ["MediaTek"],
         "Bugs": ["RCE", "Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2024-08-30",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "Key and E: A Pentester’s Tale on How a Photo Opened Real Doors",
               "Link": "https://gosecure.ai/blog/2024/08/30/key-and-e-a-pentesters-tale-on-how-a-photo-opened-real-doors/"
            }
         ],
         "Authors": ["Patricia Gagnon-Renaud"],
         "Programs": ["-"],
         "Bugs": ["Red team"],
         "Bounty": "-",
         "PublicationDate": "2024-08-30",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "Bypassing airport security via SQL injection",
               "Link": "https://ian.sh/tsa"
            }
         ],
         "Authors": ["Ian Carroll (@iangcarroll)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-08-29",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "Analysis of CVE-2024-43044 — From file read to RCE in Jenkins through agents",
               "Link": "https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/"
            }
         ],
         "Authors": ["Gabriel Quadros (@gqsilva)", "Ricardo Silva (@rick2600)"],
         "Programs": ["Jenkins"],
         "Bugs": ["RCE", "Arbitrary file read"],
         "Bounty": "-",
         "PublicationDate": "2024-08-29",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "$15k RCE Through Monitoring Debug Mode",
               "Link": "https://medium.com/@0xold/15k-rce-through-monitoring-debug-mode-4f474d8549d5"
            }
         ],
         "Authors": ["Omar (@0x0ld)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "LFI", "Debug mode enabled"],
         "Bounty": "15,000",
         "PublicationDate": "2024-08-28",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "CSRF Bypass Using Domain Confusion Leads To ATO",
               "Link": "https://infosecwriteups.com/csrf-bypass-using-domain-confusion-leads-to-ato-ac682dd17722"
            }
         ],
         "Authors": ["Osama Aly"],
         "Programs": ["-"],
         "Bugs": ["CSRF", "Account takeover"],
         "Bounty": "4,000",
         "PublicationDate": "2024-08-28",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "3CX Phone System Local Privilege Escalation Vulnerability",
               "Link": "https://www.praetorian.com/blog/3cx-phone-system-local-privilege-escalation-vulnerability/"
            }
         ],
         "Authors": ["Adam Crosser"],
         "Programs": ["3CX"],
         "Bugs": ["Local Privilege Escalation", "Arbitrary file read"],
         "Bounty": "-",
         "PublicationDate": "2024-08-28",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-37079:",
               "Link": "https://www.zerodayinitiative.com/blog/2024/8/27/cve-2024-37079-vmware-vcenter-server-integer-underflow-code-execution-vulnerability"
            }
         ],
         "Authors": ["Grigory Dorodnov", "Guy Lederfein (@glederfein)"],
         "Programs": ["VMware"],
         "Bugs": ["Integer underflow", "Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2024-08-28",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "[$500] How I was able to give verification badge to any YouTube channel and bypass needed requirements",
               "Link": "https://vojtechcekal.medium.com/how-i-was-able-to-give-verification-badge-to-any-youtube-channel-and-bypass-needed-requirements-b88855afe4b7"
            }
         ],
         "Authors": ["Vojtech Cekal"],
         "Programs": ["Google (Youtube)"],
         "Bugs": ["Parameter tampering"],
         "Bounty": "500",
         "PublicationDate": "2024-08-27",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "Back To School - Exploiting A Remote Code Execution Vulnerability In Moodle",
               "Link": "https://blog.redteam-pentesting.de/2024/moodle-rce/"
            }
         ],
         "Authors": ["RedTeam Pentesting (@RedTeamPT)"],
         "Programs": ["Moodle"],
         "Bugs": ["RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-27",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information",
               "Link": "https://embracethered.com/blog/posts/2024/m365-copilot-prompt-injection-tool-invocation-and-data-exfil-using-ascii-smuggling/"
            }
         ],
         "Authors": ["Johann Rehberger (wunderwuzzi23)"],
         "Programs": ["GitHub (Copilot)"],
         "Bugs": ["AI", "LLM", "Prompt injection"],
         "Bounty": "-",
         "PublicationDate": "2024-08-26",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "WordPress GiveWP POP to RCE (CVE-2024-5932)",
               "Link": "https://www.rcesecurity.com/2024/08/wordpress-givewp-pop-to-rce-cve-2024-5932/"
            }
         ],
         "Authors": ["Julien Ahrens (@MrTuxracer)"],
         "Programs": ["Wordfence"],
         "Bugs": ["RCE", "PHP pop chain", "PHP object injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-26",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "“Like” Bypass on Customer Reviews — €500 bounty",
               "Link": "https://medium.com/@asharm.khan7/like-bypass-on-customer-reviews-500-bounty-b8d45a98c096"
            }
         ],
         "Authors": ["Ashar Mahmood (@Hx_0p)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw"],
         "Bounty": "500",
         "PublicationDate": "2024-08-26",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "How I got $24000 Bounty from a Log4j RCE in Apple App Store.",
               "Link": "https://medium.com/@meharhuzaifa777/exploiting-log4j-rce-in-apple-app-store-ca99a549de1f"
            }
         ],
         "Authors": ["Mehar huzaifa (@Hunter_Huzaifa_)"],
         "Programs": ["Apple"],
         "Bugs": ["RCE", "Components with known vulnerabilities"],
         "Bounty": "24,000",
         "PublicationDate": "2024-08-25",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Hitting the jackpot with RCE!",
               "Link": "https://medium.com/@gokulsspace/hitting-the-jackpot-with-rce-43755cac1415"
            }
         ],
         "Authors": ["Gokulsspace (@GokTest)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Unrestricted file upload"],
         "Bounty": "1,500",
         "PublicationDate": "2024-08-25",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "How I Got Bugs From Google Dorks",
               "Link": "https://ch44nd.medium.com/find-bugs-from-google-dorks-ec574c01471b"
            }
         ],
         "Authors": ["Chandan das"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-08-25",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Hidden in Plain Sight: Uncovering RCE on a Forgotten Axis2 Instance",
               "Link": "https://medium.com/@domenicoveneziano/hidden-in-plain-sight-uncovering-rce-on-a-forgotten-axis2-instance-86ddc91f1415"
            }
         ],
         "Authors": ["Domenico Veneziano"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Default credentials", "Axis2"],
         "Bounty": "-",
         "PublicationDate": "2024-08-23",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "How I can easily get four P1 at NASA using Simple Google Dorking.",
               "Link": "https://k4tedu.medium.com/how-i-can-easily-get-four-p1-at-nasa-using-simple-google-dorking-d4457bec1971"
            }
         ],
         "Authors": ["Francesco Topol / k4tedu"],
         "Programs": ["NASA"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-08-23",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Traccar 5 Remote Code Execution Vulnerabilities",
               "Link": "https://www.horizon3.ai/attack-research/disclosures/traccar-5-remote-code-execution-vulnerabilities/"
            }
         ],
         "Authors": ["Naveen Sunkavally"],
         "Programs": ["Traccar"],
         "Bugs": ["RCE", "Unrestricted file upload", "Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-23",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "NTLM Credential Theft in Python Windows Applications",
               "Link": "https://www.horizon3.ai/attack-research/disclosures/ntlm-credential-theft-in-python-windows-applications/"
            }
         ],
         "Authors": ["Naveen Sunkavally"],
         "Programs": ["Python", "Hugging Face (Gradio)", "Werkzeug", "Jupyter", "Snowflake (Streamlit)"],
         "Bugs": ["SSRF", "NTLMv2 hash disclosure", "NTLM", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-23",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Instagram and Meta 2FA Bypass by Unprotected Backup Code Retrieval in Accounts Center",
               "Link": "https://medium.com/@scriptshuva/instagram-and-meta-2fa-bypass-by-unprotected-backup-code-retrieval-in-accounts-center-c735ff650f10"
            }
         ],
         "Authors": ["Shuva Saha (@scriptshuva)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["2FA / MFA bypass", "Account takeover"],
         "Bounty": "10,000",
         "PublicationDate": "2024-08-22",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Vulnerabilities in Homepage Dashboard",
               "Link": "https://www.anvilsecure.com/blog/vulnerabilities-in-homepage-dashboard.html"
            }
         ],
         "Authors": ["Daniel Kachakil"],
         "Programs": ["Homepage"],
         "Bugs": ["RCE", "SSRF", "CSRF", "Information disclosure", "Jellyfin"],
         "Bounty": "-",
         "PublicationDate": "2024-08-22",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "WPML Multilingual CMS Authenticated Contributor+ Remote Code Execution (RCE) via Twig Server-Side Template Injection (SSTI)",
               "Link": "https://sec.stealthcopter.com/wpml-rce-via-twig-ssti/"
            }
         ],
         "Authors": ["Matthew Rollings (@stealthcopter)"],
         "Programs": ["Wordfence"],
         "Bugs": ["SSTI", "RCE", "Security code review"],
         "Bounty": "1,639",
         "PublicationDate": "2024-08-21",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Authorization bypass due to cache misconfiguration",
               "Link": "https://rikeshbaniya.medium.com/authorization-bypass-due-to-cache-misconfiguration-fde8b2332d2d"
            }
         ],
         "Authors": ["Rikesh Baniya (@rikeshbaniya)"],
         "Programs": ["-"],
         "Bugs": ["Authorization bypass", "Access control bypass", "GraphQL"],
         "Bounty": "2,000",
         "PublicationDate": "2024-08-21",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Google AI Studio: LLM-Powered Data Exfiltration Hits Again! Quickly Fixed.",
               "Link": "https://embracethered.com/blog/posts/2024/google-ai-studio-data-exfiltration-now-fixed/"
            }
         ],
         "Authors": ["Johann Rehberger (wunderwuzzi23)"],
         "Programs": ["Google (AI Studio)"],
         "Bugs": ["AI", "LLM", "Prompt injection"],
         "Bounty": "-",
         "PublicationDate": "2024-08-21",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "The Hunt for ALBeast: A Technical Walkthrough",
               "Link": "https://www.miggo.io/resources/uncovering-auth-vulnerability-in-aws-alb-albeast"
            }
         ],
         "Authors": ["Liad Eliyahu (@liadeliyahu)"],
         "Programs": ["AWS"],
         "Bugs": ["AWS ALB", "Authentication bypass", "Authorization bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-08-20",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "From MLOps to MLOops: Exposing the Attack Surface of Machine Learning Platforms",
               "Link": "https://jfrog.com/blog/from-mlops-to-mloops-exposing-the-attack-surface-of-machine-learning-platforms/"
            }
         ],
         "Authors": ["Ori Hollander", "Shachar Menashe", "Natan Nehorai", "Uriya Yavnieli"],
         "Programs": ["Jupyter", "Hugging Face", "MLflow", "KServe", "Seldon"],
         "Bugs": ["AI", "RCE", "XSS", "Missing authentication", "Container escape", "Malicious AI model", "Malicious datasets"],
         "Bounty": "-",
         "PublicationDate": "2024-08-20",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "SSRFing the Web with the help of Copilot Studio",
               "Link": "https://www.tenable.com/blog/ssrfing-the-web-with-the-help-of-copilot-studio"
            }
         ],
         "Authors": ["Evan Grant (@stargravy)"],
         "Programs": ["GitHub (Copilot)"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-08-20",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "$4,998 Bounty Awarded and 100,000 WordPress Sites Protected Against Unauthenticated Remote Code Execution Vulnerability Patched in GiveWP WordPress Plugin",
               "Link": "https://www.wordfence.com/blog/2024/08/4998-bounty-awarded-and-100000-wordpress-sites-protected-against-unauthenticated-remote-code-execution-vulnerability-patched-in-givewp-wordpress-plugin/"
            }
         ],
         "Authors": ["Villu Orav (@villu164)"],
         "Programs": ["Wordfence"],
         "Bugs": ["RCE", "PHP pop chain", "PHP object injection", "Security code review"],
         "Bounty": "4,998",
         "PublicationDate": "2024-08-19",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "How 1 Exposed Honeywell API Gave us Control Over an Internal Engineering System",
               "Link": "https://www.traceable.ai/blog-post/how-1-exposed-honeywell-api-gave-us-control-over-an-internal-engineering-system"
            }
         ],
         "Authors": ["Eaton Z. (@XeEaton)"],
         "Programs": ["Honeywell"],
         "Bugs": ["Missing authentication", "Information disclosure", "Broken authorization", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-08-19",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "World of SELECT-only PostgreSQL Injections: (Ab)using the filesystem",
               "Link": "http://phrack.org/issues/71/8.html#article"
            }
         ],
         "Authors": ["Maksym Vatsyk"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-08-19",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Another 1500$: CR/LF Injection",
               "Link": "https://medium.com/@a13h1/1500-cr-lf-injection-59152daaf413"
            }
         ],
         "Authors": ["Abhi Sharma (@a13h1_)"],
         "Programs": ["-"],
         "Bugs": ["CRLF injection"],
         "Bounty": "1,500",
         "PublicationDate": "2024-08-18",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "$1600 Bounty on a Main Domain",
               "Link": "https://medium.com/@debu8er/1600-bounty-on-a-main-domain-8c30557c0f64"
            }
         ],
         "Authors": ["debug (@debug50)"],
         "Programs": ["-"],
         "Bugs": ["Session fixation", "2FA / MFA bypass", "Information disclosure", "Authentication bypass", "Open redirect"],
         "Bounty": "1,600",
         "PublicationDate": "2024-08-18",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "500$ From Meta by reporting a HTMLi(Accidental Bug)",
               "Link": "https://armx64.medium.com/500-from-meta-by-reporting-a-htmli-accidental-bug-fef2e5a0f4c4"
            }
         ],
         "Authors": ["A.R Maheer"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["HTML injection"],
         "Bounty": "500",
         "PublicationDate": "2024-08-16",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Spip Preauth RCE 2024: Part 1, The Feather",
               "Link": "https://thinkloveshare.com/hacking/spip_preauth_rce_2024_part_1_the_feather/"
            }
         ],
         "Authors": ["Laluka (@TheLaluka)"],
         "Programs": ["SPIP"],
         "Bugs": ["RCE", "Code injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-16",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Forced SSO Session Fixation",
               "Link": "https://infosecwriteups.com/forced-sso-session-fixation-5d3b457b79cb"
            }
         ],
         "Authors": ["Serj Novoselov (@novoselov_s)"],
         "Programs": ["-"],
         "Bugs": ["SSO", "Session fixation", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-08-16",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess",
               "Link": "https://hacktodef.com/addressed-aws-defaults-risks-oidc-terraform-and-anonymous-to-administratoraccess"
            }
         ],
         "Authors": ["Eduard Agavriloae (@saw_your_packet)"],
         "Programs": ["AWS"],
         "Bugs": ["Cloud", "OIDC", "Terraform", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-08-15",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Oops I UDL'd it Again",
               "Link": "https://trustedsec.com/blog/oops-i-udld-it-again"
            }
         ],
         "Authors": ["Oddvar Moe (@Oddvarmoe)"],
         "Programs": ["-"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2024-08-15",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD",
               "Link": "https://cymulate.com/blog/exploiting-pta-credential-validation-in-azure-ad/"
            }
         ],
         "Authors": ["Ilan Kalendarov (@IKalendarov)", "Elad Beber"],
         "Programs": ["Microsoft (Entra ID / Azure AD)"],
         "Bugs": ["Cloud", "Privilege escalation", "Lateral movement"],
         "Bounty": "-",
         "PublicationDate": "2024-08-15",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "2FA Bypass - IDN Mischief",
               "Link": "https://shahjerry33.medium.com/2fa-bypass-idn-mischief-157f06cb6904"
            }
         ],
         "Authors": ["Jerry Shah (@Jerry)"],
         "Programs": ["-"],
         "Bugs": ["2FA / MFA bypass", "IDN homograph attack"],
         "Bounty": "-",
         "PublicationDate": "2024-08-15",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-38213: Copy2pwn Exploit Evades Windows Web Protections",
               "Link": "https://www.zerodayinitiative.com/blog/2024/8/14/cve-2024-38213-copy2pwn-exploit-evades-windows-web-protections"
            }
         ],
         "Authors": ["Peter Girnus (@gothburz)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["WebDAV"],
         "Bounty": "-",
         "PublicationDate": "2024-08-15",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Account takeover on 8 years old public program",
               "Link": "https://medium.com/@pranshux0x/account-takeover-on-8-years-old-public-program-c0c0a30cfdd2"
            }
         ],
         "Authors": ["Priyanshu Shakya (@pranshux0x)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Email verification bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-08-14",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "SCCMSecrets.py: Exploiting SCCM Policies Distribution For Credentials Harvesting, Initial Access And Lateral Movement",
               "Link": "https://www.synacktiv.com/publications/sccmsecretspy-exploiting-sccm-policies-distribution-for-credentials-harvesting-initial.html"
            }
         ],
         "Authors": ["Quentin Roland (@croco_byte)"],
         "Programs": ["-"],
         "Bugs": ["Active Directory", "SCCM"],
         "Bounty": "-",
         "PublicationDate": "2024-08-14",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Vulnerabilities in NodeJS C/C++ add-on extensions",
               "Link": "https://snyk.io/blog/nodejs-add-on-extensions/"
            }
         ],
         "Authors": ["Alessio Della Libera"],
         "Programs": ["Node.js third-party modules"],
         "Bugs": ["Memory corruption", "Memory leak", "Out-of-bounds Read", "Buffer Overflow", "Integer overflow", "DoS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-14",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "ArtiPACKED: Hacking Giants Through a Race Condition in GitHub Actions Artifacts",
               "Link": "https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/"
            }
         ],
         "Authors": ["Yaron Avital (@yaronavital)"],
         "Programs": ["GitHub", "Google (Firebase)", "Microsoft", "AWS",  "Red Hat", "Canonical (Ubuntu Adsys)", "OWASP"],
         "Bugs": ["Race condition", "CI/CD"],
         "Bounty": "-",
         "PublicationDate": "2024-08-13",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Breaking the Barrier: Admin Panel Takeover Worth $3500",
               "Link": "https://medium.com/@noob.assassin/breaking-the-barrier-admin-panel-takeover-worth-3500-78da79089ca3"
            }
         ],
         "Authors": ["Aditya Sharma (@Assass1nmarcos)"],
         "Programs": ["-"],
         "Bugs": ["Authentication bypass", "Password reset", "Information disclosure"],
         "Bounty": "3,500",
         "PublicationDate": "2024-08-13",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Front-End Frameworks: When Bypassing Built-in Sanitization Might Backfire",
               "Link": "https://www.sonarsource.com/blog/front-end-frameworks-when-bypassing-built-in-sanitization-might-backfire/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["Firefly III"],
         "Bugs": ["Client-side Path Traversal", "XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-13",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "How I Got $150 on HackerOne for My First Bug",
               "Link": "https://medium.com/@likithteki76/how-i-got-150-on-hackerone-for-my-first-bug-8af0ed515e79"
            }
         ],
         "Authors": ["Likith Teki (@likith_teki)"],
         "Programs": ["-"],
         "Bugs": ["2FA / MFA bypass"],
         "Bounty": "150",
         "PublicationDate": "2024-08-12",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-38428 Wget Vulnerability: All you need to know",
               "Link": "https://jfrog.com/blog/cve-2024-38428-wget-vuln-all-you-need-to-know/"
            }
         ],
         "Authors": ["Goni Golan"],
         "Programs": ["GNU Wget"],
         "Bugs": ["SSRF", "MiTM", "Phishing", "Data leak", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-12",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Stored XSS in LibreOffice",
               "Link": "https://bunny0417.medium.com/stored-xss-in-libreoffice-ed4ad22e0f56"
            }
         ],
         "Authors": ["Aayush kumar (@bunny_0417)"],
         "Programs": ["LibreOffice"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-08-11",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "How I got my first $13500 bounty through Parameter Polluting (HPP)",
               "Link": "https://infosecwriteups.com/how-i-got-my-first-13500-bounty-through-parameter-polluting-hpp-179666b8e8bb"
            }
         ],
         "Authors": ["rAmpancist"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "XSS"],
         "Bounty": "13,500",
         "PublicationDate": "2024-08-10",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "How i hacked NASA? at NASA VDP",
               "Link": "https://medium.com/@momos1337/how-i-hacked-nasa-bug-bounty-6975b833eb45"
            }
         ],
         "Authors": ["Fadhli Almunawar"],
         "Programs": ["NASA"],
         "Bugs": ["RCE", "Code injection"],
         "Bounty": "-",
         "PublicationDate": "2024-08-10",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!",
               "Link": "https://blog.orange.tw/2024/08/confusion-attacks-en.html"
            }
         ],
         "Authors": ["Orange Tsai (@orange_8361)"],
         "Programs": ["Apache HTTP Server", "ModSecurity", "Redmine"],
         "Bugs": ["Confusion attack", "RCE", "XSS", "Access control bypass", "Authentication bypass", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-08-09",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Bucket Monopoly: Breaching AWS Accounts Through Shadow Resources",
               "Link": "https://www.aquasec.com/blog/bucket-monopoly-breaching-aws-accounts-through-shadow-resources/"
            }
         ],
         "Authors": ["Yakir Kadkoda", "Ofek Itach", "Michael Katchinskiy"],
         "Programs": ["AWS"],
         "Bugs": ["Cloud", "RCE", "DoS", "Account takeover", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-08-09",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Git-Syncing into Trouble: Exploring Command Injection Flaws in Kubernetes",
               "Link": "https://www.akamai.com/blog/security-research/2024/aug/2024-august-kubernetes-gitsync-command-injection-defcon"
            }
         ],
         "Authors": ["Tomer Peled (@tomerpeled92)"],
         "Programs": ["Kubernetes"],
         "Bugs": ["Command injection"],
         "Bounty": "-",
         "PublicationDate": "2024-08-09",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Persistent XSS on Microsoft Bing.com by poisoning Bingbot indexing",
               "Link": "https://infosecwriteups.com/persistent-xss-vulnerability-on-microsoft-bings-video-indexing-system-a46db992ac7b"
            }
         ],
         "Authors": ["Supakiad S. (@Supakiad_Mee)"],
         "Programs": ["Microsoft (Bing)"],
         "Bugs": ["Stored XSS"],
         "Bounty": "3,000",
         "PublicationDate": "2024-08-08",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Gotta cache 'em all: bending the rules of web cache exploitation",
               "Link": "https://portswigger.net/research/gotta-cache-em-all"
            }
         ],
         "Authors": ["Martin Doyhenard (@tincho_508)"],
         "Programs": ["-"],
         "Bugs": ["Web cache poisoning", "Web cache deception"],
         "Bounty": "-",
         "PublicationDate": "2024-08-08",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Living off the VPN — Exploring VPN Post-Exploitation Techniques",
               "Link": "https://www.akamai.com/blog/security-research/2024-august-vpn-post-exploitation-techniques-black-hat"
            }
         ],
         "Authors": ["Ori David (@oridavid123)"],
         "Programs": ["Ivanti (Connect Secure)", "Fortinet (Fortigate VPN)"],
         "Bugs": ["Hardcoded secrets", "Credentials sent over unencrypted channel"],
         "Bounty": "-",
         "PublicationDate": "2024-08-07",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Exploring Anti-Phishing Measures in Microsoft 365",
               "Link": "https://certitude.consulting/blog/en/o365-anti-phishing-measures/"
            }
         ],
         "Authors": ["William Moody", "Wolfgang Ettlinger"],
         "Programs": ["Microsoft"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2024-08-07",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover",
               "Link": "https://oussamarahali.com/blog/butterfly-effect-zero-click-account-takeover/"
            }
         ],
         "Authors": ["Oussama Rahali (@ourahali)"],
         "Programs": ["-"],
         "Bugs": ["GraphQL", "IDOR", "Authentication bypass", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-08-07",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Listen to the whispers: web timing attacks that actually work",
               "Link": "https://portswigger.net/research/listen-to-the-whispers-web-timing-attacks-that-actually-work"
            }
         ],
         "Authors": ["James Kettle (@albinowax)"],
         "Programs": ["-"],
         "Bugs": ["Timing attack", "SSRF", "WAF bypass", "Reverse proxy misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2024-08-07",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Splitting the email atom: exploiting parsers to bypass access controls",
               "Link": "https://portswigger.net/research/splitting-the-email-atom"
            }
         ],
         "Authors": ["Gareth Heyes (@garethheyes)"],
         "Programs": ["-"],
         "Bugs": ["Web cache poisoning", "Web cache deception"],
         "Bounty": "-",
         "PublicationDate": "2024-08-07",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "UnOAuthorized: Privilege Elevation Through Microsoft Applications",
               "Link": "https://www.semperis.com/blog/unoauthorized-privilege-elevation-through-microsoft-applications/"
            }
         ],
         "Authors": ["Eric Woodruff (@ericonidentity)"],
         "Programs": ["Microsoft (Entra ID / Azure AD)"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-08-07",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Exploring Anti-Phishing Measures in Microsoft 365",
               "Link": "https://certitude.consulting/blog/en/o365-anti-phishing-measures/"
            }
         ],
         "Authors": ["William Moody"],
         "Programs": ["Microsoft"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2024-08-07",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Vestaboard: Exploring Broken Access Controls and Privilege Escalation",
               "Link": "https://rhinosecuritylabs.com/research/vestaboard-vulnerabilities/"
            }
         ],
         "Authors": ["Tyler Ramsbey (@Tyler_Ramsbey)"],
         "Programs": ["Vestaboard"],
         "Bugs": ["Broken Access Control", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-08-06",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Lambda Functions for Fun and Profit",
               "Link": "https://www.praetorian.com/blog/exploiting-lambda-functions-for-fun-and-profit/"
            }
         ],
         "Authors": ["Max Rattray", "Siddhant Kalgutkar"],
         "Programs": ["-"],
         "Bugs": ["Serverless", "AWS Lambda misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2024-08-06",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Github Actions Exploitation: Dependabot",
               "Link": "https://www.synacktiv.com/publications/github-actions-exploitation-dependabot"
            }
         ],
         "Authors": ["Hugo Vincent (@hugow_vincent)"],
         "Programs": ["Spring", "tRPC"],
         "Bugs": ["CI/CD", "Arbitrary code push", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-06",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Race Condition About The User Version and Ignored",
               "Link": "https://r0b0ts.medium.com/race-condition-about-the-user-version-and-ignored-c98fec642d1b"
            }
         ],
         "Authors": ["r0b0ts (@gimhyeo52126424)"],
         "Programs": ["-"],
         "Bugs": ["Payment bypass", "Race condition"],
         "Bounty": "-",
         "PublicationDate": "2024-08-06",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "My First Bug Bounty: CORS Misconfiguration",
               "Link": "https://r0b0ts.medium.com/my-first-bug-bounty-cors-misconfiguration-3e6f38835c4e"
            }
         ],
         "Authors": ["r0b0ts (@gimhyeo52126424)"],
         "Programs": ["-"],
         "Bugs": ["CORS misconfiguration"],
         "Bounty": "250",
         "PublicationDate": "2024-08-06",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "$500 for Cracking Invitation Code For Unauthorized Access & Account Takeover",
               "Link": "https://infosecwriteups.com/500-for-cracking-invitation-code-for-unauthorized-access-account-takeover-558c663fb947"
            }
         ],
         "Authors": ["Sachin Sharma"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "OTP bruteforce"],
         "Bounty": "500",
         "PublicationDate": "2024-08-06",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Government Emails at Risk: Critical Cross-Site Scripting Vulnerability in Roundcube Webmail",
               "Link": "https://www.sonarsource.com/blog/government-emails-at-risk-critical-cross-site-scripting-vulnerability-in-roundcube-webmail/"
            }
         ],
         "Authors": ["Oskar Zeino-Mahmalat"],
         "Programs": ["Roundcube"],
         "Bugs": ["XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-05",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Exploiting authorization by nonce in WordPress plugins",
               "Link": "https://nowotarski.info/wordpress-nonce-authorization/"
            }
         ],
         "Authors": ["Bartek Nowotarski"],
         "Programs": ["Wordfence"],
         "Bugs": ["RCE", "Arbitrary file upload", "SQL injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-08-05",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Unveiling Remote Code Execution in AI chatbot workflows 💵",
               "Link": "https://infosecwriteups.com/unveiling-remote-code-execution-in-ai-chatbot-workflows-3c7f633f63c3"
            }
         ],
         "Authors": ["Anurag__Verma"],
         "Programs": ["-"],
         "Bugs": ["AI", "Chatbot", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-08-05",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "CSWSH Meets LLM Chatbots",
               "Link": "https://medium.com/@r3vsh/cswsh-meets-llm-chatbots-3ab09af5ab6f"
            }
         ],
         "Authors": ["Sachin Sharma"],
         "Programs": ["-"],
         "Bugs": ["LLM", "Chatbot", "Websockets", "Cross-Site WebSocket Hijacking (CSWH)"],
         "Bounty": "-",
         "PublicationDate": "2024-08-05",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Unveiling Remote Code Execution in AI chatbot workflows 💵",
               "Link": "https://varmaanu001.medium.com/unveiling-remote-code-execution-in-ai-chatbot-workflows-3c7f633f63c3"
            }
         ],
         "Authors": ["Anurag__Verma"],
         "Programs": ["-"],
         "Bugs": ["AI", "Chatbot", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-08-05",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "AI Under Siege: Discovering and Exploiting Vulnerabilities",
               "Link": "https://sallam.gitbook.io/sec-88/bug-bounty/ai-under-siege-discovering-and-exploiting-vulnerabilities"
            }
         ],
         "Authors": ["Mosaad Sallam (@h0tak88r)", "Mohamed Walid (@L0daW)"],
         "Programs": ["-"],
         "Bugs": ["AI", "Prompt injection", "CSRF", "Markdown injection", "OAuth"],
         "Bounty": "-",
         "PublicationDate": "2024-08-05",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "How I Got Critical P2 Bug on Google VRP",
               "Link": "https://medium.com/@rhashibur75/how-i-got-critical-p2-bug-on-google-vrp-165017145af8"
            }
         ],
         "Authors": ["Kazi Hashibur Rahman"],
         "Programs": ["Google"],
         "Bugs": ["Missing authentication", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-08-04",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "No Database No Table, how do you do MSSQL Injection?",
               "Link": "https://cyku.tw/no-database-mssql-injection/"
            }
         ],
         "Authors": ["Cyku (@cyku_tw)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-08-04",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "How I Earned $469 Bounty: Bypassing Plan Restriction",
               "Link": "https://medium.com/@a13h1/how-i-earned-469-bounty-bypassing-plan-restriction-58f6d3120b6e"
            }
         ],
         "Authors": ["Abhi Sharma (@a13h1_)"],
         "Programs": ["-"],
         "Bugs": ["Privilege escalation", "Broken Access Control"],
         "Bounty": "469",
         "PublicationDate": "2024-08-04",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Auditing Atlassian Plugins, 53 0-Days Later",
               "Link": "https://cyllective.com/blog/posts/atlassian-audit-plugins"
            }
         ],
         "Authors": ["cyllective (@cyllective)"],
         "Programs": ["Atlassian"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-08-02",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Beyond the Limit: Expanding single-packet race condition with a first sequence sync for breaking the 65,535 byte limit",
               "Link": "https://flatt.tech/research/posts/beyond-the-limit-expanding-single-packet-race-condition-with-first-sequence-sync/"
            }
         ],
         "Authors": ["RyotaK (@ryotkak)"],
         "Programs": ["-"],
         "Bugs": ["Race condition"],
         "Bounty": "-",
         "PublicationDate": "2024-08-02",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "KnowBe4 RCE and LPE",
               "Link": "https://www.pentestpartners.com/security-blog/knowbe4-rce-and-lpe/"
            }
         ],
         "Authors": ["Ceri Coburn"],
         "Programs": ["KnowBe4"],
         "Bugs": ["RCE", "Local Privilege Escalation", "DLL Hijacking"],
         "Bounty": "-",
         "PublicationDate": "2024-08-02",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Pwn2Own Miami: Aveva Edge Arbitrary DLL Loading Vulnerability",
               "Link": "https://piffd0s.medium.com/pwn2own-miami-aveva-edge-arbitrary-dll-loading-vulnerability-b2d10fc7d55c"
            }
         ],
         "Authors": ["Piffd0s (@piffd0s)"],
         "Programs": ["AVEVA"],
         "Bugs": ["Arbitrary DLL loading", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-08-01",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover via Broken Authentication Workflow: Free Lifetime Streaming!",
               "Link": "https://www.praetorian.com/blog/account-takeover-via-broken-authentication-workflow-free-lifetime-streaming/"
            }
         ],
         "Authors": ["Rohan Ahuja"],
         "Programs": ["-"],
         "Bugs": ["Broken authentication", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-08-01",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "SAML Authentication Bypass Leading to Admin Panel Access",
               "Link": "https://medium.com/@0x_xnum/saml-authentication-bypass-leading-to-admin-panel-access-24f23812ed76"
            }
         ],
         "Authors": ["Ahmed Tarek"],
         "Programs": ["-"],
         "Bugs": ["SAML", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-08-01",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Plug Security Holes in React Apps That Can Lead to API Exploitation",
               "Link": "https://thenewstack.io/plug-security-holes-in-react-apps-that-can-lead-to-api-exploitation/"
            }
         ],
         "Authors": ["Eaton Z. (@XeEaton)"],
         "Programs": ["Siemens"],
         "Bugs": ["SSO", "JWT", "Broken authentication", "Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2024-07-31",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Teaching the Old .NET Remoting New Exploitation Tricks",
               "Link": "https://code-white.com/blog/teaching-the-old-net-remoting-new-exploitation-tricks/"
            }
         ],
         "Authors": ["Markus Wulftange (@mwulftange)"],
         "Programs": ["Microsoft (.NET Framework)", "Apache log4net"],
         "Bugs": [".NET Remoting"],
         "Bounty": "-",
         "PublicationDate": "2024-07-31",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Credential Disclosure in LastPass",
               "Link": "https://certitude.consulting/blog/en/credential-disclosure-in-lastpass/"
            }
         ],
         "Authors": ["Wolfgang Ettlinger"],
         "Programs": ["LastPass"],
         "Bugs": ["Clickjacking"],
         "Bounty": "-",
         "PublicationDate": "2024-07-31",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Escalating Privileges in Google Cloud via Open Groups",
               "Link": "https://www.netspi.com/blog/technical-blog/cloud-pentesting/escalating-privileges-in-google-cloud-via-open-groups/"
            }
         ],
         "Authors": ["Thomas Elling"],
         "Programs": ["Google (GCP)"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-07-31",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Interesting Business Logic Error leads to Pre-Account Takeover via Verification bypass on GoogleVRP",
               "Link": "https://medium.com/@jerryhackgather/interesting-business-logic-error-leads-to-pre-account-takeover-via-verification-bypass-on-googlevrp-d362f9469e3d"
            }
         ],
         "Authors": ["Jerry1319 (@Mdhsan19)"],
         "Programs": ["Google"],
         "Bugs": ["Account takeover", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2024-07-30",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Stealing First Party Access Token of Facebook Users: Meta Bug Bounty",
               "Link": "https://iamsaugat.medium.com/stealing-first-party-access-token-of-facebook-users-meta-bug-bounty-44b3b2e87d07"
            }
         ],
         "Authors": ["Saugat Pokharel (@saugatscript)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["OAuth", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-07-30",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "MITMing the Xbox 360 Dashboard for Fun and RCE",
               "Link": "https://landaire.net/mitming-the-xbox-360-dashboard-for-rce-and-fun/"
            }
         ],
         "Authors": ["lander (@landaire)"],
         "Programs": ["Microsoft (Xbox)"],
         "Bugs": ["MiTM", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-07-30",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-42929: Why do we need the App Container Protection",
               "Link": "https://jhftss.github.io/CVE-2023-42929-Why-Do-We-Need-The-App-Container-Protection/"
            }
         ],
         "Authors": ["Mickey Jin (@patch1t)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["TCC bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-07-30",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Oracle Retail Xstore Suite: Pre-authenticated Path Traversal",
               "Link": "https://www.synacktiv.com/advisories/oracle-retail-xstore-suite-pre-authenticated-path-traversal"
            }
         ],
         "Authors": ["Louis Wolfers (@TG91aXMK)", "Quentin Roland (@croco_byte)"],
         "Programs": ["Oracle"],
         "Bugs": ["Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-29",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Over 1 Million websites are at risk of sensitive information leakage - XSS is dead. Long live XSS",
               "Link": "https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss"
            }
         ],
         "Authors": ["Aviad Carmel (@AviadCarmel)"],
         "Programs": ["Hotjar"],
         "Bugs": ["XSS", "OAuth"],
         "Bounty": "-",
         "PublicationDate": "2024-07-29",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel",
               "Link": "https://secreltyhiddenwriteups.blogspot.com/2024/07/a-creative-way-to-get-someones-youtube.html"
            }
         ],
         "Authors": ["Cam (@SecretlyHidden1)"],
         "Programs": ["Google (Youtube)"],
         "Bugs": ["IDOR", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2024-07-29",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Bypass Plan Restriction & Get 350$ Bounty",
               "Link": "https://medium.com/@a13h1/bypass-plan-restriction-get-350-bounty-2df24f406462"
            }
         ],
         "Authors": ["Abhi Sharma (@a13h1_)"],
         "Programs": ["-"],
         "Bugs": ["Privilege escalation"],
         "Bounty": "350",
         "PublicationDate": "2024-07-29",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Drop the Mic (CVE-2019-1166)",
               "Link": "https://www.praetorian.com/blog/drop-the-mic-cve20191166/"
            }
         ],
         "Authors": ["AJ Hammond (@4JMAN)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["NTLM", "MiTM", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2024-07-29",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Unlocking the Weak Spot: Exploiting Insecure Password Reset Tokens",
               "Link": "https://sallam.gitbook.io/sec-88/bug-bounty/unlocking-the-weak-spot-exploiting-insecure-password-reset-tokens"
            }
         ],
         "Authors": ["Mosaad Sallam (@h0tak88r)"],
         "Programs": ["-"],
         "Bugs": ["Bruteforce", "Lack of rate limiting", "Password reset", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-07-28",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Jailbreak of Meta AI (Llama -3.1) revealing configuration details",
               "Link": "https://medium.com/@kiranmaraju/jailbreak-of-meta-ai-llama-3-1-revealing-configuration-details-9f0759f5006a"
            }
         ],
         "Authors": ["Kiran Maraju"],
         "Programs": ["Meta / Facebook (Llama)"],
         "Bugs": ["AI", "LLM", "Prompt injection", "LLM Jailbreak"],
         "Bounty": "-",
         "PublicationDate": "2024-07-27",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Zeroday on Github Copilot",
               "Link": "https://gccybermonks.com/posts/github/"
            }
         ],
         "Authors": ["Marlon Fabiano (@astrounder)"],
         "Programs": ["GitHub (Copilot)"],
         "Bugs": ["AI", "LLM", "Prompt injection"],
         "Bounty": "-",
         "PublicationDate": "2024-07-27",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "ElasticSearch Smash & Grab",
               "Link": "https://hogarth45.medium.com/elasticsearch-smash-grab-99cf36cdefbb"
            }
         ],
         "Authors": ["Jesse Clark (@Hogarth45_)"],
         "Programs": ["-"],
         "Bugs": ["Elasticsearch", "Information disclosure", "Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2024-07-26",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Leaking All Users Google Drive Files",
               "Link": "https://secreltyhiddenwriteups.blogspot.com/2024/07/leaking-all-users-google-drive-files.html"
            }
         ],
         "Authors": ["Cam (@SecretlyHidden1)"],
         "Programs": ["Google (Drive)"],
         "Bugs": ["Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2024-07-26",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Path Traversal and Code Execution in CSLA.NET (CVE-2024-28698)",
               "Link": "https://www.intruder.io/research/path-traversal-and-code-execution-in-csla-net-cve-2024-28698"
            }
         ],
         "Authors": ["Sam Pizzey"],
         "Programs": ["CSLA.NET"],
         "Bugs": ["Path traversal", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-25",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Gudifu: Guided Differential Fuzzing for HTTP Request Parsing Discrepancies",
               "Link": "https://spaces-cdn.owlstown.com/blobs/exmixv7d3xutvlj6ksq80zkv4mot"
            }
         ],
         "Authors": ["Bahruz Jabiyev (@BahruzJabiyev)", "Anthony Gavazzi", "Kaan Onarlioglu", "Engin Kirda"],
         "Programs": ["ATS", "Nginx", "HAProxy"],
         "Bugs": ["Web cache poisoning", "CPDoS", "HTTP request smuggling", "Access control bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-07-25",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Hacking Moodle Apps Via External Functions",
               "Link": "https://medium.com/@dub-flow/hacking-moodle-apps-via-external-functions-1fc88a6d697c"
            }
         ],
         "Authors": ["Florian Walter"],
         "Programs": ["-"],
         "Bugs": ["Broken Access Control", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-25",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Repo Jacking: The Great Source-code Swindle",
               "Link": "https://snyk.io/blog/repo-jacking-the-great-source-code-swindle/"
            }
         ],
         "Authors": ["Elliot Ward"],
         "Programs": ["Hashicorp (Terraform)", "Composer (Packagist)"],
         "Bugs": ["Repojacking"],
         "Bounty": "-",
         "PublicationDate": "2024-07-25",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Recursive Amplification Attacks: Botnet-as-a-Service",
               "Link": "https://www.praetorian.com/blog/recursive-amplification-attacks-botnet-as-a-service/"
            }
         ],
         "Authors": ["Ben Kofman", "Ryan Grunsten"],
         "Programs": ["-"],
         "Bugs": ["DDoS"],
         "Bounty": "-",
         "PublicationDate": "2024-07-24",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "ConfusedFunction: A Privilege Escalation Vulnerability Impacting GCP Cloud Functions",
               "Link": "https://www.tenable.com/blog/confusedfunction-a-privilege-escalation-vulnerability-impacting-gcp-cloud-functions"
            }
         ],
         "Authors": ["Liv Matan (@terminatorLM)"],
         "Programs": ["Google (GCP)"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-07-24",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Studying 0days: How we hacked Anki, the world's most popular flashcard app",
               "Link": "https://skii.dev/anki-0day/"
            },
            {
               "Title": "We hacked Anki - 0 day exploit from studying someone elses flashcards",
               "Link": "https://skerritt.blog/anki-0day/"
            }
         ],
         "Authors": ["Jacob", "Autumn Skerritt"],
         "Programs": ["Anki"],
         "Bugs": ["RCE", "Components with known vulnerabilities", "Arbitrary file read", "Arbitrary file write", "XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-24",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Anyone can Access Deleted and Private Repository Data on GitHub",
               "Link": "https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github"
            }
         ],
         "Authors": ["Joe Leon (@JoeLeonJr)"],
         "Programs": ["GitHub"],
         "Bugs": ["Cross Fork Object Reference (CFOR)"],
         "Bounty": "-",
         "PublicationDate": "2024-07-24",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Broken Authentication Control In GraphQL",
               "Link": "https://www.praetorian.com/blog/exploiting-broken-authentication-control-graphql/"
            }
         ],
         "Authors": ["Aleksa Zatezalo (@ZatezaloAleksa)"],
         "Programs": ["-"],
         "Bugs": ["Cloud", "GraphQL", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-07-24",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "ConfusedFunction: A Privilege Escalation Vulnerability Impacting GCP Cloud Functions",
               "Link": "https://www.tenable.com/blog/confusedfunction-a-privilege-escalation-vulnerability-impacting-gcp-cloud-functions"
            }
         ],
         "Authors": ["Liv Matan (@terminatorLM)"],
         "Programs": ["Google (GCP)"],
         "Bugs": ["Privilege escalation", "Cloud", "CI/CD"],
         "Bounty": "-",
         "PublicationDate": "2024-07-24",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "How Almost Sacrificing a University Group Project led to a Microsoft Bug Bounty",
               "Link": "https://medium.com/@pyrus369/how-almost-sacrificing-a-university-group-project-led-to-a-microsoft-bug-bounty-9801e0f8f006"
            }
         ],
         "Authors": ["Alex Bryant", "Aditya Dindi", "Eric Esquivel"],
         "Programs": ["Microsoft (GroupMe)"],
         "Bugs": ["XSS", "CSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-07-23",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "3 ways to get Remote Code Execution in Kafka UI",
               "Link": "https://github.blog/security/vulnerability-research/3-ways-to-get-remote-code-execution-in-kafka-ui/"
            }
         ],
         "Authors": ["Michael Stepankin (@artsploit)"],
         "Programs": ["Kafka UI"],
         "Bugs": ["RCE", "Insecure deserialization", "Groovy scripting", "JMX"],
         "Bounty": "-",
         "PublicationDate": "2024-07-23",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Canary Token OSS Security Audit Report (Q2 2024)",
               "Link": "https://doyensec.com/resources/Doyensec_ThinkstCanaryTokensOSS_Report_Q22024_WithRetesting.pdf"
            }
         ],
         "Authors": ["Viktor Chuchurski (@viktorot)", "Francesco Lacerenza (@lacerenza_fra)"],
         "Programs": ["Thinkst (OSS Canary Tokens)"],
         "Bugs": ["DoS", "Stored XSS", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-07-23",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Injecting Java In-memory Payloads For Post-exploitation",
               "Link": "https://www.synacktiv.com/publications/injecting-java-in-memory-payloads-for-post-exploitation.html"
            }
         ],
         "Authors": ["Clément Amic (@loadlow)", "Hugo Vincent (@hugow_vincent)"],
         "Programs": ["-"],
         "Bugs": ["Post-exploitation"],
         "Bounty": "-",
         "PublicationDate": "2024-07-23",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "NO_WILDCARD: How I discovered the Organization ID of any AWS Account",
               "Link": "https://tracebit.com/blog/no-wildcard-how-i-discovered-the-organization-id-of-any-aws-account"
            }
         ],
         "Authors": ["Sam Cox"],
         "Programs": ["AWS"],
         "Bugs": ["Information disclosure", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2024-07-22",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "I hacked a card printer software (CVE-2024-34329)",
               "Link": "https://p0pcycle.com/2024/07/21/i-hacked-a-card-printer-software/"
            }
         ],
         "Authors": ["p0pcycle"],
         "Programs": ["Entrust"],
         "Bugs": ["Local Privilege Escalation", "DLL Hijacking", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2024-07-21",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "JNDI Injection Remote Code Execution via Path Manipulation in MemoryUserDatabaseFactory",
               "Link": "https://srcincite.io/blog/2024/07/21/jndi-injection-rce-via-path-manipulation-in-memoryuserdatabasefactory.html"
            }
         ],
         "Authors": ["Steven Seeley (@steventseeley)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "JNDI Injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-21",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Information Disclosure that made me $2000 in under 5 minutes",
               "Link": "https://medium.com/@sugamdangal52/information-disclosure-that-made-me-2000-in-under-5-minutes-63e1ce00ca07"
            }
         ],
         "Authors": ["Sugam Dangal (@SugamDangal2)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "2,000",
         "PublicationDate": "2024-07-20",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "How I Found and Bypassed a Spring Boot Actuator Information Disclosure Bug",
               "Link": "https://cametom006.medium.com/how-i-found-and-bypassed-a-spring-boot-actuator-information-disclosure-bug-c4930b740a50"
            }
         ],
         "Authors": ["Fahad Faisal (@cametome006)"],
         "Programs": ["-"],
         "Bugs": ["Spring Boot", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-07-19",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Capturing Exposed AWS Keys During Dynamic Web Application Tests",
               "Link": "https://www.praetorian.com/blog/capturing-exposed-aws-keys-during-dynamic-web-application-tests/"
            }
         ],
         "Authors": ["Aleksa Zatezalo (@ZatezaloAleksa)"],
         "Programs": ["-"],
         "Bugs": ["Cloud", "Broken authorization"],
         "Bounty": "-",
         "PublicationDate": "2024-07-18",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Windows Installer, Exploiting Custom Actions",
               "Link": "https://blog.doyensec.com/2024/07/18/custom-actions.html"
            }
         ],
         "Authors": ["Adrian Denkiewicz"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-07-18",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Multi-sandwich attack with MongoDB Object ID or the scenario for real-time monitoring of web application invitations: a new use case for the sandwich attack",
               "Link": "https://www.aeth.cc/public/Article-Reset-Tolkien/multi-sandwich-article-en.html"
            }
         ],
         "Authors": ["Aethlios (@AethliosIK)"],
         "Programs": ["-"],
         "Bugs": ["Sandwich Attack"],
         "Bounty": "-",
         "PublicationDate": "2024-07-18",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Breaking Down Barriers: Exploiting Authenticated IPC Clients",
               "Link": "https://payatu.com/blog/breaking-down-barriers-exploiting-authenticated-ipc-clients/"
            }
         ],
         "Authors": ["Ajay S.K"],
         "Programs": ["-"],
         "Bugs": ["IPC client", "D-Bus", "Shared Object Injection", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-07-18",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "GitHub Actions Exploitation: Self Hosted Runners",
               "Link": "https://www.synacktiv.com/publications/github-actions-exploitation-self-hosted-runners.html"
            }
         ],
         "Authors": ["Hugo Vincent (@hugow_vincent)"],
         "Programs": ["Haskell", "Scroll"],
         "Bugs": ["CI/CD", "Self-Hosted Runner Takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-07-17",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Account Suspension Using Anonymous Posting | Facebook Bug Bounty",
               "Link": "https://ph-hitachi.medium.com/bypassing-account-suspension-using-anonymous-posting-facebook-bug-bounty-b204433c98d1"
            }
         ],
         "Authors": ["Ph.Hitachi"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["Authorization bypass"],
         "Bounty": "500",
         "PublicationDate": "2024-07-17",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Unveiling TE.0 HTTP Request Smuggling: Discovering a Critical Vulnerability in Thousands of Google Cloud Websites",
               "Link": "https://www.bugcrowd.com/blog/unveiling-te-0-http-request-smuggling-discovering-a-critical-vulnerability-in-thousands-of-google-cloud-websites/"
            }
         ],
         "Authors": ["Paolo Arnolfo (@sw33tLie)", "Guillermo Gregorio (@bsysop)", "Francesco Mariani (@_medusa_1_)"],
         "Programs": ["Google (GCP)"],
         "Bugs": ["HTTP request smuggling", "Cloud"],
         "Bounty": "8,500",
         "PublicationDate": "2024-07-17",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts",
               "Link": "https://www.wiz.io/blog/sapwned-sap-ai-vulnerabilities-ai-security"
            }
         ],
         "Authors": ["Hillai Ben-Sasson (@hillai)", "Shir Tamari (@shirtamari)", "Nir Ohfeld (@nirohfeld)", "Sagi Tzadik (@sagitz_)", "Ronen Shustin (@ronenshh)"],
         "Programs": ["SAP"],
         "Bugs": ["AI", "Cloud", "Kubernetes", "Privilege escalation", "Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2024-07-17",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – XenForo RCE Via CSRF",
               "Link": "https://ssd-disclosure.com/ssd-advisory-xenforo-rce-via-csrf/"
            }
         ],
         "Authors": ["Egidio Romano / EgiX"],
         "Programs": ["XenForo"],
         "Bugs": ["RCE", "CSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-16",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Type confusion attacks in ProseMirror editors",
               "Link": "https://blog.calif.io/p/type-confusion-attacks-in-prosemirror"
            }
         ],
         "Authors": ["Pham Van Khanh"],
         "Programs": ["Outline"],
         "Bugs": ["Type confusion", "Stored XSS", "CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-07-16",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Identity Crisis: The Curious Case of a Delinea Local Privilege Escalation Vulnerability",
               "Link": "https://www.cyberark.com/resources/threat-research-blog/identity-crisis-the-curious-case-of-a-delinea-local-privilege-escalation-vulnerability"
            }
         ],
         "Authors": ["Brenden Meeder"],
         "Programs": ["Delinea"],
         "Bugs": ["Local Privilege Escalation", "DLL Search Order Hijacking"],
         "Bounty": "-",
         "PublicationDate": "2024-07-16",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "How to Bypass Golang SSL Verification",
               "Link": "https://www.cyberark.com/resources/threat-research-blog/how-to-bypass-golang-ssl-verification"
            }
         ],
         "Authors": ["Michael Pasternak"],
         "Programs": ["-"],
         "Bugs": ["SSL verification bypass", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-15",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Encoding Differentials: Why Charset Matters",
               "Link": "https://www.sonarsource.com/blog/encoding-differentials-why-charset-matters/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-07-15",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Unauthenticated SSRF on Havoc C2 teamserver via spoofed demon agent",
               "Link": "https://blog.chebuya.com/posts/server-side-request-forgery-on-havoc-c2/"
            }
         ],
         "Authors": ["chebuya (@_chebuya)"],
         "Programs": ["Havoc C2"],
         "Bugs": ["SSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-13",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Hacking a Secure Industrial Remote Access Gateway",
               "Link": "https://blog.syss.com/posts/hacking-a-secure-industrial-remote-access-gateway/"
            }
         ],
         "Authors": ["Moritz Abrell (@moritz_abrell)"],
         "Programs": ["HMS (Ewon Cosy+)"],
         "Bugs": ["OS command injection", "XSS", "Hardcoded secrets", "Industrial system (OT)"],
         "Bounty": "-",
         "PublicationDate": "2024-07-12",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Firmware Security: Alcatel-Lucent ALE-DeskPhone",
               "Link": "https://blog.syss.com/posts/voip-deskphone-firmware-security/"
            }
         ],
         "Authors": ["Moritz Abrell (@moritz_abrell)"],
         "Programs": ["Alcatel-Lucent"],
         "Bugs": ["VoIP hacking", "Hardware hacking", "Reverse engineering", "Arbitrary file read", "TOCTOU", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-07-12",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – SonicWall SMA100 Stored XSS To RCE",
               "Link": "https://ssd-disclosure.com/ssd-advisory-sonicwall-sma100-stored-xss-to-rce/"
            }
         ],
         "Authors": ["SeongJoon Cho"],
         "Programs": ["SonicWall"],
         "Bugs": ["RCE", "OS command injection", "Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-07-12",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Bidding Like a Billionaire - Stealing NFTs With 4-Char CSTIs",
               "Link": "https://matanber.com/blog/4-char-csti"
            }
         ],
         "Authors": ["Matan Berson (@MtnBer)"],
         "Programs": ["-"],
         "Bugs": ["CSTI"],
         "Bounty": "-",
         "PublicationDate": "2024-07-11",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Chaining Three Bugs to Access All Your ServiceNow Data",
               "Link": "https://www.assetnote.io/resources/research/chaining-three-bugs-to-access-all-your-servicenow-data"
            }
         ],
         "Authors": ["Adam Kues (@hash_kitten)"],
         "Programs": ["ServiceNow"],
         "Bugs": ["RCE", "SSTI", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-11",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "A Race to the Bottom - Database Transactions Undermining Your AppSec",
               "Link": "https://blog.doyensec.com/2024/07/11/database-race-conditions.html"
            }
         ],
         "Authors": ["Viktor Chuchurski (@viktorot)"],
         "Programs": ["-"],
         "Bugs": ["Race condition"],
         "Bounty": "-",
         "PublicationDate": "2024-07-11",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Dynamics 365 Business Central - A Journey With Ups and Downs",
               "Link": "https://frycos.github.io/vulns4free/2024/07/10/dynamics-ups-and-downs.html"
            }
         ],
         "Authors": ["Florian Hauser (@frycos)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Insecure deserialization", "Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2024-07-10",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Evernote RCE: From PDF.js font-injection to All-platform Electron exposed ipcRenderer with listened BrokerBridge Remote-Code Execution",
               "Link": "https://0reg.dev/blog/evernote-rce"
            }
         ],
         "Authors": ["Patrick Peng (@retr0reg)"],
         "Programs": ["Evernote"],
         "Bugs": ["RCE", "XSS", "Electron", "Thick client"],
         "Bounty": "-",
         "PublicationDate": "2024-07-10",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "GitHub Actions Exploitation: Repo Jacking And Environment Manipulation",
               "Link": "https://www.synacktiv.com/en/publications/github-actions-exploitation-repo-jacking-and-environment-manipulation.html"
            }
         ],
         "Authors": ["Hugo Vincent (@hugow_vincent)"],
         "Programs": ["Microsoft (Azure)", "Swagger", "Google (Firebase)", "Alibaba"],
         "Bugs": ["Repojacking", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2024-07-10",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Intigriti XSS Challenge July 2024 — Finding a new DOMPurify bug",
               "Link": "https://realansgar.dev/writeups/intigriti-xss-0724/"
            }
         ],
         "Authors": ["realansgar (@realansgar)"],
         "Programs": ["DOMPurify"],
         "Bugs": ["DOM Clobbering"],
         "Bounty": "-",
         "PublicationDate": "2024-07-09",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Bypassing ACLs – IDOR exploitation via HPP",
               "Link": "https://fortbridge.co.uk/research/idor-exploitation-via-hpp-api-hacking-case-study/"
            }
         ],
         "Authors": ["Adrian Tiron (@Adrian__T)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "HTTP parameter pollution"],
         "Bounty": "-",
         "PublicationDate": "2024-07-09",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Fickle PDFs: exploiting browser rendering discrepancies",
               "Link": "https://portswigger.net/research/fickle-pdfs-exploiting-browser-rendering-discrepancies"
            }
         ],
         "Authors": ["Zakhar Fedotkin / d4d (@d4d89704243)"],
         "Programs": ["-"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2024-07-09",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Securing Developer Tools: Unpatched Code Vulnerabilities in Gogs (2/2)",
               "Link": "https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-2/"
            }
         ],
         "Authors": ["Thomas Chauchefoin (@swapgs)", "Paul Gerste"],
         "Programs": ["Gogs"],
         "Bugs": ["Path traversal", "Arbitrary file delete", "Argument injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-09",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Lessons Learned From Exposing Unusual XSS Vulnerabilities",
               "Link": "https://www.imperva.com/blog/lessons-learned-from-exposing-unusual-xss-vulnerabilities/"
            }
         ],
         "Authors": ["Ron Masas (@RonMasas)"],
         "Programs": ["Replicate", "ZoomInfo"],
         "Bugs": ["DOM XSS", "postMessage", "Chatbot"],
         "Bounty": "-",
         "PublicationDate": "2024-07-09",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-29511 – Abusing Ghostscript’s OCR device",
               "Link": "https://codeanlabs.com/blog/research/cve-2024-29511-abusing-ghostscripts-ocr-device/"
            }
         ],
         "Authors": ["Thomas Rinsma (@thomasrinsma)"],
         "Programs": ["Ghostscript"],
         "Bugs": ["Arbitrary file read", "Arbitrary file write", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-09",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Sorry, ChatGPT Is Under Maintenance: Persistent Denial of Service through Prompt Injection and Memory Attacks",
               "Link": "https://embracethered.com/blog/posts/2024/chatgpt-persistent-denial-of-service/"
            }
         ],
         "Authors": ["Johann Rehberger (wunderwuzzi23)"],
         "Programs": ["OpenAI (ChatGPT)"],
         "Bugs": ["AI", "LLM", "Prompt injection", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2024-07-08",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Shelltorch Explained: Multiple Vulnerabilities in Pytorch Model Server (Torchserve) (CVSS 9.9, CVSS 9.8) Walkthrough",
               "Link": "https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server"
            }
         ],
         "Authors": ["Gal Elbaz", "Uri Katz", "Guy Kaplan", "Avi Lumelsky"],
         "Programs": ["PyTorch", "AWS", "Google", "Meta TorchServe", "SnakeYAML"],
         "Bugs": ["AI", "LLM", "RCE", "SSRF", "Insecure deserialization", "Zip Slip attack", "Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2024-07-08",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "WhatsUp Gold SetAdminPassword Privilege Escalation (CVE-2024-5009)",
               "Link": "https://summoning.team/blog/progress-whatsup-gold-privesc-setadminpassword-cve-2024-5009/"
            }
         ],
         "Authors": ["Sina Kheirkhah (@SinSinology)"],
         "Programs": ["Progress (WhatsUp Gold)"],
         "Bugs": ["Local Privilege Escalation", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-08",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "WhatsUp Gold Pre-Auth RCE WriteDataFile Primitive (CVE-2024-4883)",
               "Link": "https://summoning.team/blog/progress-whatsup-gold-writedatafile-cve-2024-4883-rce/"
            }
         ],
         "Authors": ["Sina Kheirkhah (@SinSinology)"],
         "Programs": ["Progress (WhatsUp Gold)"],
         "Bugs": ["RCE", "Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-08",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "WhatsUp Gold Pre-Auth RCE GetFileWithoutZip Primitive (CVE-2024-4885)",
               "Link": "https://summoning.team/blog/progress-whatsup-gold-rce-cve-2024-4885/"
            }
         ],
         "Authors": ["Sina Kheirkhah (@SinSinology)"],
         "Programs": ["Progress (WhatsUp Gold)"],
         "Bugs": ["RCE", "Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-08",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Plormbing Your Prisma ORM With Time-based Attacks",
               "Link": "https://www.elttam.com/blog/plorming-your-primsa-orm/"
            }
         ],
         "Authors": ["Alex Brown"],
         "Programs": ["-"],
         "Bugs": ["ORM Leak", "ReDoS", "Timing attack"],
         "Bounty": "-",
         "PublicationDate": "2024-07-08",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "$500 for Cracking Invitation Code For Unauthorized Access & Account Takeover",
               "Link": "https://medium.com/@a13h1/500-for-cracking-invitation-code-for-unauthorized-access-account-takeover-558c663fb947"
            }
         ],
         "Authors": ["Abhi Sharma (@a13h1_)"],
         "Programs": ["-"],
         "Bugs": ["OTP bruteforce", "Account takeover"],
         "Bounty": "500",
         "PublicationDate": "2024-07-07",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Universal Code Execution by Chaining Messages in Browser Extensions",
               "Link": "https://spaceraccoon.dev/universal-code-execution-browser-extensions/"
            }
         ],
         "Authors": ["Eugene Lim (@spaceraccoonsec)"],
         "Programs": ["-"],
         "Bugs": ["Universal XSS", "SOP bypass", "postMessage", "RCE", "Browser extension hacking"],
         "Bounty": "-",
         "PublicationDate": "2024-07-07",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "From Long-Term Hacking to Instant Rewards: Finding SQLi in 3 Minutes Worth $3125",
               "Link": "https://medium.com/@gguzelkokar.mdbf15/from-long-term-hacking-to-instant-rewards-finding-sqli-in-3-minutes-worth-3125-ac36c6e950bf"
            }
         ],
         "Authors": ["Gökhan Güzelkokar (@gkhck_)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "3,125",
         "PublicationDate": "2024-07-06",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "The PDF Trojan Horse: Leveraging HTML Injection for SSRF and Internal Resource Access",
               "Link": "https://uchihamrx.medium.com/the-pdf-trojan-horse-leveraging-html-injection-for-ssrf-and-internal-resource-access-fbf69efcb33d"
            }
         ],
         "Authors": ["Abdelrhman Amin (@0xUchihamrx)"],
         "Programs": ["-"],
         "Bugs": ["HTML injection", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-07-05",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "How I Discovered Authentication Bypass That Blocks Users from Accessing the Website ?",
               "Link": "https://sayedv2.medium.com/how-i-discovered-authentication-bypass-that-blocks-users-from-accessing-the-website-93140fa180ac"
            }
         ],
         "Authors": ["Mohamed Sayed (@Sayed_v2)"],
         "Programs": ["-"],
         "Bugs": ["Application-level DoS", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-07-04",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – Foscam R4M UDTMediaServer Buffer Overflow",
               "Link": "https://ssd-disclosure.com/ssd-advisory-foscam-r4m-udtmediaserver-buffer-overflow/"
            }
         ],
         "Authors": ["Yoseop Kim"],
         "Programs": ["Foscam"],
         "Bugs": ["Buffer Overflow", "Memory corruption", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-04",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Dumping LSA secrets: a story about task decorrelation",
               "Link": "https://sensepost.com/blog/2024/dumping-lsa-secrets-a-story-about-task-decorrelation/"
            }
         ],
         "Authors": ["Aurélien Chalot (@Defte_)"],
         "Programs": ["-"],
         "Bugs": ["EDR bypass", "Windows", "Internal pentest", "Red team"],
         "Bounty": "-",
         "PublicationDate": "2024-07-03",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "A story of a nice SSRF vulnerability.",
               "Link": "https://medium.com/@oXnoOneXo/a-story-of-a-nice-ssrf-vulnerability-51e16ff6a33f"
            }
         ],
         "Authors": ["oXnoOneXo", "Ahmed Elmorsi (@0Xhunterx)"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "DNS rebinding"],
         "Bounty": "500",
         "PublicationDate": "2024-07-03",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "From AngularJS CSTI to credentials theft",
               "Link": "https://bergee.it/blog/from-angularjs-csti-to-credentials-stealing/"
            }
         ],
         "Authors": ["Bartłomiej Bergier (@_bergee_)"],
         "Programs": ["-"],
         "Bugs": ["CSTI"],
         "Bounty": "-",
         "PublicationDate": "2024-07-03",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "Self XSS + Login CSRF + OAuth = Account Takeover",
               "Link": "https://medium.com/@l_s_/self-xss-login-csrf-oauth-account-takeover-6357f3395b49"
            }
         ],
         "Authors": ["LS (@Loupreme_)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "OAuth", "Login CSRF", "Self-XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-07-02",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "From Limited file read to full access on Jenkins (CVE-2024-23897)",
               "Link": "https://xphantom.nl/posts/crypto-attack-jenkins/"
            }
         ],
         "Authors": ["Ahmed Sherif"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Arbitrary file read"],
         "Bounty": "-",
         "PublicationDate": "2024-07-02",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "The Dangers of Transition Mode",
               "Link": "https://trustedsec.com/blog/the-dangers-of-transition-mode"
            }
         ],
         "Authors": ["Michael Bond (@bond006_5)", "David Boyd (@fir3d0g)"],
         "Programs": ["-"],
         "Bugs": ["Wifi hacking"],
         "Bounty": "-",
         "PublicationDate": "2024-07-02",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Securing Developer Tools: Unpatched Code Vulnerabilities in Gogs (1/2)",
               "Link": "https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1/"
            }
         ],
         "Authors": ["Thomas Chauchefoin (@swapgs)", "Paul Gerste"],
         "Programs": ["Gogs"],
         "Bugs": ["Argument injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-02",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "RoguePuppet – A Critical Puppet Forge Supply Chain Vulnerability",
               "Link": "https://adnanthekhan.com/2024/07/02/roguepuppet-a-critical-puppet-forge-supply-chain-vulnerability/"
            }
         ],
         "Authors": ["Adnan Khan (@adnanthekhan)"],
         "Programs": ["Puppet Labs"],
         "Bugs": ["CI/CD", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2024-07-02",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Traeger Grill D2 Wi-Fi Controller, Version 2.02.04",
               "Link": "https://bishopfox.com/blog/traeger-wifi-controller-advisory"
            }
         ],
         "Authors": ["Nick Cerne"],
         "Programs": ["Traeger"],
         "Bugs": ["IoT", "Broken authorization", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-07-02",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery - Introducing CSPT2CSRF",
               "Link": "https://blog.doyensec.com/2024/07/02/cspt2csrf.html"
            }
         ],
         "Authors": ["Maxence Schmitt (@maxenceschmitt)"],
         "Programs": ["-"],
         "Bugs": ["Client-side Path Traversal", "CSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-07-02",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "Github Actions Exploitation: Untrusted Input",
               "Link": "https://www.synacktiv.com/publications/github-actions-exploitation-untrusted-input.html"
            }
         ],
         "Authors": ["Hugo Vincent (@hugow_vincent)"],
         "Programs": ["Microsoft", "Excalidraw", "FreeRDP", "Angular", "AutoGPT", "Ant-Design", "Cypress", "Apache Doris"],
         "Bugs": ["CI/CD", "Supply chain attack", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-02",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "The Dark Side of Contact Forms: How I Identified 7 CVEs in WordPress Plugins",
               "Link": "https://blog.paniago.io/the-dark-side-of-contact-forms-how-i-identified-7-cves-in-wordpress-plugins-30f6111dfebf"
            }
         ],
         "Authors": ["Pedro Paniago (@dropn0w)"],
         "Programs": ["Wordfence"],
         "Bugs": ["Blind XSS", "Stored XSS", "HTML injection"],
         "Bounty": "2,500",
         "PublicationDate": "2024-07-02",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-29510 – Exploiting Ghostscript using format strings",
               "Link": "https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation/"
            }
         ],
         "Authors": ["Thomas Rinsma (@thomasrinsma)"],
         "Programs": ["Ghostscript"],
         "Bugs": ["RCE", "Format string vulnerability", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2024-07-02",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "You Can’t Always Win Racing the (Key)cloak",
               "Link": "https://www.cyberark.com/resources/threat-research-blog/you-cant-always-win-racing-the-keycloak"
            }
         ],
         "Authors": ["Maor Abutbul"],
         "Programs": ["Keycloak"],
         "Bugs": ["Race condition", "LDAP", "Application-level DoS"],
         "Bounty": "-",
         "PublicationDate": "2024-07-01",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Vulnerabilities In CocoaPods Open The Door To Supply Chain Attacks Against Thousands Of iOS And MacOS Applications",
               "Link": "https://www.evasec.io/blog/eva-discovered-supply-chain-vulnerabities-in-cocoapods"
            }
         ],
         "Authors": ["Reef Spektor", "Eran Vaknin"],
         "Programs": ["CocoaPods"],
         "Bugs": ["RCE", "Account takeover", "Supply chain attack", "iOS", "MacOS"],
         "Bounty": "-",
         "PublicationDate": "2024-07-01",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "3 Easy cash via cache",
               "Link": "https://medium.com/@mohamed0xmuslim/3-easy-cash-via-cache-99d600565ac5"
            }
         ],
         "Authors": ["Muhammad Mostafa (@0xSekiro)"],
         "Programs": ["-"],
         "Bugs": ["Web cache deception"],
         "Bounty": "-",
         "PublicationDate": "2024-07-01",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Story of a 1000$ Open Redirect",
               "Link": "https://infosecwriteups.com/story-of-a-1000-open-redirect-1405fb8a0e7a"
            }
         ],
         "Authors": ["Debangshu Kundu (@debangshu_kundu)"],
         "Programs": ["-"],
         "Bugs": ["Open redirect"],
         "Bounty": "1,000",
         "PublicationDate": "2024-07-01",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server",
               "Link": "https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server"
            }
         ],
         "Authors": ["Qualys Threat Research Unit (TRU)"],
         "Programs": ["OpenSSH"],
         "Bugs": ["RCE", "Race condition"],
         "Bounty": "-",
         "PublicationDate": "2024-07-01",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "Getting Unauthenticated Remote Code Execution On The Logsign Unified Secops Platform",
               "Link": "https://www.zerodayinitiative.com/blog/2024/7/1/getting-unauthenticated-remote-code-execution-on-the-logsign-unified-secops-platform"
            }
         ],
         "Authors": ["Yulin Sung", "Mehmet INCE (@mdisec)"],
         "Programs": ["Logsign"],
         "Bugs": ["RCE", "Authentication bypass", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-07-01",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-27292: docAssembling exploits for RCE",
               "Link": "https://tantosec.com/blog/docassemble/"
            }
         ],
         "Authors": ["Riyush Ghimire"],
         "Programs": ["Docassemble"],
         "Bugs": ["RCE", "SSTI", "Path traversal", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-07-01",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Cache Poisoning via Unkeyed Parameters and Headers in a Drupal Application",
               "Link": "https://medium.com/@abhijithknamboothiri96/exploiting-cache-poisoning-via-unkeyed-parameters-and-headers-in-a-drupal-application-db7a49a67ed4"
            }
         ],
         "Authors": ["Abhijith Namboothiry"],
         "Programs": ["-"],
         "Bugs": ["Web cache poisoning"],
         "Bounty": "-",
         "PublicationDate": "2024-06-30",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws",
               "Link": "https://memorycorruption.net/posts/rce-lua-factorio/"
            }
         ],
         "Authors": ["Memory Corruption"],
         "Programs": ["Factorio"],
         "Bugs": ["RCE", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2024-06-29",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "Finding Hidden Threats: How I Found Leaked AWS Credentials in an Android App API Using DAST",
               "Link": "https://blog.securitybreached.org/2024/06/28/finding-hidden-threats-how-i-found-leaked-aws-credentials-in-an-android-app-api-using-dast/"
            }
         ],
         "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
         "Programs": ["-"],
         "Bugs": ["Android", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-06-28",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Inside Xerox WorkCentre: Two Unauthenticated RCEs",
               "Link": "https://swarm.ptsecurity.com/inside-xerox-workcentre-two-unauthenticated-rces/"
            }
         ],
         "Authors": ["Arseniy Sharoglazov (@_mohemiv)"],
         "Programs": ["Xerox"],
         "Bugs": ["RCE", "Local Privilege Escalation", "Printer hacking", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-06-28",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "17 vulnerabilities in Sharp Multi-Function Printers",
               "Link": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html"
            }
         ],
         "Authors": ["Pierre Kim (@PierreKimSec)"],
         "Programs": ["Sharp", "Toshiba"],
         "Bugs": ["Printer hacking", "RCE", "Information disclosure", "Memory corruption", "Buffer Overflow", "DoS", "LFI", "XSS", "Hardcoded API keys", "Default credentials", "Missing authentication", "Directory listing", "Authentication bypass", "LDAP"],
         "Bounty": "-",
         "PublicationDate": "2024-06-27",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "How I found DOM XSS via postMessage on Bing.com - Microsoft Bug Bounty",
               "Link": "https://namcoder.com/blog/how-i-found-dom-xss-on-bingcom-microsoft-bug-bounty-write-up/"
            }
         ],
         "Authors": ["Nam Le (@namcoder_com)"],
         "Programs": ["Microsoft (Bing)"],
         "Bugs": ["DOM XSS", "postMessage"],
         "Bounty": "-",
         "PublicationDate": "2024-06-27",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "When Prompts Go Rogue: Analyzing a Prompt Injection Code Execution in Vanna.AI",
               "Link": "https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/"
            }
         ],
         "Authors": ["Natan Nehorai"],
         "Programs": ["Vanna.ai"],
         "Bugs": ["AI", "LLM", "RCE", "Prompt injection"],
         "Bounty": "-",
         "PublicationDate": "2024-06-27",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Steam: Usual and Unusual Ways in the CEF Framework",
               "Link": "https://www.darknavy.org/blog/exploiting_steam_usual_and_unusual_ways_in_the_cef_framework/"
            }
         ],
         "Authors": ["DARKNAVY (@DarkNavyOrg)"],
         "Programs": ["Valve (Steam)", "Google (Chromium)"],
         "Bugs": ["Browser hacking", "Thick client", "RCE", "OS command injection", "Arbitrary file read", "Arbitrary file creation", "Components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2024-06-27",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Can I See Your “USER AGENT” Please?",
               "Link": "https://www.whiteoaksecurity.com/blog/user-agent-issue/"
            }
         ],
         "Authors": ["Joshua Platz"],
         "Programs": ["-"],
         "Bugs": ["EDR bypass", "Red team"],
         "Bounty": "-",
         "PublicationDate": "2024-06-27",
         "AddedDate": "2024-07-02"
      },
      {
         "Links": [
            {
               "Title": "How I compromised 1500 accounts/month with no technical skill",
               "Link": "https://theclemvp.medium.com/how-i-compromised-1500-accounts-month-with-no-technical-skill-6a83ecd5c8eb"
            }
         ],
         "Authors": ["Molx32"],
         "Programs": ["-"],
         "Bugs": ["Privacy issue", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-06-26",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Why nested deserialization is harmful: Magento XXE (CVE-2024-34102)",
               "Link": "https://www.assetnote.io/resources/research/why-nested-deserialization-is-harmful-magento-xxe-cve-2024-34102"
            }
         ],
         "Authors": ["Adam Kues (@hash_kitten)", "Shubham Shah (@infosec_au)"],
         "Programs": ["Magento"],
         "Bugs": ["Insecure deserialization", "XXE", "Patch diffing", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-06-26",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Looking for vulnerabilities in Strapi (CVE-2024-34065)",
               "Link": "https://blog.quarkslab.com/looking-for-vulnerabilities-in-strapi-cve-2024-34065.html"
            }
         ],
         "Authors": ["Mathieu Farrell"],
         "Programs": ["Strapi"],
         "Bugs": ["Authentication bypass", "Open redirect", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-06-25",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "How I Found a Vulnerability in Paytm and Received a Bounty",
               "Link": "https://mufazmi.medium.com/how-i-found-a-vulnerability-in-paytm-and-received-a-bounty-d580ea14e9a8"
            }
         ],
         "Authors": ["Umair Farooqui (@mufazmi)"],
         "Programs": ["Paytm"],
         "Bugs": ["XSS", "HTML injection"],
         "Bounty": "150",
         "PublicationDate": "2024-06-25",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "A Novel DoS Vulnerability affecting WebRTC Media Servers",
               "Link": "https://www.rtcsec.com/article/novel-dos-vulnerability-affecting-webrtc-media-servers/"
            }
         ],
         "Authors": ["Sandro Gauci (@sandrogauci)", "Alfred Farrugia (@alfred_farrugia)"],
         "Programs": ["-"],
         "Bugs": ["DoS", "VoIP hacking", "WebRTC"],
         "Bounty": "-",
         "PublicationDate": "2024-06-25",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032) – Overview and Mitigations",
               "Link": "https://www.wiz.io/blog/probllama-ollama-vulnerability-cve-2024-37032"
            }
         ],
         "Authors": ["Sagi Tzadik (@sagitz_)"],
         "Programs": ["Ollama"],
         "Bugs": ["AI", "RCE", "Path traversal", "Arbitrary file write"],
         "Bounty": "0",
         "PublicationDate": "2024-06-24",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Next.js and cache poisoning: a quest for the black hole",
               "Link": "https://zhero-web-sec.github.io/research-and-things/nextjs-and-cache-poisoning-a-quest-for-the-black-hole"
            }
         ],
         "Authors": ["Rachid.A (@zhero___)"],
         "Programs": ["Vercel (NextJS)"],
         "Bugs": ["Web cache poisoning"],
         "Bounty": "5,000",
         "PublicationDate": "2024-06-24",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Phantom Secrets: Undetected Secrets Expose Major Corporations",
               "Link": "https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/"
            }
         ],
         "Authors": ["Yakir Kadkoda", "Ilay Goldman (@GoldmanIlay)"],
         "Programs": ["Mozilla", "Cisco", "Git"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-06-23",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "New 100$ Bug in My Methodology!",
               "Link": "https://medium.com/@rewmcode/new-100-bug-in-my-methodology-60d99f0dafe2"
            }
         ],
         "Authors": ["Ali Rem (@khodeRewm)"],
         "Programs": ["-"],
         "Bugs": ["Application-level DoS"],
         "Bounty": "100",
         "PublicationDate": "2024-06-23",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "Plormbing Your Django ORM",
               "Link": "https://www.elttam.com/blog/plormbing-your-django-orm/"
            }
         ],
         "Authors": ["Alex Brown"],
         "Programs": ["-"],
         "Bugs": ["ORM Leak", "ReDoS"],
         "Bounty": "-",
         "PublicationDate": "2024-06-23",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Zip Slip meets Artifactory: A Bug Bounty Story",
               "Link": "https://karmainsecurity.com/zip-slip-meets-artifactory-a-bug-bounty-story"
            }
         ],
         "Authors": ["Egidio Romano"],
         "Programs": ["JFrog (Artifactory)"],
         "Bugs": ["Zip Slip attack", "Path traversal", "Security code review"],
         "Bounty": "5,000",
         "PublicationDate": "2024-06-23",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "MongoDB NoSQL Injection with Aggregation Pipelines",
               "Link": "https://soroush.me/blog/2024/06/mongodb-nosql-injection-with-aggregation-pipelines/"
            }
         ],
         "Authors": ["Soroush Dalili (@irsdl)"],
         "Programs": ["-"],
         "Bugs": ["NoSQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-06-23",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Bypassing iCloud Web Access Restriction",
               "Link": "https://ltsirkov.medium.com/bypassing-icloud-web-access-restriction-30cdf12b979c"
            }
         ],
         "Authors": ["Lyubomir Tsirkov (@lyubo_tsirkov)"],
         "Programs": ["Apple (iCloud)"],
         "Bugs": ["HTTP response manipulation", "iOS"],
         "Bounty": "-",
         "PublicationDate": "2024-06-21",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Exploiting GCP Cloud Build for Privilege Escalation",
               "Link": "https://blog.pwnedlabs.io/blog.pwnedlabs.io/exploiting-gcp-cloud-build-for-privilege-escalation"
            }
         ],
         "Authors": ["Ayush Singh (@Hac10101)"],
         "Programs": ["Google (GCP)"],
         "Bugs": ["Privilege escalation", "Cloud", "CI/CD"],
         "Bounty": "-",
         "PublicationDate": "2024-07-20",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "From a GLPI patch bypass to RCE",
               "Link": "https://sensepost.com/blog/2024/from-a-glpi-patch-bypass-to-rce/"
            }
         ],
         "Authors": ["Guilhem Rioux (@GuilhemRioux)"],
         "Programs": ["GLPI"],
         "Bugs": ["RCE", "SQL injection", "LFI", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-06-20",
         "AddedDate": "2024-08-04"
      },
      {
         "Links": [
            {
               "Title": "Teleport Security Whitepaper - Practical Analysis of and Hardening Against Compromised IdP Scenarios",
               "Link": "https://www.doyensec.com/resources/Doyensec_Whitepaper_Teleport_PracticalAnalysisHardeningAgainstCompromisedIdP.pdf"
            }
         ],
         "Authors": ["Francesco Lacerenza (@lacerenza_fra)"],
         "Programs": ["Teleport"],
         "Bugs": ["SSO"],
         "Bounty": "-",
         "PublicationDate": "2024-06-20",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Preauth RCE on NVIDIA Triton Server",
               "Link": "https://sites.google.com/site/zhiniangpeng/blogs/Triton-RCE"
            }
         ],
         "Authors": ["zhiniang peng (@edwardzpeng)"],
         "Programs": ["Nvidia"],
         "Bugs": ["AI", "RCE", "Arbitrary file write", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2024-06-19",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "IDOR on HackerOne Embedded Submission Form",
               "Link": "https://medium.com/pinoywhitehat/idor-on-hackerone-embedded-submission-form-9e59c6f044b3"
            }
         ],
         "Authors": ["Japz Divino (@japzdivino)"],
         "Programs": ["HackerOne"],
         "Bugs": ["IDOR", "GraphQL"],
         "Bounty": "2,500",
         "PublicationDate": "2024-06-19",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Sign-in with World ID: XSS and ATO via OIDC Form Post Response Mode",
               "Link": "https://security.lauritz-holtmann.de/advisories/tfh-form_post-xss-ato/"
            }
         ],
         "Authors": ["Lauritz Holtmann (@_lauritz_)"],
         "Programs": ["Tools for Humanity (Worldcoin)"],
         "Bugs": ["OIDC", "XSS", "Account takeover", "CSP bypass", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-06-19",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "Re-moo-te Code Execution in Mailcow: Always Sanitize Error Messages",
               "Link": "https://www.sonarsource.com/blog/remote-code-execution-in-mailcow-always-sanitize-error-messages/"
            }
         ],
         "Authors": ["Paul Gerste"],
         "Programs": ["Mailcow"],
         "Bugs": ["RCE", "Path traversal", "Arbitrary file overwrite", "XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-06-17",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Brand-new prototype pollution gadget in MongoDB leading to RCE",
               "Link": "https://infosecwriteups.com/brand-new-prototype-pollution-gadget-in-mongodb-leading-to-rce-8c5e0087c15e"
            }
         ],
         "Authors": ["Vuusale"],
         "Programs": ["MongoDB"],
         "Bugs": ["RCE", "Prototype pollution"],
         "Bounty": "-",
         "PublicationDate": "2024-06-17",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Cross-Site Scripting via Web Cache Poisoning and WAF bypass",
               "Link": "https://ltsirkov.medium.com/cross-site-scripting-via-web-cache-poisoning-and-waf-bypass-6cb3412d9e11"
            }
         ],
         "Authors": ["Lyubomir Tsirkov (@lyubo_tsirkov)"],
         "Programs": ["-"],
         "Bugs": ["XSS", "Web cache poisoning", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-06-17",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Mobile OAuth Attacks - iOS URL Scheme Hijacking Revamped",
               "Link": "https://evanconnelly.github.io/post/ios-oauth/"
            }
         ],
         "Authors": ["Evan Connelly (@Evan_Connelly)", "Julien Ahrens (@MrTuxracer)"],
         "Programs": ["-"],
         "Bugs": ["OAuth", "iOS", "URL scheme hijacking", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-06-17",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Iconv, Set The Charset To RCE: Exploiting The Glibc To Hack The PHP Engine (Part 2)",
               "Link": "https://www.ambionics.io/blog/iconv-cve-2024-2961-p2"
            }
         ],
         "Authors": ["Charles Fol (@cfreal_)"],
         "Programs": ["GNU C Library (glibc)"],
         "Bugs": ["RCE", "Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2024-06-17",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "ExpressionEngine, Version 7.3.15",
               "Link": "https://bishopfox.com/blog/expressionengine-v-7-3-15-vulnerability-2"
            }
         ],
         "Authors": ["Matthieu Keller"],
         "Programs": ["Packet Tide (ExpressionEngine)"],
         "Bugs": ["XSS", "Open redirect"],
         "Bounty": "-",
         "PublicationDate": "2024-06-17",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Abusing title reporting and tmux integration in iTerm2 for code execution",
               "Link": "https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html"
            }
         ],
         "Authors": ["Vin01"],
         "Programs": ["iTerm2"],
         "Bugs": ["RCE", "Escape sequence injection"],
         "Bounty": "-",
         "PublicationDate": "2024-06-16",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Discovering a CRLF Injection Vulnerability: My Journey into the MSRC Blog Website",
               "Link": "https://ibrahimxss.medium.com/discovering-a-crlf-injection-vulnerability-my-journey-into-the-msrc-blog-website-5285169adddb"
            }
         ],
         "Authors": ["Ibrahim Husić / #IbrahimXSS (@ibrahimxss_)"],
         "Programs": ["Microsoft"],
         "Bugs": ["CRLF injection"],
         "Bounty": "-",
         "PublicationDate": "2024-06-14",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Exfiltrating Data from Sandboxed Documents",
               "Link": "https://www.monke.ie/p/exfiltrating-data-from-sandboxed-documents"
            }
         ],
         "Authors": ["Monke (@pmofcats)"],
         "Programs": ["-"],
         "Bugs": ["postMessage", "DOM XSS", "CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-06-14",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "GitHub Copilot Chat: From Prompt Injection to Data Exfiltration",
               "Link": "https://embracethered.com/blog/posts/2024/github-copilot-chat-prompt-injection-data-exfiltration/"
            }
         ],
         "Authors": ["Johann Rehberger (wunderwuzzi23)"],
         "Programs": ["GitHub (Copilot Chat)"],
         "Bugs": ["LLM", "AI", "Prompt injection", "Data leak"],
         "Bounty": "-",
         "PublicationDate": "2024-06-14",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-20693: Windows cached code signature manipulation",
               "Link": "https://sector7.computest.nl/post/2024-06-cve-2024-20693-windows-cached-code-signature-manipulation/"
            }
         ],
         "Authors": ["Sector 7 (@sector7_nl)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-06-14",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "What’s in a Name? Writing custom DNS tunnelling protocol, exploiting unexpected AWS Lambda misconfiguration – in a web app Pen test (Part 1)",
               "Link": "https://labs.jumpsec.com/whats-in-a-name-writing-custom-dns-tunnelling-protocol-on-the-fly-exploiting-unexpected-aws-lambda-misconfiguration-all-in-a-web-app-pen-test-part-1/"
            },
            {
               "Title": "Part 2",
               "Link": "https://labs.jumpsec.com/whats-in-a-name-writing-custom-dns-tunnelling-protocol-exploiting-unexpected-aws-lambda-misconfiguration-in-a-web-app-pen-test-part-2/"
            }
         ],
         "Authors": ["Sunny Chau"],
         "Programs": ["-"],
         "Bugs": ["RCE", "AWS Lambda misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2024-06-13",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "How Twitch Helper Can Be Used for Privilege Escalation",
               "Link": "https://www.kandji.io/blog/twitch-privileged-helper"
            }
         ],
         "Authors": ["Christopher Lopez"],
         "Programs": ["Twitch"],
         "Bugs": ["Local Privilege Escalation", "MacOS"],
         "Bounty": "-",
         "PublicationDate": "2024-06-12",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "How I get an easy Blind SSRF by just reading writeups",
               "Link": "https://medium.com/@mohamed0xmuslim/how-i-get-an-easy-blind-ssrf-by-just-reading-writeups-a5459bbdf96d"
            }
         ],
         "Authors": ["Muhammad Mostafa (@0xSekiro)"],
         "Programs": ["-"],
         "Bugs": ["Blind SSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-06-12",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Supply Chain Attacks: A New Era",
               "Link": "https://osec.io/blog/2024-06-10-supply-chain-attacks-a-new-era"
            }
         ],
         "Authors": ["Bruno Halltari (@BrunoModificato)", "Caue Obici (@caueobici)"],
         "Programs": ["Lavamoat"],
         "Bugs": ["Supply chain attack", "Web3 hacking"],
         "Bounty": "-",
         "PublicationDate": "2024-06-10",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Super Blind SQL Injection- $20000 bounty | Thousands of targets still vulnerable",
               "Link": "https://medium.com/@pranshux0x/super-blind-sql-injection-20000-bounty-thousands-of-targets-still-vulnerable-f9b013765448"
            }
         ],
         "Authors": ["Priyanshu Shakya (@pranshux0x)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "20,000",
         "PublicationDate": "2024-06-08",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Abusing auto mail responders to access internal workplaces",
               "Link": "https://rikeshbaniya.medium.com/abusing-auto-mail-responders-to-access-internal-workplaces-04fcc8ba2c99"
            }
         ],
         "Authors": ["Rikesh Baniya (@rikeshbaniya)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw"],
         "Bounty": "1,000",
         "PublicationDate": "2024-06-08",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Zoom Session Takeover - Cookie Tossing Payloads, OAuth Dirty Dancing, Browser Permissions Hijacking, and WAF abuse",
               "Link": "https://nokline.github.io/bugbounty/2024/06/07/Zoom-ATO.html"
            }
         ],
         "Authors": ["Harel (@h4r3l)", "Sudhanshu Rajbhar (@sudhanshur705)", "Bruno Halltari (@BrunoModificato)"],
         "Programs": ["Zoom"],
         "Bugs": ["XSS", "Cookie XSS", "Cookie tossing", "OAuth Dirty Dancing", "Account takeover"],
         "Bounty": "15,000",
         "PublicationDate": "2024-06-07",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes",
               "Link": "https://modzero.com/en/blog/beyond_the_at_symbol/"
            },
            {
               "Title": "Pentest report (PDF)",
               "Link": "https://modzero.com/static/MZ-24-01_modzero_MailCleaner.pdf"
            }
         ],
         "Authors": ["Michael Imfeld", "Pascal Zenker (@parzel2)"],
         "Programs": ["MailCleaner"],
         "Bugs": ["OS command injection", "Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-06-07",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-31735: LibEvent Library Memory Leak",
               "Link": "https://www.leviathansecurity.com/blog/cve-2024-31735-libevent-library-memory-leak"
            }
         ],
         "Authors": ["Viktoriia Reitsenshtein"],
         "Programs": ["LibEvent"],
         "Bugs": ["Memory leak", "DoS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-06-06",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "These Services Shall Not Pass: Abusing Service Tags to Bypass Azure Firewall Rules (Customer Action Required)",
               "Link": "https://www.tenable.com/blog/these-services-shall-not-pass-abusing-service-tags-to-bypass-azure-firewall-rules-customer"
            }
         ],
         "Authors": ["Liv Matan (@terminatorLM)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Cloud", "WAF bypass", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-06-03",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Molding Lies Into Reality || Exploiting CVE-2024-4358",
               "Link": "https://summoning.team/blog/progress-report-server-rce-cve-2024-4358-cve-2024-1800/"
            }
         ],
         "Authors": ["Sina Kheirkhah (@SinSinology)"],
         "Programs": ["Progress (Telerik)"],
         "Bugs": ["RCE", "Insecure deserialization", "Authentication bypass", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-06-03",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "How a Single Vulnerability Can Bring Down the JavaScript Ecosystem",
               "Link": "https://www.landh.tech/blog/20240603-npm-cache-poisoning/"
            }
         ],
         "Authors": ["Roni Carta (@0xLupin)"],
         "Programs": ["GitHub (npm)"],
         "Bugs": ["Web cache poisoning", "CPDoS", "Supply chain attack"],
         "Bounty": "500",
         "PublicationDate": "2024-06-03",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-27822: macOS PackageKit Privilege Escalation",
               "Link": "https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html"
            }
         ],
         "Authors": ["Mykola Grymalyuk (@khronokernel)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["Local Privilege Escalation", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2024-06-03",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Hacking Millions of Modems (and Investigating Who Hacked My Modem)",
               "Link": "https://samcurry.net/hacking-millions-of-modems"
            }
         ],
         "Authors": ["Sam Curry (@samwcyo)"],
         "Programs": ["Cox"],
         "Bugs": ["Authorization bypass", "Cryptographic issues", "TR-069 protocol"],
         "Bounty": "-",
         "PublicationDate": "2024-06-03",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "How I Got My First €€€€ Bounty",
               "Link": "https://machiavellli.medium.com/how-i-got-my-first-bounty-65ad8a1763de"
            }
         ],
         "Authors": ["Machiavelli (@MachIaVellill)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-06-03",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "Compromising ByteDance’s Rspack using GitHub Actions Vulnerabilities",
               "Link": "https://www.praetorian.com/blog/compromising-bytedances-rspack-github-actions-vulnerabilities/"
            }
         ],
         "Authors": ["Adam Crosser", "John Stawinski"],
         "Programs": ["ByteDance (Rspack)"],
         "Bugs": ["CI/CD", "Pwn Request"],
         "Bounty": "-",
         "PublicationDate": "2024-05-31",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "Targeting an industrial protocol gateway",
               "Link": "https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway/"
            }
         ],
         "Authors": ["Claire Vacherot (@non_curat_lex)"],
         "Programs": ["HMS Networks"],
         "Bugs": ["Industrial system (OT)", "Gateway", "DoS", "Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2024-05-30",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Dumping a Database with an AI Chatbot",
               "Link": "https://www.synack.com/blog/dumping-a-database-with-an-ai-chatbot/"
            }
         ],
         "Authors": ["Kuldeep Pandya (@kuldeepdotexe)"],
         "Programs": ["-"],
         "Bugs": ["AI", "LLM", "Chatbot"],
         "Bounty": "-",
         "PublicationDate": "2024-05-30",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "Abusing the SeRelabelPrivilege",
               "Link": "https://decoder.cloud/2024/05/30/abusing-the-serelabelprivilege/"
            }
         ],
         "Authors": ["ap (@decoder_it)"],
         "Programs": ["-"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-05-30",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "Non-Production Endpoints as an Attack Surface in AWS",
               "Link": "https://securitylabs.datadoghq.com/articles/non-production-endpoints-as-an-attack-surface-in-aws/"
            }
         ],
         "Authors": ["Nick Frichette (@frichette_n)"],
         "Programs": ["AWS"],
         "Bugs": ["Cloud", "CloudTrail bypass", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-05-28",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Multiple vulnerabilities in Eclipse ThreadX",
               "Link": "https://security.humanativaspa.it/multiple-vulnerabilities-in-eclipse-threadx/"
            }
         ],
         "Authors": ["Marco Ivaldi / Raptor (@0xdea)"],
         "Programs": ["Microsoft", "Eclipse Foundation (Eclipse ThreadX)"],
         "Bugs": ["Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2024-05-28",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "A commonly overlooked XSS vector",
               "Link": "https://creds.nl/2024-07-27-overlooked-xss-vector"
            }
         ],
         "Authors": ["Robert van Hees"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-05-27",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "mXSS: The Vulnerability Hiding in Your Code",
               "Link": "https://www.sonarsource.com/blog/mxss-the-vulnerability-hiding-in-your-code/"
            }
         ],
         "Authors": ["Yaniv Nizry (@YNizry)"],
         "Programs": ["-"],
         "Bugs": ["Mutation XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-05-27",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Iconv, Set The Charset To RCE: Exploiting The Glibc To Hack The PHP Engine (Part 1)",
               "Link": "https://www.ambionics.io/blog/iconv-cve-2024-2961-p1"
            }
         ],
         "Authors": ["Charles Fol (@cfreal_)"],
         "Programs": ["GNU C Library (glibc)"],
         "Bugs": ["RCE", "Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2024-05-27",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "Cache Me If You Can: Local Privilege Escalation in Zscaler Client Connector (CVE-2023-41973)",
               "Link": "https://spaceraccoon.dev/zscaler-client-connector-local-privilege-escalation/"
            },
            {
               "Title": "ZSATrayManager Arbitrary File Deletion (CVE-2023-41969)",
               "Link": "https://medium.com/csg-govtech/catch-me-if-you-can-local-privilege-escalation-in-zscaler-client-connector-7ad997bd7058"
            }
         ],
         "Authors": ["Eugene Lim (@spaceraccoonsec)", "Winston Ho"],
         "Programs": ["Zscaler"],
         "Bugs": ["Path traversal", "Authentication bypass", "Arbitrary file delete", "DLL Hijacking", "Local Privilege Escalation", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2024-05-27",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "Old new email attacks",
               "Link": "https://blog.slonser.info/posts/email-attacks/"
            }
         ],
         "Authors": ["Vsevolod Kokorin (slonser_)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Email spoofing", "Phishing"],
         "Bounty": "-",
         "PublicationDate": "2024-05-23",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Wikimedia/svgtranslate 2.0.1 Remote Code Execution",
               "Link": "https://chocapikk.com/posts/2024/svgtranslate/"
            }
         ],
         "Authors": ["Valentin Lobstein (@Chocapikk_)"],
         "Programs": ["Wikimedia (SVGTranslate)"],
         "Bugs": ["RCE", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-05-23",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "The risk in malicious AI models: Wiz Research discovers critical vulnerability in AI-as-a-Service provider, Replicate",
               "Link": "https://www.wiz.io/blog/wiz-research-discovers-critical-vulnerability-in-replicate"
            }
         ],
         "Authors": ["Shir Tamari (@shirtamari)", "Sagi Tzadik (@sagitz_)"],
         "Programs": ["Replicate"],
         "Bugs": ["AI", "Malicious AI model", "RCE", "Lateral movement", "TCP injection"],
         "Bounty": "-",
         "PublicationDate": "2024-05-23",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "Hijacking GitHub Runners To Compromise The Organization",
               "Link": "https://www.synacktiv.com/publications/hijacking-github-runners-to-compromise-the-organization.html"
            }
         ],
         "Authors": ["Hugo Vincent (@hugow_vincent)"],
         "Programs": ["-"],
         "Bugs": ["CI/CD", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-05-22",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Getting XXE in Web Browsers using ChatGPT",
               "Link": "https://swarm.ptsecurity.com/xxe-chrome-safari-chatgpt/"
            }
         ],
         "Authors": ["Igor Sak-Sakovskiy (@Psych0tr1a)"],
         "Programs": ["Apple (Safari)", "Google (Chrome)", "libxslt"],
         "Bugs": ["XXE"],
         "Bounty": "28,000",
         "PublicationDate": "2024-05-22",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "Abusing url handling in iTerm2 and Hyper for code execution",
               "Link": "https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html"
            }
         ],
         "Authors": ["Vin01"],
         "Programs": ["iTerm2", "Vercel (Hyper)"],
         "Bugs": ["RCE", "Escape sequence injection"],
         "Bounty": "-",
         "PublicationDate": "2024-05-21",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-4367 – Arbitrary JavaScript execution in PDF.js",
               "Link": "https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/"
            }
         ],
         "Authors": ["Thomas Rinsma (@thomasrinsma)"],
         "Programs": ["Mozilla (PDF.js)"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-05-20",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "Linguistic Lumberjack: Attacking Cloud Services via Logging Endpoints (Fluent Bit - CVE-2024-4323)",
               "Link": "https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323"
            }
         ],
         "Authors": ["Jimi Sebree (@DinoBytes)"],
         "Programs": ["Cloud Native Computing Foundation (Fluent Bit)"],
         "Bugs": ["Cloud", "Memory corruption", "Buffer Overflow"],
         "Bounty": "-",
         "PublicationDate": "2024-05-20",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "How a Single Parameter Led to Two ATO Cases",
               "Link": "https://cametom006.medium.com/how-a-single-parameter-led-to-two-ato-cases-c3cf2f4d00c2"
            }
         ],
         "Authors": ["Fahad Faisal (@cametome006)"],
         "Programs": ["-"],
         "Bugs": ["OIDC", "Account takeover", "Password reset"],
         "Bounty": "-",
         "PublicationDate": "2024-05-18",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Response Filter Denial of Service (RFDoS): shut down a website by triggering WAF rule",
               "Link": "https://blog.sicuranext.com/response-filter-denial-of-service-a-new-way-to-shutdown-a-website/"
            }
         ],
         "Authors": ["Andrea Menin (@AndreaTheMiddle)"],
         "Programs": ["-"],
         "Bugs": ["DoS", "RFDoS"],
         "Bounty": "1,200",
         "PublicationDate": "2024-05-14",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "Collabora Online Stored XSS (CVE-2024-29182)",
               "Link": "https://cyllective.com/blog/posts/cve-2024-29182-collabora"
            }
         ],
         "Authors": ["cyllective (@cyllective)"],
         "Programs": ["Collabora Productivity"],
         "Bugs": ["Stored XSS", "Websockets"],
         "Bounty": "-",
         "PublicationDate": "2024-05-13",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "My LLM Bug Bounty Journey on Hugging Face Hub via Protect AI",
               "Link": "https://medium.com/@zpbrent/my-llm-bug-bounty-journey-on-hugging-face-hub-via-protect-ai-9f3a1bc72c2e"
            }
         ],
         "Authors": ["Peng Zhou"],
         "Programs": ["Hugging Face", "Protect AI"],
         "Bugs": ["LLM", "Insecure deserialization", "RCE"],
         "Bounty": "3,250",
         "PublicationDate": "2024-05-11",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Bypassing WAFs to Exploit CSPT Using Encoding Levels",
               "Link": "https://matanber.com/blog/cspt-levels"
            }
         ],
         "Authors": ["Matan Berson (@MtnBer)"],
         "Programs": ["-"],
         "Bugs": ["Client-side Path Traversal"],
         "Bounty": "-",
         "PublicationDate": "2024-05-10",
         "AddedDate": "2024-06-05"
      },
      {
         "Links": [
            {
               "Title": "POST to XSS: Leveraging Pseudo Protocols to Gain JavaScript Evaluation in SSO Flows",
               "Link": "https://security.lauritz-holtmann.de/post/sso-security-redirect-uri-iii/"
            }
         ],
         "Authors": ["Lauritz Holtmann (@_lauritz_)"],
         "Programs": ["OneLogin", "Authentik", "FusionAuth", "Keycloak", "MiniOrange / xecurify", "LemonLDAP:NG"],
         "Bugs": ["XSS", "SSO", "SAML", "OIDC", "OAuth"],
         "Bounty": "-",
         "PublicationDate": "2024-05-10",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Digging for SSRF in NextJS apps",
               "Link": "https://www.assetnote.io/resources/research/digging-for-ssrf-in-nextjs-apps"
            }
         ],
         "Authors": ["Adam Kues (@hash_kitten)", "Shubham Shah (@infosec_au)"],
         "Programs": ["Vercel (NextJS)"],
         "Bugs": ["SSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-05-09",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-21115: An Oracle Virtualbox LPE Used To Win Pwn2Own",
               "Link": "https://www.zerodayinitiative.com/blog/2024/5/9/cve-2024-21115-an-oracle-virtualbox-lpe-used-to-win-pwn2own"
            }
         ],
         "Authors": ["Cody Gallagher (@cogallag)"],
         "Programs": ["Oracle (VirtualBox)"],
         "Bugs": ["Local Privilege Escalation", "Out-of-bounds Write", "Memory corruption", "Security code review"],
         "Bounty": "20,000",
         "PublicationDate": "2024-05-09",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "How I Found XSS In Another Govt. Site :: NCIIPC VDP !!",
               "Link": "https://medium.com/@p.ra.dee.p_0xx01/how-i-found-xss-in-another-govt-site-nciipc-vdp-84d78c0319c2"
            }
         ],
         "Authors": ["Professor0xx01"],
         "Programs": ["NCIIPC"],
         "Bugs": ["XSS", "Components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2024-05-09",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "NCIIPC VDP Bug : Open Redirection Vulnerability In Govt. Site !!",
               "Link": "https://medium.com/@p.ra.dee.p_0xx01/nciipc-vdp-bug-open-redirection-vulnerability-in-govt-site-b048860f5d2d"
            }
         ],
         "Authors": ["Professor0xx01"],
         "Programs": ["NCIIPC"],
         "Bugs": ["Open redirect"],
         "Bounty": "-",
         "PublicationDate": "2024-05-09",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Hacking Apple - SQL Injection to Remote Code Execution",
               "Link": "https://blog.projectdiscovery.io/hacking-apple-with-sql-injection/"
            }
         ],
         "Authors": ["Harsh Jaiswal (@rootxharsh)", "Rahul Maini (@iamnoooob)"],
         "Programs": ["Apple", "Mura CMS", "Masa CMS"],
         "Bugs": ["SQL injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-05-08",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Exploit Archeology - Exploiting an old unknown Server Side Browser",
               "Link": "https://blog.ajxchapman.com/posts/2024/05/08/exploit-archeology.html"
            }
         ],
         "Authors": ["Alex Chapman (@ajxchapman)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2024-05-08",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Relative Path File Injection: The Next Evolution in RPO",
               "Link": "https://blog.ionatomics.org/2024/05/08/relative-path-file-injection-the-next-evolution-in-rpo/"
            }
         ],
         "Authors": ["Ian Hickey"],
         "Programs": ["-"],
         "Bugs": ["Relative Path Overwrite (RPO)", "Relative Path File Injection (RPFI)"],
         "Bounty": "-",
         "PublicationDate": "2024-05-08",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "AWS CloudQuarry: Digging For Secrets In Public AMIs",
               "Link": "https://securitycafe.ro/2024/05/08/aws-cloudquarry-digging-for-secrets-in-public-amis/"
            }
         ],
         "Authors": ["Eduard Agavriloae (@saw_your_packet)", "Matei Josephs"],
         "Programs": ["AWS"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-05-08",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Lethal Injection: How We Hacked Microsoft's Healthcare Chat Bot",
               "Link": "https://www.breachproof.net/blog/lethal-injection-how-we-hacked-microsoft-ai-chat-bot"
            }
         ],
         "Authors": ["Yanir Tsarimi (@Yanir_)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Chatbot", "Sandbox escape", "Cross-tenant vulnerability", "RCE", "Memory leak"],
         "Bounty": "203,000",
         "PublicationDate": "2024-05-07",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "TunnelVision (CVE-2024-3661): How Attackers Can Decloak Routing-Based VPNs For a Total VPN Leak",
               "Link": "https://www.leviathansecurity.com/blog/tunnelvision"
            }
         ],
         "Authors": ["Lizzie Moratti (@MorattiSec)", "Dani Cronce"],
         "Programs": ["-"],
         "Bugs": ["Decloaking attack", "DHCP", "Privacy issue", "VPN"],
         "Bounty": "-",
         "PublicationDate": "2024-05-06",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "The Monsters in Your Build Cache – GitHub Actions Cache Poisoning",
               "Link": "https://adnanthekhan.com/2024/05/06/the-monsters-in-your-build-cache-github-actions-cache-poisoning/"
            }
         ],
         "Authors": ["Adnan Khan (@adnanthekhan)"],
         "Programs": ["Google"],
         "Bugs": ["CI/CD", "Supply chain attack"],
         "Bounty": "1,000",
         "PublicationDate": "2024-05-06",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "LLM Pentest: Leveraging Agent Integration For RCE",
               "Link": "https://www.blazeinfosec.com/post/llm-pentest-agent-hacking/"
            }
         ],
         "Authors": ["Pedro Henrique Lima"],
         "Programs": ["-"],
         "Bugs": ["LLM", "Prompt leaking", "Prompt injection", "RCE", "Code injection"],
         "Bounty": "-",
         "PublicationDate": "2024-05-06",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Crypto bounty program got me $500 — Rate Limit Bypass",
               "Link": "https://mo9khu93r.medium.com/crypto-bounty-program-got-me-500-rate-limit-bypass-d573f7b7d390"
            }
         ],
         "Authors": ["mo9khu93r"],
         "Programs": ["Kraken"],
         "Bugs": ["Rate limiting bypass"],
         "Bounty": "500",
         "PublicationDate": "2024-05-06",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Send()-ing Myself Belated Christmas Gifts - GitHub.com's Environment Variables & GHES Shell",
               "Link": "https://starlabs.sg/blog/2024/04-sending-myself-github-com-environment-variables-and-ghes-shell/"
            }
         ],
         "Authors": ["Ngo Wei Lin (@Creastery)"],
         "Programs": ["GitHub"],
         "Bugs": ["RCE", "Unsafe reflection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-05-06",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Lateral movement and on-prem NT hash dumping with Microsoft Entra Temporary Access Passes",
               "Link": "https://dirkjanm.io/lateral-movement-and-hash-dumping-with-temporary-access-passes-microsoft-entra/"
            }
         ],
         "Authors": ["Dirk-jan Mollema (@_dirkjan)"],
         "Programs": ["Microsoft (Entra ID / Azure AD)"],
         "Bugs": ["Lateral movement", "Persistence", "Post-exploitation"],
         "Bounty": "-",
         "PublicationDate": "2024-05-06",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Real World GitLab Account Take Over",
               "Link": "https://medium.com/@red.whisperer/real-world-gitlab-account-take-over-b2e9896a1835"
            }
         ],
         "Authors": ["Chux (@chux13786509)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2024-05-04",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Devfile file write vulnerability in GitLab",
               "Link": "https://gitlab-com.gitlab.io/gl-security/security-tech-notes/security-research-tech-notes/devfile/"
            }
         ],
         "Authors": ["joernchen (@joernchen)"],
         "Programs": ["GitLab"],
         "Bugs": ["Path traversal", "Arbitrary file write", "RCE", "Parser diffentials"],
         "Bounty": "-",
         "PublicationDate": "2024-05-03",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "20 Security Issues Found in Xiaomi Devices",
               "Link": "https://blog.oversecured.com/20-Security-Issues-Found-in-Xiaomi-Devices/"
            }
         ],
         "Authors": ["Oversecured (@OversecuredInc)"],
         "Programs": ["Xiaomi"],
         "Bugs": ["Android", "OS command injection", "Insecure intent", "XSS", "Memory corruption", "Hardcoded private key", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-05-02",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Poppin shells with Okta Verify on Windows",
               "Link": "https://www.securifera.com/blog/2024/05/02/okta-verify-for-windows-remote-code-execution-cve-2024-0980/"
            }
         ],
         "Authors": ["b0yd (@rwincey)"],
         "Programs": ["Okta"],
         "Bugs": ["RCE", "DLL Hijacking", "Local Privilege Escalation"],
         "Bounty": "13,337",
         "PublicationDate": "2024-05-02",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Why sneak when you can walk through the front door – A Love letter to Password Spraying against M365 in Red Team Engagements",
               "Link": "https://labs.jumpsec.com/why-sneak-when-you-can-walk-through-the-front-door/"
            }
         ],
         "Authors": ["Sunny Chau"],
         "Programs": ["-"],
         "Bugs": ["Password spraying", "Red team"],
         "Bounty": "-",
         "PublicationDate": "2024-05-02",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-2887: A Pwn2Own Winning Bug In Google Chrome",
               "Link": "https://www.zerodayinitiative.com/blog/2024/5/2/cve-2024-2887-a-pwn2own-winning-bug-in-google-chrome"
            }
         ],
         "Authors": ["Manfred Paul (@_manfp)"],
         "Programs": ["Google (Chrome)", "Microsoft (Edge)"],
         "Bugs": ["V8 JavaScript engine", "WebAssembly", "JS sandbox breakout", "Browser hacking", "Memory corruption", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-05-02",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "R-bitrary Code Execution: Vulnerability In R’s Deserialization (CVE-2024-27322)",
               "Link": "https://hiddenlayer.com/research/r-bitrary-code-execution/"
            }
         ],
         "Authors": ["Kasimir Schulz (@Abraxus7331)", "Kieran Evans (@KieranEvans89)"],
         "Programs": ["R"],
         "Bugs": ["Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2024-04-29",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Code Injection to RCE with .NET",
               "Link": "https://blog.stratumsecurity.com/2024/04/29/code-injection-to-rce-with-net/"
            }
         ],
         "Authors": ["Phil Thomas"],
         "Programs": ["-"],
         "Bugs": ["Code injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-04-29",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Full Disclosure: A Look at a Recently Patched Microsoft Graph Logging Bypass - GraphNinja",
               "Link": "https://trustedsec.com/blog/full-disclosure-a-look-at-a-recently-patched-microsoft-graph-logging-bypass-graphninja"
            }
         ],
         "Authors": ["nyxgeek (@nyxgeek)"],
         "Programs": ["Microsoft (Microsoft Graph)"],
         "Bugs": ["Password spraying", "Broken authentication"],
         "Bounty": "-",
         "PublicationDate": "2024-04-29",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "How I was able to discover ATO Via IDOR vulnerability",
               "Link": "https://medium.com/@0x_xnum/idor-leads-to-account-takeover-of-all-users-ato-27af312c8481"
            }
         ],
         "Authors": ["Ahmed Tarek"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-04-28",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "How A Blackbox Target Turned To Whitebox With Recon",
               "Link": "https://medium.com/@red.whisperer/how-a-blackbox-target-turned-to-whitebox-with-recon-e46536672702"
            }
         ],
         "Authors": ["Chux (@chux13786509)"],
         "Programs": ["-"],
         "Bugs": ["Docker Registry"],
         "Bounty": "-",
         "PublicationDate": "2024-04-27",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Found Multiple Bugs :: XSS, MITM, Sec-MisConf :: In a GOVT Educational Site",
               "Link": "https://medium.com/@p.ra.dee.p_0xx01/found-multiple-bugs-xss-mitm-sec-misconf-in-an-educational-site-5a3804085da0"
            }
         ],
         "Authors": ["Professor0xx01"],
         "Programs": ["-"],
         "Bugs": ["XSS", "MiTM", "Components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2024-04-26",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Arbitrary 1-click Azure tenant takeover via MS application",
               "Link": "https://falconforce.nl/arbitrary-1-click-azure-tenant-takeover-via-ms-application/"
            }
         ],
         "Authors": ["Arnau Ortega"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Cloud", "Privilege escalation", "Cross-tenant vulnerability", "Phishing"],
         "Bounty": "-",
         "PublicationDate": "2024-04-26",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Local Privilege Escalation Vulnerability in Ant Media Server (CVE-2024-32656)",
               "Link": "https://www.praetorian.com/blog/local-privilege-escalation-vulnerability-ant-media-server-cve202432656/"
            }
         ],
         "Authors": ["Adam Crosser"],
         "Programs": ["Ant Media"],
         "Bugs": ["Local Privilege Escalation", "JMX"],
         "Bounty": "-",
         "PublicationDate": "2024-04-26",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-21111 – Local Privilege Escalation in Oracle VirtualBox",
               "Link": "https://www.mdsec.co.uk/2024/04/cve-2024-21111-local-privilege-escalation-in-oracle-virtualbox/"
            }
         ],
         "Authors": ["Filip Dragovic (@filip_dragovic)"],
         "Programs": ["Oracle (VirtualBox)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-04-25",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Hello: I’m your Domain Admin and I want to authenticate against you",
               "Link": "https://decoder.cloud/2024/04/24/hello-im-your-domain-admin-and-i-want-to-authenticate-against-you/"
            }
         ],
         "Authors": ["ap (@decoder_it)"],
         "Programs": ["Microsoft"],
         "Bugs": ["RCE", "Privilege escalation", "Authentication coercion", "Active Directory", "NTLM", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2024-04-24",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "So I Became A Node: Exploiting Bootstrap Tokens In Azure Kubernetes Service",
               "Link": "https://www.synacktiv.com/publications/so-i-became-a-node-exploiting-bootstrap-tokens-in-azure-kubernetes-service.html"
            }
         ],
         "Authors": ["Paul Barbé", "Kévin Schouteeten (@Scouty__)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Kubernetes", "Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-04-23",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Deno: Digging Tunnels out of a JS Sandbox",
               "Link": "https://secfault-security.com/blog/deno.html"
            }
         ],
         "Authors": ["finn", "lx", "olli"],
         "Programs": ["Deno"],
         "Bugs": ["V8 JavaScript engine", "JS sandbox breakout"],
         "Bounty": "-",
         "PublicationDate": "2024-04-23",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-26465 - Breaking Through XSS Filters in Pega Platform",
               "Link": "https://www.secforce.com/blog/cve-2023-26465-breaking-through-xss-filters-in-pega-platform/"
            }
         ],
         "Authors": ["Maciej Piechota (@haqpl)", "Adam Simuntis (@adamsimuntis)"],
         "Programs": ["PEGA"],
         "Bugs": ["Markdown XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-04-22",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Dependency Confusion Vulnerability Found in an Archived Apache Project",
               "Link": "https://www.legitsecurity.com/blog/dependency-confusion-vulnerability-found-in-an-archived-apache-project"
            }
         ],
         "Authors": ["Ofek Haviv"],
         "Programs": ["Apache"],
         "Bugs": ["Dependency confusion"],
         "Bounty": "-",
         "PublicationDate": "2024-04-22",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "How i Find Database Credentials via Mass Recon & Recon Scoping on Gcash",
               "Link": "https://ph-hitachi.medium.com/how-i-find-database-credentials-via-mass-recon-recon-scoping-on-gcash-f43a0dae3ec1"
            }
         ],
         "Authors": ["Ph.Hitachi"],
         "Programs": ["Globe Telecom (Gcash)"],
         "Bugs": ["Information disclosure", "File disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-04-22",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "BlackBerry MDM Has Some Authentication Flaws",
               "Link": "https://emptynebuli.github.io/tooling/2024/04/22/blackberryMDM.html"
            }
         ],
         "Authors": ["Matt Burch (@emptynebuli)"],
         "Programs": ["BlackBerry"],
         "Bugs": ["Android", "Hardcoded API keys", "Username enumeration"],
         "Bounty": "-",
         "PublicationDate": "2024-04-22",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Unsecured Content Provider leads to Account Takeover",
               "Link": "https://medium.com/@ahmedelmorsy312/unsecure-content-provider-led-to-account-takeover-1e45d716bd7c"
            }
         ],
         "Authors": ["Ahmed Elmorsi (@0Xhunterx)"],
         "Programs": ["-"],
         "Bugs": ["Android", "Account takeover", "Improper Export of Android Application Components"],
         "Bounty": "-",
         "PublicationDate": "2024-04-20",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "How i Manage to Get Sensitive Informations via docker image",
               "Link": "https://ph-hitachi.medium.com/how-i-hacked-globe-gcash-services-and-manage-to-get-access-on-multiple-databases-including-ssh-9ca781348e8f"
            }
         ],
         "Authors": ["Ph.Hitachi"],
         "Programs": ["Globe Telecom (Gcash)"],
         "Bugs": ["Information disclosure", "Hardcoded credentials"],
         "Bounty": "-",
         "PublicationDate": "2024-04-18",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM",
               "Link": "https://labs.nettitude.com/blog/cve-2024-20356-jailbreaking-a-cisco-appliance-to-run-doom/"
            }
         ],
         "Authors": ["Aaron Thacker (@thackeraaron)"],
         "Programs": ["Cisco"],
         "Bugs": ["BIOS", "Jailbreaking"],
         "Bounty": "-",
         "PublicationDate": "2024-04-18",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Element Android CVE-2024-26131, CVE-2024-26132 - Never Take Intents From Strangers",
               "Link": "https://www.shielder.com/blog/2024/04/element-android-cve-2024-26131-cve-2024-26132-never-take-intents-from-strangers/"
            }
         ],
         "Authors": ["TheZero (@Th3Zer0)", "suidpit (@suidpit)"],
         "Programs": ["Element"],
         "Bugs": ["Intent redirection", "Insecure intent", "Android"],
         "Bounty": "-",
         "PublicationDate": "2024-04-18",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Taking over accounts in multiple ways",
               "Link": "https://vict0ni.me/taking-over-accounts-in-multiple-ways/"
            }
         ],
         "Authors": ["vict0ni (@vict0ni)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "IDOR", "XSS", "Sandwich Attack", "Password reset"],
         "Bounty": "-",
         "PublicationDate": "2024-04-17",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Exploiting American Conquest",
               "Link": "https://www.synacktiv.com/en/publications/exploiting-american-conquest.html"
            }
         ],
         "Authors": ["Thomas Dubier (@tomtombinary)"],
         "Programs": ["-"],
         "Bugs": ["Reverse engineering", "Buffer Overflow", "Memory corruption", "Game hacking"],
         "Bounty": "-",
         "PublicationDate": "2024-04-16",
         "AddedDate": "2024-05-13"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster",
               "Link": "https://rhinosecuritylabs.com/research/cve-2024-2448-kemp-loadmaster/"
            }
         ],
         "Authors": ["David Yesland (@daveysec)"],
         "Programs": ["Progress (Kemp LoadMaster)"],
         "Bugs": ["OS command injection", "CSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-04-16",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "LeakyCLI: AWS and Google Cloud Command-Line Tools Can Expose Sensitive Credentials in Build Logs",
               "Link": "https://orca.security/resources/blog/leakycli-aws-google-cloud-command-line-tools-can-expose-sensitive-credentials-build-logs/"
            }
         ],
         "Authors": ["Roi Nisimi (@roinisimi)"],
         "Programs": ["AWS", "Google (GCP)"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-04-16",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Dangerous Import: SourceForge Patches Critical Code Vulnerability",
               "Link": "https://www.sonarsource.com/blog/dangerous-import-sourceforge-patches-critical-code-vulnerability"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["SourceForge", "Apache Allura"],
         "Bugs": ["Arbitrary file read", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-04-16",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Fixing Typos And Breaching Microsoft’s Perimeter",
               "Link": "https://johnstawinski.com/2024/04/15/fixing-typos-and-breaching-microsofts-perimeter/"
            }
         ],
         "Authors": ["John Stawinski", "Adnan Khan (@adnanthekhan)"],
         "Programs": ["Microsoft"],
         "Bugs": ["RCE", "CI/CD", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2024-04-15",
         "AddedDate": "2024-05-13"
      },
      {
         "Links": [
            {
               "Title": "An Obscure Actions Workflow Vulnerability in Google’s Flank",
               "Link": "https://adnanthekhan.com/2024/04/15/an-obscure-actions-workflow-vulnerability-in-googles-flank/"
            }
         ],
         "Authors": ["Adnan Khan (@adnanthekhan)"],
         "Programs": ["Google"],
         "Bugs": ["CI/CD", "Supply chain attack"],
         "Bounty": "7,500",
         "PublicationDate": "2024-04-15",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Amplified exposure: How AWS flaws made Amplify IAM roles vulnerable to takeover (CVE-2024-28056)",
               "Link": "https://securitylabs.datadoghq.com/articles/amplified-exposure-how-aws-flaws-made-amplify-iam-roles-vulnerable-to-takeover/"
            }
         ],
         "Authors": ["Nick Frichette (@frichette_n)"],
         "Programs": ["AWS"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-04-13",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "How Did I Easily Find Stored XSS at Apple And Earn $5000 ?",
               "Link": "https://medium.com/@xrypt0/how-did-i-easily-find-stored-xss-at-apple-and-earn-5000-3aadbae054b2"
            }
         ],
         "Authors": ["Crypto (@xryptc)"],
         "Programs": ["Apple"],
         "Bugs": ["Stored XSS"],
         "Bounty": "5,000",
         "PublicationDate": "2024-04-13",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "Hack ZTE router's admin panel",
               "Link": "https://websec.nl/blog/hack-zte-routers-admin-panel-66190e773cc251453bda7a0c"
            }
         ],
         "Authors": ["Zhassulan Zhussupov"],
         "Programs": ["ZTE"],
         "Bugs": ["Bruteforce"],
         "Bounty": "-",
         "PublicationDate": "2024-04-12",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Why you shouldn't use a commercial VPN: Amateur hour with Windscribe",
               "Link": "https://gergelykalman.com/why-you-shouldnt-use-a-commercial-vpn-amateur-hour-with-windscribe.html"
            }
         ],
         "Authors": ["Gergely Kalman (@gergely_kalman)"],
         "Programs": ["Windscribe"],
         "Bugs": ["Local Privilege Escalation", "Race condition"],
         "Bounty": "-",
         "PublicationDate": "2024-04-12",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Using E-Notation to bypass Access Control restrictions to access arbitrary user PII-discussions",
               "Link": "https://medium.com/@keizobugbounty/using-e-notation-to-bypass-access-control-restrictions-to-access-arbitrary-user-pii-discussions-1fa014b544d4"
            }
         ],
         "Authors": ["Keizo (@KeiZo_Zo)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2024-04-12",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "CreateRCE — Yet Another Vulnerability in CreateUri",
               "Link": "https://www.akamai.com/blog/security-research/2024/apr/critical-vulnerability-create-uri-remote-code-execution"
            }
         ],
         "Authors": ["Ben Barnea (@nachoskrnl)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["RCE", "Parsing issue"],
         "Bounty": "-",
         "PublicationDate": "2024-04-12",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "How i Almost got 2K$ through a Race condition",
               "Link": "https://medium.com/@0x3adly/how-i-almost-got-2k-through-a-race-condition-3b09232b3a25"
            }
         ],
         "Authors": ["Anas Eladly (@0xanas_eladly)"],
         "Programs": ["-"],
         "Bugs": ["Race condition"],
         "Bounty": "-",
         "PublicationDate": "2024-04-12",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "BatBadBut: You can't securely execute commands on Windows",
               "Link": "https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/"
            }
         ],
         "Authors": ["RyotaK (@ryotkak)"],
         "Programs": ["PHP", "Node.js", "Rust", "Haskell", "yt-dlp"],
         "Bugs": ["OS command injection", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2024-04-09",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "The Fast and the Curious: Finding a Race Condition in Worldcoin",
               "Link": "https://medium.com/@gonzo-hacks/the-fast-and-the-curious-finding-a-race-condition-in-worldcoin-621c89bfbd61"
            }
         ],
         "Authors": ["Dane Sherrets (@DaneSherrets)"],
         "Programs": ["Tools for Humanity (Worldcoin)"],
         "Bugs": ["Race condition", "Web3 hacking"],
         "Bounty": "3,000",
         "PublicationDate": "2024-04-08",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Hacking Swisscom’s End-to-End Encrypted Cloud Storage for $4,000",
               "Link": "https://www.thomashouhou.com/post/logic-vulnerabilities-swisscom-e2ee-cloud-storage"
            }
         ],
         "Authors": ["Thomas Houhou (@Th0h0)"],
         "Programs": ["Swisscom"],
         "Bugs": ["Password reset", "Security code review"],
         "Bounty": "4,000",
         "PublicationDate": "2024-04-08",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Google AI Studio Data Exfiltration via Prompt Injection - Possible Regression and Fix",
               "Link": "https://embracethered.com/blog/posts/2024/google-aistudio-mass-data-exfil/"
            }
         ],
         "Authors": ["Johann Rehberger (wunderwuzzi23)"],
         "Programs": ["Google (AI Studio)"],
         "Bugs": ["LLM", "AI", "Prompt injection", "Data leak"],
         "Bounty": "-",
         "PublicationDate": "2024-04-07",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "How we escalated a DOM XSS to a sophisticated 1-click Account Takeover for $8000 - Part 1",
               "Link": "https://thefrogsec.github.io/2024/04/06/How-we-escalated-a-DOM-XSS-to-a-sophisticated-1-click-Account-Takeover-for-8000-Part-1/"
            },
            {
               "Title": "Part 2",
               "Link": "https://thefrogsec.github.io/2024/04/06/How-we-escalated-a-DOM-XSS-to-a-sophisticated-1-click-Account-Takeover-for-8000-Part-2/"
            }
         ],
         "Authors": ["Benasin (@Benasin3)", "LongTheShrimp (@LongShrimp0812)"],
         "Programs": ["-"],
         "Bugs": ["DOM XSS", "Account takeover", "OAuth"],
         "Bounty": "8,000",
         "PublicationDate": "2024-04-06",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Race Condition Authentication Bypass leads to Full Account Takeover",
               "Link": "https://medium.com/@keizobugbounty/race-condition-authentication-bypass-leads-to-full-account-takeover-6b5c9bc0a54d"
            }
         ],
         "Authors": ["Keizo (@KeiZo_Zo)"],
         "Programs": ["-"],
         "Bugs": ["Race condition", "Authentication bypass", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-04-05",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Galactical Bug Hunting: How we discovered new issues in CD Projekt Red’s Gaming Platform",
               "Link": "https://www.anvilsecure.com/blog/galactical-bug-hunting-how-we-discovered-new-issues-in-cd-projekt-reds-gaming-platform.html"
            }
         ],
         "Authors": ["Lautaro Fain (@LautaroFain)"],
         "Programs": ["GOG"],
         "Bugs": ["Local Privilege Escalation", "DoS", "Arbitrary file overwrite"],
         "Bounty": "-",
         "PublicationDate": "2024-04-04",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Wiz Research finds architecture risks that may compromise AI-as-a-Service providers and consequently risk customer data; works with Hugging Face on mitigations",
               "Link": "https://www.wiz.io/blog/wiz-and-hugging-face-address-risks-to-ai-infrastructure"
            }
         ],
         "Authors": ["Shir Tamari (@shirtamari)", "Sagi Tzadik (@sagitz_)"],
         "Programs": ["Hugging Face"],
         "Bugs": ["AI", "Malicious AI model", "Cloud", "CI/CD", "RCE", "Insecure deserialization", "Privilege escalation", "Supply chain attack", "Cross-tenant vulnerability"],
         "Bounty": "200",
         "PublicationDate": "2024-04-04",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "HTTP/2 CONTINUATION Flood: Technical Details",
               "Link": "https://nowotarski.info/http2-continuation-flood-technical-details/"
            }
         ],
         "Authors": ["Bartek Nowotarski"],
         "Programs": ["Golang", "Node.js", "Apache Tomcat", "Apache HTTP Server", "Apache Traffic Server", "IBM (WebSphere)", "Mozilla (Thunderbird)", "Envoy", "Tempesta FW", "H2 (Rust crate)", "CERT/CC"],
         "Bugs": ["HTTP/2 CONTINUATION Flood", "DDoS"],
         "Bounty": "-",
         "PublicationDate": "2024-04-03",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Oauth Misconfiguration Leads to 0-Click ATO",
               "Link": "https://medium.com/@mohamed0xmuslim/oauth-misconfiguration-leads-to-0-click-ato-b407fe05fdf4"
            }
         ],
         "Authors": ["Muhammad Mostafa (@0xSekiro)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Authentication bypass", "OAuth"],
         "Bounty": "-",
         "PublicationDate": "2024-04-02",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Bypassing DOMPurify with good old XML",
               "Link": "https://flatt.tech/research/posts/bypassing-dompurify-with-good-old-xml/"
            }
         ],
         "Authors": ["RyotaK (@ryotkak)"],
         "Programs": ["DOMPurify"],
         "Bugs": ["WAF bypass", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-04-01",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Apache Dubbo Consumer Risks: The Road Not Taken",
               "Link": "https://www.sonarsource.com/blog/apache-dubbo-consumer-risks/"
            }
         ],
         "Authors": ["Yaniv Nizry (@YNizry)"],
         "Programs": ["Apache Dubbo"],
         "Bugs": ["Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-04-01",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Kobold Letters - Why HTML emails are a risk to your organization",
               "Link": "https://lutrasecurity.com/en/articles/kobold-letters/"
            }
         ],
         "Authors": ["Konstantin Weddige"],
         "Programs": ["Mozilla (Thunderbird)", "Microsoft (Outlook)", "Google (Gmail)"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2024-03-31",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Unsecure time-based secret and Sandwich Attack - Analysis of my research and release of the “Reset Tolkien” tool",
               "Link": "https://www.aeth.cc/public/Article-Reset-Tolkien/secret-time-based-article-en.html"
            }
         ],
         "Authors": ["Aethlios (@AethliosIK)"],
         "Programs": ["-"],
         "Bugs": ["Sandwich Attack"],
         "Bounty": "-",
         "PublicationDate": "2024-03-29",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "From ChatBot To SpyBot: ChatGPT Post Exploitation",
               "Link": "https://www.imperva.com/blog/from-chatbot-to-spybot-chatgpt-post-exploitation/"
            }
         ],
         "Authors": ["Ron Masas (@RonMasas)"],
         "Programs": ["OpenAI (ChatGPT)"],
         "Bugs": ["AI", "LLM", "XSS", "Data exfiltration", "Post-exploitation"],
         "Bounty": "-",
         "PublicationDate": "2024-03-28",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Imperva SecureSphere WAF (CVE-2023-50969)",
               "Link": "https://www.hoyahaxa.com/2024/03/imperva-waf-bypass-cve-2023-50969.html"
            }
         ],
         "Authors": ["Brian (@hoyahaxa)"],
         "Programs": ["Imperva"],
         "Bugs": ["WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-03-27",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "1500$: CR/LF Injection",
               "Link": "https://medium.com/@a13h1/1500-cr-lf-injection-0d2a75f02ef3"
            }
         ],
         "Authors": ["Abhi Sharma (@a13h1_)"],
         "Programs": ["-"],
         "Bugs": ["CRLF injection"],
         "Bounty": "1,500",
         "PublicationDate": "2024-03-23",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Pwn Dat Domain: Becoming Domain Admin With A Little Help From Veeam Backup",
               "Link": "https://www.blazeinfosec.com/post/leveraging-veeam-to-become-domain-admin/"
            }
         ],
         "Authors": ["Roberto Soares (@espreto)"],
         "Programs": ["-"],
         "Bugs": ["Active Directory", "Red team", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2024-03-22",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "From Discovery to Disclosure: ReCrystallize Server Vulnerabilities",
               "Link": "https://sensepost.com/blog/2024/from-discovery-to-disclosure-recrystallize-server-vulnerabilities/"
            }
         ],
         "Authors": ["Paul van der Haas (@PvdH)"],
         "Programs": ["ReCrystallize Software"],
         "Bugs": ["Default credentials", "LFI", "Authentication bypass", "Privilege escalation", "Unrestricted file upload", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-03-22",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "FlowFixation: AWS Apache Airflow Service Takeover Vulnerability and Why Neglecting Guardrails Puts Major CSPs at Risk",
               "Link": "https://www.tenable.com/blog/flowfixation-aws-apache-airflow-service-takeover-vulnerability-and-why-neglecting-guardrails"
            }
         ],
         "Authors": ["Liv Matan (@terminatorLM)"],
         "Programs": ["AWS", "Microsoft (Azure)", "Google (GCP)"],
         "Bugs": ["Cloud", "Account takeover", "RCE", "Cookie tossing", "Session fixation"],
         "Bounty": "-",
         "PublicationDate": "2024-03-21",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "OpenStack Admin Account Takeover due to Unsafe Environment Handling in MuranoPL",
               "Link": "https://sites.google.com/site/zhiniangpeng/blogs/Openstack"
            }
         ],
         "Authors": ["zhiniang peng (@edwardzpeng)"],
         "Programs": ["Openstack"],
         "Bugs": ["Account takeover", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2024-03-21",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "Micro Services, Major Headaches: Detecting Vulnerabilities in Erxes' Microservices",
               "Link": "https://www.sonarsource.com/blog/micro-services-major-headaches-detecting-vulnerabilities-in-erxes-microservices/"
            }
         ],
         "Authors": ["Paul Gerste"],
         "Programs": ["Erxes"],
         "Bugs": ["RCE", "Path traversal", "Authentication bypass", "Arbitrary file overwrite", "GraphQL", "SSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-03-21",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "The story of exposed service, SSRF, CSP bypass and credentials stealing via XSS",
               "Link": "https://bergee.it/blog/the-story-of-exposed-service-ssrf-csp-bypass-and-credentials-stealing-via-xss/"
            }
         ],
         "Authors": ["Bartłomiej Bergier (@_bergee_)"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "HTML injection", "CSP bypass", "XSS"],
         "Bounty": "200",
         "PublicationDate": "2024-03-20",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Bypassing an IDOR A couple of times — $$$$",
               "Link": "https://medium.com/@bxrowski0x/bypassing-an-idor-a-couple-of-times-4d67555a1545"
            }
         ],
         "Authors": ["Omar ElSayed (@bxrowski0x)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "2,000",
         "PublicationDate": "2024-03-20",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "DOM Purify - untrusted Node bypass",
               "Link": "https://blog.slonser.info/posts/dompurify-node-type-confusion/"
            }
         ],
         "Authors": ["Vsevolod Kokorin (slonser_)"],
         "Programs": ["DOMPurify"],
         "Bugs": ["WAF bypass", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-03-19",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Making desync attacks easy with TRACE",
               "Link": "https://portswigger.net/research/trace-desync-attack"
            }
         ],
         "Authors": ["Martin Doyhenard (@tincho_508)"],
         "Programs": ["-"],
         "Bugs": ["Desync attack", "HTTP request smuggling", "Web cache poisoning"],
         "Bounty": "-",
         "PublicationDate": "2024-03-19",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Java Deserialization Tricks",
               "Link": "https://www.synacktiv.com/en/publications/java-deserialization-tricks.html"
            }
         ],
         "Authors": ["Clément Amic (@loadlow)"],
         "Programs": ["-"],
         "Bugs": ["Insecure deserialization", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-03-19",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-1212: Unauthenticated Command Injection In Progress Kemp LoadMaster",
               "Link": "https://rhinosecuritylabs.com/research/cve-2024-1212unauthenticated-command-injection-in-progress-kemp-loadmaster/"
            }
         ],
         "Authors": ["David Yesland (@daveysec)"],
         "Programs": ["Progress (Kemp LoadMaster)"],
         "Bugs": ["OS command injection", "RCE", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2024-03-19",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "TP-Link TDDP Buffer Overflow Vulnerability",
               "Link": "https://boschko.ca/tp-link-tddp-bof/"
            }
         ],
         "Authors": ["Olivier Laflamme (@olivier_boschko)"],
         "Programs": ["TP-Link"],
         "Bugs": ["Reverse engineering", "Buffer Overflow", "Memory corruption", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2024-03-19",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Broken access control in GoAnywhere Admin portal",
               "Link": "https://blog.viettelcybersecurity.com/authentication-bypass-in-goanywhere-admin-portal/"
            }
         ],
         "Authors": ["Vu Chi Thanh"],
         "Programs": ["Fortra (GoAnywhere)"],
         "Bugs": ["Broken Access Control", "Privilege escalation", "Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-03-18",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Subdomain Fuzzing worth 35k bounty!",
               "Link": "https://medium.com/@HX007/subdomain-fuzzing-worth-35k-bounty-daebcb56d9bc"
            }
         ],
         "Authors": ["Abdullah Nawaf / HX007", "Orwa Atyat (@GodfatherOrwa)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Authentication bypass", "SQL injection"],
         "Bounty": "35,000",
         "PublicationDate": "2024-03-18",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "How did we find the same vulnerability in 9 Android Apps",
               "Link": "https://medium.com/@ahmedelmorsy312/how-did-we-find-the-same-vulnerability-in-9-android-apps-caca254a5ba9"
            }
         ],
         "Authors": ["Ahmed Elmorsi (@0Xhunterx)"],
         "Programs": ["-"],
         "Bugs": ["Android", "Insecure deeplink"],
         "Bounty": "-",
         "PublicationDate": "2024-03-15",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762",
               "Link": "https://www.assetnote.io/resources/research/two-bytes-is-plenty-fortigate-rce-with-cve-2024-21762"
            }
         ],
         "Authors": ["Dylan Pindur"],
         "Programs": ["Fortinet"],
         "Bugs": ["RCE", "Out-of-bounds Write", "Memory corruption", "Patch diffing"],
         "Bounty": "-",
         "PublicationDate": "2024-03-15",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "I Love Lucee: Building Lucee Extensions for Remote Code Execution",
               "Link": "https://www.sprocketsecurity.com/resources/building-lucee-extensions-for-remote-code-execution"
            }
         ],
         "Authors": ["Will Vandevanter", "Juan Pablo Gomez Postigo"],
         "Programs": ["-"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-03-15",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Security Flaws within ChatGPT Ecosystem Allowed Access to Accounts On Third-Party Websites and Sensitive Data",
               "Link": "https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data"
            }
         ],
         "Authors": ["Aviad Carmel (@AviadCarmel)"],
         "Programs": ["OpenAI (ChatGPT)", "PluginLab.AI", "KesemAI"],
         "Bugs": ["AI", "LLM", "Account takeover", "OAuth"],
         "Bounty": "-",
         "PublicationDate": "2024-03-13",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Discovering Deserialization Gadget Chains in Rubyland",
               "Link": "https://blog.includesecurity.com/2024/03/discovering-deserialization-gadget-chains-in-rubyland/"
            }
         ],
         "Authors": ["Alex Leahu"],
         "Programs": ["-"],
         "Bugs": ["Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2024-03-13",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "New Google Gemini Vulnerability Enabling Profound Misuse",
               "Link": "https://hiddenlayer.com/research/new-google-gemini-content-manipulation-vulns-found/#Overview"
            }
         ],
         "Authors": ["Kenneth Yeung"],
         "Programs": ["Google (Gemini)"],
         "Bugs": ["AI", "LLM", "LLM Jailbreak", "Indirect Prompt Injection", "Prompt leaking"],
         "Bounty": "-",
         "PublicationDate": "2024-03-12",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "The Art of Intrusion: File Upload Bypass & WAF XSS Evasion in AWS S3 Demystified",
               "Link": "https://laburity.com/file-upload-bypass-waf-xss/"
            }
         ],
         "Authors": ["Laburity Research Team"],
         "Programs": ["-"],
         "Bugs": ["XSS", "File upload", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-03-12",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "CRLF Injection Shenanigans",
               "Link": "https://moopinger.github.io/blog/crlf/injection/2024/03/12/CRLF-Injection-Shenanigans.html"
            }
         ],
         "Authors": ["Moopinger (@moopinger)"],
         "Programs": ["-"],
         "Bugs": ["CRLF injection"],
         "Bounty": "-",
         "PublicationDate": "2024-03-12",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "OpenOlat - XML external entity (XXE) injection (CVE-2024-28198)",
               "Link": "https://secfault-security.com/blog/openolat-xxe.html"
            }
         ],
         "Authors": ["Maik"],
         "Programs": ["OpenOlat"],
         "Bugs": ["XXE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-03-12",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Reply to calc: The Attack Chain to Compromise Mailspring",
               "Link": "https://www.sonarsource.com/blog/reply-to-calc-the-attack-chain-to-compromise-mailspring/"
            }
         ],
         "Authors": ["Yaniv Nizry (@YNizry)"],
         "Programs": ["Mailspring"],
         "Bugs": ["Mutation XSS", "RCE", "Electron", "CSS exfiltration"],
         "Bounty": "-",
         "PublicationDate": "2024-03-11",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-21378 — Remote Code Execution in Microsoft Outlook",
               "Link": "https://www.netspi.com/blog/technical/red-team-operations/microsoft-outlook-remote-code-execution-cve-2024-21378/"
            }
         ],
         "Authors": ["Rich Wolferd", "Nick Landers (@monoxgas)"],
         "Programs": ["Microsoft (Outlook)"],
         "Bugs": ["RCE", "Code injection"],
         "Bounty": "-",
         "PublicationDate": "2024-03-11",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Securing the Computer Security Course: Discovering a Session Hijacking Vulnerability in EPFL's COM-301 Website",
               "Link": "https://www.thomashouhou.com/post/vulnerability-in-epfl-computer-security-course"
            }
         ],
         "Authors": ["Thomas Houhou (@Th0h0)"],
         "Programs": ["EPFL"],
         "Bugs": ["Session management issue"],
         "Bounty": "-",
         "PublicationDate": "2024-03-10",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Hacking My ISP Part 1: Exposing a Critical Bug Allowing SIM Swapping",
               "Link": "https://izn0u.github.io/2024/03/07/Hacking-My-ISP-Part-1.html"
            }
         ],
         "Authors": ["izn0u (@izn0u)"],
         "Programs": ["-"],
         "Bugs": ["Missing authentication"],
         "Bounty": "15,000",
         "PublicationDate": "2024-03-07",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "Source Code Disclosure in ASP.NET apps",
               "Link": "https://swarm.ptsecurity.com/source-code-disclosure-in-asp-net-apps/"
            }
         ],
         "Authors": ["Arseniy Sharoglazov (@_mohemiv)"],
         "Programs": ["-"],
         "Bugs": ["Source code disclosure", "ASP.NET"],
         "Bounty": "-",
         "PublicationDate": "2024-03-07",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-36049: Microsoft .NET CRLF Injection Arbitrary File Write/deletion Vulnerability",
               "Link": "https://www.zerodayinitiative.com/blog/2024/3/6/cve-2023-36049-microsoft-net-crlf-injection-arbitrary-file-writedeletion-vulnerability"
            }
         ],
         "Authors": ["Justin Hung", "Yazhi Wang", "Piotr Bazydło (@chudyPB)"],
         "Programs": ["Microsoft (.NET Framework, Visual Studio)"],
         "Bugs": ["CRLF injection", "FTP"],
         "Bounty": "-",
         "PublicationDate": "2024-03-06",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Angular-ing for AuthZ, Problematic anti-patterns in Single Sign On Systems",
               "Link": "https://www.traceable.ai/blog-post/angular-ing-for-authz-problematic-anti-patterns-in-single-sign-on-systems"
            }
         ],
         "Authors": ["Traceable ASPEN"],
         "Programs": ["-"],
         "Bugs": ["SSO", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-03-05",
         "AddedDate": "2024-09-18"
      },
      {
         "Links": [
            {
               "Title": "Security Implications of net/textproto.Reader Misuse",
               "Link": "https://nowotarski.info/golang-textproto-reader/"
            }
         ],
         "Authors": ["Bartek Nowotarski (@bartn_)"],
         "Programs": ["Golang"],
         "Bugs": ["Out Of Memory crash", "Memory leak", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-03-05",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Breaking SIP With Apple-signed Packages",
               "Link": "https://www.l3harris.com/newsroom/editorial/2024/03/breaking-sip-apple-signed-packages"
            }
         ],
         "Authors": ["Michael Cowell"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["SIP bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-03-04",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "$20,300 Bounties from a 200 Hour Hacking Challenge",
               "Link": "https://blog.voorivex.team/20300-bounties-from-a-200-hour-hacking-challenge"
            }
         ],
         "Authors": ["Mohammad Zaheri (@mzaherii)", "Mohammad Nikouei (@NikoueiMohammad)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "Information disclosure", "Stored XSS", "IDOR", "File disclosure"],
         "Bounty": "20,300",
         "PublicationDate": "2024-03-04",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-27198 and CVE-2024-27199: JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities",
               "Link": "https://www.rapid7.com/blog/post/2024/03/04/etr-cve-2024-27198-and-cve-2024-27199-jetbrains-teamcity-multiple-authentication-bypass-vulnerabilities-fixed/"
            }
         ],
         "Authors": ["Rapid7"],
         "Programs": ["JetBrains (TeamCity)"],
         "Bugs": ["Authentication bypass", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-03-04",
         "AddedDate": "2024-07-22"
      },
      {
         "Links": [
            {
               "Title": "We Hacked Google A.I. for $50,000",
               "Link": "https://www.landh.tech/blog/20240304-google-hack-50000/"
            }
         ],
         "Authors": ["Roni Carta (@0xLupin)"],
         "Programs": ["Google"],
         "Bugs": ["LLM", "AI", "GraphQL", "DoS", "IDOR", "CSP bypass"],
         "Bounty": "50,000",
         "PublicationDate": "2024-03-04",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "OpenNMS Vulnerabilities: Securing Code against Attackers’ Unexpected Ways",
               "Link": "https://www.sonarsource.com/blog/opennms-vulnerabilities-securing-code-against-attackers-unexpected-ways/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["OpenNMS"],
         "Bugs": ["XSS", "OS command injection", "SNMP", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-29",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Judge0 Sandbox Escape",
               "Link": "https://tantosec.com/blog/judge0/"
            }
         ],
         "Authors": ["Daniel Cooper"],
         "Programs": ["Judge0"],
         "Bugs": ["Sandbox escape", "SSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-29",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Bypassing a login page and getting full admin access on an internal training platform",
               "Link": "https://medium.com/@l_s_/bypassing-a-login-page-and-getting-full-admin-access-on-an-internal-training-platform-ff5abd88135e"
            }
         ],
         "Authors": ["LS (@Loupreme_)"],
         "Programs": ["-"],
         "Bugs": ["Authentication bypass", "Broken Access Control", "HTTP response manipulation", "Directory listing"],
         "Bounty": "-",
         "PublicationDate": "2024-02-28",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "MeshCentral Cross-Site Websocket Hijacking Vulnerability (CVE-2024-26135)",
               "Link": "https://www.praetorian.com/blog/meshcentral-cross-site-websocket-hijacking-vulnerability/"
            }
         ],
         "Authors": ["Adam Crosser"],
         "Programs": ["MeshCentral"],
         "Bugs": ["Cross-Site WebSocket Hijacking (CSWH)"],
         "Bounty": "-",
         "PublicationDate": "2024-02-28",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Hacking Terraform State for Privilege Escalation",
               "Link": "https://blog.plerion.com/hacking-terraform-state-privilege-escalation/"
            }
         ],
         "Authors": ["Daniel Grzelak (@dagrz)"],
         "Programs": ["-"],
         "Bugs": ["Privilege escalation", "Terraform"],
         "Bounty": "-",
         "PublicationDate": "2024-02-28",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Leaking ObjRefs to Exploit HTTP .NET Remoting",
               "Link": "https://code-white.com/blog/leaking-objrefs-to-exploit-http-dotnet-remoting/"
            }
         ],
         "Authors": ["Markus Wulftange (@mwulftange)"],
         "Programs": ["Microsoft (.NET Framework)"],
         "Bugs": ["Information disclosure","RCE", ".NET Remoting", "ASP.NET", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-27",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "How I hacked into Google’s internal corporate assets",
               "Link": "https://observationsinsecurity.com/2024/04/25/how-i-hacked-into-googles-internal-corporate-assets/"
            }
         ],
         "Authors": ["Michael Hyndman"],
         "Programs": ["Google"],
         "Bugs": ["Dependency confusion", "RCE", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2024-02-25",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Exploiting embedded mitel phones for unauthenticated remote code execution",
               "Link": "https://baldur.dk/blog/embedded-mitel-exploitation.html"
            }
         ],
         "Authors": ["Kevin Joensen (@ggisx)"],
         "Programs": ["Mitel"],
         "Bugs": ["RCE", "Reverse engineering", "Buffer Overflow", "Memory corruption", "Authentication bypass", "OS command injection"],
         "Bounty": "-",
         "PublicationDate": "2024-02-25",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Hello: I’m your ADCS server and I want to authenticate against you",
               "Link": "https://decoder.cloud/2024/02/26/hello-im-your-adcs-server-and-i-want-to-authenticate-against-you/"
            }
         ],
         "Authors": ["ap (@decoder_it)"],
         "Programs": ["-"],
         "Bugs": ["ADCS", "Authentication coercion", "Active Directory Privilege Escalation", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2024-02-25",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "How I Got $5,000 for Out-of-Scope XSS",
               "Link": "https://7odamoo.medium.com/how-i-got-5-000-for-out-of-scope-xss-f96938a8c561"
            }
         ],
         "Authors": ["Mahmoud Hamed (@7odamo_)"],
         "Programs": ["-"],
         "Bugs": ["CORS misconfiguration", "Self-XSS", "Samesite cookie bypass"],
         "Bounty": "5,000",
         "PublicationDate": "2024-02-25",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "From CRLF Injection to XSS: Elevating the Stakes in Apple iTunes Security",
               "Link": "https://xelkomy.medium.com/from-crlf-injection-to-xss-elevating-the-stakes-in-apple-itunes-security-597dc435fd82"
            }
         ],
         "Authors": ["Khaled Mohamed (@0xElkomy)"],
         "Programs": ["Apple (iTunes)"],
         "Bugs": ["CRLF injection", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-02-24",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Go Go XSS Gadgets: Chaining a DOM Clobbering Exploit in the Wild",
               "Link": "https://buer.haus/2024/02/23/go-go-xss-gadgets-chaining-a-dom-clobbering-exploit-in-the-wild/"
            }
         ],
         "Authors": ["Brett Buerhaus (@bbuerhaus)", "Sam Curry (@samwcyo)", "Maik Robert (@xEHLE_)"],
         "Programs": ["-"],
         "Bugs": ["DOM Clobbering", "XSS", "postMessage", "CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-02-23",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Defeating Length Filters to Dump the Database - SQLi",
               "Link": "https://kuldeep.io/posts/defeating-length-filters-to-dump-the-database-sqli/"
            }
         ],
         "Authors": ["Kuldeep Pandya (@kuldeepdotexe)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-02-23",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "How Automation Detected Default Admin Credential Worth $500",
               "Link": "https://vijetareigns.medium.com/how-automation-detected-default-admin-credential-worth-500-d6c09719d307"
            }
         ],
         "Authors": ["the_unluck_guy (@7he_unlucky_guy)"],
         "Programs": ["-"],
         "Bugs": ["Default credentials"],
         "Bounty": "500",
         "PublicationDate": "2024-02-23",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "SCCM Hierarchy Takeover with High Availability",
               "Link": "https://posts.specterops.io/sccm-hierarchy-takeover-with-high-availability-7dcbd3696b43"
            }
         ],
         "Authors": ["Garrett Foster (@garrfoster)"],
         "Programs": ["-"],
         "Bugs": ["SCCM site takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-02-22",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – TP-LINK NCXXX Authentication Bypass",
               "Link": "https://ssd-disclosure.com/ssd-advisory-tp-link-ncxxx-authentication-bypass/"
            }
         ],
         "Authors": ["-"],
         "Programs": ["TP-Link"],
         "Bugs": ["Authentication bypass", "Stack overflow", "Memory corruption", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-22",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Hijacking Safetensors Conversion On Hugging Face",
               "Link": "https://hiddenlayer.com/research/silent-sabotage/"
            }
         ],
         "Authors": ["Eoin Wickens (@enwckns)", "Kasimir Schulz (@Abraxus7331)"],
         "Programs": ["Hugging Face"],
         "Bugs": ["Malicious AI model", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2024-02-21",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Continuing the Citrix Saga: CVE-2023-5914 & CVE-2023-6184",
               "Link": "https://www.assetnote.io/resources/research/continuing-the-citrix-saga-cve-2023-5914-cve-2023-6184"
            }
         ],
         "Authors": ["Dylan Pindur", "Shubham Shah (@infosec_au)", "Adam Kues (@hash_kitten)"],
         "Programs": ["Citrix Systems"],
         "Bugs": ["Reflected XSS", "SSO", "RCE", ".NET Remoting", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-20",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Nom for Security: A Proactive Security Review of Nomulus",
               "Link": "https://bughunters.google.com/blog/5294234841776128/nom-for-security-a-proactive-security-review-of-nomulus"
            }
         ],
         "Authors": ["Sam Erb (@erbbysam)", "Justin Taft"],
         "Programs": ["Google (Nomulus)"],
         "Bugs": ["Insecure deserialization", "Verbose logging", "Information disclosure", "Cryptographic issues", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-02-20",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Joomla: PHP Bug Introduces Multiple XSS Vulnerabilities (CVE-2024-21726)",
               "Link": "https://www.sonarsource.com/blog/joomla-multiple-xss-vulnerabilities/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["Joomla!"],
         "Bugs": ["XSS", "Regex", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-20",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Security Vulnerabilities in Apex Code Could Leak Salesforce Data",
               "Link": "https://www.varonis.com/blog/apex-code-vulnerabilities"
            }
         ],
         "Authors": ["Nitay Bachrach"],
         "Programs": ["-"],
         "Bugs": ["Salesforce", "SOQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-02-20",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "XSS Marks the Spot: Digging Up Vulnerabilities in ChatGPT",
               "Link": "https://www.imperva.com/blog/xss-marks-the-spot-digging-up-vulnerabilities-in-chatgpt/"
            }
         ],
         "Authors": ["Ron Masas (@RonMasas)"],
         "Programs": ["OpenAI (ChatGPT)"],
         "Bugs": ["AI", "LLM", "XSS", "CSP bypass", "Samesite cookie bypass", "Mass assignment"],
         "Bounty": "-",
         "PublicationDate": "2024-02-19",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "CSP bypass on PortSwigger.net using Google script resources",
               "Link": "https://joaxcar.com/blog/2024/02/19/csp-bypass-on-portswigger-net-using-google-script-resources/"
            }
         ],
         "Authors": ["Johan Carlsson (@joaxcar)"],
         "Programs": ["PortSwigger"],
         "Bugs": ["CSP bypass"],
         "Bounty": "1,500",
         "PublicationDate": "2024-02-19",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Tableau Server - There Ain't No Vulns",
               "Link": "https://frycos.github.io/vulns4free/2024/02/19/tableau-server-no-vulns.html"
            }
         ],
         "Authors": ["Florian Hauser (@frycos)"],
         "Programs": ["Salesforce (Tableau)"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-02-19",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Cross Window Forgery: A Web Attack Vector",
               "Link": "https://www.paulosyibelo.com/2024/02/cross-window-forgery-web-attack-vector.html"
            }
         ],
         "Authors": ["Paulos Yibelo (@PaulosYibelo)"],
         "Programs": ["-"],
         "Bugs": ["Cross Window Forgery", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-02-18",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "weird bug using fake id via photoshop worth $***",
               "Link": "https://hamzadzworm.medium.com/weird-bug-using-fake-id-via-photoshop-worth-1fe5dbd04497"
            }
         ],
         "Authors": ["Abdelkader Mouaz (@hamzadzworm)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw", "HTML injection"],
         "Bounty": "-",
         "PublicationDate": "2024-02-17",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Hacking the Dutch Government",
               "Link": "https://medium.com/@jackson_80133/hacking-the-dutch-government-153678a191c0"
            }
         ],
         "Authors": ["Jackson"],
         "Programs": ["Dutch Government"],
         "Bugs": ["Path traversal", "40x bypass", "Nginx misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2024-02-17",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Cache Deception Without Path Confusion",
               "Link": "https://kuldeep.io/posts/web-cache-deception-without-path-confusion/"
            }
         ],
         "Authors": ["Kuldeep Pandya (@kuldeepdotexe)"],
         "Programs": ["-"],
         "Bugs": ["Web cache deception"],
         "Bounty": "-",
         "PublicationDate": "2024-02-16",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Hacking Microsoft and Wix with Keyboard Shortcuts",
               "Link": "https://www.imperva.com/blog/hacking-microsoft-and-wix-with-keyboard-shortcuts/"
            }
         ],
         "Authors": ["Ron Masas (@RonMasas)"],
         "Programs": ["Microsoft", "Wix"],
         "Bugs": ["Stored XSS", "SSO", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-02-15",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Hello Lucee! Let us hack Apple again?",
               "Link": "https://blog.projectdiscovery.io/hello-lucee-let-us-hack-apple-again/"
            }
         ],
         "Authors": ["Harsh Jaiswal (@rootxharsh)", "Rahul Maini (@iamnoooob)"],
         "Programs": ["Apple", "Lucee"],
         "Bugs": ["RCE", "Insecure deserialization", "ColdFusion", "Security code review"],
         "Bounty": "20,000",
         "PublicationDate": "2024-02-15",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "The effectiveness of employing BChecks to uncover significant secrets",
               "Link": "https://xelkomy.medium.com/the-effectiveness-of-employing-bchecks-to-uncover-significant-secrets-788e15a8a952"
            }
         ],
         "Authors": ["Khaled Mohamed (@0xElkomy)"],
         "Programs": ["-"],
         "Bugs": ["Hardcoded credentials"],
         "Bounty": "-",
         "PublicationDate": "2024-02-15",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Playing with DOMPurify custom elements handling",
               "Link": "https://mizu.re/post/playing-with-dompurify-ce-handling"
            }
         ],
         "Authors": ["Mizu (@kevin_mizu)"],
         "Programs": ["DOMPurify"],
         "Bugs": ["Mutation XSS", "Filter bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-02-15",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover [It Looked Secure at First]",
               "Link": "https://cristivlad.medium.com/account-takeover-it-looked-secure-at-first-f14a31cb7f5c"
            }
         ],
         "Authors": ["Cristi Vlad (@CristiVlad25)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Account takeover", "Privilege escalation", "Password reset"],
         "Bounty": "-",
         "PublicationDate": "2024-02-15",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Mintty NTLM Leak - CVE-2023-50627",
               "Link": "https://blog.solidsnail.com/posts/mintty-hash-leak"
            }
         ],
         "Authors": ["solid-snail"],
         "Programs": ["MinTTY"],
         "Bugs": ["NTLM", "ANSI escape sequences"],
         "Bounty": "-",
         "PublicationDate": "2024-02-14",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Snap Trap: The Hidden Dangers Within Ubuntu’s Package Suggestion System",
               "Link": "https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/"
            }
         ],
         "Authors": ["Ilay Goldman (@GoldmanIlay)"],
         "Programs": ["Ubuntu"],
         "Bugs": ["Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2024-02-14",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Empire C2 Framework",
               "Link": "https://aceresponder.com/blog/exploiting-empire-c2-framework"
            }
         ],
         "Authors": ["ACE Responder (@ACEResponder)"],
         "Programs": ["BC Security (Empire)"],
         "Bugs": ["RCE", "Path traversal", "Arbitrary file overwrite"],
         "Bounty": "-",
         "PublicationDate": "2024-02-14",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "ADCS ESC13 Abuse Technique",
               "Link": "https://posts.specterops.io/adcs-esc13-abuse-technique-fda4272fbd53"
            }
         ],
         "Authors": ["Jonas Bülow Knudsen"],
         "Programs": ["-"],
         "Bugs": ["ADCS", "Active Directory"],
         "Bounty": "-",
         "PublicationDate": "2024-02-14",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "How I Got Multiple Privilege Escalations - The Easy Trick?",
               "Link": "https://rashahacks.com/how-i-got-multiple-privilege-escalations/"
            }
         ],
         "Authors": ["Inderjeet Singh (@3nc0d3dGuY)"],
         "Programs": ["-"],
         "Bugs": ["Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-02-13",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "PHP deserialization attacks and a new gadget chain in Laravel",
               "Link": "https://blog.quarkslab.com/php-deserialization-attacks-and-a-new-gadget-chain-in-laravel.html"
            }
         ],
         "Authors": ["Mathieu Farrell"],
         "Programs": ["-"],
         "Bugs": ["Insecure deserialization", "PHP pop chain"],
         "Bounty": "-",
         "PublicationDate": "2024-02-13",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-23724: Ghost CMS Stored XSS Leading to Owner Takeover",
               "Link": "https://rhinosecuritylabs.com/research/cve-2024-23724-ghost-cms-stored-xss/"
            }
         ],
         "Authors": ["Tyler Ramsbey (@Tyler_Ramsbey)"],
         "Programs": ["Ghost"],
         "Bugs": ["Stored XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-02-13",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Kubernetes through Operator Injection",
               "Link": "https://www.praetorian.com/blog/exploiting-kubernetes-through-operator-injection/"
            }
         ],
         "Authors": ["Zach Grace"],
         "Programs": ["-"],
         "Bugs": ["Kubernetes", "GraphQL"],
         "Bounty": "-",
         "PublicationDate": "2024-02-13",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "How I Hacked the Dutch Government: Exploiting an Innocent Image for Remote Code Execution",
               "Link": "https://medium.com/@mukundbhuva/how-i-hacked-the-dutch-government-exploiting-an-innocent-image-for-remote-code-execution-df1fa936e46a"
            }
         ],
         "Authors": ["Mukund Bhuva (@MukundBhuva)"],
         "Programs": ["Dutch Government"],
         "Bugs": ["RCE", "Code injection"],
         "Bounty": "-",
         "PublicationDate": "2024-02-12",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-0685 Ninja Contact Forms Data Export SQLi",
               "Link": "https://sec.stealthcopter.com/ninja-contact-forms/"
            }
         ],
         "Authors": ["Matthew Rollings (@stealthcopter)"],
         "Programs": ["Wordfence"],
         "Bugs": ["SQL injection", "Security code review"],
         "Bounty": "165",
         "PublicationDate": "2024-02-10",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "JSON CSRF in Microsoft Bing Maps Collections",
               "Link": "https://infosecwriteups.com/json-csrf-in-microsoft-bing-maps-collections-74afc2b197d5"
            }
         ],
         "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
         "Programs": ["Microsoft (Bing)"],
         "Bugs": ["JSON CSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-02-09",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Form Tools Remote Code Execution: We Need To Talk About PHP",
               "Link": "https://labs.watchtowr.com/form-tools-we-need-to-talk-about-php/"
            }
         ],
         "Authors": ["watchTowr (@watchtowrcyber)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "LFI", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-08",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Java applet + serialization in 2024! What could go wrong?",
               "Link": "https://security.humanativaspa.it/java-applet-serialization-in-2024-what-could-go-wrong/"
            }
         ],
         "Authors": ["Federico Dotta (@apps3c)"],
         "Programs": ["-"],
         "Bugs": ["Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2024-02-08",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-25365 / XSS via file upload bypass",
               "Link": "https://cupc4k3.medium.com/cve-2023-25365-xss-via-file-upload-bypass-ddf4d2a106a7"
            }
         ],
         "Authors": ["cupc4k3", "Gabriel V. Mendes"],
         "Programs": ["October CMS"],
         "Bugs": ["Stored XSS", "Unrestricted file upload"],
         "Bounty": "-",
         "PublicationDate": "2024-02-08",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Conditional Love for AWS Metadata Enumeration",
               "Link": "https://blog.plerion.com/conditional-love-for-aws-metadata-enumeration/"
            }
         ],
         "Authors": ["Daniel Grzelak (@dagrz)"],
         "Programs": ["-"],
         "Bugs": ["AWS misconfiguration", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2024-02-07",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Null Byte on Steroids",
               "Link": "https://medium.com/@0xold/null-byte-on-steroids-23f8104a25ec"
            }
         ],
         "Authors": ["Omar (@0x0ld)"],
         "Programs": ["-"],
         "Bugs": ["Null-Byte injection", "Account takeover", "Password reset", "SQL injection", "Path traversal", "XSS", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-02-06",
         "AddedDate": "2024-09-04"
      },
      {
         "Links": [
            {
               "Title": "Pitfalls of Desanitization: Leaking Customer Data from osTicket",
               "Link": "https://www.sonarsource.com/blog/pitfalls-of-desanitization-leaking-customer-data-from-osticket/"
            }
         ],
         "Authors": ["Oskar Zeino-Mahmalat"],
         "Programs": ["Enhancesoft (osTicket)"],
         "Bugs": ["Stored XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-06",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Azure HDInsight: The Sequel – Unveiling 3 New Vulnerabilities That Could Have Led to Privilege Escalations and Denial of Service",
               "Link": "https://orca.security/resources/blog/azure-hd-insight-vulnerabilities-privilege-escalation/"
            }
         ],
         "Authors": ["Lidor Ben Shitrit"],
         "Programs": ["Microsoft (Azure HDInsight)"],
         "Bugs": ["XXE", "Privilege escalation", "ReDoS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-06",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "ALWAYS test 404 Not Found in Bug Bounties!",
               "Link": "https://medium.com/@mares.viktor/always-test-404-not-found-in-bug-bounties-2be47801b4c0"
            }
         ],
         "Authors": ["Viktor Mares"],
         "Programs": ["-"],
         "Bugs": ["Hardcoded credentials", "Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-02-06",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "The UI Slip I Hit 750$: UI Manipulation Leading to Unauthorized Permission Changes",
               "Link": "https://medium.com/bugbountywriteup/the-ui-slip-i-hit-750-ui-manipulation-leading-to-unauthorized-permission-changes-d65621d8dd96"
            }
         ],
         "Authors": ["Sumit Kumar"],
         "Programs": ["-"],
         "Bugs": ["Privilege escalation", "Client-side enforcement of server-side security"],
         "Bounty": "750",
         "PublicationDate": "2024-02-04",
         "AddedDate": "2024-05-08"
      },
      {
         "Links": [
            {
               "Title": "Unveiling a Security Vulnerability in Zoho Meet: Gaining Unauthorized Access to Private Meetings",
               "Link": "https://medium.com/@sumitkumardas8487/unveiling-a-security-vulnerability-in-zoho-meet-gaining-unauthorized-access-to-private-meetings-ad428b1990ad"
            }
         ],
         "Authors": ["Sumit Kumar"],
         "Programs": ["Zoho (Meet)"],
         "Bugs": ["Bruteforce"],
         "Bounty": "-",
         "PublicationDate": "2024-02-04",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Back to the (Clip)board with Microsoft Whiteboard and Excalidraw in Meta (CVE-2023-26140)",
               "Link": "https://spaceraccoon.dev/clipboard-microsoft-whiteboard-excalidraw-meta/"
            }
         ],
         "Authors": ["Eugene Lim (@spaceraccoonsec)"],
         "Programs": ["Meta / Facebook", "Microsoft (Whiteboard)", "Excalidraw"],
         "Bugs": ["XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-04",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "ChatGPT Account Takeover - Wildcard Web Cache Deception",
               "Link": "https://nokline.github.io/bugbounty/2024/02/04/ChatGPT-ATO.html"
            }
         ],
         "Authors": ["Harel (@h4r3l)"],
         "Programs": ["OpenAI (ChatGPT)"],
         "Bugs": ["AI", "LLM", "Web cache deception", "Account takeover", "Path traversal", "URL parsing issue"],
         "Bounty": "6,500",
         "PublicationDate": "2024-02-04",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "How I secured the United Nations Hall of Fame",
               "Link": "https://medium.com/@kamilrahman32/how-i-secured-the-united-nations-hall-of-fame-67b036ff2620"
            }
         ],
         "Authors": ["Kamil Rahuman"],
         "Programs": ["United Nations"],
         "Bugs": ["Components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2024-02-03",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "How I got RCE in one of Bugcrowd's Public Programs",
               "Link": "https://medium.com/@yousefmoh15/how-i-got-rce-in-one-of-bugcrowds-public-programs-5725c8dc46ce"
            }
         ],
         "Authors": ["Yousef Mohamed Elsaid"],
         "Programs": ["-"],
         "Bugs": ["RCE", "OGNL injection", "Apache Struts 2"],
         "Bounty": "-",
         "PublicationDate": "2024-02-03",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "SSRF on a Headless Browser Becomes Critical!",
               "Link": "https://medium.com/@Nightbloodz/ssrf-on-a-headless-browser-becomes-critical-c08daaa1017e"
            }
         ],
         "Authors": ["Alvaro Balada"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "2,000",
         "PublicationDate": "2024-02-03",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Hacking a Smart Home Device",
               "Link": "https://jmswrnr.com/blog/hacking-a-smart-home-device"
            }
         ],
         "Authors": ["James Warner"],
         "Programs": ["-"],
         "Bugs": ["IoT", "Android", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2024-02-03",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "LedgerSMB – CVE-2024-23831: Privilege escalation through CSRF attack on “setup.pl”",
               "Link": "https://twelvesec.com/2024/02/02/cve-2024-23831/"
            }
         ],
         "Authors": ["George Roumeliotis"],
         "Programs": ["LedgerSMB"],
         "Bugs": ["CSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-02-02",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Misconfiguration lead to company identity theft via bypass email verification.",
               "Link": "https://hamzadzworm.medium.com/misconfiguration-lead-to-company-identity-theft-via-bypass-email-verification-0dd60b61d943"
            }
         ],
         "Authors": ["Abdelkader Mouaz (@hamzadzworm)"],
         "Programs": ["-"],
         "Bugs": ["Email verification bypass", "HTML injection"],
         "Bounty": "-",
         "PublicationDate": "2024-02-02",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "How i was able to hack a Company via watching a YouTube video",
               "Link": "https://ahmadmansourr.medium.com/how-i-was-able-to-hack-a-company-via-watching-a-youtube-video-without-any-technical-pentesting-4941753a150a"
            }
         ],
         "Authors": ["Ahmad Mansour"],
         "Programs": ["-"],
         "Bugs": ["Weak credentials"],
         "Bounty": "-",
         "PublicationDate": "2024-02-02",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "This is arguably the dumbest bug I’ve ever found.",
               "Link": "https://medium.com/@deadoverflow/this-is-arguably-the-dumbest-bug-ive-ever-found-3e451951d727"
            }
         ],
         "Authors": ["Imad Husanovic (@deadoverflow_)"],
         "Programs": ["-"],
         "Bugs": ["Self-XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-02-02",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Remote Code Execution by Bypassing Cloudflare: CVE-2022–29464 Analysis",
               "Link": "https://medium.com/@alii76tt/remote-code-execution-by-bypassing-cloudflare-cve-2022-29464-analysis-02328e0e284a"
            }
         ],
         "Authors": ["Ali İltizar (@alii76tt)"],
         "Programs": ["-"],
         "Bugs": ["Components with known vulnerabilities", "RCE", "WSO2", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-02-02",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Auth Bypass Round Two",
               "Link": "https://www.assetnote.io/resources/research/ivantis-pulse-connect-secure-auth-bypass-round-two"
            }
         ],
         "Authors": ["Dylan Pindur"],
         "Programs": ["Ivanti"],
         "Bugs": ["SAML", "SSRF", "RCE", "Authentication bypass", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-02-02",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "ModSecurity: Path Confusion and really easy bypass on v2 and v3",
               "Link": "https://blog.sicuranext.com/modsecurity-path-confusion-bugs-bypass/"
            }
         ],
         "Authors": ["Andrea Menin (@AndreaTheMiddle)"],
         "Programs": ["ModSecurity"],
         "Bugs": ["WAF bypass", "Path confusion"],
         "Bounty": "-",
         "PublicationDate": "2024-02-02",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Azure Devops Zero-Click CI/CD Vulnerability",
               "Link": "https://www.legitsecurity.com/blog/azure-devops-zero-click-ci/cd-vulnerability"
            }
         ],
         "Authors": ["Nadav Noy"],
         "Programs": ["Microsoft (Azure DevOps Pipelines)"],
         "Bugs": ["CI/CD", "Supply chain attack", "Privilege escalation", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-01-31",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Jumpserver Preauth RCE Exploit Chain",
               "Link": "https://sites.google.com/site/zhiniangpeng/blogs/Jumpserver"
            }
         ],
         "Authors": ["zhiniang peng (@edwardzpeng)"],
         "Programs": ["JumpServer"],
         "Bugs": ["RCE", "Password reset", "Authentication bypass", "Path traversal", "Cryptographic issues", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-31",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Relution Remote Code Execution via Java Deserialization Vulnerability",
               "Link": "https://www.praetorian.com/blog/relution-remote-code-execution-java-deserialization-vulnerability/"
            }
         ],
         "Authors": ["Adam Crosser"],
         "Programs": ["Relution"],
         "Bugs": ["RCE", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-31",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Leaky Vessels: Docker and runc container breakout vulnerabilities",
               "Link": "https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/"
            }
         ],
         "Authors": ["Rory McNamara (@PsychoMario)"],
         "Programs": ["Docker", "opencontainers (runc)"],
         "Bugs": ["Container escape"],
         "Bounty": "-",
         "PublicationDate": "2024-01-31",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Bypass Admin approval, Mute Member and Posting Permissions for Only admins in Facebook groups",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/bypass-admin-approval-mute-member-and-posting-permissions-for-only-admins-in-facebook-groups/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Disclose private mockups for other users in facebook Creative Hub",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/disclose-private-mockups-for-other-users-in-facebook-creative-hub/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Persistent Distorted Posts Issue and Unremovable Content in Facebook Group",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/persistent-distorted-posts-issue-and-unremovable-content-in-facebook-group/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Add comment on a private Oculus Developer support",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/add-comment-on-a-private-oculus-developer-support/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Disclose latest stream video asset earnings for any gaming streamer page",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/disclose-latest-stream-video-asset-earnings-for-any-gaming-streamer-page/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Send messages through notification to facebook & workplace users without getting blocked",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/send-messages-through-notification-to-facebook-workplace-users-without-getting-blocked/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Break saved option for other users in facebook – From N/A to valid bug",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/break-saved-option-for-other-users-in-facebook-from-n-a-to-valid-bug/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Sign up for Brand Collabs Manager on behalf of other page admins – Privilege Escalation",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/sign-up-for-brand-collabs-manager-on-behalf-of-other-page-admins-privilege-escalation/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "How I found a simple bug in Facebook events without any Test",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/how-i-found-a-simple-bug-in-facebook-events-without-any-test/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["Broken Access Control", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Disclose Instagram Personal Private Archived posts when switching to Professional account through creative hub",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/disclose-instagram-personal-private-archived-posts-when-switching-to-professional-account-through-creative-hub/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook (Instagram)"],
         "Bugs": ["Privacy issue", "Authorization bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "From empty page to POST based JSON XSS",
               "Link": "https://blog.flawminers.com/index.php/2024/01/30/from-empty-page-to-post-based-json-xss/"
            }
         ],
         "Authors": ["Daoud Youssef (@daoud_youssef)"],
         "Programs": ["-"],
         "Bugs": ["JSON XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog()",
               "Link": "https://blog.qualys.com/vulnerabilities-threat-research/2024/01/30/qualys-tru-discovers-important-vulnerabilities-in-gnu-c-librarys-syslog"
            }
         ],
         "Authors": ["Qualys Threat Research Unit (TRU)"],
         "Programs": ["GNU C Library (glibc)"],
         "Bugs": ["Memory corruption", "Integer overflow", "Heap buffer overflow", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-5372 - Post-auth blind Python code injection vulnerabilities in Zyxel’s NAS326 and NAS542 devices",
               "Link": "https://bugprove.com/knowledge-hub/cve-2023-5372-post-auth-blind-python-code-injection-vulnerabilities-in-zyxel-s-nas-326-and-nas-542-devices/"
            }
         ],
         "Authors": ["Gábor Selján (@GaborSeljan)"],
         "Programs": ["Zyxel"],
         "Bugs": ["Code injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Hunting for Unauthenticated n-days in Asus Routers",
               "Link": "https://www.shielder.com/blog/2024/01/hunting-for-~~un~~authenticated-n-days-in-asus-routers/"
            }
         ],
         "Authors": ["TheZero (@Th3Zer0)", "suidpit (@suidpit)"],
         "Programs": ["Asus"],
         "Bugs": ["RCE", "Format string vulnerability", "Reverse engineering", "Patch diffing"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Analysis Of Multiple Vulnerabilities In Ofbiz",
               "Link": "https://blog.securelayer7.net/ofbiz-authentication-bypass-cve-2023-51467/0"
            }
         ],
         "Authors": ["SecureLayer7 (@SecureLayer7)"],
         "Programs": ["Ofbiz"],
         "Bugs": ["Authentication bypass", "RCE", "Groovy scripting", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "macOS AUHelperService Full TCC Bypass",
               "Link": "https://jhftss.github.io/macOS-AUHelperService-Full-TCC-Bypass/"
            }
         ],
         "Authors": ["Mickey Jin (@patch1t)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["TCC bypass", "Local Privilege Escalation"],
         "Bounty": "23,000",
         "PublicationDate": "2024-01-30",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Who are you? The Importance of Verifying Message Origins",
               "Link": "https://www.sonarsource.com/blog/who-are-you-the-importance-of-verifying-message-origins/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["Squidex"],
         "Bugs": ["XSS", "postMessage", "Arbitrary file write", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-29",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "XML External Entity injection with error-based data exfiltration",
               "Link": "https://infosecwriteups.com/xml-external-entity-injection-with-error-based-data-exfiltration-985b063ec820"
            }
         ],
         "Authors": ["Serj Novoselov (@novoselov_s)"],
         "Programs": ["-"],
         "Bugs": ["XXE"],
         "Bounty": "-",
         "PublicationDate": "2024-01-29",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Device Code Phishing – Add Your Own Sign-In Methods on Entra ID",
               "Link": "https://blog.compass-security.com/2024/01/device-code-phishing-add-your-own-sign-in-methods-on-entra-id/"
            }
         ],
         "Authors": ["Felix Aeppli"],
         "Programs": ["Microsoft"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2024-01-28",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "500$: MFA bypass By Race Condition",
               "Link": "https://medium.com/@a13h1/500-mfa-bypass-by-race-condition-176421462902"
            }
         ],
         "Authors": ["Abhi Sharma (@a13h1_)"],
         "Programs": ["-"],
         "Bugs": ["Race condition", "2FA / MFA bypass"],
         "Bounty": "500",
         "PublicationDate": "2024-01-28",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Local Privilege Escalation in Lenovo UDC",
               "Link": "https://blog.advact.ch/local-privilege-escalation-in-lenovo-udc-19dc86d72142"
            }
         ],
         "Authors": ["Moritz Rauch"],
         "Programs": ["Lenovo"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-01-27",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Hunting for Prototype Pollution gadgets in jQuery (intigriti 0124 challenge)",
               "Link": "https://joaxcar.com/blog/2024/01/26/hunting-for-prototype-pollution-gadgets-in-jquery-intigriti-0124-challenge/"
            }
         ],
         "Authors": ["Johan Carlsson (@joaxcar)"],
         "Programs": ["-"],
         "Bugs": ["Prototype pollution", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-01-26",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Chaining IDOR and Host Header can takeover 18 Billion of users account",
               "Link": "https://nullr3x.medium.com/chaining-idor-and-host-header-can-takeover-18-billion-of-users-account-3f0c3fdbc29b"
            }
         ],
         "Authors": ["Sahil Mehra (@nullr3x)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Host header injection", "Password reset", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-01-26",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Spoofing 802.11 Wireless Beacon Management Frames with Manipulated Power Values Resulting in Denial of Service for Wireless Clients",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/spoofing-802-11-wireless-beacon-management-frames-with-manipulated-power-values-resulting-in-denial-of-service-for-wireless-clients/"
            }
         ],
         "Authors": ["Tom Neaves"],
         "Programs": ["-"],
         "Bugs": ["DoS", "Wifi hacking", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-26",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-5480: Chrome new XSS Vector",
               "Link": "https://blog.slonser.info/posts/cve-2023-5480/"
            }
         ],
         "Authors": ["Vsevolod Kokorin (slonser_)"],
         "Programs": ["Google (Chrome & Chromium)"],
         "Bugs": ["XSS", "Logic flaw", "Browser hacking"],
         "Bounty": "16,000",
         "PublicationDate": "2024-01-25",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Shipping your Private Key - CVE-2023-43870, Paxton do a Lenovo",
               "Link": "https://www.cryptic.red/post/shipping-your-private-key-cve-2023-43870-paxton-do-a-lenovo"
            }
         ],
         "Authors": ["craig72947 (@craigsblackie)"],
         "Programs": ["Paxton"],
         "Bugs": ["Thick client", "MiTM", "Hardcoded credentials"],
         "Bounty": "-",
         "PublicationDate": "2024-01-25",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Rook to XSS: How I hacked chess.com with a rookie exploit",
               "Link": "https://skii.dev/rook-to-xss/"
            }
         ],
         "Authors": ["Jacob"],
         "Programs": ["Chess.com"],
         "Bugs": ["XSS", "OSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-01-25",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Bypassing browser tracking protection for CORS misconfiguration abuse",
               "Link": "https://swarm.ptsecurity.com/bypassing-browser-tracking-protection-for-cors-misconfiguration-abuse/"
            }
         ],
         "Authors": ["Nikita Sveshnikov"],
         "Programs": ["Mozilla (Firefox)", "Apple (Safari)"],
         "Bugs": ["CORS misconfiguration", "Browser hacking"],
         "Bounty": "-",
         "PublicationDate": "2024-01-25",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Excessive Expansion: Uncovering Critical Security Vulnerabilities in Jenkins (CVE-2024-23897 & CVE-2024-23898)",
               "Link": "https://www.sonarsource.com/blog/excessive-expansion-uncovering-critical-security-vulnerabilities-in-jenkins/"
            }
         ],
         "Authors": ["Yaniv Nizry (@YNizry)"],
         "Programs": ["Jenkins"],
         "Bugs": ["Cross-Site WebSocket Hijacking (CSWH)", "Data leak", "Arbitrary file read", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-25",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – Zyxel VPN Series Pre-auth Remote Command Execution",
               "Link": "https://ssd-disclosure.com/ssd-advisory-zyxel-vpn-series-pre-auth-remote-command-execution/"
            }
         ],
         "Authors": ["-"],
         "Programs": ["Zyxel"],
         "Bugs": ["RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-25",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Multiple vulnerabilities in Cisco Unified Communications Manager version 11.5.1",
               "Link": "https://www.synacktiv.com/sites/default/files/2024-01/cisco_ucm_multiple_vulnerabilities.pdf"
            }
         ],
         "Authors": ["Julien Egloff"],
         "Programs": ["Cisco"],
         "Bugs": ["Insecure deserialization", "RCE", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-01-24",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Unleashing the power of CSS injection: The access key to an internal API",
               "Link": "https://sanderwind.medium.com/unleashing-the-power-of-css-injection-the-access-key-to-an-internal-api-789b166d0527"
            }
         ],
         "Authors": ["Sander Wind (@SanderWind)"],
         "Programs": ["Prince"],
         "Bugs": ["CSS injection", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-01-24",
         "AddedDate": "2024-01-03"
      },
      {
         "Links": [
            {
               "Title": "*nix libX11: Uncovering and exploiting a 35-year-old vulnerability – Part 2 of 2",
               "Link": "https://jfrog.com/blog/xorg-libx11-vulns-cve-2023-43786-cve-2023-43787-part-two/"
            }
         ],
         "Authors": ["Yair Mizrahi"],
         "Programs": ["X.Org (libX11)"],
         "Bugs": ["RCE", "Memory corruption", "Heap buffer overflow", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-24",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Response Manipulation Lead To Premium Feature By Normal User Reward of $500",
               "Link": "https://medium.com/@zikola1/response-manipulation-lead-to-premium-feature-by-normal-user-reward-of-500-43381f769ab1"
            }
         ],
         "Authors": ["Abdulrahman badawi (@zikolaasec)"],
         "Programs": ["-"],
         "Bugs": ["HTTP response manipulation", "Privilege escalation", "Payment bypass"],
         "Bounty": "500",
         "PublicationDate": "2024-01-24",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "Sys:All: How A Simple Loophole in Google Kubernetes Engine Puts Clusters at Risk of Compromise",
               "Link": "https://orca.security/resources/research-pod/sys-all-google-kubernetes-engine-risk/"
            },
            {
               "Title": "How the Sys:All Loophole Allowed Us To Penetrate GKE Clusters in Production",
               "Link": "https://orca.security/resources/research-pod/sys-all-google-kubernetes-engine-risk-example/"
            }
         ],
         "Authors": ["Roi Nisimi (@roinisimi)", "Ofir Yakobi"],
         "Programs": ["Google (GKE)"],
         "Bugs": ["Kubernetes", "Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-01-24",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "Bypass instructions to manipulate Google Bard AI (Conversational generative AI chatbot) to reveal its security vulnerability i.e. configuration file details exposure",
               "Link": "https://medium.com/@kiranmaraju/bypass-instructions-to-manipulate-google-bard-ai-conversational-generative-ai-chatbot-to-reveal-ac23156d5eee"
            }
         ],
         "Authors": ["Kiran Maraju"],
         "Programs": ["Google (Bard)"],
         "Bugs": ["AI", "LLM", "LLM Jailbreak"],
         "Bounty": "-",
         "PublicationDate": "2024-01-23",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
           {
              "Title": "CVE-2024-0204: Fortra GoAnywhere MFT Authentication Bypass Deep-Dive",
              "Link": "https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/"
           }
          ],
         "Authors": ["Zach Hanley (@hacks_zach)"],
         "Programs": ["Fortra (GoAnywhere)"],
         "Bugs": ["Authentication bypass", "Path traversal", "Security code review", "Patch diffing"],
         "Bounty": "-",
         "PublicationDate": "2024-01-23",
         "AddedDate": "2024-02-06"
       },
      {
         "Links": [
           {
              "Title": "A christmas tale: pwning GTB Central Console (CVE-2024-22107 & CVE-2024-22108)",
              "Link": "https://adepts.of0x.cc/gtbcc-pwned/"
           }
          ],
         "Authors": ["X-C3LL (@TheXC3LL)"],
         "Programs": ["GTB Technologies"],
         "Bugs": ["DLP software", "SQL injection", "OS command injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-23",
         "AddedDate": "2024-02-01"
       },
      {
         "Links": [
           {
              "Title": "SQL Injection on PostgreSQL",
              "Link": "https://medium.com/@yagizkocer/sql-injection-on-postgresql-8c8f823e44aa"
           }
          ],
         "Authors": ["Yağız Koçer"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-01-23",
         "AddedDate": "2024-01-25"
       },
       {
         "Links": [
           {
              "Title": "ELECTRONizing macOS privacy",
              "Link": "https://wojciechregula.blog/post/electroniz3r/"
           }
          ],
         "Authors": ["Wojciech Reguła (@_r3ggi)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["TCC bypass", "Electron", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-01-23",
         "AddedDate": "2024-01-25"
       },
       {
         "Links": [
           {
              "Title": "Do not trust this Group Policy!",
              "Link": "https://decoder.cloud/2024/01/23/do-not-trust-this-group-policy/"
           }
          ],
         "Authors": ["ap (@decoder_it)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-01-23",
         "AddedDate": "2024-01-25"
       },
       {
         "Links": [
            {
               "Title": "Multiple Vulnerabilities On GestSup 3.2.44",
               "Link": "https://www.synacktiv.com/advisories/multiple-vulnerabilities-on-gestsup-3244"
            }
         ],
         "Authors": ["Pierre Martin (@_Worty)", "Romain Brun (@SpawnZii)"],
         "Programs": ["GetSup"],
         "Bugs": ["Account takeover", "SQL injection", "Stored XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-22",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Leaked SQL Error Leading To XSS And Another BSQLi",
               "Link": "https://medium.com/@zatikyan.sevada/leaked-sql-error-leading-to-xss-and-another-bsqli-cdadde032687"
            }
         ],
         "Authors": ["Zatikyan Sevada"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-01-22",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Atlassian Confluence - Remote Code Execution (CVE-2023-22527)",
               "Link": "https://blog.projectdiscovery.io/atlassian-confluence-ssti-remote-code-execution/"
            }
         ],
         "Authors": ["Rahul Maini (@iamnoooob)", "Harsh Jaiswal (@rootxharsh)"],
         "Programs": ["Atlassian"],
         "Bugs": ["RCE", "OGNL injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-22",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "How I Bypassed A.i. Based Facial Detection Restriction With An Intended Feature On A Photo Sharing App ?",
               "Link": "https://medium.com/@Ishwar-Kumar/how-i-bypassed-a-i-6aa433370050"
            }
         ],
         "Authors": ["Ishwar Kumar"],
         "Programs": ["-"],
         "Bugs": ["AI", "Logic flaw", "Facial recognition bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-01-20",
         "AddedDate": "2024-08-22"
      },
      {
         "Links": [
            {
               "Title": "Web3’s Achilles’ Heel: A Supply Chain Attack on Astar Network",
               "Link": "https://adnanthekhan.com/2024/01/19/web3s-achilles-heel-a-supply-chain-attack-on-astar-network/"
            }
         ],
         "Authors": ["Adnan Khan (@adnanthekhan)"],
         "Programs": ["Astar Network"],
         "Bugs": ["Supply chain attack", "Self-Hosted Runner Takeover", "CI/CD"],
         "Bounty": "-",
         "PublicationDate": "2024-01-19",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Dangling CNAME/Orphaned CNAME leads P2 on Google VRP",
               "Link": "https://medium.com/@jerryhackgather/dangling-cname-orphaned-cname-leads-p2-on-google-vrp-fca8964d983c"
            }
         ],
         "Authors": ["Jerry1319 (@Mdhsan19)"],
         "Programs": ["Google"],
         "Bugs": ["Subdomain takeover"],
         "Bounty": "-",
         "PublicationDate": "2024-01-19",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE (CVE-2023-46805 & CVE-2024-21887)",
               "Link": "https://www.assetnote.io/resources/research/high-signal-detection-and-exploitation-of-ivantis-pulse-connect-secure-auth-bypass-rce"
            }
         ],
         "Authors": ["Shubham Shah (@infosec_au)", "Dylan Pindur"],
         "Programs": ["Ivanti"],
         "Bugs": ["RCE", "Authentication bypass", "Path traversal", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-19",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "Gambio 4.9.2.0 - Insecure Deserialization",
               "Link": "https://herolab.usd.de/security-advisories/usd-2023-0046/"
            }
         ],
         "Authors": ["Christian Poeschl", "Lukas Schraven"],
         "Programs": ["Gambio"],
         "Bugs": ["RCE", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-19",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "Secret Input Header leads to Password Reset Poisoning",
               "Link": "https://medium.com/@mares.viktor/secret-input-header-leads-to-password-reset-poisoning-ad3081fd8488"
            }
         ],
         "Authors": ["Viktor Mares"],
         "Programs": ["-"],
         "Bugs": ["Password reset"],
         "Bounty": "-",
         "PublicationDate": "2024-01-18",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "A Practical Guide to PrintNightmare in 2024",
               "Link": "https://itm4n.github.io/printnightmare-exploitation/"
            }
         ],
         "Authors": ["Clément Labro (@itm4n)"],
         "Programs": ["-"],
         "Bugs": ["Local Privilege Escalation", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2024-01-18",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Nokia vBMC — BMC Log Scanner Remote Code Execution",
               "Link": "https://mattchew-gregory.medium.com/nokia-vbmc-bmc-log-scanner-remote-code-execution-52421b3f928d"
            }
         ],
         "Authors": ["Matthew Gregory"],
         "Programs": ["Nokia"],
         "Bugs": ["RCE", "OS command injection"],
         "Bounty": "-",
         "PublicationDate": "2024-01-18",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "AWS Fixes Data Exfiltration Attack Angle in Amazon Q for Business",
               "Link": "https://embracethered.com/blog/posts/2024/aws-amazon-q-fixes-markdown-rendering-vulnerability/"
            }
         ],
         "Authors": ["Johann Rehberger (wunderwuzzi23)"],
         "Programs": ["AWS"],
         "Bugs": ["Indirect Prompt Injection", "LLM", "Data leak", "Chatbot"],
         "Bounty": "-",
         "PublicationDate": "2024-01-18",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes (CVE-2023-35636)",
               "Link": "https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes"
            }
         ],
         "Authors": ["Dolev Taler"],
         "Programs": ["Microsoft (Outlook)"],
         "Bugs": ["NTLM", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-01-18",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "How I was able to delete any image in Facebook community question forum",
               "Link": "https://blog.flawminers.com/index.php/2024/01/17/how-i-was-able-to-delete-any-image-in-facebook-community-question-forum-1500/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "How I found RXSS in Facebook, Twitter and Google training academy",
               "Link": "https://blog.flawminers.com/index.php/2024/01/17/how-i-found-rxss-in-facebook-twitter-and-google-training-academy-2620/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook", "Twitter", "Google", "Intellum"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Unauthorized Disclosure of Video Thumbnails in Facebook Workplace",
               "Link": "https://blog.flawminers.com/index.php/2024/01/17/unauthorized-disclosure-of-video-thumbnails-in-facebook-workplace-3000/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Calling Home, Get Your Callbacks Through RBI",
               "Link": "https://posts.specterops.io/calling-home-get-your-callbacks-through-rbi-50633a233999"
            }
         ],
         "Authors": ["Lance B. Cain", "Alexander DeMine"],
         "Programs": ["-"],
         "Bugs": ["Red team", "Phishing", "Remote Browser Isolation (RBI)", "Command and Control (C2)"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Hi Meta, WhatsApp with privacy?",
               "Link": "https://medium.com/@TalBeerySec/hi-meta-whatsapp-with-privacy-6d646c5aa3bc"
            }
         ],
         "Authors": ["Tal Be'ery (@TalBeerySec)"],
         "Programs": ["Meta / Facebook (WhatsApp)"],
         "Bugs": ["Privacy issue", "Information disclosure", "Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "*nix libX11: Uncovering and exploiting a 35-year-old vulnerability – Part 1 of 2",
               "Link": "https://jfrog.com/blog/xorg-libx11-vulns-cve-2023-43786-cve-2023-43787-part-one/"
            }
         ],
         "Authors": ["Yair Mizrahi"],
         "Programs": ["X.Org (libX11)"],
         "Bugs": ["DoS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Multiple vulnerabilities in Ivanti Connect Secure",
               "Link": "https://www.synacktiv.com/sites/default/files/2024-01/synacktiv-pulseconnectsecure-multiple-vulnerabilities.pdf"
            }
         ],
         "Authors": ["Jérôme Mampianinazakason"],
         "Programs": ["Ivanti"],
         "Bugs": ["Path traversal", "RCE", "Local Privilege Escalation", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "I found 2 Zero-Days in popular Linux distros that includes Mint, Kali, Parrot",
               "Link": "https://febinj.medium.com/i-found-2-zero-days-in-popular-linux-distros-that-includes-mint-kali-parrot-04e1cee800bd"
            }
         ],
         "Authors": ["Febin Mon Saji"],
         "Programs": ["Linux Mint (Xreader)", "MATE Desktop (Atril)"],
         "Bugs": ["RCE", "Argument injection", "Path traversal", "Arbitrary file write"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website",
               "Link": "https://eaton-works.com/2024/01/17/ttibi-email-hack/"
            }
         ],
         "Authors": ["Eaton Z. (@XeEaton)"],
         "Programs": ["Toyota"],
         "Bugs": ["Information disclosure", "Android", "Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "How to Discover IDOR from a Blank Page — Bug Bounty Tuesday",
               "Link": "https://medium.com/@kerstan/how-to-discovered-idor-from-a-blank-page-bug-bounty-tuesday-5af784533d1a"
            }
         ],
         "Authors": ["kerstan"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "200",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Understanding GitLab EE/CE Account TakeOver (CVE-2023-7028)",
               "Link": "https://secops.group/understanding-gitlab-ee-ce-account-takeover-cve-2023-7028/"
            }
         ],
         "Authors": ["Ravi Solanki (@SolankiRV3)", "Punit"],
         "Programs": ["GitLab"],
         "Bugs": ["Account takeover", "Password reset"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Introducing MavenGate: a supply chain attack method for Java and Android applications",
               "Link": "https://blog.oversecured.com/Introducing-MavenGate-a-supply-chain-attack-method-for-Java-and-Android-applications/#vulnerable-dependencies-in-real-projects"
            }
         ],
         "Authors": ["Oversecured (@OversecuredInc)"],
         "Programs": ["Google", "Facebook", "Amazon", "Microsoft", "Adobe", "LinkedIn", "Netflix"],
         "Bugs": ["Dependency hijacking", "Android", "Maven", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "1 Program, 4 Business Logic Bugs and Cashing in 2300$.",
               "Link": "https://infosecwriteups.com/1-program-4-business-logic-bugs-and-cashing-in-2300-299b42236993"
            }
         ],
         "Authors": ["Manav Bankatwala (@ManavBankatwala)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw", "Race condition", "Broken Access Control"],
         "Bounty": "2,300",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Accessing deleted comment for $$: A Bug Bounty Writeup",
               "Link": "https://vijetareigns.medium.com/accessing-deleted-comment-for-a-bug-bounty-writeup-95d56662d209"
            }
         ],
         "Authors": ["the_unluck_guy (@7he_unlucky_guy)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Finding vulnerabilities in Swiss Post's e-voting system: part 3",
               "Link": "https://www.reversemode.com/2024/01/finding-vulnerabilities-in-swiss-posts.html"
            }
         ],
         "Authors": ["Ruben Santamarta (@reversemode)"],
         "Programs": ["Swiss E-Voting"],
         "Bugs": ["Cryptographic issues", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-17",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Adding Descriptions to Instagram Posts on Behalf of Other Users",
               "Link": "https://blog.flawminers.com/index.php/2024/01/16/adding-descriptions-to-instagram-posts-on-behalf-of-other-users-6500/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook (Instagram)"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-16",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Linux Kernel GSM Multiplexing Race Condition Local Privilege Escalation Vulnerability (CVE-2023-6546)",
               "Link": "https://github.com/Nassim-Asrir/ZDI-24-020/"
            }
         ],
         "Authors": ["Nassim Asrir (@p1k4l4)"],
         "Programs": ["-"],
         "Bugs": ["Local Privilege Escalation", "Use-After-Free", "Kernel hacking"],
         "Bounty": "-",
         "PublicationDate": "2024-01-16",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Reversing and Tooling a Signed Request Hash in Obfuscated JavaScript",
               "Link": "https://buer.haus/2024/01/16/reversing-and-tooling-a-signed-request-hash-in-obfuscated-javascript/"
            }
         ],
         "Authors": ["Brett Buerhaus (@bbuerhaus)"],
         "Programs": ["-"],
         "Bugs": ["JavaScript reversing", "Signature bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-01-16",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Disclose private attachments in Facebook Messenger Infrastructure",
               "Link": "https://blog.flawminers.com/index.php/2024/01/15/disclose-private-attachments-in-facebook-messenger-infrastructure-15000/"
            }
         ],
         "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
         "Programs": ["Meta / Facebook (Instagram)"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-15",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "DLS 2024 - RedTeam Fails - \"Oops my bad I ruined the operation\"",
               "Link": "https://swisskyrepo.github.io/Drink-Love-Share-Rump/"
            }
         ],
         "Authors": ["Swissky (@pentest_swissky)"],
         "Programs": ["-"],
         "Bugs": ["Red team"],
         "Bounty": "-",
         "PublicationDate": "2024-01-15",
         "AddedDate": "2024-05-11"
      },
      {
         "Links": [
            {
               "Title": "“MyFlaw” — Cross Platform 0-Day RCE Vulnerability Discovered in Opera’s Browser",
               "Link": "https://labs.guard.io/myflaw-cross-platform-0-day-rce-vulnerability-discovered-in-operas-browsers-099361a808ab"
            }
         ],
         "Authors": ["Oleg Zaytsev"],
         "Programs": ["Opera"],
         "Bugs": ["RCE", "CSP bypass", "Browser extension hacking", "Browser hacking"],
         "Bounty": "-",
         "PublicationDate": "2024-01-15",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "TensorFlow Supply Chain Compromise via Self-Hosted Runner Attack",
               "Link": "https://www.praetorian.com/blog/tensorflow-supply-chain-compromise-via-self-hosted-runner-attack/"
            }
         ],
         "Authors": ["Adnan Khan (@adnanthekhan)", "John Stawinski"],
         "Programs": ["Google (OSS)", "TensorFlow"],
         "Bugs": ["CI/CD", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2024-01-15",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "Android-based PAX POS vulnerabilities (Part 1)",
               "Link": "https://blog.stmcyber.com/pax-pos-cves-2023/"
            }
         ],
         "Authors": ["Adam Kliś", "Hubert Jasudowicz (@hjasudowicz)"],
         "Programs": ["PAX Technology"],
         "Bugs": ["POS", "Android", "Local Privilege Escalation", "Parameter injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-15",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Unrestricted File Upload Lead to Stored XSS at Microsoft main domain",
               "Link": "https://medium.com/@cavdarbashas/unrestricted-file-upload-lead-to-stored-xss-at-microsoft-main-domain-baa9cadac6bd"
            }
         ],
         "Authors": ["Sokol Çavdarbasha (@sokolicav)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Unrestricted file upload", "Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-01-15",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "XSS to OAuth access token leak in office online which can be used to account takeover",
               "Link": "https://gist.github.com/RenwaX23/0311842bb790ce98fe0cd8f41141fdf0"
            }
         ],
         "Authors": ["Renwa (@RenwaX23)"],
         "Programs": ["Microsoft"],
         "Bugs": ["XSS", "CSP bypass", "postMessage"],
         "Bounty": "500",
         "PublicationDate": "2024-01-12",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-40361 Writeup",
               "Link": "https://hazemhussien99.wordpress.com/2024/01/12/cve-2022-40361-writeup/"
            }
         ],
         "Authors": ["Hazem Hussien (@_bughunter)"],
         "Programs": ["Elite CRM"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-01-12",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Unveiling Vulnerabilities: Loose Permissions in Salesforce Lightning Pose Data Security Threats",
               "Link": "https://samshadow.medium.com/unveiling-vulnerabilities-loose-permissions-in-salesforce-lightning-pose-data-security-threats-41eaba372937"
            }
         ],
         "Authors": ["Sam Shadow"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "Salesforce"],
         "Bounty": "-",
         "PublicationDate": "2024-01-12",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "tRPC Security Research: Hunting for Vulnerabilities in Modern APIs",
               "Link": "https://medium.com/@LogicalHunter/trpc-security-research-hunting-for-vulnerabilities-in-modern-apis-b0d38e06fa71"
            }
         ],
         "Authors": ["Borna Nematzadeh (@LogicalHunter)"],
         "Programs": ["-"],
         "Bugs": ["tRPC"],
         "Bounty": "-",
         "PublicationDate": "2024-01-12",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Weird bug to steal users credentials",
               "Link": "https://medium.com/@fuadahmad062/weird-bug-to-steal-users-credentials-5e80c5d4565f"
            }
         ],
         "Authors": ["von001"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "Phishing"],
         "Bounty": "-",
         "PublicationDate": "2024-01-12",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "IDN Homograph Attack - Reborn of the Rare Case",
               "Link": "https://shahjerry33.medium.com/idn-homograph-attack-reborn-of-the-rare-case-99fa1e342352"
            }
         ],
         "Authors": ["Jerry Shah (@Jerry)"],
         "Programs": ["-"],
         "Bugs": ["IDN homograph attack", "Account takeover", "Password reset"],
         "Bounty": "-",
         "PublicationDate": "2024-01-12",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024-20656 – Local Privilege Escalation in the VSStandardCollectorService150 Service",
               "Link": "https://www.mdsec.co.uk/2024/01/cve-2024-20656-local-privilege-escalation-in-vsstandardcollectorservice150-service/"
            }
         ],
         "Authors": ["Filip Dragovic (@filip_dragovic)"],
         "Programs": ["Microsoft (VS Code)"],
         "Bugs": ["Local Privilege Escalation", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2024-01-12",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Writeup for CVE-2023-39143: PaperCut WebDAV Vulnerability",
               "Link": "https://www.horizon3.ai/writeup-for-cve-2023-39143-papercut-webdav-vulnerability/"
            }
         ],
         "Authors": ["Naveen Sunkavally"],
         "Programs": ["PaperCut"],
         "Bugs": ["WebDAV", "Path traversal", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-12",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "(Response) Splitting Up Reverse Proxies To Reach Internal Only Paths",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/response-splitting-up-reverse-proxies-to-reach-internal-only-paths/"
            }
         ],
         "Authors": ["Tom Neaves"],
         "Programs": ["-"],
         "Bugs": ["HTTP response splitting"],
         "Bounty": "-",
         "PublicationDate": "2024-01-11",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Hunting for SSRF Bugs in PDF Generators",
               "Link": "https://www.blackhillsinfosec.com/hunting-for-ssrf-bugs-in-pdf-generators/"
            }
         ],
         "Authors": ["Sean Verity (@SeanVerity)"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2024-01-11",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "How I Earned My First Bug Bounty Reward of $600",
               "Link": "https://medium.com/@zikola1/how-i-earned-my-first-bug-bounty-reward-of-600-14c268f94bbd"
            }
         ],
         "Authors": ["Abdulrahman badawi (@zikolaasec)"],
         "Programs": ["-"],
         "Bugs": ["Broken Access Control", "Payment tampering"],
         "Bounty": "600",
         "PublicationDate": "2024-01-11",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "Attack of the week: Airdrop tracing",
               "Link": "https://blog.cryptographyengineering.com/2024/01/11/attack-of-the-week-airdrop-tracing/"
            }
         ],
         "Authors": ["Matthew Green (@matthew_d_green)"],
         "Programs": ["Apple (AirDrop)"],
         "Bugs": ["Cryptographic issues", "Privacy issue"],
         "Bounty": "-",
         "PublicationDate": "2024-01-11",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Playing With Fire – How We Executed A Critical Supply Chain Attack On Pytorch",
               "Link": "https://johnstawinski.com/2024/01/11/playing-with-fire-how-we-executed-a-critical-supply-chain-attack-on-pytorch/"
            }
         ],
         "Authors": ["John Stawinski", "Adnan Khan (@adnanthekhan)"],
         "Programs": ["PyTorch", "Meta / Facebook"],
         "Bugs": ["CI/CD", "Supply chain attack"],
         "Bounty": "5,500",
         "PublicationDate": "2024-01-11",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Privilege escalation using the XAML diagnostics API (CVE-2023-36003)",
               "Link": "https://m417z.com/Privilege-escalation-using-the-XAML-diagnostics-API-CVE-2023-36003/"
            }
         ],
         "Authors": ["Michael Maltsev (@m417z)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation", "DLL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-01-11",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Unauthenticated RCE in Adobe Coldfusion – CVE-2023-26360",
               "Link": "https://blog.securelayer7.net/unauthorized-rce-in-adobe-coldfusion/"
            }
         ],
         "Authors": ["SecureLayer7 (@SecureLayer7)"],
         "Programs": ["Adobe (ColdFusion)"],
         "Bugs": ["RCE", "Insecure deserialization", "Arbitrary file read", "Patch diffing", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-10",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023–50220 — Inductive Automation Ignition XML Deserialization to RCE",
               "Link": "https://petrusviet.medium.com/cve-2023-50220-inductive-automation-ignition-xml-deserialization-to-rce-7b395412c6cf"
            }
         ],
         "Authors": ["Petrus Viet (@VietPetrus)"],
         "Programs": ["Inductive Automation Ignition"],
         "Bugs": ["Insecure deserialization", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-10",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "How I Helped Indonesian Startup Company to Prevent Millions of PII Data Leaks",
               "Link": "https://medium.com/@blackarazi/how-i-helped-indonesian-startup-company-to-prevent-millions-of-pii-data-leaks-55ef3edbd35d"
            }
         ],
         "Authors": ["Azhari Harahap (@blackarazi)"],
         "Programs": ["-"],
         "Bugs": ["Android", "Broken Access Control", "Information disclosure"],
         "Bounty": "500",
         "PublicationDate": "2024-01-10",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "Fuzzing and Bypassing the AWS WAF",
               "Link": "https://sysdig.com/blog/fuzzing-and-bypassing-the-aws-waf/"
            }
         ],
         "Authors": ["Daniele Linguaglossa"],
         "Programs": ["AWS"],
         "Bugs": ["WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-01-09",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Roles allowing to abuse Entra ID federation for persistence and privilege escalation",
               "Link": "https://medium.com/tenable-techblog/roles-allowing-to-abuse-entra-id-federation-for-persistence-and-privilege-escalation-df9ca6e58360"
            }
         ],
         "Authors": ["Clémentin Notin (@cnotin)"],
         "Programs": ["Microsoft (Azure AD)"],
         "Bugs": ["Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2024-01-09",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Payments In Apple For Free Trails For Lifetime",
               "Link": "https://medium.com/@sam0-0/bypassing-payments-in-apple-for-free-trails-for-lifetime-8e3019dfe57b"
            }
         ],
         "Authors": ["Sam (@__Sam0_0)"],
         "Programs": ["Apple"],
         "Bugs": ["Payment bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-01-09",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "A  Straight 5-hour Escalation! Exploiting Boolean-Based SQL Injection.👽",
               "Link": "https://medium.com/@Ajakcybersecurity/a-straight-5-hour-escalation-exploiting-boolean-based-sql-injection-5d828fd3dacf"
            }
         ],
         "Authors": ["AjakCybersecurity"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-01-09",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "HTTP Chunk Extension Processing Vulnerabilities",
               "Link": "https://nowotarski.info/http-chunk-extensions/"
            }
         ],
         "Authors": ["Bartek Nowotarski"],
         "Programs": ["Golang", "Node.js", "Hyper (Rust HTTP library)", "Puma (Rails HTTP library)"],
         "Bugs": ["HTTP/2 CONTINUATION Flood", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2024-01-08",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "Blind Boolean Based SQLi By Manipulating URL",
               "Link": "https://medium.com/@zatikyan.sevada/blind-boolean-based-sqli-by-manipulating-url-96e1e086378c"
            }
         ],
         "Authors": ["Zatikyan Sevada"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2024-01-08",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Exploring Counter-strike: Global Offensive Attack Surface",
               "Link": "https://www.synacktiv.com/publications/exploring-counter-strike-global-offensive-attack-surface"
            }
         ],
         "Authors": ["Victor Cutillas (@v1csec)", "Louis Jacotot (@myr463)"],
         "Programs": ["Valve (CS:GO)"],
         "Bugs": ["Out-of-bounds Write", "Memory corruption", "Game hacking", "Reverse engineering", "Security code review"],
         "Bounty": "750",
         "PublicationDate": "2024-01-08",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-50916: Authentication Coercion Vulnerability in Kyocera Device Manager",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/"
            }
         ],
         "Authors": ["Jordan Hedges"],
         "Programs": ["Kyocera"],
         "Bugs": ["Authentication coercion", "NTLM"],
         "Bounty": "-",
         "PublicationDate": "2024-01-08",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "Bypass Cognito Account Enumeration Controls",
               "Link": "https://hackingthe.cloud/aws/enumeration/bypass_cognito_user_enumeration_controls/"
            }
         ],
         "Authors": ["Nick Frichette (@frichette_n)"],
         "Programs": ["AWS"],
         "Bugs": ["Username enumeration"],
         "Bounty": "-",
         "PublicationDate": "2024-01-08",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "MobSF Remote code execution (via CVE-2024-21633)",
               "Link": "https://github.com/0x33c0unt/CVE-2024-21633"
            }
         ],
         "Authors": ["0x33c0unt (@cybaqkebm)"],
         "Programs": ["MobSF", "iBotPeaches (apktool)"],
         "Bugs": ["Arbitrary file write", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-01-07",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "500$ Access Control Bug: Performed Restricted Actions in Developer Settings by low level user.",
               "Link": "https://medium.com/@a13h1/500-access-control-bug-performed-restricted-actions-in-developer-settings-by-low-level-user-b4ecaa6d1aa1"
            }
         ],
         "Authors": ["Abhi Sharma (@a13h1_)"],
         "Programs": ["ExamNote"],
         "Bugs": ["Broken Access Control", "Privilege escalation"],
         "Bounty": "500",
         "PublicationDate": "2024-01-07",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "How I was able to takeover any account (Zero-click ATO)",
               "Link": "https://m4dm0e.github.io/blog/2023/01/06/cognito-misconfig.html"
            }
         ],
         "Authors": ["Mohammed Al-Barbari (@m4dm0e)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Amazon cognito misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2024-01-06",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "How I Prevented a Mass Data Breach - $15,000 bounty - @bxmbn",
               "Link": "https://bxmbn.medium.com/how-i-prevented-a-mass-data-breach-15-000-bounty-bxmbn-1096e6400e3d"
            }
         ],
         "Authors": ["Kevin (@bxmbn)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "15,000",
         "PublicationDate": "2024-01-05",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "I received a Bank offer in my mailbox and discovered an IDOR vulnerability - $5,000 bounty - @bxmbn",
               "Link": "https://bxmbn.medium.com/i-received-a-bank-offer-in-my-mailbox-and-discovered-an-idor-vulnerability-5-000-bounty-bxmbn-5209cab1fba8"
            }
         ],
         "Authors": ["Kevin (@bxmbn)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "5,000",
         "PublicationDate": "2024-01-05",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "Exploiting a difficult Out-Of-Band XXE via FTP connections.",
               "Link": "https://medium.com/@p0lyxena/exploiting-a-difficult-out-of-band-xxe-via-ftp-connections-c8506f799e8b"
            }
         ],
         "Authors": ["Fuleki Ioan"],
         "Programs": ["-"],
         "Bugs": ["XXE"],
         "Bounty": "-",
         "PublicationDate": "2024-01-05",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "Stealing private messages using XSS on subdomain",
               "Link": "https://medium.com/@shcyber/stealing-private-messages-using-xss-on-subdomain-97f0304b132f"
            }
         ],
         "Authors": ["SHCyber"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-01-05",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "Entra ID Connect Arbitrary Password Overwrite",
               "Link": "https://nullg0re.com/2024/01/entra-id-connect-arbitrary-password-overwrite/"
            }
         ],
         "Authors": ["Anthony Larcher-Gore (@nullg0re)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Post-exploitation", "Active Directory", "Azure AD", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2024-01-04",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Bitwarden Heist - How To Break Into Password Vaults Without Using Passwords",
               "Link": "https://blog.redteam-pentesting.de/2024/bitwarden-heist/"
            }
         ],
         "Authors": ["RedTeam Pentesting (@RedTeamPT)"],
         "Programs": ["Bitwarden"],
         "Bugs": ["Thick client", "Insecure storage of sensitive information", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2024-01-03",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Panic!! At the YAML",
               "Link": "https://www.labs.greynoise.io/grimoire/2024-01-03-snakeyaml-deserialization/"
            }
         ],
         "Authors": ["Ron Bowes (@iagox86)"],
         "Programs": ["snakeyaml"],
         "Bugs": ["Insecure deserialization", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2024-01-03",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "Genie Aladdin Connect Retrofit Garage Door Opener: Multiple Vulnerabilities",
               "Link": "https://www.rapid7.com/blog/post/2024/01/03/genie-aladdin-connect-retrofit-garage-door-opener-multiple-vulnerabilities/"
            }
         ],
         "Authors": ["Deral Heiland (@Percent_X)"],
         "Programs": ["The Genie Company (Aladdin Connect)"],
         "Bugs": ["Android", "XSS", "Insecure data storage", "Missing authentication", "IDOR"],
         "Bounty": "-",
         "PublicationDate": "2024-01-03",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "CVE-2024–22720 / HTML Injection Vulnerability in Kanboard Group Management",
               "Link": "https://cupc4k3.medium.com/html-injection-vulnerability-in-kanboard-group-management-d9fe5154bb1b"
            }
         ],
         "Authors": ["cupc4k3"],
         "Programs": ["Kanboard"],
         "Bugs": ["HTML injection"],
         "Bounty": "-",
         "PublicationDate": "2024-01-02",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "SonicWall Discovers Critical Apache OFBiz Zero-day -AuthBiz",
               "Link": "https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/"
            }
         ],
         "Authors": ["Hasib Vhora (@HSVhora)"],
         "Programs": ["Ofbiz"],
         "Bugs": ["Authentication bypass", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2024-01-02",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "From Disclosure to High Severity: Leveraging Dyte API Key for Maximum Impact",
               "Link": "https://padsalatushal.medium.com/from-disclosure-to-high-severity-leveraging-dyte-api-key-for-maximum-impact-468c444963c6"
            }
         ],
         "Authors": ["Padsala Tushal (@PadsalaTushal)"],
         "Programs": ["-"],
         "Bugs": ["Hardcoded API keys", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2024-01-02",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "Technical Advisory – Multiple Vulnerabilities in PandoraFMS Enterprise",
               "Link": "https://research.nccgroup.com/2024/01/02/technical-advisory-multiple-vulnerabilities-in-pandorafms-enterprise/"
            }
         ],
         "Authors": ["Oliver Brooks"],
         "Programs": ["PandoraFMS"],
         "Bugs": ["Account takeover", "Information disclosure", "RCE", "Unrestricted file upload", "Stored XSS", "Arbitrary file read", "Local Privilege Escalation", "Path traversal", "DoS", "IDOR", "Hardcoded credentials"],
         "Bounty": "-",
         "PublicationDate": "2024-01-02",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "The power of Client-Side Path Traversal: How I found and escalated 2 bugs through “../”",
               "Link": "https://medium.com/@Nightbloodz/the-power-of-client-side-path-traversal-how-i-found-and-escalated-2-bugs-through-670338afc90f"
            }
         ],
         "Authors": ["Alvaro Balada"],
         "Programs": ["-"],
         "Bugs": ["Client-side Path Traversal", "CSRF", "Self-XSS", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2024-01-01",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "How I made 7K on Epic Games Bug Bounty",
               "Link": "https://infosecwriteups.com/how-i-made-7k-on-epic-games-bug-bounty-8529728b9fcf"
            }
         ],
         "Authors": ["SynapticSpace"],
         "Programs": ["Epic Games"],
         "Bugs": ["RCE", "Websockets"],
         "Bounty": "7,000",
         "PublicationDate": "2023-12-29",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "URL Redirection To DOM XSS on Hackerone Programs — Bug Bounty Tuesday",
               "Link": "https://medium.com/@kerstan/dom-xss-on-hackerone-programs-bug-bounty-tuesday-8973ecf6af95"
            }
         ],
         "Authors": ["kerstan"],
         "Programs": ["-"],
         "Bugs": ["DOM XSS", "Open redirect"],
         "Bounty": "-",
         "PublicationDate": "2023-12-28",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "Multiple RXSS",
               "Link": "https://medium.com/@0xchoudhary/multiple-rxss-f3f796287f34"
            }
         ],
         "Authors": ["Sushil Choudhary (@0xchoudhary)"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-12-28",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "Finding Insecure TrustManagers and Disabled Hostname Verification with CodeQL",
               "Link": "https://intrigus.org/research/2023/11/27/finding-insecure-trust-managers-and-disabled-hostname-verification-with-codeql/"
            }
         ],
         "Authors": ["intrigus (@intrigus_)"],
         "Programs": ["Apache Software Foundation", "Opencast", "ballerina-platform", "openMF"],
         "Bugs": ["Security code review", "MiTM", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-12-27",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Account takeover vulnerability that resulted in $2500 bounty!",
               "Link": "https://medium.com/@deadoverflow/account-takeover-vulnerability-that-resulted-in-2500-bounty-e1618363878d"
            }
         ],
         "Authors": ["Imad Husanovic (@deadoverflow_)"],
         "Programs": ["-"],
         "Bugs": ["Password reset", "Information disclosure", "Account takeover"],
         "Bounty": "2,500",
         "PublicationDate": "2023-12-25",
         "AddedDate": "2024-08-14"
      },
      {
         "Links": [
            {
               "Title": "The ART of Chaining Vulnerabilities",
               "Link": "https://ahmdhalabi.medium.com/the-art-of-chaining-vulnerabilities-e65382b7c627"
            }
         ],
         "Authors": ["Ahmad Halabi (@Ahmad_Halabi_)"],
         "Programs": ["-"],
         "Bugs": ["Android", "WAF bypass", "Bruteforce", "Hardcoded credentials", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-12-24",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Hacking Cloudflare Pages part 2",
               "Link": "https://ec0.io/post/hacking-cloudflare-pages-part-2/"
            }
         ],
         "Authors": ["ec0"],
         "Programs": ["Cloudflare"],
         "Bugs": ["Path traversal", "RCE", "Arbitrary Code Execution"],
         "Bounty": "-",
         "PublicationDate": "2023-12-23",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Out-of-Scope, Not Out-of-Impact: Unveiling Significant Sensitive Information Disclosure",
               "Link": "https://padsalatushal.medium.com/out-of-scope-not-out-of-impact-unveiling-significant-sensitive-information-disclosure-c8e76c1806e8"
            }
         ],
         "Authors": ["Padsala Tushal (@PadsalaTushal)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-12-23",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "How I Discovered SSRF on Hackerone Program",
               "Link": "https://medium.com/@kerstan/how-i-discovered-ssrf-on-hackerone-program-7bbe72334f74"
            }
         ],
         "Authors": ["kerstan"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-12-22",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Hunting for Android Privilege Escalation with a 32 Line Fuzzer",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/hunting-for-android-privilege-escalation-with-a-32-line-fuzzer/"
            }
         ],
         "Authors": ["Maksymilian Motyl"],
         "Programs": ["STM", "Xiaomi"],
         "Bugs": ["Android", "Fuzzing", "Memory corruption", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-12-22",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "DoubleTrouble",
               "Link": "https://github.com/TecR0c/DoubleTrouble"
            }
         ],
         "Authors": ["Rocco Calvi (@TecR0c)", "Steven Seeley (@steventseeley)"],
         "Programs": ["Inductive Automation Ignition"],
         "Bugs": ["RCE", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-12-22",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "Weaponizing DHCP DNS Spoofing — A Hands-On Guide",
               "Link": "https://www.akamai.com/blog/security-research/2023/dec/weaponizing-dhcp-dns-spoofing-hands-on-guide"
            }
         ],
         "Authors": ["Ori David (@oridavid123)"],
         "Programs": ["Microsoft"],
         "Bugs": ["DHCP", "Active Directory", "DNS spoofing"],
         "Bounty": "-",
         "PublicationDate": "2023-12-21",
         "AddedDate": "2024-01-03"
      },
      {
         "Links": [
            {
               "Title": "Advisory CVE-2023-43042 – IBM Backup Products Superuser Information Disclosure",
               "Link": "https://labs.jumpsec.com/advisory-cve-2023-43042-ibm-backup-products-superuser-information-disclosure/"
            }
         ],
         "Authors": ["Max Corbridge (@CorbridgeMax)"],
         "Programs": ["IBM"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-12-21",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "SSH ProxyCommand == unexpected code execution (CVE-2023-51385)",
               "Link": "https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.html"
            }
         ],
         "Authors": ["Vin01"],
         "Programs": ["OpenSSH"],
         "Bugs": ["OS command injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-12-20",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "One Supply Chain Attack to Rule Them All",
               "Link": "https://adnanthekhan.com/2023/12/20/one-supply-chain-attack-to-rule-them-all/"
            }
         ],
         "Authors": ["Adnan Khan (@adnanthekhan)"],
         "Programs": ["GitHub"],
         "Bugs": ["CI/CD", "Supply chain attack"],
         "Bounty": "20,000",
         "PublicationDate": "2023-12-20",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "How I Found SQL Injection worth of $4,000 bounty",
               "Link": "https://roberto99.medium.com/how-i-found-sql-injection-worth-of-4-000-bounty-16ca09cbf8ec"
            }
         ],
         "Authors": ["Roberto Nunes (@0x_Akoko)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "4,000",
         "PublicationDate": "2023-12-20",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Duplicate CSRF… Leads to",
               "Link": "https://shellbreaker.hashnode.dev/duplicate-csrf-leads-to"
            }
         ],
         "Authors": ["Bhavesh aka ShellBreaker (@shellbreaker_)"],
         "Programs": ["-"],
         "Bugs": ["Self-XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-12-19",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "How One Bug Scored Me Double Rewards!",
               "Link": "https://anasbetis023.medium.com/how-one-bug-scored-me-double-rewards-355b8d02cdbf"
            }
         ],
         "Authors": ["Anas H Hmaidy"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "IDOR"],
         "Bounty": "300",
         "PublicationDate": "2023-12-19",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "That time I broke into an API and became a billionaire",
               "Link": "https://danaepp.com/that-time-i-broke-into-an-api-and-became-a-billionaire"
            }
         ],
         "Authors": ["Dana Epp (@DanaEpp)"],
         "Programs": ["-"],
         "Bugs": ["XXE"],
         "Bounty": "-",
         "PublicationDate": "2023-12-19",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "Hacking ISP CPE equipment: FiberHome",
               "Link": "https://gergelykalman.com/hacking-isp-cpe-equipment-fiberhome.html"
            }
         ],
         "Authors": ["Gergely Kalman (@gergely_kalman)"],
         "Programs": ["FiberHome"],
         "Bugs": ["Cryptographic issues", "Weak credentials", "Missing authentication", "XSS", "Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-12-18",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Exploiting QUIC's Path Validation",
               "Link": "https://seemann.io/posts/2023-12-18-exploiting-quics-path-validation/"
            }
         ],
         "Authors": ["Marten Seemann (@m4r73n)"],
         "Programs": ["-"],
         "Bugs": ["QUIC"],
         "Bounty": "-",
         "PublicationDate": "2023-12-18",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Terrapin Attack",
               "Link": "https://terrapin-attack.com"
            }
         ],
         "Authors": ["Fabian Bäumer (@TrueSkrillor)", "Marcus Brinkmann (@lambdafu)", "Jörg Schwenk (@JoergSchwenk)"],
         "Programs": ["OpenSSH", "AsyncSSH"],
         "Bugs": ["Downgrade attack", "MiTM", "Prefix truncation attack", "Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2023-12-18",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-6483: Improper/missing API authentication in ADiTaaS v5.1",
               "Link": "https://eaton-works.com/2023/12/18/aditaas-cve-2023-6483/"
            }
         ],
         "Authors": ["Eaton Z. (@XeEaton)"],
         "Programs": ["ADiTaaS"],
         "Bugs": ["Missing authentication", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-12-18",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "SMTP Smuggling - Spoofing E-Mails Worldwide",
               "Link": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"
            }
         ],
         "Authors": ["Timo Longin (@timolongin)"],
         "Programs": ["Microsoft", "Cisco", "GMX"],
         "Bugs": ["SMTP smuggling"],
         "Bounty": "-",
         "PublicationDate": "2023-12-18",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Mute the Sound: Chaining Vulnerabilities to Achieve RCE on Outlook: Pt 1",
               "Link": "https://www.akamai.com/blog/security-research/2023/dec/chaining-vulnerabilities-to-achieve-rce-part-one"
            },
            {
               "Title": "Pt 2",
               "Link": "https://www.akamai.com/blog/security-research/chaining-vulnerabilities-to-achieve-rce-part-two"
            }
         ],
         "Authors": ["Ben Barnea (@nachoskrnl)"],
         "Programs": ["Microsoft (Outlook)"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-12-18",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Apache Lucene Injection on Auth0 Integration",
               "Link": "https://blog.stratumsecurity.com/2023/12/18/apache-lucene-injection-on-auth0-implementation/"
            }
         ],
         "Authors": ["Colin McQueen"],
         "Programs": ["-"],
         "Bugs": ["Lucene injection"],
         "Bounty": "-",
         "PublicationDate": "2023-12-18",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "From an Innocent Client-Side Path Traversal to Account Takeover",
               "Link": "https://kapytein.nl/from-an-innocent-client-side-path-traversal-to-account-takeover"
            }
         ],
         "Authors": ["Nadir (@kapytein)"],
         "Programs": ["-"],
         "Bugs": ["Client-side Path Traversal", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-12-17",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "When not to rely on Automated Tools",
               "Link": "https://medium.com/@rodriguezjorgex/when-not-to-rely-on-automated-tools-429b331e0613"
            }
         ],
         "Authors": ["Rodriguezjorgex"],
         "Programs": ["-"],
         "Bugs": ["Prototype pollution"],
         "Bounty": "-",
         "PublicationDate": "2023-12-16",
         "AddedDate": "2024-01-03"
      },
      {
         "Links": [
            {
               "Title": "$500 Bounty by Escalating DOM XSS to Stored XSS",
               "Link": "https://medium.com/@rodriguezjorgex/escalating-dom-xss-to-stored-xss-eb6f3a669af3"
            }
         ],
         "Authors": ["Rodriguezjorgex"],
         "Programs": ["-"],
         "Bugs": ["DOM XSS", "Stored XSS", "Self-XSS"],
         "Bounty": "500",
         "PublicationDate": "2023-12-16",
         "AddedDate": "2024-01-03"
      },
      {
         "Links": [
            {
               "Title": "Self-XSS to Stored XSS",
               "Link": "https://medium.com/@rodriguezjorgex/self-xss-to-stored-xss-b4b999610c5b"
            }
         ],
         "Authors": ["Rodriguezjorgex"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS", "Self-XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-12-16",
         "AddedDate": "2024-01-03"
      },
      {
         "Links": [
            {
               "Title": "Subdomain Takeover in Azure Trafficmanager for Fun & Profit",
               "Link": "https://padsalatushal.medium.com/subdomain-takeover-in-azure-trafficmanager-for-fun-profit-09c858ca3d0e"
            }
         ],
         "Authors": ["Padsala Tushal (@PadsalaTushal)"],
         "Programs": ["-"],
         "Bugs": ["Subdomain takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-12-15",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "One port can be a costly mistake | Attack The Rsync Service in a Private Program",
               "Link": "https://medium.com/@sword0x00/one-port-can-be-a-costly-mistake-attack-the-rsync-service-in-a-private-program-cdbf9ecc650d"
            }
         ],
         "Authors": ["Mohanad Hesham (@sword0x00)"],
         "Programs": ["-"],
         "Bugs": ["Rsync", "Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2023-12-15",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "Google OAuth is broken (sort of)",
               "Link": "https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/"
            }
         ],
         "Authors": ["Dylan Ayrey (@insecurenature)"],
         "Programs": ["Google", "Zoom", "Slack"],
         "Bugs": ["OAuth"],
         "Bounty": "1,337",
         "PublicationDate": "2023-12-15",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "How I Automatically Discovered SSRF in Hackerone Program",
               "Link": "https://medium.com/@kerstan/how-i-automatically-discovered-ssrf-in-hackerone-program-2ae0b7a6ef1b"
            }
         ],
         "Authors": ["kerstan"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-12-15",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-22524: RCE Vulnerability in Atlassian Companion for macOS",
               "Link": "https://www.imperva.com/blog/cve-2023-22524-rce-vulnerability-in-atlassian-companion-for-macos/"
            }
         ],
         "Authors": ["Ron Masas (@RonMasas)"],
         "Programs": ["Atlassian"],
         "Bugs": ["RCE", "MacOS", "Websockets", "Thick client", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-12-14",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "npm search RCE? - Escape Sequence Injection",
               "Link": "https://blog.solidsnail.com/posts/npm-esc-seq"
            }
         ],
         "Authors": ["solid-snail"],
         "Programs": ["Radare2", "GitHub", "NPM CLI"],
         "Bugs": ["RCE", "Escape sequence injection"],
         "Bounty": "-",
         "PublicationDate": "2023-12-14",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Spamming Microsoft 365 Like It’s 1995 ",
               "Link": "https://www.blackhillsinfosec.com/spamming-microsoft-365-like-its-1995/"
            }
         ],
         "Authors": ["Steve Borosh (@424f424f)"],
         "Programs": ["Microsoft (Exchange)"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2023-12-14",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "Remote Code execution at ws1.aholdusa.com — Compromising logins of Ahold Delhaize USA employees for >3.5 years (or even 18 years?)",
               "Link": "https://medium.com/@jonathanbouman/remote-code-execution-at-ws1-aholdusa-com-compromising-logins-of-ahold-delhaize-usa-employees-c7c9aca7e05d"
            }
         ],
         "Authors": ["Jonathan Bouman (@JonathanBouman)"],
         "Programs": ["Ahold Delhaize"],
         "Bugs": ["RCE", "Reflected XSS", "SSTI"],
         "Bounty": "300",
         "PublicationDate": "2023-12-14",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "OS Command Injection in cPH2 Charging Station <2.0.0 (CVE-2023-46359 and CVE-2023-46360)",
               "Link": "https://www.offensity.com/en/blog/os-command-injection-in-cph2-charging-station-200-cve-2023-46359-and-cve-2023-46360/"
            }
         ],
         "Authors": ["Ewen Coppens"],
         "Programs": ["eCharge Hardy Barth"],
         "Bugs": ["OS command injection"],
         "Bounty": "-",
         "PublicationDate": "2023-12-14",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "2023 Starlink Router Gen 2 XSS",
               "Link": "https://medium.com/@hackintoanetwork/starlink-router-gen-2-is-vulnerable-to-xss-48cfcadd0b13"
            }
         ],
         "Authors": ["hackintoanetwork"],
         "Programs": ["SpaceX/Starlink"],
         "Bugs": ["XSS", "gRPC"],
         "Bounty": "-",
         "PublicationDate": "2023-12-14",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "How OAuth Implicit Flow Led To Hundreds Of User Accounts Being Accessed? ",
               "Link": "https://payatu.com/blog/how-oauth-implicit-flow-led-to-hundreds-of-user-accounts-being-accessed/"
            }
         ],
         "Authors": ["Sufiyan Gouri (@gouri_sufyan)"],
         "Programs": ["-"],
         "Bugs": ["OAuth"],
         "Bounty": "-",
         "PublicationDate": "2023-12-13",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Technical Advisory – Multiple Vulnerabilities in Nagios XI",
               "Link": "https://research.nccgroup.com/2023/12/13/technical-advisory-multiple-vulnerabilities-in-nagios-xi/"
            }
         ],
         "Authors": ["Oliver Brooks"],
         "Programs": ["Nagios"],
         "Bugs": ["RCE", "Missing authentication", "OS command injection", "Local Privilege Escalation", "Stored XSS", "Plaintext Storage of a Password", "Weak credentials", "Privilege escalation", "Post-exploitation"],
         "Bounty": "-",
         "PublicationDate": "2023-12-13",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Securing our home labs: Frigate code review",
               "Link": "https://github.blog/2023-12-13-securing-our-home-labs-frigate-code-review/"
            }
         ],
         "Authors": ["Logan MacLaren", "Jorge Rosillo (@jorge_ctf)"],
         "Programs": ["Frigate"],
         "Bugs": ["OAuth", "Broken authorization", "Broken authentication", "SSRF", "CI/CD", "Supply chain attack", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-12-13",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Unauthenticated Access to GCP Dataproc Can Lead to Data Leak",
               "Link": "https://orca.security/resources/blog/unauthenticated-access-to-google-cloud-dataproc/"
            }
         ],
         "Authors": ["Roi Nisimi (@roinisimi)"],
         "Programs": ["Google (GCP)"],
         "Bugs": ["Cloud", "Data leak", "Post-exploitation"],
         "Bounty": "-",
         "PublicationDate": "2023-12-12",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "One Scheme to Rule Them All: OAuth Account Takeover",
               "Link": "https://blog.ostorlab.co/one-scheme-to-rule-them-all.html"
            }
         ],
         "Authors": ["Ostorlab (@OstorlabSec)"],
         "Programs": ["-"],
         "Bugs": ["OAuth", "Account takeover", "Android", "iOS"],
         "Bounty": "-",
         "PublicationDate": "2023-12-12",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "pfSense Security: Sensing Code Vulnerabilities with SonarCloud",
               "Link": "https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/"
            }
         ],
         "Authors": ["Oskar Zeino-Mahmalat"],
         "Programs": ["pfSense"],
         "Bugs": ["Reflected XSS", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-12-12",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "Silverpeas App: Multiple CVEs leading to File Read on Server",
               "Link": "https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/"
            }
         ],
         "Authors": ["Tyler Ramsbey (@Tyler_Ramsbey)"],
         "Programs": ["Silverpeas"],
         "Bugs": ["Stored XSS", "Arbitrary file read"],
         "Bounty": "-",
         "PublicationDate": "2023-12-12",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "How I got $300 for Default Credential Login at Bugcrowd 🎉",
               "Link": "https://medium.com/@avbhijitdutta99/how-i-got-300-for-default-credential-login-at-bugcrowd-30368eb698f7"
            }
         ],
         "Authors": ["Abhijit Dutta (@Abhijit9799)"],
         "Programs": ["-"],
         "Bugs": ["Default credentials"],
         "Bounty": "300",
         "PublicationDate": "2023-12-12",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "So you found Auth0 secrets, now what?",
               "Link": "https://blog.prodefense.io/so-you-found-auth0-secrets-now-what-0945642ac09b"
            }
         ],
         "Authors": ["Matthew Keeley (@Nightbanes)"],
         "Programs": ["-"],
         "Bugs": ["LFI", "Auth0", "Azure AD"],
         "Bounty": "-",
         "PublicationDate": "2023-12-11",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Introducing Wrapwrap: Using PHP Filters To Wrap A File With A Prefix And Suffix",
               "Link": "https://www.ambionics.io/blog/wrapwrap-php-filters-suffix"
            }
         ],
         "Authors": ["Charles Fol (@cfreal_)"],
         "Programs": ["-"],
         "Bugs": ["PHP filter chain", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-12-11",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Remote code execution and elevation of local privileges in Mitel Unify OpenStage and OpenScape VoIP phones",
               "Link": "https://www.pentagrid.ch/en/blog/rce-and-local-root-in-openstage-and-openscape-phones/"
            }
         ],
         "Authors": ["Pentagrid (@pentagridsec)"],
         "Programs": ["Mitel (Atos Unify)"],
         "Bugs": ["VoIP", "RCE", "Missing authentication", "MiTM", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-12-11",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "CORS Misconfiguration -> PII Leak",
               "Link": "https://medium.com/@boogsta/cors-misconfiguration-pii-leak-2765ff5b7115"
            }
         ],
         "Authors": ["Boogsta"],
         "Programs": ["-"],
         "Bugs": ["CORS misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-12-10",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "3 Symfony (RCE): A Peek Behind the Curtain",
               "Link": "https://medium.com/@bxrowski0x/3-symfony-rce-a-peek-behind-the-curtain-83da5433e149"
            }
         ],
         "Authors": ["Omar ElSayed (@bxrowski0x)"],
         "Programs": ["-"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-12-09",
         "AddedDate": "2024-01-03"
      },
      {
         "Links": [
            {
               "Title": "How i got $15000 Reward by Apple - Information Disclosure",
               "Link": "http://whitehathaji.blogspot.com/2023/12/how-i-got-15000-reward-by-apple.html"
            }
         ],
         "Authors": ["Mohd haji (@mohdhaji24)"],
         "Programs": ["Apple"],
         "Bugs": ["Information disclosure"],
         "Bounty": "15,000",
         "PublicationDate": "2023-12-09",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Unraveling The Story of Multiple Admin Panel Compromises",
               "Link": "https://vedanttekale20.medium.com/unraveling-the-story-of-multiple-admin-panel-compromises-baac4444285f"
            }
         ],
         "Authors": ["Vedant Tekale (@_justYnot)"],
         "Programs": ["-"],
         "Bugs": ["Weak credentials", "Authentication bypass", "HTTP response manipulation"],
         "Bounty": "500",
         "PublicationDate": "2023-12-08",
         "AddedDate": "2024-01-05"
      },
      {
         "Links": [
            {
               "Title": "Spoofing DNS Records by Abusing DHCP DNS Dynamic Updates",
               "Link": "https://www.akamai.com/blog/security-research/spoofing-dns-by-abusing-dhcp"
            }
         ],
         "Authors": ["Ori David (@oridavid123)"],
         "Programs": ["Microsoft"],
         "Bugs": ["DHCP", "Active Directory", "DNS spoofing"],
         "Bounty": "-",
         "PublicationDate": "2023-12-07",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "SonicWall WXA – Authentication Bypass and Remote Code Execution Vulnerability",
               "Link": "https://www.praetorian.com/blog/sonicwall-wxa-authentication-bypass-and-rce-vulnerability/"
            }
         ],
         "Authors": ["Adam Crosser"],
         "Programs": ["SonicWall"],
         "Bugs": ["Authentication bypass", "Hardcoded credentials", "RCE", "Argument injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-12-07",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Tricks for Reliable Split-Second DNS Rebinding in Chrome and Safari",
               "Link": "https://www.intruder.io/research/split-second-dns-rebinding-in-chrome-and-safari"
            }
         ],
         "Authors": ["Daniel Thatcher (@_danielthatcher)"],
         "Programs": ["Google (Chrome)", "Apple (Safari)"],
         "Bugs": ["DNS rebinding"],
         "Bounty": "-",
         "PublicationDate": "2023-12-06",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Writing Burp Bambda Filters Like a Boss",
               "Link": "https://danaepp.com/writing-burp-bambda-filters"
            }
         ],
         "Authors": ["Dana Epp (@DanaEpp)"],
         "Programs": ["-"],
         "Bugs": ["JWT", "Broken authorization"],
         "Bounty": "-",
         "PublicationDate": "2023-12-05",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Analyzing the SonicWall Custom Grub LUKS Encryption Modifications",
               "Link": "https://www.praetorian.com/blog/sonicwall-custom-grub-luks-encryption/"
            }
         ],
         "Authors": ["Adam Crosser", "Michael Weber (@BouncyHat)"],
         "Programs": ["SonicWall"],
         "Bugs": ["Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2023-12-05",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Blind CSS Exfiltration: exfiltrate unknown web pages",
               "Link": "https://portswigger.net/research/blind-css-exfiltration"
            }
         ],
         "Authors": ["Gareth Heyes (@garethheyes)"],
         "Programs": ["-"],
         "Bugs": ["Blind CSS exfiltration", "Blind HTML injection"],
         "Bounty": "-",
         "PublicationDate": "2023-12-05",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Argument injection vulnerability in multiple Atos Unify OpenScape products",
               "Link": "https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/"
            }
         ],
         "Authors": ["Armin Weihbold (@koyaan5)"],
         "Programs": ["Mitel (Atos Unify)"],
         "Bugs": ["Argument injection", "RCE", "Authentication bypass", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-12-05",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "Multiple Vulnerabilities In Extreme Networks ExtremeXOS",
               "Link": "https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/"
            }
         ],
         "Authors": ["David Yesland (@daveysec)"],
         "Programs": ["Extreme Networks"],
         "Bugs": ["Arbitrary file read", "Arbitrary file write", "SSRF", "RCE", "Privilege escalation", "Local Privilege Escalation", "CSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-12-05",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Achieving Remote Code Execution in Steam: a journey into the Remote Play protocol",
               "Link": "https://blog.thalium.re/posts/achieving-remote-code-execution-in-steam-remote-play/"
            }
         ],
         "Authors": ["Valentino Ricotta"],
         "Programs": ["Valve"],
         "Bugs": ["RCE", "Reverse engineering", "Fuzzing", "Path traversal", "Memory corruption", "Heap overflow", "Format string vulnerability"],
         "Bounty": "-",
         "PublicationDate": "2023-12-04",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "It's not a Feature, It's a Vulnerability",
               "Link": "https://blog.solidsnail.com/posts/vscode-shell-integ-rce"
            }
         ],
         "Authors": ["solid-snail"],
         "Programs": ["Microsoft"],
         "Bugs": ["RCE", "OS command injection"],
         "Bounty": "-",
         "PublicationDate": "2023-12-04",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "Owncloud: details about CVE-2023-49103 and CVE-2023-49105",
               "Link": "https://www.ambionics.io/blog/owncloud-cve-2023-49103-cve-2023-49105"
            }
         ],
         "Authors": ["Charles Fol (@cfreal_)"],
         "Programs": ["ownCloud"],
         "Bugs": ["RCE", "Privilege escalation", "Authentication bypass", "Information disclosure", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-12-04",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "We Hacked Ourselves With DNS Rebinding",
               "Link": "https://www.intruder.io/research/we-hacked-ourselves-with-dns-rebinding"
            }
         ],
         "Authors": ["Daniel Thatcher (@_danielthatcher)"],
         "Programs": ["Intruder"],
         "Bugs": ["DNS rebinding"],
         "Bounty": "-",
         "PublicationDate": "2023-12-01",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-37927 & CVE-2023-37928 - Multiple post-auth blind OS command and Python code injection vulnerabilities in Zyxel’s NAS326 devices",
               "Link": "https://bugprove.com/knowledge-hub/cve-2023-37927-and-cve-2023-37928-multiple-post-auth-blind-os-command-and-python-code-injection-vulnerabilities-in-zyxel-s-nas-326-devices/"
            }
         ],
         "Authors": ["Gábor Selján (@GaborSeljan)"],
         "Programs": ["Zyxel"],
         "Bugs": ["Code injection", "OS command injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-11-30",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-4473 & CVE-2023-4474 - Authentication bypass and multiple blind OS command injection vulnerabilities in Zyxel’s NAS326 devices",
               "Link": "https://bugprove.com/knowledge-hub/cve-2023-4473-and-cve-2023-4474-authentication-bypass-and-multiple-blind-os-command-injection-vulnerabilities-in-zyxel-s-nas-326-devices/"
            }
         ],
         "Authors": ["Gábor Selján (@GaborSeljan)"],
         "Programs": ["Zyxel"],
         "Bugs": ["Authentication bypass", "OS command injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-11-30",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Securing our home labs: Home Assistant code review",
               "Link": "https://github.blog/2023-11-30-securing-our-home-labs-home-assistant-code-review/"
            }
         ],
         "Authors": ["Alvaro Muñoz (@pwntester)"],
         "Programs": ["Home Assistant"],
         "Bugs": ["Insecure deserialization", "CSRF", "RCE", "Code injection", "Android", "iOS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-11-30",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Gadgets chain in Laravel",
               "Link": "https://fenrisk.com/publications/blogpost/2023/11/30/gadgets-chain-in-laravel/"
            }
         ],
         "Authors": ["Maxime Rinaudo (@MaxRio13)"],
         "Programs": ["-"],
         "Bugs": ["Insecure deserialization", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-11-30",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "TRAP; RESET; POISON; - Taking over a country Kaminsky style",
               "Link": "https://sec-consult.com/blog/detail/taking-over-a-country-kaminsky-style/"
            }
         ],
         "Authors": ["Timo Longin (@timolongin)"],
         "Programs": ["-"],
         "Bugs": ["DNS cache poisoning", "Kaminsky attack", "DoS", "Email spoofing"],
         "Bounty": "-",
         "PublicationDate": "2023-11-29",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "PII Disclosure Worth $750",
               "Link": "https://vijetareigns.medium.com/pii-disclosure-worth-750-758b72e7e8ca"
            }
         ],
         "Authors": ["the_unluck_guy (@7he_unlucky_guy)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "750",
         "PublicationDate": "2023-11-29",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Gadgets chain in WordPress",
               "Link": "https://fenrisk.com/publications/blogpost/2023/11/22/gadgets-chain-in-wordpress/"
            }
         ],
         "Authors": ["Maxime Rinaudo (@MaxRio13)"],
         "Programs": ["-"],
         "Bugs": ["Insecure deserialization", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-11-29",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Bypassing a noexec by elf roping",
               "Link": "https://blog.xilokar.info/bypassing-a-noexec-by-elf-roping.html"
            }
         ],
         "Authors": ["Xilokar (@xilokar)"],
         "Programs": ["-"],
         "Bugs": ["noexec bypass", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-11-27",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "Ray, Versions 2.6.3, 2.8.0",
               "Link": "https://bishopfox.com/blog/ray-versions-2-6-3-2-8-0"
            }
         ],
         "Authors": ["Berenice Flores Garcia"],
         "Programs": ["Anyscale (Ray)"],
         "Bugs": ["Missing authentication", "SSRF", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-11-27",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "Unmasking an RFI to LFI Escalation",
               "Link": "https://laburity.com/unmasking-an-rfi-to-lfi-escalation/"
            }
         ],
         "Authors": ["Laburity Research Team"],
         "Programs": ["-"],
         "Bugs": ["RFI", "LFI", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-11-23",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Account takeover through register functionnality",
               "Link": "https://web.archive.org/web/20240106050326/https://izn0u.github.io/2023/11/23/account-takeover-through-register-functionnality.html"
            }
         ],
         "Authors": ["izn0u (@izn0u)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-11-23",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "Zeal Wallet Browser Extension and Backend Security Audit Report (Q3 2023)",
               "Link": "https://doyensec.com/resources/Doyensec_Zeal_SecurityReport_Q32023_v5_AfterRetest.pdf"
            }
         ],
         "Authors": ["Norbert Szetei (@73696e65)", "Szymon Drosdzol", "John Villamil"],
         "Programs": ["Grwth Lbs Ltd"],
         "Bugs": ["SSRF", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-11-22",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Visual Studio Code Security: Finding New Vulnerabilities in the NPM Integration (3/3)",
               "Link": "https://www.sonarsource.com/blog/vscode-security-finding-new-vulnerabilities-npm-integration/"
            }
         ],
         "Authors": ["Thomas Chauchefoin (@swapgs)", "Paul Gerste"],
         "Programs": ["Microsoft (VS Code)"],
         "Bugs": ["RCE", "Argument injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-11-21",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Hijacking OAuth Code via Reverse Proxy for Account Takeover",
               "Link": "https://blog.voorivex.team/hijacking-oauth-code-via-reverse-proxy-for-account-takeover"
            }
         ],
         "Authors": ["0xrz (@omidxrz)"],
         "Programs": ["-"],
         "Bugs": ["OAuth", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-11-17",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Magento Template Engine, A Story Of CVE-2022-24086",
               "Link": "https://www.synacktiv.com/publications/magento-template-engine-a-story-of-cve-2022-24086"
            }
         ],
         "Authors": ["Antoine Gicquel (@blueshhit)"],
         "Programs": ["Magento"],
         "Bugs": ["SSTI", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-11-16",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Critical Variable Mass Assignment Vulnerability in Adobe ColdFusion (CVE-2023-44350)",
               "Link": "https://www.hoyahaxa.com/2023/11/critical-variable-mass-assignment.html"
            }
         ],
         "Authors": ["Brian (@hoyahaxa)"],
         "Programs": ["Adobe (ColdFusion)"],
         "Bugs": ["Mass assignment", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-11-15",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "sqlol (CVE-2023-32422) - a macOS TCC bypass",
               "Link": "https://gergelykalman.com/sqlol-CVE-2023-32422-a-macos-tcc-bypass.html"
            }
         ],
         "Authors": ["Gergely Kalman (@gergely_kalman)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["TCC bypass", "Local Privilege Escalation"],
         "Bounty": "30,500",
         "PublicationDate": "2023-11-15",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "All the Small Things: Azure CLI Leakage and Problematic Usage Patterns",
               "Link": "https://www.paloaltonetworks.com/blog/prisma-cloud/secrets-leakage-user-error-azure-cli/"
            }
         ],
         "Authors": ["Aviad Hahami (@_0xffd)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["CI/CD", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-11-14",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "OMGCICD - Attacking GitLab CI/CD Via Shared Runners",
               "Link": "https://pulsesecurity.co.nz/articles/OMGCICD-gitlab"
            }
         ],
         "Authors": ["Denis Andzakovic"],
         "Programs": ["-"],
         "Bugs": ["CI/CD"],
         "Bounty": "-",
         "PublicationDate": "2023-11-14",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Tapping into a telecommunications company’s office cameras",
               "Link": "https://eaton-works.com/2023/11/14/telecom-camera-hack/"
            }
         ],
         "Authors": ["Eaton Z. (@XeEaton)"],
         "Programs": ["-"],
         "Bugs": ["Missing authentication", "Privacy issue"],
         "Bounty": "-",
         "PublicationDate": "2023-11-14",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "lateralus (CVE-2023-32407) - a macOS TCC bypass",
               "Link": "https://gergelykalman.com/lateralus-CVE-2023-32407-a-macos-tcc-bypass.html"
            }
         ],
         "Authors": ["Gergely Kalman (@gergely_kalman)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["TCC bypass", "Local Privilege Escalation"],
         "Bounty": "30,500",
         "PublicationDate": "2023-11-14",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "HTTP is dead... Long live HTTP?!",
               "Link": "https://blog.malicious.group/http-is-dead-long-live-http/"
            }
         ],
         "Authors": ["d3d (@deadvolvo)"],
         "Programs": ["Akamai", "F5"],
         "Bugs": ["HTTP request smuggling", "Web cache poisoning"],
         "Bounty": "-",
         "PublicationDate": "2023-11-14",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "Uncovering a crazy privilege escalation from Chrome extensions",
               "Link": "https://0x44.xyz/blog/cve-2023-4369/index.html"
            }
         ],
         "Authors": ["Derin Eryılmaz (@deryilz)"],
         "Programs": ["Google (Chrome, ChromeOS)"],
         "Bugs": ["XSS", "Browser hacking"],
         "Bounty": "10,000",
         "PublicationDate": "2023-11-14",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "Visual Studio Code Security: Markdown Vulnerabilities in Third-Party Extensions (2/3)",
               "Link": "https://www.sonarsource.com/blog/vscode-security-markdown-vulnerabilities-in-extensions/"
            }
         ],
         "Authors": ["Thomas Chauchefoin (@swapgs)", "Paul Gerste"],
         "Programs": ["GitKraken", "Microsoft"],
         "Bugs": ["RCE", "Arbitrary Code Execution", "Markdown injection", "Security code review"],
         "Bounty": "100",
         "PublicationDate": "2023-11-14",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Forging signed commits on GitHub",
               "Link": "https://iter.ca/post/gh-sig-pwn/"
            }
         ],
         "Authors": ["iter.ca (@_smitop)"],
         "Programs": ["GitHub"],
         "Bugs": ["Parsing issue", "Regex", "Signature bypass"],
         "Bounty": "10,000",
         "PublicationDate": "2023-11-11",
         "AddedDate": "2024-01-25"
      },
      {
         "Links": [
            {
               "Title": "Not Your Stdout Bug - RCE in Cosmos SDK",
               "Link": "https://maxwelldulin.com/BlogPost/stdout-cosmos-sdk-rce"
            }
         ],
         "Authors": ["Maxwell Dulin (@Dooflin5)"],
         "Programs": ["Cosmos"],
         "Bugs": ["RCE", "DoS", "Security code review"],
         "Bounty": "2,500",
         "PublicationDate": "2023-11-10",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "Navigating the Sea, Exploiting DigitalOcean APIs",
               "Link": "https://www.imperva.com/blog/navigating-the-sea-exploiting-digitalocean-apis/"
            }
         ],
         "Authors": ["Ron Masas (@RonMasas)"],
         "Programs": ["DigitalOcean"],
         "Bugs": ["Broken Access Control", "BFLA"],
         "Bounty": "-",
         "PublicationDate": "2023-11-07",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Discovering and Exploiting a XML External Entity (XXE) Vulnerability in a Public Bug Bounty Program",
               "Link": "https://medium.com/@medz20876/discovering-and-exploiting-a-xml-external-entity-xxe-vulnerability-in-a-public-bug-bounty-program-88bd35dd1095"
            }
         ],
         "Authors": ["r3aper__"],
         "Programs": ["-"],
         "Bugs": ["XXE"],
         "Bounty": "-",
         "PublicationDate": "2023-11-06",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "Race Conditions with pipelining",
               "Link": "https://infosecwriteups.com/race-conditions-with-pipelining-9034358a2781"
            }
         ],
         "Authors": ["Abbas Heybati (@abbas_heybati)"],
         "Programs": ["-"],
         "Bugs": ["Race condition"],
         "Bounty": "-",
         "PublicationDate": "2023-11-05",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Attacking Go's Lagged Fibonacci Generator",
               "Link": "https://www.leviathansecurity.com/blog/attacking-gos-lagged-fibonacci-generator"
            }
         ],
         "Authors": ["Dylan Katz (@Plazmaz)"],
         "Programs": ["-"],
         "Bugs": ["Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2023-11-03",
         "AddedDate": "2024-07-30"
      },
      {
         "Links": [
            {
               "Title": "Hacking Google Bard - From Prompt Injection to Data Exfiltration",
               "Link": "https://embracethered.com/blog/posts/2023/google-bard-data-exfiltration/"
            }
         ],
         "Authors": ["Johann Rehberger (wunderwuzzi23)"],
         "Programs": ["Google (Bard)"],
         "Bugs": ["LLM", "AI", "Prompt injection", "Image Markdown Injection", "CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-11-03",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "The Deputy Is Confused About AWS Security Hub",
               "Link": "https://blog.plerion.com/the-deputy-is-confused-about-aws-security-hub/"
            }
         ],
         "Authors": ["Daniel Grzelak (@dagrz)"],
         "Programs": ["AWS"],
         "Bugs": ["Confused deputy", "Information disclosure", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-11-03",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "OLE object are still dangerous today — Exploiting Microsoft Office",
               "Link": "https://github.com/edwardzpeng/presentations/blob/main/POC%202023/OLE%20object%20are%20still%20dangerous%20today%20%E2%80%94%20Exploiting%20Microsoft%20Office.pdf"
            }
         ],
         "Authors": ["zhiniang peng (@edwardzpeng)"],
         "Programs": ["Microsoft (Office)"],
         "Bugs": ["Memory corruption", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-11-02",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Blog Post: Bypassing an Admin Panel with SQL Injection",
               "Link": "https://medium.com/@medz20876/blog-post-bypassing-an-admin-panel-with-sql-injection-20b844442711"
            }
         ],
         "Authors": ["r3aper__"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-11-02",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "$7000 Bounty on a Single Web Application",
               "Link": "https://blog.voorivex.team/7000-bounty-on-a-single-web-application"
            }
         ],
         "Authors": ["Amir Abbas (@ImAyrix)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Unrestricted file upload", "Stored XSS", "Reflected XSS", "Account takeover", "IDOR", "Logic flaw"],
         "Bounty": "7,000",
         "PublicationDate": "2023-11-01",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "XSS on the Oauth callback URL with CSP bypass leading to zero-click account takeover",
               "Link": "https://infosecwriteups.com/xss-on-the-oauth-callback-url-with-csp-bypass-leading-to-zero-click-account-takeover-c6c870b234bd"
            }
         ],
         "Authors": ["Serj Novoselov (@novoselov_s)"],
         "Programs": ["-"],
         "Bugs": ["OAuth", "XSS", "CSP bypass", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-10-29",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "DOM-based race condition: racing in the browser for fun",
               "Link": "https://blog.ryotak.net/post/dom-based-race-condition/"
            }
         ],
         "Authors": ["RyotaK (@ryotkak)"],
         "Programs": ["-"],
         "Bugs": ["Race condition", "XSS", "XSLeaks"],
         "Bounty": "-",
         "PublicationDate": "2023-10-29",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Turning a boring file move into a privilege escalation on Mac",
               "Link": "https://pwn.win/2023/10/28/file-move-privesc-mac.html"
            }
         ],
         "Authors": ["kn32"],
         "Programs": ["Parallels"],
         "Bugs": ["Local Privilege Escalation", "MacOS"],
         "Bounty": "-",
         "PublicationDate": "2023-10-28",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023–4632: Local Privilege Escalation in Lenovo System Updater",
               "Link": "https://posts.specterops.io/cve-2023-4632-local-privilege-escalation-in-lenovo-system-updater-2762e9667120"
            }
         ],
         "Authors": ["Matt Nelson (@enigma0x3)"],
         "Programs": ["Lenovo"],
         "Bugs": ["Local Privilege Escalation", "Arbitrary file write"],
         "Bounty": "-",
         "PublicationDate": "2023-10-26",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "From Akamai to F5 to NTLM... with love.",
               "Link": "https://blog.malicious.group/from-akamai-to-f5-to-ntlm/"
            }
         ],
         "Authors": ["d3d (@deadvolvo)"],
         "Programs": ["Akamai", "F5"],
         "Bugs": ["HTTP request smuggling", "Web cache poisoning"],
         "Bounty": "-",
         "PublicationDate": "2023-10-26",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "Refresh: Compromising F5 BIG-IP With Request Smuggling | CVE-2023-46747",
               "Link": "https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/"
            }
         ],
         "Authors": ["Michael Weber (@BouncyHat)", "Thomas Hendrickson"],
         "Programs": ["F5"],
         "Bugs": ["HTTP request smuggling", "Authentication bypass", "RCE", "Apache JServ Protocol (AJP)"],
         "Bounty": "-",
         "PublicationDate": "2023-10-26",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Revisiting an Old Bug: File Upload to Code Execution",
               "Link": "https://www.securifera.com/blog/2023/10/25/cve-2021-27198/"
            }
         ],
         "Authors": ["b0yd (@rwincey)"],
         "Programs": ["Visualware"],
         "Bugs": ["Unrestricted file upload", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-10-25",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "A web cache deception chained to a CSRF, the recipe",
               "Link": "https://infosecwriteups.com/a-web-cache-deception-chained-to-a-csrf-the-recipe-9e9a5b5f53aa"
            }
         ],
         "Authors": ["Rachid.A (@zhero___)"],
         "Programs": ["-"],
         "Bugs": ["Web cache deception", "CSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-10-25",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "Citrix Bleed: Leaking Session Tokens with CVE-2023-4966",
               "Link": "https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966"
            }
         ],
         "Authors": ["Dylan Pindur"],
         "Programs": ["Citrix Systems"],
         "Bugs": ["Buffer over-read", "Memory corruption", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-10-25",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-33466 - Exploiting Healthcare Servers with Polyglot Files",
               "Link": "https://www.shielder.com/blog/2023/10/cve-2023-33466-exploiting-healthcare-servers-with-polyglot-files/"
            }
         ],
         "Authors": ["TheZero (@Th3Zer0)", "suidpit (@suidpit)"],
         "Programs": ["Asus"],
         "Bugs": ["DICOM", "RCE", "Arbitrary file overwrite", "Arbitrary file upload", "Patch diffing"],
         "Bounty": "-",
         "PublicationDate": "2023-10-24",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Oh-Auth - Abusing OAuth to take over millions of accounts",
               "Link": "https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts"
            }
         ],
         "Authors": ["Aviad Carmel (@AviadCarmel)"],
         "Programs": ["Grammarly", "Vidio", "Bukalapak"],
         "Bugs": ["OAuth", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-10-24",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "You Are Not Where You Think You Are, Opera Browsers Address Bar Spoofing Vulnerabilities",
               "Link": "https://medium.com/@renwa/you-are-not-where-you-think-you-are-opera-browsers-address-bar-spoofing-vulnerabilities-aa36ad8321d8"
            }
         ],
         "Authors": ["Renwa (@RenwaX23)"],
         "Programs": ["Opera"],
         "Bugs": ["Address Bar Spoofing", "XSS", "Android"],
         "Bounty": "11,100",
         "PublicationDate": "2023-10-24",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Behind the Query: Unearthing NTLM Hashes with SQL Injection",
               "Link": "https://shubhamchaskar.com/sqli-to-ntlm/"
            }
         ],
         "Authors": ["Shubham Chaskar (@chaskar_shubham)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "NTLM"],
         "Bounty": "-",
         "PublicationDate": "2023-10-22",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "$9240 Bounty in 30 days Hunt Challenge",
               "Link": "https://blog.voorivex.team/9240-bounty-in-30-days-hunt-challenge"
            }
         ],
         "Authors": ["0xrz (@omidxrz)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "Reflected XSS", "Account takeover", "CORS misconfiguration", "Web cache deception", "Logic flaw", "CSV injection", "HTML injection", "Client-side enforcement of server-side security", "2FA / MFA bypass", "Broken Access Control", "Privilege escalation", "Pre-account takeover"],
         "Bounty": "9,240",
         "PublicationDate": "2023-10-21",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Interesting case of a DOM XSS in www.figma.com",
               "Link": "https://github.com/Sudistark/xss-writeups/blob/main/figma.com-xss.md"
            }
         ],
         "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)", "huli (@aszx87410)"],
         "Programs": ["Figma"],
         "Bugs": ["DOM XSS"],
         "Bounty": "1,000",
         "PublicationDate": "2023-10-20",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "OAuth 2.0 Redirect URI Validation Falls Short, Literally",
               "Link": "https://innotommy.com/Wrong_redirect_uri_validation_in_OAuth-4.pdf"
            },
            {
               "Title": "Alternative link",
               "Link": "https://dl.acm.org/doi/pdf/10.1145/3627106.3627140"
            }
         ],
         "Authors": ["Tommaso Innocenti (@innotommy)", "Matteo Golinelli", "Kaan Onarlioglu", "Ali Mirheidari", "Bruno Crispo", "Engin Kirda"],
         "Programs": ["Atlassian", "Meta / Facebook", "GitHub", "Microsoft", "Yahoo! / Verizon Media", "LinkedIn", "Slack", "VK", "LINE", "AuthDigital (Naver)", "OK", "ORCID"],
         "Bugs": ["OAuth", "Path confusion", "Open redirect", "HTTP parameter pollution", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-10-18",
         "AddedDate": "2024-08-06"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-33733 RCE via HTMLi in reportlab",
               "Link": "https://github.com/Sudistark/BB-Writeups/blob/main/2023/CVE-2023-33733-rce-via-htmli-in-reportlab.md"
            }
         ],
         "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
         "Programs": ["ReportLab"],
         "Bugs": ["RCE", "HTML injection", "Code injection", "SSRF", "Components with known vulnerabilities"],
         "Bounty": "4,500",
         "PublicationDate": "2023-10-18",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Technical Advisory: Vulnerabilities Identified within ListServ",
               "Link": "https://www.praetorian.com/blog/vulnerabilities-within-listserv/"
            }
         ],
         "Authors": ["Adam Crosser"],
         "Programs": ["ListServ"],
         "Bugs": ["CSRF", "Samesite cookie bypass", "Reflected XSS", "Stored XSS", "Unrestricted file upload", "DLL Hijacking", "Local Privilege Escalation", "Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-10-18",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "Persistent cross-site scripting vulnerabilities in Liferay Portal",
               "Link": "https://www.pentagrid.ch/de/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/"
            }
         ],
         "Authors": ["Pentagrid (@pentagridsec)"],
         "Programs": ["Liferay"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-10-17",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Client Side Path Manipulation",
               "Link": "https://www.erasec.be/blog/client-side-path-manipulation/"
            }
         ],
         "Authors": ["Antoine Roly (@aroly)"],
         "Programs": ["-"],
         "Bugs": ["Client-side Path Traversal"],
         "Bounty": "-",
         "PublicationDate": "2023-10-17",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "crewjam/saml - IdP XSS Via Missing Binding Syntax Validation In ACS Location",
               "Link": "https://doyensec.com/resources/Doyensec_SecurityAdvisory_crewjam_saml_Q32023.pdf"
            }
         ],
         "Authors": ["Francesco Lacerenza (@lacerenza_fra)"],
         "Programs": ["Crewjam"],
         "Bugs": ["XSS", "SAML", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-10-17",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Security Vulnerabilities in CasaOS",
               "Link": "https://www.sonarsource.com/blog/security-vulnerabilities-in-casaos/"
            }
         ],
         "Authors": ["Thomas Chauchefoin (@swapgs)"],
         "Programs": ["CasaOS"],
         "Bugs": ["Authentication bypass", "JWT", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-10-17",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "The Nightmare of Apple's OTA Update: Bypassing the Signature Verification and Pwning the Kernel",
               "Link": "https://jhftss.github.io/The-Nightmare-of-Apple-OTA-Update/"
            }
         ],
         "Authors": ["Mickey Jin (@patch1t)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["Signature validation bypass", "TOCTOU", "SIP bypass", "Downgrade attack", "Kernel hacking", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2023-10-15",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Uncovering a Command Injection, $2400 Bounty",
               "Link": "https://blog.voorivex.team/uncovering-a-command-injection-2400-bounty"
            }
         ],
         "Authors": ["0xrz (@omidxrz)"],
         "Programs": ["-"],
         "Bugs": ["OS command injection", "RCE", "File upload", "Weak credentials"],
         "Bounty": "2,400",
         "PublicationDate": "2023-10-14",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Finding A RCE Gadget Chain In WordPress Core",
               "Link": "https://wpscan.com/blog/finding-a-rce-gadget-chain-in-wordpress-core/"
            }
         ],
         "Authors": ["Marc Montpas"],
         "Programs": ["WordPress"],
         "Bugs": ["RCE", "PHP pop chain", "Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2023-10-13",
         "AddedDate": "2024-01-08"
      },
      {
         "Links": [
            {
               "Title": "How can I obtain a $2k bounty solely based on curiosity?",
               "Link": "https://medium.com/@nanwinata/how-can-i-obtain-a-2k-bounty-solely-based-on-curiosity-56ef84e93aca"
            }
         ],
         "Authors": ["nanwn"],
         "Programs": ["-"],
         "Bugs": ["Missing authentication"],
         "Bounty": "2,158",
         "PublicationDate": "2023-10-13",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "How I Exposed Instagram's Private Posts by Blocking Users",
               "Link": "https://003random.com/posts/meta-bountycon-instagram-writeup/"
            }
         ],
         "Authors": ["003random (@rub003)"],
         "Programs": ["Meta / Facebook (Instagram)"],
         "Bugs": ["XSLeaks", "Logic flaw"],
         "Bounty": "14,500",
         "PublicationDate": "2023-10-12",
         "AddedDate": "2023-12-27"
      },
      {
         "Links": [
            {
               "Title": "EvilSln: Don't open .sln files",
               "Link": "https://github.com/cjm00n/EvilSln"
            }
         ],
         "Authors": ["zhiniang peng (@edwardzpeng)"],
         "Programs": ["Microsoft (Visual Studio)"],
         "Bugs": ["Phishing", "1-click RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-10-11",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "How I Made A Heap Overflow In Curl",
               "Link": "https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/"
            }
         ],
         "Authors": ["Daniel Stenberg (@bagder)"],
         "Programs": ["Internet Bug Bounty (curl)"],
         "Bugs": ["Heap buffer overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-10-11",
         "AddedDate": "2024-01-02"
      },
      {
         "Links": [
            {
               "Title": "Finding A Pop Chain On A Common Symfony Bundle: Part 2",
               "Link": "https://www.synacktiv.com/publications/finding-a-pop-chain-on-a-common-symfony-bundle-part-2"
            }
         ],
         "Authors": ["Rémi Matasse (@_remsio_)"],
         "Programs": ["doctrine-bundle (Symfony package)"],
         "Bugs": ["Insecure deserialization", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-10-11",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Identify Tor user across browser restarts",
               "Link": "https://ndevtk.github.io/writeups/2023/10/10/tor/"
            }
         ],
         "Authors": ["NDevTK (@ndevtk)"],
         "Programs": ["Tor"],
         "Bugs": ["Information disclosure", "Privacy issue"],
         "Bounty": "-",
         "PublicationDate": "2023-10-10",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-4908: SOP bypass in Chrome using Navigation API",
               "Link": "https://joaxcar.com/blog/2023/10/06/cve-2022-4908-sop-bypass-in-chrome-using-navigation-api/"
            }
         ],
         "Authors": ["Johan Carlsson (@joaxcar)"],
         "Programs": ["Google (Chrome & Chromium)"],
         "Bugs": ["SOP bypass", "Browser hacking", "OAuth"],
         "Bounty": "2,000",
         "PublicationDate": "2023-10-06",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "403 Forbidden? No Problem, Here’s a POST XSS",
               "Link": "https://medium.com/@remmy9/403-forbidden-no-problem-heres-a-post-xss-eba84020ff70"
            }
         ],
         "Authors": ["Remmy (@NineRemmy)"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-10-05",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "Reversing 'France Identité': the new French digital ID.",
               "Link": "https://www.reversemode.com/2023/10/reversing-france-identite-new-french.html"
            }
         ],
         "Authors": ["Ruben Santamarta (@reversemode)"],
         "Programs": ["France Identité"],
         "Bugs": ["Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2023-10-04",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "2023 Microsoft Office XSS",
               "Link": "https://blog.pksecurity.io/2023/10/04/microsoft-office.html"
            }
         ],
         "Authors": ["adm1nkyj (@adm1nkyj1)", "Kim Donguk (@justlikebono)"],
         "Programs": ["Microsoft (Office)"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-10-04",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "How to build custom scanners for web security research automation",
               "Link": "https://portswigger.net/research/how-to-build-custom-scanners-for-web-security-research-automation"
            }
         ],
         "Authors": ["James Kettle (@albinowax)"],
         "Programs": ["-"],
         "Bugs": ["Race condition"],
         "Bounty": "-",
         "PublicationDate": "2023-10-03",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "The Path to the Cloud is Filled with Holes: Exploiting 4G Edge Routers",
               "Link": "https://claroty.com/team82/research/the-path-to-the-cloud-is-filled-with-holes-exploiting-4g-edge-routers"
            }
         ],
         "Authors": ["Noam Moshe"],
         "Programs": ["Connected IO"],
         "Bugs": ["IoT", "RCE", "MQTT"],
         "Bounty": "-",
         "PublicationDate": "2023-10-03",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "[CVE-2023–38743] ManageEngine ADManager Command Injection",
               "Link": "https://petrusviet.medium.com/cve-2023-38743-manageengine-admanager-command-injection-6afccbb196fe"
            }
         ],
         "Authors": ["Petrus Viet (@VietPetrus)"],
         "Programs": ["Zoho (ManageEngine)"],
         "Bugs": ["OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-10-02",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Okta for Red Teamers",
               "Link": "https://blog.xpnsec.com/okta-for-redteamers/"
            }
         ],
         "Authors": ["Adam Chester (@_xpn_)"],
         "Programs": ["-"],
         "Bugs": ["Post-exploitation"],
         "Bounty": "-",
         "PublicationDate": "2023-10-02",
         "AddedDate": "2023-12-26"
      },
      {
         "Links": [
            {
               "Title": "nOAuth: Account Takeover via Microsoft Oauth",
               "Link": "https://bibek-shah.medium.com/noauth-account-takeover-via-microsoft-oauth-cc653410b886"
            }
         ],
         "Authors": ["Bibek Shah"],
         "Programs": ["-"],
         "Bugs": ["OAuth", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-10-02",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "XPATH Injection - Exploiting Error-based SQL Injection",
               "Link": "https://sklnhunt.github.io/posts/xpathinjectionerrorbased/"
            }
         ],
         "Authors": ["Krunal Savaliya"],
         "Programs": ["-"],
         "Bugs": ["XPATH injection", "SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-10-01",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "RCE in Progress WS_FTP Ad Hoc via IIS HTTP Modules (CVE-2023-40044)",
               "Link": "https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044"
            }
         ],
         "Authors": ["Shubham Shah (@infosec_au)", "Sean Yeoh (@seanyeoh)"],
         "Programs": ["Progress (MOVEit Transfer)"],
         "Bugs": ["Insecure deserialization", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-10-01",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "You can add extra zeroes. XSS bypass on a private bug bounty program",
               "Link": "https://medium.com/@snoopy101/you-can-add-extra-zeroes-xss-bypass-on-a-private-bug-bounty-program-77440495e448"
            }
         ],
         "Authors": ["snoopy (@snoopy101101)"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "500",
         "PublicationDate": "2023-10-01",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "root with a single command: sudo logrotate",
               "Link": "https://joshua.hu/gaining-root-with-logrotate-sudo-ubuntu"
            }
         ],
         "Authors": ["Joshua Rogers (@MegaManSec)"],
         "Programs": ["-"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-10-01",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Exploiting ASP.NET TemplateParser — Part II: SharePoint (CVE-2023-33160)",
               "Link": "https://code-white.com/blog/exploiting-asp.net-templateparser-part-2/"
            }
         ],
         "Authors": ["Markus Wulftange (@mwulftange)"],
         "Programs": ["Microsoft (Sharepoint)"],
         "Bugs": ["RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-29",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Using Cloudflare To Bypass Cloudflare",
               "Link": "https://certitude.consulting/blog/en/using-cloudflare-to-bypass-cloudflare/"
            }
         ],
         "Authors": ["Stefan Proksch", "Florian Schweitzer (@FSchweitzer)"],
         "Programs": ["Cloudflare"],
         "Bugs": ["WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-09-28",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "A QUIC Shutdown: DoS Vulnerability in Windows Servers Running SMB over QUIC",
               "Link": "https://www.akamai.com/blog/security-research/2023/sep/smb-over-quic-dos-windows-servers"
            }
         ],
         "Authors": ["Ben Barnea (@nachoskrnl)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["DoS", "QUIC"],
         "Bounty": "-",
         "PublicationDate": "2023-09-28",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Getting SYSTEM on Windows in style",
               "Link": "https://sector7.computest.nl/post/2023-09-getting-system-on-windows-in-style/"
            }
         ],
         "Authors": ["Sector 7 (@sector7_nl)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["RCE", "Local Privilege Escalation", "TOCTOU", "DLL Hijacking"],
         "Bounty": "-",
         "PublicationDate": "2023-09-28",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Unzipping Dangers: OpenRefine Zip Slip Vulnerability",
               "Link": "https://www.sonarsource.com/blog/openrefine-zip-slip/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["OpenRefine"],
         "Bugs": ["Zip Slip attack", "Arbitrary Code Execution", "Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-27",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Source Code at Risk: Critical Code Vulnerability in CI/CD Platform TeamCity",
               "Link": "https://www.sonarsource.com/blog/teamcity-vulnerability/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["JetBrains (TeamCity)"],
         "Bugs": ["RCE", "CI/CD"],
         "Bounty": "-",
         "PublicationDate": "2023-09-26",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Long Live the Pwn Request: Hacking Microsoft GitHub Repositories and More",
               "Link": "https://www.praetorian.com/blog/pwn-request-hacking-microsoft-github-repositories-and-more/"
            }
         ],
         "Authors": ["Adnan Khan (@adnanthekhan)"],
         "Programs": ["Microsoft", "Red Hat"],
         "Bugs": ["CI/CD", "Pwn Request"],
         "Bounty": "-",
         "PublicationDate": "2023-09-26",
         "AddedDate": "2023-09-27"
      },
      {
         "Links": [
            {
               "Title": "SCCM Hierarchy Takeover",
               "Link": "https://posts.specterops.io/sccm-hierarchy-takeover-41929c61e087"
            }
         ],
         "Authors": ["Chris Thompson (@_Mayyhem)"],
         "Programs": ["-"],
         "Bugs": ["SCCM site takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-09-26",
         "AddedDate": "2023-09-27"
      },
      {
         "Links": [
            {
               "Title": "[P2O Vancouver 2023] SharePoint Pre-Auth RCE chain (CVE-2023–29357 & CVE-2023–24955)",
               "Link": "https://starlabs.sg/blog/2023/09-sharepoint-pre-auth-rce-chain/"
            }
         ],
         "Authors": ["Nguyễn Tiến Giang (@testanull)"],
         "Programs": ["Microsoft (Sharepoint)"],
         "Bugs": ["RCE", "Authentication bypass", "JWT", "Code injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-25",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "$1,250 worth of Host Header Injection",
               "Link": "https://medium.com/@salman_bugskipper/1-250-worth-of-host-header-injection-96563a2ac7e8"
            }
         ],
         "Authors": ["Salman Khan (@salman_ashlor)"],
         "Programs": ["-"],
         "Bugs": ["Host header injection", "Web cache poisoning", "Account takeover", "Password reset"],
         "Bounty": "1,250",
         "PublicationDate": "2023-09-25",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Exploiting stale ADIDNS entries",
               "Link": "https://blog.scrt.ch/2023/09/25/exploiting-stale-adidns-entries/"
            }
         ],
         "Authors": ["Alain Mowat (@plopz0r)"],
         "Programs": ["-"],
         "Bugs": ["Internal pentest", "Active Directory"],
         "Bounty": "-",
         "PublicationDate": "2023-09-25",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Rooting Xiaomi WiFi Routers",
               "Link": "https://blog.thalium.re/posts/rooting-xiaomi-wifi-routers/"
            }
         ],
         "Authors": ["Julien R.", "Marin Duroyon"],
         "Programs": ["Xiaomi"],
         "Bugs": ["OS command injection", "Buffer Overflow", "Memory corruption", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-25",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Exploiting ASP.NET TemplateParser — Part I: Sitecore (CVE-2023-35813)",
               "Link": "https://code-white.com/blog/exploiting-asp.net-templateparser-part-1/"
            }
         ],
         "Authors": ["Markus Wulftange (@mwulftange)"],
         "Programs": ["Sitecore"],
         "Bugs": ["RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-25",
         "AddedDate": "2023-09-27"
      },
      {
         "Links": [
            {
               "Title": "Discovering 7 Open Redirect Bypasses and 3 XSS Bypasses Within a Single Program Using the Same Parameters",
               "Link": "https://0xm5awy.medium.com/discovering-7-open-redirect-bypasses-and-3-xss-bypasses-within-a-single-program-using-same-8e87581e1a75"
            }
         ],
         "Authors": ["Mohamed Anani (@0xM5awy)"],
         "Programs": ["-"],
         "Bugs": ["XSS", "Open redirect", "URL validation bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-09-24",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Staff and Triage can modify the initial post of a report",
               "Link": "https://medium.com/@abhinavsecondary/staff-and-triage-can-modify-the-initial-post-of-a-report-ed99b1f1d9d3"
            }
         ],
         "Authors": ["Abhinav Kumar (@abhinavsecond)"],
         "Programs": ["HackerOne"],
         "Bugs": ["Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2023-09-23",
         "AddedDate": "2023-09-27"
      },
      {
         "Links": [
            {
               "Title": "DoubleQlik: Bypassing the Fix for CVE-2023-41265 to Achieve Unauthenticated Remote Code Execution",
               "Link": "https://www.praetorian.com/blog/doubleqlik-bypassing-the-original-fix-for-cve-2023-41265/"
            }
         ],
         "Authors": ["Adam Crosser"],
         "Programs": ["Qlik"],
         "Bugs": ["RCE", "Path traversal", "HTTP request tunneling", "HTTP request smuggling", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-22",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Van1338: Design Flaw in Riot Vanguard: $6,000",
               "Link": "https://github.com/kkent030315/Van1338"
            }
         ],
         "Authors": ["Kento Oki (@kento932376)"],
         "Programs": ["Riot Games"],
         "Bugs": ["Game hacking"],
         "Bounty": "6,000",
         "PublicationDate": "2023-09-22",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Uncovering a Critical Vulnerability in Samsung Mobile Security: A Bug Bounty Journey",
               "Link": "https://medium.com/@garkolym/uncovering-a-critical-vulnerability-in-samsung-mobile-security-a-bug-bounty-journey-95d614ba1841"
            }
         ],
         "Authors": ["David Albert"],
         "Programs": ["Samsung"],
         "Bugs": ["Android", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-09-22",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "How to break SAML if I have paws?",
               "Link": "https://speakerdeck.com/greendog/how-to-break-saml-if-i-have-paws"
            }
         ],
         "Authors": ["Aleksei Tiurin"],
         "Programs": ["-"],
         "Bugs": ["SAML"],
         "Bounty": "-",
         "PublicationDate": "2023-09-21",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Finding Deserialization Bugs In The Solarwind Platform",
               "Link": "https://www.zerodayinitiative.com/blog/2023/9/21/finding-deserialization-bugs-in-the-solarwind-platform"
            }
         ],
         "Authors": ["Piotr Bazydło (@chudyPB)"],
         "Programs": ["SolarWinds"],
         "Bugs": ["RCE", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-21",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "How 2 Cute Bugs offered me a reward of 650€",
               "Link": "https://medium.com/@anirudhkrishna012/how-2-cute-bugs-offered-me-a-reward-of-650-7f13abf36c65"
            }
         ],
         "Authors": ["Anirudh Krishnakumar"],
         "Programs": ["-"],
         "Bugs": ["XSS", "SQL injection"],
         "Bounty": "691",
         "PublicationDate": "2023-09-21",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "One Bug at a Time: $1,500 worth of XSS",
               "Link": "https://medium.com/@atomiczsec/one-bug-at-a-time-1-500-worth-of-xss-33455b384b8a"
            }
         ],
         "Authors": ["Gavin Kramer (@atomiczsec)"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS", "Reflected XSS"],
         "Bounty": "1,500",
         "PublicationDate": "2023-09-20",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Tricky 2FA Bypass Leads to 4 digit Bounty $$$$",
               "Link": "https://medium.com/@roohaa_n/tricky-2fa-bypass-leads-to-4-digit-bounty-3a148bc7d4a"
            }
         ],
         "Authors": ["Rohaangupta (@roohaa_n)"],
         "Programs": ["-"],
         "Bugs": ["2FA / MFA bypass"],
         "Bounty": "1,000",
         "PublicationDate": "2023-09-20",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "Remote Code Execution in Tutanota Desktop due to Code Flaw",
               "Link": "https://www.sonarsource.com/blog/remote-code-execution-in-tutanota-desktop-due-to-code-flaw/"
            }
         ],
         "Authors": ["Paul Gerste"],
         "Programs": ["Tutanota"],
         "Bugs": ["XSS", "CSP bypass", "Parsing issue", "Electron", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-20",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "The Not So Pleasant Password Manager",
               "Link": "https://www.mdsec.co.uk/2023/09/the-not-so-pleasant-password-manager/"
            }
         ],
         "Authors": ["Sean Doherty (@au5_mate)", "Juan Manuel Fernandez (@TheXC3LL)"],
         "Programs": ["Pleasant Solutions (Pleasant Password Server)"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-09-19",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "How I Got 4 SQLI Vulnerabilities At One Target Manually Using The Repeater Tab",
               "Link": "https://medium.com/@bug4y0u/how-i-got-4-sqli-vulnerabilities-at-one-target-manually-using-the-repeater-tab-ed4eb1f84147"
            }
         ],
         "Authors": ["bug4you (@bug4you)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-09-19",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "From Oversight to Ownership: How I Discovered the Path to Root on ISP’s Multiple Servers",
               "Link": "https://medium.com/@hektoravdyli12/from-oversight-to-ownership-how-i-discovered-the-path-to-root-on-isps-multiple-servers-6f14fb55b4f"
            }
         ],
         "Authors": ["Hektor"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "File disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-09-19",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)",
               "Link": "https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/"
            }
         ],
         "Authors": ["Tobias Ospelt (@floyd_ch)", "Martin Schobert"],
         "Programs": ["Wind River"],
         "Bugs": ["Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-19",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "Hacking into gRPC-Web",
               "Link": "https://infosecwriteups.com/hacking-into-grpc-web-a54053757a45"
            }
         ],
         "Authors": ["Amin Nasiri (@0xnxenon)"],
         "Programs": ["-"],
         "Bugs": ["gRPC", "SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-09-18",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Fileless Remote Code Execution on Juniper Firewalls",
               "Link": "https://vulncheck.com/blog/juniper-cve-2023-36845"
            }
         ],
         "Authors": ["Jacob Baines (@Junior_Baines)"],
         "Programs": ["Juniper"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-09-18",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Phar Deserialization (CVE-2023-28115 Patch Bypass)",
               "Link": "https://www.synacktiv.com/advisories/phar-deserialization-cve-2023-28115-patch-bypass"
            }
         ],
         "Authors": ["Rémi Matasse (@_remsio_)"],
         "Programs": ["knplabs/knp-snappy"],
         "Bugs": ["Phar deserialization"],
         "Bounty": "-",
         "PublicationDate": "2023-09-18",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "challenge writeup content-type shenanigans",
               "Link": "https://gist.github.com/avlidienbrunn/8db7f692404cdd3c325aa20d09437e13"
            }
         ],
         "Authors": ["Mathias Karlsson (@avlidienbrunn)"],
         "Programs": ["k-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-09-18",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "How i found an Stored XSS on Google Books",
               "Link": "https://medium.com/@cavdarbashas/how-i-found-an-stored-xss-on-google-books-732d9eb64e36"
            }
         ],
         "Authors": ["Sokol Çavdarbasha (@sokolicav)"],
         "Programs": ["Google"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-09-18",
         "AddedDate": "2023-09-27"
      },
      {
         "Links": [
            {
               "Title": "Weird LFI and escalating the impact from High to Critical",
               "Link": "https://medium.com/@snoopy101/weird-lfi-and-escalating-the-impact-from-high-to-critical-3e804f5366e9"
            }
         ],
         "Authors": ["snoopy (@snoopy101101)"],
         "Programs": ["-"],
         "Bugs": ["LFI"],
         "Bounty": "-",
         "PublicationDate": "2023-09-18",
         "AddedDate": "2023-09-27"
      },
      {
         "Links": [
            {
               "Title": "Insecure Authentication Tokens leading to Account Takeover",
               "Link": "https://www.vaadata.com/blog/insecure-authentication-tokens-leading-to-account-takeover/"
            }
         ],
         "Authors": ["Thomas Delfino"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Android", "Hardcoded credentials", "Weak crypto", "Authentication bypass", "Client-side enforcement of server-side security"],
         "Bounty": "-",
         "PublicationDate": "2023-09-18",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "38TB of data accidentally exposed by Microsoft AI researchers",
               "Link": "https://www.wiz.io/blog/38-terabytes-of-private-data-accidentally-exposed-by-microsoft-ai-researchers"
            }
         ],
         "Authors": ["Hillai Ben-Sasson (@hillai)", "Ronny Greenberg"],
         "Programs": ["Microsoft"],
         "Bugs": ["Cloud", "Broken authorization"],
         "Bounty": "-",
         "PublicationDate": "2023-09-18",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "Okta For Red Teamers",
               "Link": "https://www.trustedsec.com/blog/okta-for-red-teamers/"
            }
         ],
         "Authors": ["Adam Chester (@_xpn_)"],
         "Programs": ["-"],
         "Bugs": ["Post-exploitation"],
         "Bounty": "-",
         "PublicationDate": "2023-09-18",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "22.6k+ GitHub Stars Note-Taking App Hit by XSS Vulnerability",
               "Link": "https://infosecwriteups.com/22-6k-github-stars-note-taking-app-hit-by-critical-xss-vulnerability-842da56ae265"
            }
         ],
         "Authors": ["Chirag Agrawal (@__Raiders)"],
         "Programs": ["Trillium"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-09-17",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "A Easy Vertical Privilege Escalation via Session Storage",
               "Link": "https://amjadali110.medium.com/a-easy-vertical-privilege-escalation-via-session-storage-cfa9f558c94"
            }
         ],
         "Authors": ["Amjad Ali"],
         "Programs": ["-"],
         "Bugs": ["Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-09-16",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "Hijacking Someone Else’s DCSync",
               "Link": "https://nullg0re.com/2023/09/hijacking-someone-else-dcsync/"
            }
         ],
         "Authors": ["Anthony Larcher-Gore (@nullg0re)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Post-exploitation", "Active Directory", "Azure AD", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-09-15",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution",
               "Link": "https://pyn3rd.github.io/2023/09/15/CVE-2023-34040-Spring-Kafka-Deserialization-Remote-Code-Execution/"
            },
            {
               "Title": "PoC",
               "Link": "https://github.com/Contrast-Security-OSS/Spring-Kafka-POC-CVE-2023-34040"
            }
         ],
         "Authors": ["pyn3rd (@pyn3rd)"],
         "Programs": ["VMware (Spring Kafka)"],
         "Bugs": ["Insecure deserialization", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-09-15",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "The GitHub Actions Worm: Compromising GitHub Repositories Through the Actions Dependency Tree",
               "Link": "https://www.paloaltonetworks.com/blog/prisma-cloud/github-actions-worm-dependencies/"
            }
         ],
         "Authors": ["Asi Greenholts (@TupleType)"],
         "Programs": ["Veracode", "Hangfire"],
         "Bugs": ["CI/CD"],
         "Bounty": "-",
         "PublicationDate": "2023-09-14",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Neighbourhood Watch - Hikvision Intercom Eavesdropping",
               "Link": "https://skylightcyber.com/2023/09/14/neighbourhood-watch-hikvision-intercom-eavesdropping/"
            }
         ],
         "Authors": ["Peter Szot"],
         "Programs": ["Hikvision"],
         "Bugs": ["IoT", "UDP", "SIP", "DoS", "Authentication bypass", "Bruteforce", "Restricted shell escape"],
         "Bounty": "-",
         "PublicationDate": "2023-09-14",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "CraftCMS RCE",
               "Link": "https://blog.calif.io/p/craftcms-rce"
            }
         ],
         "Authors": ["Thanh"],
         "Programs": ["Craft CMS"],
         "Bugs": ["RCE", "Code injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-14",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "Uncursing the ncurses: Memory corruption vulnerabilities found in library",
               "Link": "https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/"
            }
         ],
         "Authors": ["Microsoft Threat Intelligence (@MsftSecIntel)"],
         "Programs": ["ncurses"],
         "Bugs": ["Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-09-14",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "Unauthenticated Massive PII Leak",
               "Link": "https://cristivlad.medium.com/unauthenticated-massive-pii-leak-d182ad3f7553"
            }
         ],
         "Authors": ["Cristi Vlad (@CristiVlad25)"],
         "Programs": ["-"],
         "Bugs": ["Rate limiting bypass", "Bruteforce"],
         "Bounty": "-",
         "PublicationDate": "2023-09-13",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-38146: Arbitrary Code Execution via Windows Themes",
               "Link": "https://exploits.forsale/themebleed/"
            }
         ],
         "Authors": ["gabe_k"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["RCE", "TOCTOU", "DLL Hijacking"],
         "Bounty": "5,000",
         "PublicationDate": "2023-09-13",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "Azure HDInsight Riddled With XSS Vulnerabilities via Apache Services",
               "Link": "https://orca.security/resources/blog/cross-site-scripting-vulnerabilities-in-apache-services-azure-hd-insight/"
            }
         ],
         "Authors": ["Lidor Ben Shitrit"],
         "Programs": ["Microsoft (Azure HDInsight)"],
         "Bugs": ["Stored XSS", "Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-09-13",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "Can't Be Contained: Finding a Command Injection Vulnerability in Kubernetes",
               "Link": "https://www.akamai.com/blog/security-research/kubernetes-critical-vulnerability-command-injection"
            }
         ],
         "Authors": ["Tomer Peled (@tomerpeled92)"],
         "Programs": ["Kubernetes"],
         "Bugs": ["RCE", "Command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-13",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "Exploiting CVE-2017-11286 Six Years Later: XXE in ColdFusion via WDDX Packet",
               "Link": "https://www.hoyahaxa.com/2023/09/exploiting-cve-2017-11286.html"
            }
         ],
         "Authors": ["Brian (@hoyahaxa)"],
         "Programs": ["Adobe (ColdFusion)"],
         "Bugs": ["XXE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-12",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Finding A Pop Chain On A Common Symfony Bundle: Part 1",
               "Link": "https://www.synacktiv.com/en/publications/finding-a-pop-chain-on-a-common-symfony-bundle-part-1.html"
            }
         ],
         "Authors": ["Rémi Matasse (@_remsio_)"],
         "Programs": ["doctrine-bundle (Symfony package)"],
         "Bugs": ["Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-12",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "Code Vulnerabilities Put Skiff Emails at Risk",
               "Link": "https://www.sonarsource.com/blog/code-vulnerabilities-put-skiff-emails-at-risk/"
            }
         ],
         "Authors": ["Paul Gerste"],
         "Programs": ["Skiff"],
         "Bugs": ["XSS", "Sandbox bypass", "CSP bypass", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-12",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "From MQTT Fundamentals to CVE",
               "Link": "https://blog.compass-security.com/2023/09/from-mqtt-fundamentals-to-cve/"
            }
         ],
         "Authors": ["Mischa Bachmann (@MischaBachmann)"],
         "Programs": ["Eclipse Foundation"],
         "Bugs": ["DoS", "Memory leak", "IoT", "MQTT"],
         "Bounty": "-",
         "PublicationDate": "2023-09-12",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "Persistent Threat: New Exploit Puts Thousands of GitHub Repositories and Millions of Users at Risk",
               "Link": "https://checkmarx.com/blog/persistent-threat-new-exploit-puts-thousands-of-github-repositories-and-millions-of-users-at-risk/"
            }
         ],
         "Authors": ["Elad Rapoport (@eladrapoport)", "Yehuda Gelb"],
         "Programs": ["GitHub"],
         "Bugs": ["Repojacking", "Race condition", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2023-09-12",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-4039: GCC's -fstack-protector fails to guard dynamic stack allocations on ARM64",
               "Link": "https://rtx.meta.security/mitigation/2023/09/12/CVE-2023-4039.html#h-vulnerability-details"
            }
         ],
         "Authors": ["Tom Hebb"],
         "Programs": ["GCC"],
         "Bugs": ["Memory corruption", "Buffer Overflow"],
         "Bounty": "-",
         "PublicationDate": "2023-09-12",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "Blog: OmniSpace, from automated 0day XSS to RCE",
               "Link": "https://preprod.patrowl.io/blog-omnispace-from-automated-xss-to-rce-cve-2023-40228/"
            }
         ],
         "Authors": ["Florent (@Pepito_oh)"],
         "Programs": ["Agora-Project (OmniSpace)"],
         "Bugs": ["RCE", "XSS", "Account takeover", "CSRF", "Insecure file upload", "LFI", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-12",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "MyBB Admin Panel RCE CVE-2023-41362",
               "Link": "https://blog.sorcery.ie/posts/mybb_acp_rce/"
            }
         ],
         "Authors": ["Sorcery IE (@SorceryIE)"],
         "Programs": ["MyBB"],
         "Bugs": ["RCE", "ReDoS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-11",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "Account hijack for anyone using Google sign-in with , due to response-type switch + leaking href to XSS on login.redacted.com",
               "Link": "https://github.com/Sudistark/xss-writeups/blob/main/oauth-dance.md"
            }
         ],
         "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
         "Programs": ["-"],
         "Bugs": ["OAuth", "XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-09-10",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "Single XSS with Earn $600",
               "Link": "https://medium.com/@yeyinthtet305/single-xss-with-earn-600-c1199f5c7fce"
            }
         ],
         "Authors": ["Yeyinthtet (@ye_yint_htet)"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "600",
         "PublicationDate": "2023-09-09",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "Leaked Database and SMTP credentials through .env file",
               "Link": "https://medium.com/bugbountywriteup/leaked-database-and-smtp-credentials-through-env-file-d003df418313"
            }
         ],
         "Authors": ["Nithissh"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "File disclosure", "40x bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-09-08",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Hacking a Large Company in MINUTES by Reading Docs",
               "Link": "https://medium.com/@dan.lig/hacking-a-large-company-in-minutes-by-reading-docs-62dfafced22e"
            }
         ],
         "Authors": ["dan.lig"],
         "Programs": ["-"],
         "Bugs": ["Broken Access Control", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-09-08",
         "AddedDate": "2023-09-27"
      },
      {
         "Links": [
            {
               "Title": "Orbeon Forms: The Final Form? On A Journey To RCE",
               "Link": "https://labs.watchtowr.com/orbeon-forms-the-final-form/"
            }
         ],
         "Authors": ["watchTowr (@watchtowrcyber)"],
         "Programs": ["Orbeon"],
         "Bugs": ["RCE", "XSLT", "XXE", "XPATH"],
         "Bounty": "-",
         "PublicationDate": "2023-09-08",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "Unveiling RCE on Dutch Government Website",
               "Link": "https://medium.com/@nayeems3c/unveiling-rce-on-dutch-government-website-f001a1c5b4fb"
            }
         ],
         "Authors": ["Nayeem Islam (@nayeems3c)"],
         "Programs": ["Dutch Government"],
         "Bugs": ["RCE", "Unrestricted file upload"],
         "Bounty": "-",
         "PublicationDate": "2023-09-08",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "How I got $$$ from AT&T",
               "Link": "https://medium.com/@nomad8061/how-i-got-from-my-first-valid-bug-17462f94c827"
            }
         ],
         "Authors": ["Ahmed Badry"],
         "Programs": ["AT&T"],
         "Bugs": ["Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2023-09-07",
         "AddedDate": "2023-09-19"
      },
      {
         "Links": [
            {
               "Title": "My debut with a Critical Bug: How I found my first bug (API misconfiguration)",
               "Link": "https://medium.com/@jay_rana/my-debut-with-a-critical-bug-how-i-found-my-first-bug-api-misconfiguration-2f7cadc89669"
            }
         ],
         "Authors": ["whit3ros3"],
         "Programs": ["-"],
         "Bugs": ["Hardcoded API keys", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-09-07",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "Paranoids Vulnerability Research: Ivanti Issues Security Alert",
               "Link": "https://www.yahooinc.com/paranoids/paranoids-vulnerability-research-ivanti-issues-security-alert"
            }
         ],
         "Authors": ["Blaine Herro"],
         "Programs": ["Ivanti"],
         "Bugs": ["RCE", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-07",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "Back to the 90s: Fujitsu “IP series”  Real-time Video Transmission Gear Hard Coded Credentials",
               "Link": "https://www.praetorian.com/blog/fujitsu-ip-series-hard-coded-credentials/"
            }
         ],
         "Authors": ["Adnan Khan (@adnanthekhan)"],
         "Programs": ["Fujitsu"],
         "Bugs": ["Hardcoded credentials"],
         "Bounty": "-",
         "PublicationDate": "2023-09-06",
         "AddedDate": "2023-09-27"
      },
      {
         "Links": [
            {
               "Title": "Kirby < 3.9.6 XML External Entity (XXE) vulnerability — CVE-2023-38490",
               "Link": "https://www.acceis.fr/kirby-3-9-6-xml-external-entity-xxe-vulnerability-cve-2023-38490/"
            }
         ],
         "Authors": ["Bastian Allgeier (@bastianallgeier)", "Lukas Bestle (@lukasbestle)"],
         "Programs": ["Kirby"],
         "Bugs": ["XXE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-06",
         "AddedDate": "2023-09-07"
      },
      {
         "Links": [
            {
               "Title": "Apache Superset Part II: RCE, Credential Harvesting and More",
               "Link": "https://www.horizon3.ai/apache-superset-part-ii-rce-credential-harvesting-and-more/"
            }
         ],
         "Authors": ["Naveen Sunkavally"],
         "Programs": ["Apache Superset"],
         "Bugs": ["RCE", "Insecure deserialization", "URL validation bypass", "Broken authorization", "Arbitrary file read", "Insufficiently Protected Credentials", "Default Flask Secret Key", "Hardcoded credentials"],
         "Bounty": "-",
         "PublicationDate": "2023-09-06",
         "AddedDate": "2023-09-07"
      },
      {
         "Links": [
            {
               "Title": "Again? Subdomain takeover via ideanote.io",
               "Link": "https://kresec.medium.com/again-subdomain-takeover-via-ideanote-io-6c7221161ba"
            }
         ],
         "Authors": ["Hasyim"],
         "Programs": ["-"],
         "Bugs": ["Subdomain takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-09-06",
         "AddedDate": "2023-09-07"
      },
      {
         "Links": [
            {
               "Title": "4,500 of the Top 1 Million Websites Leaked Source Code, Secrets",
               "Link": "https://trufflesecurity.com/blog/4500-of-the-top-1-million-websites-leaked-source-code-secrets/"
            }
         ],
         "Authors": ["Truffle Security (@trufflesec)", "Harsh Bothra (@harshbothra_)", "Luke Stephens (@hakluke)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-09-05",
         "AddedDate": "2024-01-10"
      },
      {
         "Links": [
            {
               "Title": "Part 3: Learning iOS App Pentesting and Application Security with Real-World Case Studies",
               "Link": "https://www.cobalt.io/blog/part-3-learning-ios-app-pentesting-and-application-security-with-real-world-case-studies"
            }
         ],
         "Authors": ["Swaroop Yermalkar (@swaroopsy)"],
         "Programs": ["-"],
         "Bugs": ["iOS", "Insecure deserialization", "SSL pinning bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-09-05",
         "AddedDate": "2023-09-22"
      },
      {
         "Links": [
            {
               "Title": "From NTAuthCertificates to “Silver” Certificate",
               "Link": "https://decoder.cloud/2023/09/05/from-ntauthcertificates-to-silver-certificate/"
            }
         ],
         "Authors": ["ap (@decoder_it)"],
         "Programs": ["-"],
         "Bugs": ["ADCS", "Active Directory", "Persistence", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2023-09-05",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "Subdomain takeover via nolt.io",
               "Link": "https://kresec.medium.com/subdomain-takeover-via-nolt-io-be536c275974"
            }
         ],
         "Authors": ["Hasyim"],
         "Programs": ["-"],
         "Bugs": ["Subdomain takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-09-05",
         "AddedDate": "2023-09-07"
      },
      {
         "Links": [
            {
               "Title": "Blog: CVE-2023-4634 - Tricky Unauthenticated RCE on Wordpress Media Library Assistant Plugin using a good old Imagick",
               "Link": "https://patrowl.io/blog-wordpress-media-library-rce-cve-2023-4634/"
            }
         ],
         "Authors": ["Florent (@Pepito_oh)"],
         "Programs": ["Media Library Assistant (WordPress plugin)"],
         "Bugs": ["LFI", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-05",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "When URL parsers disagree (CVE-2023-38633)",
               "Link": "https://www.canva.dev/blog/engineering/when-url-parsers-disagree-cve-2023-38633/"
            }
         ],
         "Authors": ["Zac Sims"],
         "Programs": ["Canva", "librsvg"],
         "Bugs": ["Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-09-05",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "Uncovering Web Cache Deception: A Missed Vulnerability in the Most Unexpected Places",
               "Link": "https://blog.agilehunt.com/blogs/security/web-cache-deception-attack-on-404-page-exposing-pii-data-to-unauthenticated-users"
            }
         ],
         "Authors": ["Vikas Anil Sharma (@vikzsharma)"],
         "Programs": ["-"],
         "Bugs": ["Web cache deception"],
         "Bounty": "-",
         "PublicationDate": "2023-09-04",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Code Vulnerabilities Put Proton Mails at Risk",
               "Link": "https://www.sonarsource.com/blog/code-vulnerabilities-leak-emails-in-proton-mail/"
            }
         ],
         "Authors": ["Paul Gerste"],
         "Programs": ["Proton Mail"],
         "Bugs": ["XSS", "Sandbox bypass", "CSP bypass", "Parsing issue"],
         "Bounty": "750",
         "PublicationDate": "2023-09-04",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "GPOddity: Exploiting Active Directory GPOs Through NTLM Relaying, And More!",
               "Link": "https://www.synacktiv.com/en/publications/gpoddity-exploiting-active-directory-gpos-through-ntlm-relaying-and-more.html"
            }
         ],
         "Authors": ["Quentin Roland (@croco_byte)"],
         "Programs": ["-"],
         "Bugs": ["Active Directory Privilege Escalation", "NTLM", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2023-09-04",
         "AddedDate": "2023-09-13"
      },
      {
         "Links": [
            {
               "Title": "Bypass WAF by a simple trick gained $1000 bounty",
               "Link": "https://0xbartita.medium.com/bypass-waf-by-a-simple-trick-gained-1000-bounty-cfa0fa63779e"
            }
         ],
         "Authors": ["0xBartita (@0xBaRtiTa)"],
         "Programs": ["-"],
         "Bugs": ["WAF bypass"],
         "Bounty": "1,000",
         "PublicationDate": "2023-09-04",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "RCE on Application’s Tracking Admin Panel",
               "Link": "https://infosecwriteups.com/rce-on-applications-tracking-admin-panel-fdc7e8320366"
            }
         ],
         "Authors": ["Nithissh"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Unrestricted file upload"],
         "Bounty": "-",
         "PublicationDate": "2023-09-03",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "How I was able to find the P4 vulnerability in the United States Department of Agriculture by phone.",
               "Link": "https://royzsec.medium.com/how-i-was-able-to-find-the-p4-vulnerability-in-the-united-states-department-of-agriculture-by-phone-a841fcfe7d1e"
            }
         ],
         "Authors": ["Prince Roy"],
         "Programs": ["United States Department of Agriculture"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-09-01",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "How I could view any Facebook Groups Notes media, and they paid me a $10,000",
               "Link": "https://medium.com/@rajasudhakar/how-i-could-view-any-facebook-groups-notes-media-and-they-paid-me-a-10-000-fe22f8949d7c"
            }
         ],
         "Authors": ["Raja Sudhakar (@Rajasudhakar)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR"],
         "Bounty": "10,000",
         "PublicationDate": "2023-08-31",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "ZeroQlik: Achieving Unauthenticated Remote Code Execution via HTTP Request Tunneling and Path Traversal",
               "Link": "https://www.praetorian.com/blog/qlik-sense-technical-exploit/"
            }
         ],
         "Authors": ["Adam Crosser"],
         "Programs": ["Qlik"],
         "Bugs": ["RCE", "Path traversal", "HTTP request tunneling", "HTTP request smuggling", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-31",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "How I was able to modify and delete any user’s data file (filestack API)",
               "Link": "https://spideynati.medium.com/how-i-was-able-to-modify-and-delete-any-users-data-file-filestack-api-7377bc52856f"
            }
         ],
         "Authors": ["Spideynati (@yashparwekar)"],
         "Programs": ["-"],
         "Bugs": ["Hardcoded API keys"],
         "Bounty": "-",
         "PublicationDate": "2023-08-31",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – File History Service (FHSVC.DLL) Elevation Of Privilege",
               "Link": "https://ssd-disclosure.com/ssd-advisory-file-history-service-fhsvc-dll-elevation-of-privilege/"
            }
         ],
         "Authors": ["-"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-08-31",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "Leveraging VSCode Extensions for Initial Access",
               "Link": "https://www.mdsec.co.uk/2023/08/leveraging-vscode-extensions-for-initial-access/"
            }
         ],
         "Authors": ["Matt Johnson (@breakfix)"],
         "Programs": ["-"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2023-08-31",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "Dependency Confusion Attack: A Route to RCE",
               "Link": "https://sklnhunt.github.io/posts/dependencyconfusion/"
            }
         ],
         "Authors": ["Krunal Savaliya"],
         "Programs": ["-"],
         "Bugs": ["Dependency confusion", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-08-30",
         "AddedDate": "2024-08-26"
      },
      {
         "Links": [
            {
               "Title": "Leaking Jupyter instance auth token chaining CVE-2023-39968, CVE-2024-22421 and a chromium bug",
               "Link": "https://blog.xss.am/2023/08/cve-2023-39968-jupyter-token-leak/"
            }
         ],
         "Authors": ["Davit (@davwwwx)"],
         "Programs": ["Jupyter", "Google (Chromium)"],
         "Bugs": ["Client-side Path Traversal", "Open redirect"],
         "Bounty": "-",
         "PublicationDate": "2023-08-30",
         "AddedDate": "2024-07-08"
      },
      {
         "Links": [
            {
               "Title": "Technical Details for CVE-2023-29301: Adobe ColdFusion Access Control Bypass for a CFAdmin Authentication Component",
               "Link": "https://hoyahaxa.blogspot.com/2023/08/technical-details-for-cve-2023-29301.html"
            }
         ],
         "Authors": ["Brian (@hoyahaxa)"],
         "Programs": ["Adobe"],
         "Bugs": ["Broken Access Control", "Bruteforce", "ColdFusion"],
         "Bounty": "-",
         "PublicationDate": "2023-08-30",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "PII at Your Fingertips: How I Stumbled Upon an Easy-to-Find Data Leakage Vulnerability @ Swisscom",
               "Link": "https://medium.com/@husein.ayoub/pii-at-your-fingertips-how-i-stumbled-upon-an-easy-to-find-data-leakage-vulnerability-swisscom-b3c0cff47f24"
            }
         ],
         "Authors": ["Hussein Ayoub"],
         "Programs": ["Swisscom"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-08-30",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "From Terminal Output to Arbitrary Remote Code Execution",
               "Link": "https://blog.solidsnail.com/posts/2023-08-28-iterm2-rce"
            }
         ],
         "Authors": ["solid-snail"],
         "Programs": ["iTerm2"],
         "Bugs": ["RCE", "Escape sequence injection"],
         "Bounty": "-",
         "PublicationDate": "2023-08-28",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Playing Dominos with Moodle's Security (2/2)",
               "Link": "https://www.sonarsource.com/blog/playing-dominos-with-moodles-security-2/"
            }
         ],
         "Authors": ["Yaniv Nizry (@YNizry)"],
         "Programs": ["Moodle"],
         "Bugs": ["Self-XSS", "Account takeover", "OAuth", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-28",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "Leaking File Contents with a Blind File Oracle in Flarum",
               "Link": "https://blog.assetnote.io/2023/08/28/leaking-file-contents-with-a-blind-file-oracle-in-flarum/"
            }
         ],
         "Authors": ["Adam Kues (@hash_kitten)"],
         "Programs": ["Flarum"],
         "Bugs": ["PHP filter chain", "Arbitrary file read", "LFI", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-28",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "Hacking GTA V RP Servers Using Web Exploitation Techniques",
               "Link": "https://www.nullpt.rs/hacking-gta-servers-using-web-exploitation"
            }
         ],
         "Authors": ["veritas (@blastbots)"],
         "Programs": ["Rockstar Games (FiveM)"],
         "Bugs": ["Game hacking", "XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-28",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Hardened Android Applications",
               "Link": "https://notsosecure.com/bypassing-hardened-android-applications"
            }
         ],
         "Authors": ["Sanjay Gondaliya (@devsecboy)"],
         "Programs": ["-"],
         "Bugs": ["Android"],
         "Bounty": "-",
         "PublicationDate": "2023-08-27",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-36844 And Friends: RCE In Juniper Devices",
               "Link": "https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/"
            }
         ],
         "Authors": ["watchTowr (@watchtowrcyber)"],
         "Programs": ["Juniper"],
         "Bugs": ["RCE", "Missing authentication", "Arbitrary file upload", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-25",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "RCE via Account Takeover",
               "Link": "https://medium.com/vault-infosec/rce-via-account-takeover-a6fea7390385"
            }
         ],
         "Authors": ["Karthikeyan.V (@karthithehacker)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Account takeover", "IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-08-25",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "Implement a Blind Error-Based SQLMap payload for SQLite",
               "Link": "https://sokarepo.github.io/web/2023/08/24/implement-blind-sqlite-sqlmap.html"
            }
         ],
         "Authors": ["soka (@pentest_soka)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-08-24",
         "AddedDate": "2023-08-25"
      },
      {
         "Links": [
            {
               "Title": "Hacking a Tapo TC60 Camera",
               "Link": "https://medium.com/@two06/hacking-a-tapo-tc60-camera-e6ce7ca6cad1"
            }
         ],
         "Authors": ["James (@two06)"],
         "Programs": ["Tapo"],
         "Bugs": ["IoT", "Hardware hacking", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2023-08-23",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "Exploits Explained: Persisting Through a Client-Side Prototype Pollution",
               "Link": "https://www.synack.com/blog/persisting-through-a-client-side-prototype-pollution/"
            }
         ],
         "Authors": ["Virendra Pawar"],
         "Programs": ["-"],
         "Bugs": ["Client-side prototype pollution", "DOM XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-08-23",
         "AddedDate": "2023-08-25"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-35150: Arbitrary Code Injection In XWiki.Org XWiki",
               "Link": "https://www.zerodayinitiative.com/blog/2023/8/22/cve-2023-35150-arbitrary-code-injection-in-xwikiorg-xwiki"
            }
         ],
         "Authors": ["Simon Humbert", "Lucas Miller"],
         "Programs": ["XWiki"],
         "Bugs": ["Code injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-23",
         "AddedDate": "2023-08-25"
      },
      {
         "Links": [
            {
               "Title": "Shambles: The Next-Generation IoT Reverse Engineering Tool to Discover 0-Day Vulnerabilities",
               "Link": "https://boschko.ca/shambles/"
            }
         ],
         "Authors": ["Olivier Laflamme (@olivier_boschko)"],
         "Programs": ["-"],
         "Bugs": ["IoT", "Buffer Overflow", "Command injection", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2023-08-23",
         "AddedDate": "2023-08-25"
      },
      {
         "Links": [
            {
               "Title": "(CVE-2023-32530) Trend Micro Apex Central 2019 (<= Build 6016) Authenticated RCE",
               "Link": "https://starlabs.sg/advisories/23/23-32530/"
            }
         ],
         "Authors": ["Poh Jia Hao (@Chocologicall)"],
         "Programs": ["Trend Micro"],
         "Bugs": ["RCE", "SQL injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-22",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "My First Bug: How I Was Able to Bypass the WAF and Uncover a Reflected XSS",
               "Link": "https://fares7elsadek.medium.com/my-first-bug-how-i-was-able-to-bypass-the-waf-and-uncover-a-reflected-xss-e0534b6f05e4"
            }
         ],
         "Authors": ["Fares Elsadek (@err0rbyn1ght)"],
         "Programs": ["-"],
         "Bugs": ["WAF bypass", "Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-08-22",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "ATO | How I exploited security issue to take over admin account",
               "Link": "https://ar1fshaikh.medium.com/1st-ato-how-i-exploited-security-issue-to-take-over-admin-account-e0ae309dc356"
            }
         ],
         "Authors": ["ar1fshaikh (@ar1fshaikh)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Stored XSS", "CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-08-22",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "Bypass Two-Factor Authentication of Facebook Accounts ($25,300)",
               "Link": "https://medium.com/@bazzounbassem/bypass-two-factor-authentication-of-facebook-accounts-25-300-7ae152d7836a"
            }
         ],
         "Authors": ["Bassem M Bazzoun (@bassemmbazzoun)"],
         "Programs": ["Meta / Facebook (Instagram)"],
         "Bugs": ["2FA / MFA bypass"],
         "Bounty": "25,300",
         "PublicationDate": "2023-08-22",
         "AddedDate": "2023-08-25"
      },
      {
         "Links": [
            {
               "Title": "Exploitation of Openfire CVE-2023-32315",
               "Link": "https://vulncheck.com/blog/openfire-cve-2023-32315"
            }
         ],
         "Authors": ["Jacob Baines (@Junior_Baines)"],
         "Programs": ["Openfire"],
         "Bugs": ["Path traversal", "Authentication bypass", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-08-22",
         "AddedDate": "2023-08-25"
      },
      {
         "Links": [
            {
               "Title": "Technical Details of CVE-2023-30988 - IBM Facsimile Support Privilege Escalation",
               "Link": "https://blog.silentsignal.eu/2023/08/22/2023-08-22-Facsimile-Support-CVE-2023-30988/"
            }
         ],
         "Authors": ["pz"],
         "Programs": ["IBM"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-08-22",
         "AddedDate": "2023-08-25"
      },
      {
         "Links": [
            {
               "Title": "Playing Dominos with Moodle's Security (1/2)",
               "Link": "https://www.sonarsource.com/blog/playing-dominos-with-moodles-security-1/"
            }
         ],
         "Authors": ["Yaniv Nizry (@YNizry)"],
         "Programs": ["Moodle"],
         "Bugs": ["Stored XSS", "Arbitrary folder creation", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-21",
         "AddedDate": "2023-08-25"
      },
      {
         "Links": [
            {
               "Title": "An IDOR lead joins any group makes me $2,500",
               "Link": "https://infosecwriteups.com/an-idor-leads-join-any-group-makes-me-2-500-406eb9e463a3"
            }
         ],
         "Authors": ["Arman (@M7arm4n)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "2,500",
         "PublicationDate": "2023-08-19",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "Google Extensions (Awarded $18833.7)",
               "Link": "https://ndevtk.github.io/writeups/2023/08/18/extensions/"
            }
         ],
         "Authors": ["NDevTK (@ndevtk)"],
         "Programs": ["Google", "Proton AG"],
         "Bugs": ["RCE", "Information disclosure", "SOP bypass", "postMessage", "XSS", "Universal XSS"],
         "Bounty": "18,833.7",
         "PublicationDate": "2023-08-18",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "(IDOR) How do I find the first vulnerability with a $2500 bounty on hackerone.",
               "Link": "https://medium.com/@muhammadiman2468/idor-how-do-i-find-the-first-vulnerability-with-a-2500-bounty-on-hackerone-7afb3d8b5739"
            }
         ],
         "Authors": ["Muhammad Iman"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "2,500",
         "PublicationDate": "2023-08-18",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "InfluxDB NoSQL Injection",
               "Link": "https://rafa.hashnode.dev/influxdb-nosql-injection"
            }
         ],
         "Authors": ["Rafael da Costa Santos (@rafabyte_)"],
         "Programs": ["InfluxData (InfluxDB)"],
         "Bugs": ["NoSQL injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-17",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "SAMLjacking a poisoned tenant",
               "Link": "https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/"
            }
         ],
         "Authors": ["Luke Jennings"],
         "Programs": ["-"],
         "Bugs": ["SAMLjacking", "SAML", "SSO", "OAuth", "Supply chain attack", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-08-17",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "mTLS: When certificate authentication is done wrong",
               "Link": "https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/"
            }
         ],
         "Authors": ["Michael Stepankin (@artsploit)"],
         "Programs": ["Keycloak", "Bouncy Castle", "Apereo CAS"],
         "Bugs": ["mTLS", "Improper Certificate Validation", "LDAP injection", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-08-17",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "ScienceLogic Dumpster Fire",
               "Link": "https://web.archive.org/web/20230816081531/https://www.securifera.com/blog/2023/08/16/sciencelogic-dumpster-fire/"
            }
         ],
         "Authors": ["b0yd (@rwincey)"],
         "Programs": ["-"],
         "Bugs": ["Default credentials", "Local Privilege Escalation", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-08-16",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "Privilege Escalation In Ibm Spectrum Virtualize",
               "Link": "https://certitude.consulting/blog/en/privilege-escalation-in-ibm-spectrum-virtualize/"
            }
         ],
         "Authors": ["Wolfgang Ettlinger"],
         "Programs": ["IBM"],
         "Bugs": ["Privilege escalation", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-08-15",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "Istio outboundTrafficPolicy Egress Control Bypass",
               "Link": "https://pulsesecurity.co.nz/advisories/istio-egress-bypass"
            }
         ],
         "Authors": ["Denis Andzakovic"],
         "Programs": ["Istio"],
         "Bugs": ["Kubernetes"],
         "Bounty": "-",
         "PublicationDate": "2023-08-15",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "Podman API service listening on TCP can be used from websites",
               "Link": "https://proofnet.de/publikationen/podman_tcp_api.html"
            }
         ],
         "Authors": ["Dennis Dast"],
         "Programs": ["Podman"],
         "Bugs": ["Container security"],
         "Bounty": "-",
         "PublicationDate": "2023-08-15",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "Authenticated Arbitrary File Download (Path Traversal)",
               "Link": "https://research.aurainfosec.io/disclosure/papercut/"
            }
         ],
         "Authors": ["Chris McCurley (@chrisrmccurley)"],
         "Programs": ["PaperCut"],
         "Bugs": ["Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-14",
         "AddedDate": "2023-08-14"
      },
      {
         "Links": [
            {
               "Title": "Customer account takeover in Shopify stores",
               "Link": "https://ophionsecurity.com/blog/shopify-acount-takeover"
            }
         ],
         "Authors": ["Ophion Security (@OphionSecurity)"],
         "Programs": ["Shopify"],
         "Bugs": ["Account takeover", "OAuth"],
         "Bounty": "-",
         "PublicationDate": "2023-08-13",
         "AddedDate": "2023-08-14"
      },
      {
         "Links": [
            {
               "Title": "From Revealing Emails to Taking Over Accounts (Hacking Telecom)",
               "Link": "https://ahmdhalabi.medium.com/from-revealing-emails-to-taking-over-accounts-hacking-telecom-ead1fcbffc32"
            }
         ],
         "Authors": ["Ahmad Halabi (@Ahmad_Halabi_)"],
         "Programs": ["-"],
         "Bugs": ["OTP bypass", "Password reset", "HTTP response manipulation", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-08-13",
         "AddedDate": "2023-08-14"
      },
      {
         "Links": [
            {
               "Title": "My first Critical on hackerone with a $6,400 bounty — SQL Injection",
               "Link": "https://aryasec.medium.com/my-first-critical-on-hackerone-with-a-6-400-bounty-sql-injection-913566a12c6b"
            }
         ],
         "Authors": ["Tengku Arya Saputra (@AryaaSec)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "6,400",
         "PublicationDate": "2023-08-13",
         "AddedDate": "2023-08-14"
      },
      {
         "Links": [
            {
               "Title": "[IDOR] $400 — Deleting Other Project in Shopee",
               "Link": "https://aryasec.medium.com/idor-400-deleting-other-project-in-shopee-657239913416"
            }
         ],
         "Authors": ["Tengku Arya Saputra (@AryaaSec)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "400",
         "PublicationDate": "2023-08-13",
         "AddedDate": "2023-08-14"
      },
      {
         "Links": [
            {
               "Title": "What the Function: Decrypting Azure Function App Keys ",
               "Link": "https://www.netspi.com/blog/technical/cloud-penetration-testing/what-the-function-decrypting-azure-function-app-keys/"
            }
         ],
         "Authors": ["Thomas Elling"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-08-12",
         "AddedDate": "2023-09-05"
      },
      {
         "Links": [
            {
               "Title": "0 Click ATO with the Sandwich Attack",
               "Link": "https://www.landh.tech/blog/20230811-sandwich-attack/"
            }
         ],
         "Authors": ["Roni Carta (@0xLupin)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Sandwich Attack", "Password reset", "UUID", "Bruteforce"],
         "Bounty": "5,000",
         "PublicationDate": "2023-08-11",
         "AddedDate": "2024-07-01"
      },
      {
         "Links": [
            {
               "Title": "Site Takeover via SCCM’s AdminService API",
               "Link": "https://posts.specterops.io/site-takeover-via-sccms-adminservice-api-d932e22b2bf"
            }
         ],
         "Authors": ["Garrett Foster (@garrfoster)"],
         "Programs": ["-"],
         "Bugs": ["NTLM", "SCCM site takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-08-10",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "How I got Two RCE at BBP Program @0xbartita",
               "Link": "https://0xbartita.medium.com/how-i-got-two-rce-at-bbp-program-0xbartita-232727c5b3f0"
            }
         ],
         "Authors": ["0xBartita (@0xBaRtiTa)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Default credentials", "SAP", "Groovy scripting"],
         "Bounty": "-",
         "PublicationDate": "2023-08-10",
         "AddedDate": "2023-08-14"
      },
      {
         "Links": [
            {
               "Title": "Chained to hit: Discovering new vectors to gain remote and root access in SAP Enterprise Software",
               "Link": "https://i.blackhat.com/BH-US-23/Presentations/US-23-Genuer-chained-to-hit-discovering-new-vectors-to-gain-remote-and-root-access-in-sap-enterprise-software-wp.pdf"
            }
         ],
         "Authors": ["Pablo Artuso (@lmkalg)", "Yvan Genuer"],
         "Programs": ["SAP"],
         "Bugs": ["SAP", "Java RMI", "RCE", "JNDI Injection", "SQL injection", "DoS", "SSRF", "Missing authentication", "HTTP header injection", "Privilege escalation", "Information disclosure", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-08-09",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "A Pain in the NAS: Exploiting Cloud Connectivity to PWN your NAS: Synology DS920+ Edition",
               "Link": "https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition"
            }
         ],
         "Authors": ["Vera Mens", "Sharon Brizinov"],
         "Programs": ["Synology"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-08-09",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "A Pain in the NAS: Exploiting Cloud Connectivity to PWN your NAS: WD PR4100 Edition",
               "Link": "https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-wd-pr4100-edition"
            }
         ],
         "Authors": ["Noam Moshe"],
         "Programs": ["Western Digital"],
         "Bugs": ["Authentication bypass", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-08-09",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "Advisory | NetModule Router Software Race Condition Leads to Remote Code Execution",
               "Link": "https://pentest.blog/advisory-netmodule-router-software-race-condition-leads-to-remote-code-execution/"
            }
         ],
         "Authors": ["Nuri Çilengir"],
         "Programs": ["NetModule"],
         "Bugs": ["Race condition", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-08-09",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "“Please do not make it public” - Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping",
               "Link": "https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/"
            }
         ],
         "Authors": ["Jeffrey Knockel", "Zoë Reichert", "Mona Wang"],
         "Programs": ["Tencent"],
         "Bugs": ["Cryptographic issues", "Padding oracle attack", "Windows", "Android", "iOS"],
         "Bounty": "-",
         "PublicationDate": "2023-08-09",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "Smashing the state machine: the true potential of web race conditions",
               "Link": "https://portswigger.net/research/smashing-the-state-machine"
            }
         ],
         "Authors": ["James Kettle (@albinowax)"],
         "Programs": ["Devise", "GitLab"],
         "Bugs": ["Race condition"],
         "Bounty": "-",
         "PublicationDate": "2023-08-09",
         "AddedDate": "2023-08-14"
      },
      {
         "Links": [
            {
               "Title": "Finding and Exploiting Citrix NetScaler Buffer Overflow (CVE-2023-3519) (Part 3)",
               "Link": "https://blog.assetnote.io/2023/08/09/exploiting-citrix-netscaler-cve-2023-3519/"
            }
         ],
         "Authors": ["Dylan Pindur"],
         "Programs": ["Citrix Systems (NetScaler)"],
         "Bugs": ["Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-08-09",
         "AddedDate": "2023-08-14"
      },
      {
         "Links": [
            {
               "Title": "Cookieless DuoDrop: IIS Auth Bypass & App Pool Privesc in ASP.NET Framework (CVE-2023-36899 & CVE-2023-36560)",
               "Link": "https://soroush.me/blog/2023/08/cookieless-duodrop-iis-auth-bypass-app-pool-privesc-in-asp-net-framework-cve-2023-36899/"
            }
         ],
         "Authors": ["Soroush Dalili (@irsdl)"],
         "Programs": ["-"],
         "Bugs": ["Authentication bypass", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-08-08",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "My secret to API privesc: Tapping compromised web servers",
               "Link": "https://danaepp.com/my-secret-to-api-privesc-tapping-compromised-web-servers"
            }
         ],
         "Authors": ["Dana Epp (@DanaEpp)"],
         "Programs": ["-"],
         "Bugs": ["Persistence", "Post-exploitation"],
         "Bounty": "-",
         "PublicationDate": "2023-08-08",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "Spring WebFlux – CVE-2023-34034 – Write-Up and Proof-of-Concept",
               "Link": "https://jfrog.com/blog/spring-webflux-cve-2023-34034-write-up-and-proof-of-concept/"
            }
         ],
         "Authors": ["Yair Mizrahi", "Liam Aslan"],
         "Programs": ["Spring"],
         "Bugs": ["Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-08-08",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "HackerOne redacted usernames disclosure in “Export as .pdf” feature",
               "Link": "https://medium.com/pinoywhitehat/redacted-usernames-disclosure-in-export-as-pdf-feature-d00ce3f3e2fc"
            }
         ],
         "Authors": ["Japz Divino (@japzdivino)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "500",
         "PublicationDate": "2023-08-08",
         "AddedDate": "2023-08-14"
      },
      {
         "Links": [
            {
               "Title": "BBP Writeup Series #1 – Turning “useless” HTMLi on [REDACTED] into a P1",
               "Link": "https://0x80dotblog.wordpress.com/2023/08/07/bbp-writeup-series-1-turning-useless-htmli-on-redacted-into-a-p1/"
            }
         ],
         "Authors": ["MLT (@0dayWizard)"],
         "Programs": ["-"],
         "Bugs": ["HTML injection", "CSS injection"],
         "Bounty": "-",
         "PublicationDate": "2023-08-07",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Phishing the anti-phishers: Exploiting anti-phishing tools for internal access",
               "Link": "https://ophionsecurity.com/blog/phishing-the-anti-phishers"
            }
         ],
         "Authors": ["Rojan Rijal (@uraniumhacker)", "Tanner Emek (@itscachemoney)"],
         "Programs": ["Atlassian", "Netflix", "Amazon"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2023-08-07",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "PII-nacles of Discovery: Deep Recon, Fourth-Level Subdomains, and Abusing Exposed .git Repositories",
               "Link": "https://medium.com/@armandjasharaj/pii-nacles-of-discovery-deep-recon-fourth-level-subdomains-and-abusing-exposed-git-repositories-7e282442bd02"
            }
         ],
         "Authors": ["Armand Jasharaj"],
         "Programs": ["-"],
         "Bugs": [".git folder disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-08-07",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "Privilege Escalation — Playing with the various stages of a session state",
               "Link": "https://medium.com/@ashlyn.lau_17206/privilege-escalation-playing-with-the-various-stages-of-a-session-state-fe0157bcb2b9"
            }
         ],
         "Authors": ["Ashlyn Lau (@ashlyn_lau)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-08-06",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "$1000 for a simple Stored XSS",
               "Link": "https://medium.com/@snoopy101/1000-for-a-simple-stored-xss-8be7083a7c2d"
            }
         ],
         "Authors": ["snoopy (@snoopy101101)"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS", "Account takeover"],
         "Bounty": "1,000",
         "PublicationDate": "2023-08-06",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "Cross-Tenant Information Disclosure: Unraveling Microsoft Connections, Custom Connectors, and OAuth 2.0 in Power Automate",
               "Link": "https://fatnassifiras.medium.com/cross-tenant-information-disclosure-unraveling-microsoft-connections-custom-connectors-and-oauth-6487321d28b3"
            }
         ],
         "Authors": ["Firas Fatnassi (@Fatnass1F1ras)"],
         "Programs": ["Microsoft"],
         "Bugs": ["OAuth", "Cross-tenant vulnerability"],
         "Bounty": "-",
         "PublicationDate": "2023-08-04",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "Using Browser Tools For Bug Hunting: An Interesting 0$ Write IDOR On Instagram",
               "Link": "https://faizanwrites.medium.com/using-browser-tools-for-bug-hunting-an-interesting-0-write-idor-on-instagram-7d5318299c1a"
            }
         ],
         "Authors": ["Faizan Ahmad Wani"],
         "Programs": ["Meta / Facebook (Instagram)"],
         "Bugs": ["IDOR", "iOS"],
         "Bounty": "-",
         "PublicationDate": "2023-08-04",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "Leaked Secrets and Unlimited Miles: Hacking the Largest Airline and Hotel Rewards Platform",
               "Link": "https://samcurry.net/points-com/"
            }
         ],
         "Authors": ["Ian Carroll (@iangcarroll)", "Shubham Shah (@infosec_au)", "Sam Curry (@samwcyo)"],
         "Programs": ["points.com", "United Airlines", "Virgin"],
         "Bugs": ["Path traversal", "Authorization bypass", "Hardcoded credentials", "Weak Flask Session Secret", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-08-03",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "Hook, Line, and Phishlet: Conquering AD FS with Evilginx",
               "Link": "https://research.aurainfosec.io/pentest/hook-line-and-phishlet/"
            }
         ],
         "Authors": ["Daniel Underhay (@dunderhay)"],
         "Programs": ["-"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2023-08-03",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "“PhishForce” — Vulnerability Uncovered in Salesforce’s Email Services Exploited for Phishing Facebook Accounts In-The-Wild",
               "Link": "https://labs.guard.io/phishforce-vulnerability-uncovered-in-salesforces-email-services-exploited-for-phishing-32024ad4b5fa"
            }
         ],
         "Authors": ["Oleg Zaytsev", "Nati Tal"],
         "Programs": ["Salesforce"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2023-08-02",
         "AddedDate": "2023-08-21"
      },
      {
         "Links": [
            {
               "Title": "Identifying and Exploiting Unsafe Deserialization in Ruby",
               "Link": "https://medium.com/@plenumlab/identifying-and-exploiting-unsafe-deserialization-in-ruby-97c7cbd6c05d"
            }
         ],
         "Authors": ["Plenum (@plenumlab)"],
         "Programs": ["-"],
         "Bugs": ["Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2023-08-02",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "Anchor Tag XSS Exploitation in Firefox with Target=”_blank”",
               "Link": "https://soroush.me/blog/2023/08/anchor-tag-xss-exploitation-in-firefox-with-target_blank/"
            }
         ],
         "Authors": ["Soroush Dalili (@irsdl)"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-08-01",
         "AddedDate": "2023-08-24"
      },
      {
         "Links": [
            {
               "Title": "Thirteen Years On: Advancing the Understanding of IIS Short File Name (SFN) Disclosure!",
               "Link": "https://soroush.me/blog/2023/07/thirteen-years-on-advancing-the-understanding-of-iis-short-file-name-sfn-disclosure/"
            }
         ],
         "Authors": ["Soroush Dalili (@irsdl)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-07-31",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "How I Hacked Microsoft Teams and got $150,000 in Pwn2Own",
               "Link": "https://speakerdeck.com/masatokinugawa/how-i-hacked-microsoft-teams-and-got-150000-dollars-in-pwn2own"
            }
         ],
         "Authors": ["Masato Kinugawa (@kinugawamasato)"],
         "Programs": ["Microsoft (Teams)"],
         "Bugs": ["Electron", "XSS", "RCE"],
         "Bounty": "150,000",
         "PublicationDate": "2023-07-31",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Knocking on the Front Door (client side desync attack on Azure CDN)",
               "Link": "https://blog.jeti.pw/posts/knocking-on-the-front-door/"
            }
         ],
         "Authors": ["Jeti (@0xJeti)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Client-Side Desync attack"],
         "Bounty": "7,500",
         "PublicationDate": "2023-07-31",
         "AddedDate": "2023-08-14"
      },
      {
         "Links": [
            {
               "Title": "How Cross-Site Frame Counting Exposes Private Repositories On Github",
               "Link": "https://mr-medi.github.io/research/2023/07/31/exploring-cross-site-frame-counting-attacks.html"
            }
         ],
         "Authors": ["Medi (@medi_0ne)"],
         "Programs": ["GitHub"],
         "Bugs": ["Cross-Site Frame Counting"],
         "Bounty": "-",
         "PublicationDate": "2023-07-31",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "Desperate XSS",
               "Link": "https://medium.com/@ramkumarnadar47/desperate-xss-ce3619343f57"
            }
         ],
         "Authors": ["Ramkumar Nadar"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-07-31",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Samesite Cookie Restrictions with Method Override",
               "Link": "https://hazanasec.github.io/2023-07-30-Samesite-bypass-method-override.md/"
            }
         ],
         "Authors": ["Hazana (@HazanaSec)"],
         "Programs": ["-"],
         "Bugs": ["Samesite cookie bypass", "CSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-07-30",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "HTML Over the Wire",
               "Link": "https://bountyplz.xyz/bugbounty/2023/07/30/HTML-Over-The-Wire.html"
            }
         ],
         "Authors": ["Ryan (@healthyoutlet)"],
         "Programs": ["Hotwire Turbo", "htmx"],
         "Bugs": ["CSRF", "Token leak"],
         "Bounty": "-",
         "PublicationDate": "2023-07-30",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "Bypassing email verification of high-profile tech company ($$$)",
               "Link": "https://infosecwriteups.com/bypassing-email-verification-of-high-profile-tech-company-e592cc4a89ce"
            }
         ],
         "Authors": ["can1337 (@canmustdie)"],
         "Programs": ["-"],
         "Bugs": ["Email verification bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-07-30",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "Access of Android protected components via embedded intent | Android App Pentesting",
               "Link": "https://medium.com/@abhishek.karle92/access-of-android-protected-components-via-embedded-intent-android-app-pentesting-5618ae3cc9b2"
            }
         ],
         "Authors": ["Abhishek Karle (@AbhishekKarle3)"],
         "Programs": ["-"],
         "Bugs": ["Android", "Improper Export of Android Application Components", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-07-30",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "CSRFing VS Code's Debug Adapter Protocol",
               "Link": "https://www.mcnulty.blog/posts/dap-csrf"
            }
         ],
         "Authors": ["Dan McNulty (@_Z7mcnulty)"],
         "Programs": ["Microsoft (VS Code)"],
         "Bugs": ["CSRF", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-07-28",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "How I found two api vulnerabilities by analyzing JS source code",
               "Link": "https://medium.com/@mohammed0x04/how-i-found-two-api-vulnerabilities-using-website-source-code-6c4b0dc54d6f"
            }
         ],
         "Authors": ["Mohammed Waleed"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-07-28",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "GameOver(lay): Easy-to-exploit local privilege escalation vulnerabilities in Ubuntu Linux affect 40% of Ubuntu cloud workloads",
               "Link": "https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability"
            }
         ],
         "Authors": ["Sagi Tzadik (@sagitz_)", "Shir Tamari (@shirtamari)"],
         "Programs": ["Ubuntu"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-07-27",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "No keys attached: Exploring GitHub-to-AWS keyless authentication flaws",
               "Link": "https://securitylabs.datadoghq.com/articles/exploring-github-to-aws-keyless-authentication-flaws/"
            }
         ],
         "Authors": ["Christophe Tafani-Dereeper (@christophetd)"],
         "Programs": ["UK Cabinet Office"],
         "Bugs": ["OIDC", "CI/CD", "Cloud", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-07-27",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "Huawei Theme Manager Arbitrary Code Execution",
               "Link": "https://blog.doyensec.com/2023/07/26/huawei-theme-arbitrary-code-exec.html"
            }
         ],
         "Authors": ["Luca Carettoni (@lucacarettoni)"],
         "Programs": ["Huawei"],
         "Bugs": ["Arbitrary Code Execution", "Android"],
         "Bounty": "-",
         "PublicationDate": "2023-07-26",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "AWS WAF Bypass: invalid JSON object and unicode escape sequences",
               "Link": "https://blog.sicuranext.com/aws-waf-bypass/"
            }
         ],
         "Authors": ["Andrea Menin (@AndreaTheMiddle)"],
         "Programs": ["AWS"],
         "Bugs": ["WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-07-26",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "Opinions are like Bugs - Every Spec has one.",
               "Link": "https://bountyplz.xyz/bugbounty/2023/07/24/Opinions-are-like-bugs.html"
            }
         ],
         "Authors": ["Ryan (@healthyoutlet)"],
         "Programs": ["-"],
         "Bugs": ["HTML injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-07-24",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "Analysis of CVE-2023-3519 in Citrix ADC and NetScaler Gateway",
               "Link": "https://blog.assetnote.io/2023/07/21/citrix-CVE-2023-3519-analysis/"
            },
            {
               "Title": "Part 2",
               "Link": "https://blog.assetnote.io/2023/07/24/citrix-rce-part-2-cve-2023-3519/"
            }
         ],
         "Authors": ["Dylan Pindur", "Shubham Shah (@infosec_au)"],
         "Programs": ["Citrix Systems"],
         "Bugs": ["RCE", "Code injection", "SAML", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-24",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Chaining our way to Pre-Auth RCE in Metabase (CVE-2023-38646)",
               "Link": "https://blog.assetnote.io/2023/07/22/pre-auth-rce-metabase/"
            }
         ],
         "Authors": ["Shubham Shah (@infosec_au)", "Maxwell Garrett (@TheGrandPew)"],
         "Programs": ["Metabase"],
         "Bugs": ["RCE", "SQL injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-22",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "Hijacking Cloud CI/CD Systems for Fun and Profit",
               "Link": "https://divyanshu-mehta.gitbook.io/researchs/hijacking-cloud-ci-cd-systems-for-fun-and-profit#azure"
            }
         ],
         "Authors": ["Divyanshu (@gh0st_r1d3r_0x9)"],
         "Programs": ["Google (GCP)", "AWS", "Microsoft (Azure)"],
         "Bugs": ["Cloud", "CI/CD", "Repojacking"],
         "Bounty": "50,000",
         "PublicationDate": "2023-07-22",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "How I was Able To Bypass The Admin Panel",
               "Link": "https://medium.com/@mohameddiv77/how-i-was-able-to-bypass-the-admin-panel-9a5a81e2ec11"
            }
         ],
         "Authors": ["Mohamed Ibrahim (@mOhamedd7w)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-07-20",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "A Tale of OG XSS",
               "Link": "https://medium.com/@mullangisashank/a-tale-of-og-xss-89af3d4725dc"
            }
         ],
         "Authors": ["Mullangisashank (@manisashankm)"],
         "Programs": ["-"],
         "Bugs": ["XSS", "Open Graph"],
         "Bounty": "-",
         "PublicationDate": "2023-07-20",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-38408: Remote Code Execution in OpenSSH’s forwarded ssh-agent",
               "Link": "https://blog.qualys.com/vulnerabilities-threat-research/2023/07/19/cve-2023-38408-remote-code-execution-in-opensshs-forwarded-ssh-agent"
            }
         ],
         "Authors": ["Qualys Threat Research Unit (TRU)"],
         "Programs": ["OpenSSH"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-07-20",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Escalating Privileges With SSRF",
               "Link": "https://kuldeep.io/posts/escalating-privileges-with-ssrf/"
            }
         ],
         "Authors": ["Kuldeep Pandya (@kuldeepdotexe)"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "JWT"],
         "Bounty": "-",
         "PublicationDate": "2023-07-20",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "One LFI bypass to rule them all (using base64)",
               "Link": "https://matan-h.com/one-lfi-bypass-to-rule-them-all-using-base64/"
            }
         ],
         "Authors": ["matan-h"],
         "Programs": ["-"],
         "Bugs": ["LFI"],
         "Bounty": "-",
         "PublicationDate": "2023-07-20",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-36934: Progress Software MOVEit Transfer SQL Injection Remote Code Execution Vulnerability",
               "Link": "https://www.zerodayinitiative.com/blog/2023/7/19/cve-2023-36934-progress-software-moveit-transfer-sql-injection-remote-code-execution-vulnerability"
            }
         ],
         "Authors": ["Guy Lederfein (@glederfein)", "Lucas Miller"],
         "Programs": ["Progress (MOVEit Transfer)"],
         "Bugs": ["SQL injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-20",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Shifting boundaries: Exploiting an Integer Overflow in Apple Safari",
               "Link": "https://blog.exodusintel.com/2023/07/20/shifting-boundaries-exploiting-an-integer-overflow-in-apple-safari/"
            }
         ],
         "Authors": ["Vignesh Rao"],
         "Programs": ["Apple"],
         "Bugs": ["Integer overflow", "Memory corruption", "Browser hacking"],
         "Bounty": "-",
         "PublicationDate": "2023-07-20",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory –  TP-Link TL-WR840N Stack Buffe Overflow DOSy",
               "Link": "https://ssd-disclosure.com/ssd-advisory-tp-link-tl-wr840n-stack-buffer-overflow-dos/"
            }
         ],
         "Authors": ["delsploit (@delsploit)"],
         "Programs": ["TP-Link"],
         "Bugs": ["Buffer Overflow", "Memory corruption", "DoS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-20",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Session Token Enumeration in RWS WorldServer",
               "Link": "https://www.redteam-pentesting.de/de/advisories/rt-sa-2023-001/-session-token-enumeration-in-rws-worldserver"
            }
         ],
         "Authors": ["RedTeam Pentesting (@RedTeamPT)"],
         "Programs": ["Trados (WorldServer)"],
         "Bugs": ["Session management issue", "Bruteforce"],
         "Bounty": "-",
         "PublicationDate": "2023-07-19",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Escalating Privileges via Third-Party Windows Installers",
               "Link": "https://www.mandiant.com/resources/blog/privileges-third-party-windows-installers"
            }
         ],
         "Authors": ["Andrew Oliveau (@AndrewOliveau)"],
         "Programs": ["Atera"],
         "Bugs": ["Local Privilege Escalation", "DLL Hijacking"],
         "Bounty": "-",
         "PublicationDate": "2023-07-19",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "A Twist in the Code: OpenMeetings Vulnerabilities through Unexpected Application State",
               "Link": "https://www.sonarsource.com/blog/a-twist-in-the-code-openmeetings-vulnerabilities-through-unexpected-application-state/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["Apache OpenMeetings"],
         "Bugs": ["Account takeover", "RCE", "Null-Byte injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-19",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-38205: Adobe ColdFusion Access Control Bypass [FIXED]",
               "Link": "https://www.rapid7.com/blog/post/2023/07/19/cve-2023-38205-adobe-coldfusion-access-control-bypass-fixed/"
            }
         ],
         "Authors": ["Stephen Fewer (@stephenfewer)"],
         "Programs": ["Adobe"],
         "Bugs": ["Broken Access Control", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-19",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Lenovo Update Your Privileges",
               "Link": "https://blog.compass-security.com/2023/07/lenovo-update-your-privileges/"
            }
         ],
         "Authors": ["Raphael Rosenast"],
         "Programs": ["Lenovo"],
         "Bugs": ["Local Privilege Escalation", "DLL Hijacking", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2023-07-19",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Shodan Recon to $1000 bounty in 2 mins",
               "Link": "https://medium.com/@aditya043k/shodan-recon-to-1000-bounty-in-2-mins-b168ced3bfb0"
            }
         ],
         "Authors": ["Aditya Singh (@CyberBeast10100)"],
         "Programs": ["-"],
         "Bugs": ["Missing authentication"],
         "Bounty": "1,000",
         "PublicationDate": "2023-07-18",
         "AddedDate": "2023-07-31"
      },
      {
         "Links": [
            {
               "Title": "Bad.Build: A Critical Privilege Escalation Design Flaw in Google Cloud Build Enables a Supply Chain Attack",
               "Link": "https://orca.security/resources/blog/bad-build-google-cloud-build-potential-supply-chain-attack-vulnerability/"
            }
         ],
         "Authors": ["Roi Nisimi (@roinisimi)"],
         "Programs": ["Google"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-07-18",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Absuing Amazon VPC CNI Plugin For Kubernetes",
               "Link": "https://www.elttam.com/blog/amazon-vpc-cni/"
            }
         ],
         "Authors": ["Beme Carnpbell (@BerneCampbell)"],
         "Programs": ["-"],
         "Bugs": ["Kubernetes", "Privilege escalation", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-07-17",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Blind SQL injection with a little WAF",
               "Link": "https://kair0s3.medium.com/blind-sql-injection-with-a-little-waf-871e69d06e2c"
            }
         ],
         "Authors": ["tb"],
         "Programs": ["-"],
         "Bugs": ["Blind SQL injection", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-07-17",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "The Buffer Curse: A tale of unusual exploitation in Web Application",
               "Link": "https://infosecwriteups.com/the-buffer-curse-3591efb4a724"
            }
         ],
         "Authors": ["Felix Alexander (@felixalexxx)"],
         "Programs": ["-"],
         "Bugs": ["CSP bypass", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-07-16",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "Poch, Poch, is this thing on? Bypass AMSI with Divide & Conquer",
               "Link": "https://badoption.eu/blog/2023/07/15/divideconqer.html"
            }
         ],
         "Authors": ["pfiatDe (@pfiatde)"],
         "Programs": ["Microsoft (Windows Defender)"],
         "Bugs": ["AMSI bypass", "Local Privilege Escalation", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2023-07-15",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "PenTales: Old Vulns, New Tricks",
               "Link": "https://www.rapid7.com/blog/post/2023/07/13/pentales-old-vulns-new-tricks/"
            }
         ],
         "Authors": ["Austin Guidry"],
         "Programs": ["-"],
         "Bugs": ["Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2023-07-14",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "https://infosecwriteups.com/exploiting-incorrectly-configured-load-balancer-with-xss-to-steal-cookies-99d7cb6129d7",
               "Link": "https://infosecwriteups.com/exploiting-incorrectly-configured-load-balancer-with-xss-to-steal-cookies-99d7cb6129d7"
            }
         ],
         "Authors": ["Serj Novoselov (@novoselov_s)"],
         "Programs": ["-"],
         "Bugs": ["Load balancer", "Host header injection", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-07-13",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Let’s Go For Whole Company",
               "Link": "https://infosecwriteups.com/lets-go-for-whole-company-d2e24bcfb5ef"
            }
         ],
         "Authors": ["Arman (@M7arm4n)"],
         "Programs": ["-"],
         "Bugs": ["Default credentials"],
         "Bounty": "-",
         "PublicationDate": "2023-07-13",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "Demo: Brute-forcing a macOS user’s real name from a browser using mDNS",
               "Link": "https://fingerprint.com/blog/apple-macos-mdns-brute-force/"
            }
         ],
         "Authors": ["Konstantin Darutkin"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["Privacy issue", "Bruteforce", "mDNS"],
         "Bounty": "-",
         "PublicationDate": "2023-07-13",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "Modeling Malicious Code: Hacking In 3D",
               "Link": "https://www.trustedsec.com/blog/modeling-malicious-code-hacking-in-3d/"
            }
         ],
         "Authors": ["Zach Bevilacqua"],
         "Programs": ["-"],
         "Bugs": ["Phishing", "RCE", "Initial access"],
         "Bounty": "-",
         "PublicationDate": "2023-07-13",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementation",
               "Link": "https://blog.talosintelligence.com/weaknesses-mac-os-vmware-msrpc/"
            }
         ],
         "Authors": ["Aleksandar Nikolic", "Dimitrios Tatsis"],
         "Programs": ["Apple (macOS)", "VMware"],
         "Bugs": ["Kernel hacking", "MS-RPC", "DoS", "Memory corruption", "Use-After-Free", "Heap overflow", "Buffer Overflow"],
         "Bounty": "-",
         "PublicationDate": "2023-07-13",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "Adobe ColdFusion Pre-Auth RCE(s)",
               "Link": "https://blog.projectdiscovery.io/adobe-coldfusion-rce/"
            }
         ],
         "Authors": ["Harsh Jaiswal (@rootxharsh)", "Rahul Maini (@iamnoooob)"],
         "Programs": ["Adobe (ColdFusion)"],
         "Bugs": ["RCE", "ColdFusion", "JNDI Injection", "Insecure deserialization", "Security code review", "Patch diffing"],
         "Bounty": "-",
         "PublicationDate": "2023-07-12",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Major Security Flaws in Popular QuickBlox Chat And Video Framework Expose Sensitive Data Of Millions",
               "Link": "https://claroty.com/team82/research/major-security-flaws-in-popular-quickblox-chat-and-video-framework-expose-sensitive-data-of-millions"
            }
         ],
         "Authors": ["Amir Preminger", "Sharon Brizinov", "Itay Cohen", "Oleg Ilushin"],
         "Programs": ["QuickBlox"],
         "Bugs": ["IDOR", "Information disclosure", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-07-12",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Performance, Diagnostics, and WMI",
               "Link": "https://posts.specterops.io/performance-diagnostics-and-wmi-21f3e01790d3"
            }
         ],
         "Authors": ["Steven Flores (@0xthirteen)"],
         "Programs": ["-"],
         "Bugs": ["Lateral movement", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2023-07-12",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "How Private Cache Can Lead to Mass Account Takeover – pentest case",
               "Link": "https://research.securitum.com/how-private-cache-can-lead-to-mass-account-takeover-pentest-case/"
            }
         ],
         "Authors": ["Mateusz Kowalczyk"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-07-12",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "Security Feature Bypass In ASP.NET and Visual Studio – Race Condition",
               "Link": "https://zxsecurity.co.nz/research/advisories/race-condition-asp-net-core-signinmanager/"
            }
         ],
         "Authors": ["Jack Moran", "TC", "Ethan McKee-Harris"],
         "Programs": ["Microsoft"],
         "Bugs": ["Race condition", "Bruteforce"],
         "Bounty": "-",
         "PublicationDate": "2023-07-12",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "Story of Clickjacking on Microsoft Leads To Privilege Escalation & Account Takeover Of Admin",
               "Link": "https://medium.com/@abdulparkar9554/story-of-clickjacking-in-microsoft-leads-to-privilege-escalation-account-takeover-of-admin-a04453ed47fc"
            }
         ],
         "Authors": ["Abdul Rehman Parkar"],
         "Programs": ["Microsoft"],
         "Bugs": ["Clickjacking", "Privilege escalation", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-07-12",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "Executing Arbitrary Code & Executables in Read-Only FileSystems",
               "Link": "https://labs.withsecure.com/publications/executing-arbitrary-code-executables-in-read-only-filesystems"
            }
         ],
         "Authors": ["Golan Myers"],
         "Programs": ["-"],
         "Bugs": ["Kubernetes", "Container security", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-07-12",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "Bee-yond Capacity: Unauthenticated RCE in Extreme Networks/Aerohive Wireless APs - CVE-2023-35803",
               "Link": "https://research.aurainfosec.io/pentest/bee-yond-capacity/"
            }
         ],
         "Authors": ["Lachlan Davidson (@lachlan2k)"],
         "Programs": ["Extreme Networks"],
         "Bugs": ["Memory corruption", "Buffer Overflow", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-07-12",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "Proof of Concept Developed for Ghostscript CVE-2023-36664 Code Execution Vulnerability",
               "Link": "https://www.kroll.com/en/insights/publications/cyber/ghostscript-cve-2023-36664-remote-code-execution-vulnerability"
            }
         ],
         "Authors": ["Dave Truman"],
         "Programs": ["Artifex Ghostscript"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-07-11",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Exploiting JMeter via RMI",
               "Link": "https://medium.com/workday-engineering/exploiting-jmeter-via-rmi-e8e12392bba8"
            }
         ],
         "Authors": ["Christopher Ellis"],
         "Programs": ["Apache JMeter"],
         "Bugs": ["Insecure deserialization", "Java RMI", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-11",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "All your parcel are belong to us – Talk at Troopers 2023",
               "Link": "https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/"
            }
         ],
         "Authors": ["Dennis Kniel", "Florian Bausch"],
         "Programs": ["DHL"],
         "Bugs": ["Privacy issue", "Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2023-07-11",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "Exploiting XSS in hidden inputs and meta tags",
               "Link": "https://portswigger.net/research/exploiting-xss-in-hidden-inputs-and-meta-tags"
            }
         ],
         "Authors": ["Gareth Heyes (@garethheyes)"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-07-11",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "An interesting RCE on a Synack Red Team target!",
               "Link": "https://d4ly.medium.com/an-interesting-rce-on-a-synack-red-team-target-516edb63fd04"
            }
         ],
         "Authors": ["Daly Whyte (@_d4ly_)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Groovy scripting"],
         "Bounty": "-",
         "PublicationDate": "2023-07-11",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "Critical Foswiki Vulnerablities: A Logic Error Turned Remote Code Execution",
               "Link": "https://herolab.usd.de/en/critical-foswiki-vulnerablities-a-logic-error-turned-remote-code-execution/"
            }
         ],
         "Authors": ["Christian Pöschl"],
         "Programs": ["Foswiki"],
         "Bugs": ["RCE", "Privilege escalation", "Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2023-07-11",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-29298: Adobe ColdFusion Access Control Bypass",
               "Link": "https://www.rapid7.com/blog/post/2023/07/11/cve-2023-29298-adobe-coldfusion-access-control-bypass/"
            }
         ],
         "Authors": ["Stephen Fewer (@stephenfewer)"],
         "Programs": ["Adobe"],
         "Bugs": ["Broken Access Control", "Logic flaw", "Security code review", "ColdFusion"],
         "Bounty": "-",
         "PublicationDate": "2023-07-11",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "Unexpected Zero in MySQL Injection",
               "Link": "https://dimazarno.medium.com/unexpected-zero-in-mysql-injection-511f632714b0"
            }
         ],
         "Authors": ["Dimaz Arno (@dimazarno)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-07-11",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "Unveiling Access Control Flaws: How a Viewer Became an Editor",
               "Link": "https://amjadali110.medium.com/unveiling-access-control-flaws-how-a-viewer-became-an-editor-b4aa83a5a0ec"
            }
         ],
         "Authors": ["Amjad Ali"],
         "Programs": ["-"],
         "Bugs": ["Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-07-10",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "How I got Two RCE at EPAM-Bounty Program",
               "Link": "https://web.archive.org/web/20230710001307/https://0xbartita.medium.com/how-i-got-two-rce-at-epam-bounty-program-389eb9fc7938"
            }
         ],
         "Authors": ["0xBartita (@0xBaRtiTa)"],
         "Programs": ["EPAM"],
         "Bugs": ["SAP", "Default credentials", "RCE", "Groovy scripting"],
         "Bounty": "-",
         "PublicationDate": "2023-07-10",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "Account (of the CEO) Takeover via Password Reset",
               "Link": "https://cristivlad.medium.com/account-of-the-ceo-takeover-via-password-reset-7e55c0175425"
            }
         ],
         "Authors": ["Cristi Vlad (@CristiVlad25)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Password reset", "IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-07-10",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "AWS CodeBuild + S3 == Privilege Escalation",
               "Link": "https://www.shielder.com/blog/2023/07/aws-codebuild--s3-privilege-escalation/"
            }
         ],
         "Authors": ["Paolo Cavaglià (@Paupu_95)"],
         "Programs": ["-"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-07-10",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "From Blackbox .NET Remoting to Unauthenticated Remote Code Execution",
               "Link": "https://code-white.com/blog/2023-07-from-blackbox-dotnet-remoting-to-rce/"
            }
         ],
         "Authors": ["Florian Hauser (@frycos)"],
         "Programs": ["act!"],
         "Bugs": ["RCE", ".NET Remoting", "Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2023-07-10",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "IDN Homograph Attack and Response Manipulation - The Rarest Case",
               "Link": "https://shahjerry33.medium.com/idn-homograph-attack-and-response-manipulation-the-rarest-case-85f64c272a1c"
            }
         ],
         "Authors": ["Jerry Shah (@Jerry)"],
         "Programs": ["-"],
         "Bugs": ["IDN homograph attack", "HTTP response manipulation", "Account takeover", "Password reset"],
         "Bounty": "-",
         "PublicationDate": "2023-07-09",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-36934 Analysis: MOVEit Transfer SQL Injection",
               "Link": "https://blog.projectdiscovery.io/moveit-transfer-sql-injection/"
            }
         ],
         "Authors": ["Rahul Maini (@iamnoooob)", "Harsh Jaiswal (@rootxharsh)"],
         "Programs": ["Progress (MOVEit Transfer)"],
         "Bugs": ["SQL injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-09",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "macOS Atlassian Companion Remote Code Execution",
               "Link": "https://www.wojciechregula.blog/post/macos-atlassian-companion-rce/"
            }
         ],
         "Authors": ["Wojciech Reguła (@_r3ggi)"],
         "Programs": ["Atlassian"],
         "Bugs": ["RCE", "MacOS", "Thick client"],
         "Bounty": "-",
         "PublicationDate": "2023-07-09",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover via Custom OTP, No User Interaction Required!",
               "Link": "https://bhavukjain.com/blog/2023/07/08/account-takeover-custom-otp/"
            }
         ],
         "Authors": ["Bhavuk Jain (@bhavukjain1)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "OTP bypass", "Authentication bypass", "Rate limiting bypass", "Captcha bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-07-08",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "[REL] A Journey Into Hacking Google Search Appliance",
               "Link": "https://devco.re/blog/2023/07/07/a-journey-into-hacking-google-search-appliance-en/"
            }
         ],
         "Authors": ["DEVCORE (@d3vc0r3)"],
         "Programs": ["Google"],
         "Bugs": ["RCE", "Line Feed injection", "Path traversal", "Arbitrary file read", "Information disclosure", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-07",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "New Vulnerability in protobufjs: Prototype Pollution - CVE-2023-36665",
               "Link": "https://www.code-intelligence.com/blog/cve-protobufjs-prototype-pollution-cve-2023-36665"
            }
         ],
         "Authors": ["Peter Samarin"],
         "Programs": ["protobufjs"],
         "Bugs": ["Prototype pollution", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-06",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "PenTales: “User enumeration is not a vulnerability” – I beg to differ",
               "Link": "https://www.rapid7.com/blog/post/2023/07/06/user-enumeration-is-not-a-vulnerability-i-beg-to-differ/"
            }
         ],
         "Authors": ["Ben Leiden"],
         "Programs": ["-"],
         "Bugs": ["Username enumeration", "Password spraying", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-07-06",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "Full Disclosure - DOM-based XSS And Failures In Bug Bounty Hunting",
               "Link": "https://kuldeep.io/posts/fulldisclosure-dom-based-xss/"
            }
         ],
         "Authors": ["Kuldeep Pandya (@kuldeepdotexe)"],
         "Programs": ["-"],
         "Bugs": ["DOM XSS", "CSS injection"],
         "Bounty": "-",
         "PublicationDate": "2023-07-06",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "RCE In GitLab's CLI Tool",
               "Link": "http://blog.takemyhand.xyz/2023/07/remote-code-execution-in-gitlabs-cli.html"
            }
         ],
         "Authors": ["ameya (@0xtakemyhand)"],
         "Programs": ["GitLab"],
         "Bugs": ["RCE", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-06",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "Windows Installer arbitrary content manipulation Elevation of Privilege (CVE-2020-0911)",
               "Link": "https://offsec.almond.consulting/windows-msiexec-eop-cve-2020-0911.html"
            }
         ],
         "Authors": ["clem (@clavoillotte)", "Jonas L (@jonasLyk)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-07-06",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "Story Of My First RCE :)",
               "Link": "https://medium.com/@0utlawh4ck3r/story-of-my-first-rce-9d74373fbc11"
            }
         ],
         "Authors": ["0utlawh4ck3r (@outlawh4ck3r)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Default credentials"],
         "Bounty": "-",
         "PublicationDate": "2023-07-06",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "Recon only bugs are sweet!",
               "Link": "https://hazemhussien99.wordpress.com/2023/07/05/recon-only-bugs-are-sweet/"
            }
         ],
         "Authors": ["Hazem Hussien (@_bughunter)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "Local file disclosure (LFD)", "Stored XSS", "Self-XSS", "vHost misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-07-05",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Chaining for Critical: Unauthorized to Cloud Administrator",
               "Link": "https://www.klogixsecurity.com/scorpion-labs-blog/chaining-for-critical-unauthorized-to-cloud-administrator"
            }
         ],
         "Authors": ["Jake Wnuk"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "HTML injection"],
         "Bounty": "-",
         "PublicationDate": "2023-07-05",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "Sometimes What Sounds Benign Can Bite You: An Unexpected Implication of Lambda Privileges",
               "Link": "https://ermetic.com/blog/aws/sometimes-what-sounds-benign-can-bite-you-an-unexpected-implication-of-lambda-privileges/"
            }
         ],
         "Authors": ["Ermetic Team"],
         "Programs": ["AWS"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-07-04",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Non-Cloud SSRF for More Fun & Profit",
               "Link": "https://basu-banakar.medium.com/exploiting-non-cloud-ssrf-for-more-fun-profit-3597934518c8"
            }
         ],
         "Authors": ["Basavaraj Banakar (@basu_banakar)"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-07-04",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "Linux local electron application script-src: self bypass",
               "Link": "https://mizu.re/post/linux-local-electron-application-script-src-self-bypass#final_bypass"
            }
         ],
         "Authors": ["Mizu (@kevin_mizu)"],
         "Programs": ["-"],
         "Bugs": ["Electron", "CSP bypass", "XSS", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-07-04",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "Encrypted Doesn't Mean Authenticated: ShareFile RCE (CVE-2023-24489)",
               "Link": "https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce/"
            }
         ],
         "Authors": ["Dylan Pindur"],
         "Programs": ["Citrix (ShareFile)"],
         "Bugs": ["RCE", "Path traversal", "Cryptographic issues", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-04",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "Getting email address of any HackerOne user worth $7,500",
               "Link": "https://medium.com/pinoywhitehat/getting-email-address-of-any-hackerone-user-worth-7-500-afb8076ee395"
            }
         ],
         "Authors": ["Japz Divino (@japzdivino)"],
         "Programs": ["HackerOne"],
         "Bugs": ["Information disclosure"],
         "Bounty": "7,500",
         "PublicationDate": "2023-07-04",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "Partial File Read in phpList <= 3.6.12 (CVE-2023-35834)",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-07/synacktiv-phplist-partial-file-read.pdf"
            }
         ],
         "Authors": ["Vincent Herbulot", "Rémi Matasse (@_remsio_)"],
         "Programs": ["phpList"],
         "Bugs": ["Arbitrary file read", "PHP filter chain", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-04",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "Technical Advisory – Nullsoft Scriptable Installer System (NSIS) – Insecure Temporary Directory Usage",
               "Link": "https://research.nccgroup.com/2023/07/03/technical-advisory-nullsoft-scriptable-installer-system-nsis-insecure-temporary-directory-usage/"
            }
         ],
         "Authors": ["Richard Warren (@buffaloverflow)"],
         "Programs": ["Nullsoft Scriptable Installer System (NSIS)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-07-03",
         "AddedDate": "2023-07-24"
      },
      {
         "Links": [
            {
               "Title": "On ColdFusion, AES, and Padding Oracle Attacks: Hic Sunt Dracones",
               "Link": "https://hoyahaxa.blogspot.com/2023/07/on-coldfusion-aes-and-padding-oracle.html"
            }
         ],
         "Authors": ["Brian (@hoyahaxa)"],
         "Programs": ["-"],
         "Bugs": ["Padding oracle attack", "ColdFusion", "Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2023-07-03",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "Hunting for Nginx Alias Traversals in the wild",
               "Link": "https://labs.hakaioffsec.com/nginx-alias-traversal/"
            }
         ],
         "Authors": ["Daniel (Celesian) Matsumoto (@c3l3si4n)"],
         "Programs": ["Bitwarden", "Google"],
         "Bugs": ["Path traversal"],
         "Bounty": "6,500",
         "PublicationDate": "2023-07-03",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "How We Found Another GitHub Action Environment Injection Vulnerability in a Google Project",
               "Link": "https://www.legitsecurity.com/blog/-how-we-found-another-github-action-environment-injection-vulnerability-in-a-google-project"
            }
         ],
         "Authors": ["Noam Dotan"],
         "Programs": ["Google (Orbit)"],
         "Bugs": ["CI/CD", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-07-03",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "Technical Details of CVE-2023-30990 - Unauthenticated RCE in IBM i DDM Service",
               "Link": "https://blog.silentsignal.eu/2023/07/03/ibm-i-dde-vulnerability-cve-2023-30990/"
            }
         ],
         "Authors": ["pz"],
         "Programs": ["IBM"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-07-03",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "Patch Diffing CVE-2023-28121 to Compromise a WooCommerce",
               "Link": "https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/"
            }
         ],
         "Authors": ["Julien Ahrens (@MrTuxracer)"],
         "Programs": ["-"],
         "Bugs": ["Authentication bypass", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-07-03",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "How Abusing AWS CloudFormation Led to a Total Takeover of an AWS Environment",
               "Link": "https://blog.prodefense.io/how-abusing-aws-cloudformation-led-to-a-total-takeover-of-an-aws-environment-7f94cabd671d"
            }
         ],
         "Authors": ["Matthew Keeley (@Nightbanes)"],
         "Programs": ["-"],
         "Bugs": ["Cloud", "Information disclosure", "Privilege escalation", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-07-02",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "How did I get 200$ with WordPress vulnerability!!!",
               "Link": "https://medium.com/@nguhuynh.148/how-did-i-get-200-with-wordpress-vulnerability-4ce80f106709"
            }
         ],
         "Authors": ["Nguhuynh"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "200",
         "PublicationDate": "2023-07-02",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "Multiple vulnerabilities on Chamilo 1.11.18",
               "Link": "https://www.randorisec.fr/chamilo-1.11.18-multiple-vulnerabilities"
            }
         ],
         "Authors": ["Aituglo (@aituglo)"],
         "Programs": ["Chamilo"],
         "Bugs": ["OS command injection", "RCE", "SSRF", "IDOR", "XSS", "CSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-07-01",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "How i was able to get Account Takeover via Insecure Data Storage and WebView With Exported Activity",
               "Link": "https://medium.com/@M0X0101/how-i-was-able-to-get-account-takeover-via-insecure-data-storage-and-webview-with-exported-activity-5308a330ab80"
            }
         ],
         "Authors": ["Mohamed Reda (@M0x0101)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Android", "Webview", "Insecure data storage", "Firebase"],
         "Bounty": "-",
         "PublicationDate": "2023-07-01",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "Multiple Vulnerabilities In Cockpit CMS <= V2.5.2",
               "Link": "https://www.ghostccamm.com/blog/multi_cockpit_vulns/"
            }
         ],
         "Authors": ["GhostCcamm (@GhostCcamm)"],
         "Programs": ["Cockpit CMS"],
         "Bugs": ["CSRF", "Unrestricted file upload", "RCE", "XSS", "IDOR", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-30",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "Domain Takeover Without Domain Admin Permissions",
               "Link": "https://medium.themayor.tech/domain-takeover-without-domain-admin-permissions-28a7bd330501"
            }
         ],
         "Authors": ["Joe Helle (@joehelle)"],
         "Programs": ["-"],
         "Bugs": ["Active Directory Privilege Escalation", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2023-06-30",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "Server-side Template Injection Leading to RCE on Google VRP",
               "Link": "https://neupanemizzle.medium.com/server-side-template-injection-leading-to-rce-on-google-vrp-75f0a4bc6ebc"
            }
         ],
         "Authors": ["mizzleneupane (@mizzle_neupane5)"],
         "Programs": ["Google"],
         "Bugs": ["SSTI", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-06-30",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "Chaining Self Blind XSS with Broken Access Control To Make it Non Self Blind XSS",
               "Link": "https://sudhanshukashyap123.medium.com/chaining-self-blind-xss-with-broken-access-control-to-make-it-non-self-blind-xss-626a70c8bbc7"
            }
         ],
         "Authors": ["sudhanshu Kumar kashyap (@ReebootToInit5)"],
         "Programs": ["-"],
         "Bugs": ["Blind XSS", "Self-XSS", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-06-30",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-33298 - Perimeter81 Local Privilege Escalation",
               "Link": "https://www.ns-echo.com/posts/cve_2023_33298.html"
            }
         ],
         "Authors": ["NSEcho (@lateralusd_)"],
         "Programs": ["Perimeter81"],
         "Bugs": ["Local Privilege Escalation", "MacOS", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2023-06-30",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "SSO Gadgets II: Unauthenticated Client-Side Template Injection to Account Takeover using SSO Gadget Chain",
               "Link": "https://security.lauritz-holtmann.de/post/csti-xss-sso-gadget-chain/"
            }
         ],
         "Authors": ["Lauritz Holtmann (@_lauritz_)"],
         "Programs": ["-"],
         "Bugs": ["CSTI", "Account takeover", "SSO", "OIDC"],
         "Bounty": "-",
         "PublicationDate": "2023-06-30",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "Laravel debug mode left on at Zouikwatzeggen.nl leaks admin credentials & potentially submitted reports of improper behaviour at Amsterdam University Medical Centers",
               "Link": "https://medium.com/@jonathanbouman/laravel-debug-mode-left-on-at-zouikwatzeggen-nl-948a7365409f"
            }
         ],
         "Authors": ["Jonathan Bouman (@JonathanBouman)"],
         "Programs": ["AmsterdamUMC"],
         "Bugs": ["Debug mode enabled", "Android", "Email spoofing", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-06-30",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "How I get 1000$ bounty for Discovering Account Takeover in Android Application",
               "Link": "https://medium.com/@amolbhavar/how-i-get-1000-bounty-for-discovering-account-takeover-in-android-application-3c4f54fbde39"
            }
         ],
         "Authors": ["Amol Bhavar"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Android", "Client-side enforcement of server-side security", "OTP bypass"],
         "Bounty": "1,000",
         "PublicationDate": "2023-06-30",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "Exploiting the HP Printer without the printer (Pwn2Own 2022)",
               "Link": "https://www.interruptlabs.co.uk/articles/pwn2own-2022-hp-printer"
            }
         ],
         "Authors": ["Interrupt Labs (@InterruptLabs)"],
         "Programs": ["HP"],
         "Bugs": ["Printer hacking", "Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-06-29",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "Bug Writeup: Stored XSS to Account Takeover (ATO) via GraphQL API",
               "Link": "https://www.pmnh.site/post/witeup_lhe_graphql_stored_xss/"
            }
         ],
         "Authors": ["Peter M (@pmnh_)"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS", "CSP bypass", "Account takeover", "GraphQL"],
         "Bounty": "-",
         "PublicationDate": "2023-06-29",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "Reversing Citrix Gateway for XSS",
               "Link": "https://blog.assetnote.io/2023/06/29/binary-reversing-citrix-xss/"
            }
         ],
         "Authors": ["Dylan Pindur"],
         "Programs": ["Citrix Systems"],
         "Bugs": ["Reflected XSS", "Open redirect", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2023-06-29",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "Weakness of Integration",
               "Link": "https://medium.com/@ahmedelmorsy312/weakness-of-integration-bce1520ba672"
            }
         ],
         "Authors": ["Ahmed Elmorsi (@0Xhunterx)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-06-29",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-20864: Remote Code Execution In VMware Aria Operations For Logs",
               "Link": "https://www.zerodayinitiative.com/blog/2023/6/29/cve-2023-20864-remote-code-execution-in-vmware-aria-operations-for-logs"
            }
         ],
         "Authors": ["Dustin Childs"],
         "Programs": ["VMware"],
         "Bugs": ["RCE", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-29",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "Libcurl CRLF",
               "Link": "https://github.com/W0rty/libcurl-crlf"
            }
         ],
         "Authors": ["Pierre Martin (@_Worty)"],
         "Programs": ["PHP libcurl library"],
         "Bugs": ["CRLF injection", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-06-28",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-26258 – Remote Code Execution in ArcServe UDP Backup",
               "Link": "https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/"
            }
         ],
         "Authors": ["Juan Manuel Fernandez (@TheXC3LL)", "Sean Doherty"],
         "Programs": ["ArcServe"],
         "Bugs": ["RCE", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-28",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "Process Mockingjay: Echoing RWX In Userland To Achieve Code Execution",
               "Link": "https://www.securityjoes.com/post/process-mockingjay-echoing-rwx-in-userland-to-achieve-code-execution"
            }
         ],
         "Authors": ["Security Joes (@SecurityJoes)"],
         "Programs": ["-"],
         "Bugs": ["DLL injection", "EDR bypass", "Process injection", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2023-06-27",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "The massive bug at the heart of the npm ecosystem",
               "Link": "https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem"
            }
         ],
         "Authors": ["Darcy Clarke (@darcy)"],
         "Programs": ["-"],
         "Bugs": ["Supply chain attack", "Manifest confusion"],
         "Bounty": "-",
         "PublicationDate": "2023-06-27",
         "AddedDate": "2023-07-03"
      },
      {
         "Links": [
            {
               "Title": "How BAC(Broken Access Control) got me a Pre Account Takeover",
               "Link": "https://bharat-singh.medium.com/how-bac-broken-access-control-got-me-a-pre-account-takeover-2481931b7b3a"
            }
         ],
         "Authors": ["Bharat Singh"],
         "Programs": ["-"],
         "Bugs": ["Pre-account takeover", "IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-06-27",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Unleashing the Power of Recon: How I Earned $2500 in 5 Minutes",
               "Link": "https://infosecwriteups.com/unleashing-the-power-of-recon-how-i-earned-2500-in-5-minutes-cve-2017-5638-ognl-injection-23ece4811f14"
            },
            {
               "Title": "Taking Entire server control Part 2 of How I Earned $2500 in 5 Minutes | CVE-2017–5638 | OGNL injection | RCE",
               "Link": "https://medium.com/@karthithehacker/taking-entire-server-control-part-2-of-how-i-earned-2500-in-5-minutes-cve-2017-5638-ognl-92f4213ca219"
            }
         ],
         "Authors": ["Karthikeyan.V (@karthithehacker)"],
         "Programs": ["-"],
         "Bugs": ["OGNL injection", "RCE", "Components with known vulnerabilities"],
         "Bounty": "2,500",
         "PublicationDate": "2023-06-27",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "DNS Analyzer - Finding DNS vulnerabilities with Burp Suite",
               "Link": "https://sec-consult.com/blog/detail/dns-analyzer-finding-dns-vulnerabilities-with-burp-suite/"
            }
         ],
         "Authors": ["Timo Longin (@timolongin)"],
         "Programs": ["-"],
         "Bugs": ["DNS"],
         "Bounty": "-",
         "PublicationDate": "2023-06-26",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "iOS App Pentesting and Security with Real-World Case Studies Part 2",
               "Link": "https://www.cobalt.io/blog/ios-app-pentesting-and-security-with-real-world-case-studies-part-2"
            }
         ],
         "Authors": ["Swaroop Yermalkar (@swaroopsy)"],
         "Programs": ["-"],
         "Bugs": ["iOS", "Hardcoded credentials", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-06-26",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Why ORMs and Prepared Statements Can't (Always) Win",
               "Link": "https://www.sonarsource.com/blog/why-orms-and-prepared-statements-cant-always-win/"
            }
         ],
         "Authors": ["Thomas Chauchefoin (@swapgs)"],
         "Programs": ["Soko", "Gentoo Linux"],
         "Bugs": ["SQL injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-26",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "Multiple vulnerabilities in UCOPIA <= 6.0.7 (CVE-2022-44719 / CVE-2022-44720)",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-06/synacktiv-ucopia-multiple-vulnerabilities-2022.pdf"
            }
         ],
         "Authors": ["Jean Bonnevie", "Paul Barbé"],
         "Programs": ["Weblib (Ucopia)"],
         "Bugs": ["Security misconfiguration", "Local Privilege Escalation", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2023-06-26",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "ServiceNow Insecure Access Control To Full Admin Takeover",
               "Link": "https://x64.sh/posts/ServiceNow-Insecure-access-control-to-admin/"
            }
         ],
         "Authors": ["Rezk0n (@Rezk0n)"],
         "Programs": ["ServiceNow"],
         "Bugs": ["Broken Access Control", "Privilege escalation", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-06-26",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "DOS attack possible on Reset 2FA feature of #Hackerone",
               "Link": "https://medium.com/@lokesh.leads13/disallow-any-hackerone-user-permanent-access-to-his-her-own-hackerone-account-using-vulnerability-147ce9957692"
            }
         ],
         "Authors": ["Lokesh Ranjan"],
         "Programs": ["HackerOne"],
         "Bugs": ["Application-level DoS", "Lack of rate limiting"],
         "Bounty": "-",
         "PublicationDate": "2023-06-26",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "A Classical Account Takeover Case via Multiple Bypasses",
               "Link": "http://www.kamilonurozkaleli.com/posts/a-classical-account-takeover-case-via-multiple-bypasses/"
            }
         ],
         "Authors": ["Kamil Onur Özkaleli (@ko2sec)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Password reset", "Host header injection", "URL validation bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-26",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover: Unraveling IDOR + Stored XSS Flaws in an NFT Marketplace",
               "Link": "https://medium.com/@pratiky054/account-takeover-unraveling-idor-stored-xss-flaws-in-an-nft-marketplace-158679660fa7"
            }
         ],
         "Authors": ["Pratik Yadav (@PratikY9967)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Stored XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-06-26",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Stored XSS via Exif Data",
               "Link": "https://medium.com/@0day_exploit/stored-xss-via-exif-data-37b279ceb3e9"
            }
         ],
         "Authors": ["0 day exploit (@0day_exploit_)"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-06-26",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "My first two valid and rewarded Web Cache Deceptions, earning $2250",
               "Link": "https://medium.com/@hbenja47/my-first-two-valid-and-rewarded-web-cache-deceptions-earning-2250-c8d2a6968713"
            }
         ],
         "Authors": ["Benja (bronxi) (@hbenja_m)"],
         "Programs": ["-"],
         "Bugs": ["Web cache deception", "CSRF"],
         "Bounty": "2,250",
         "PublicationDate": "2023-06-25",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Using Dark Web in Bug Bounty",
               "Link": "https://realm3ter.medium.com/using-dark-web-in-bug-bounty-3a9530fd454c"
            }
         ],
         "Authors": ["Muhammad Mater (@micro0x00)"],
         "Programs": ["-"],
         "Bugs": ["Credential stuffing"],
         "Bounty": "-",
         "PublicationDate": "2023-06-25",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "How I Hacked Scopely and Got $$$",
               "Link": "https://medium.com/@mydudehello91/how-i-hacked-scopely-and-got-c60772f77d41"
            }
         ],
         "Authors": ["Aryan W13DOM (@NeuRosis23)"],
         "Programs": ["Scopely"],
         "Bugs": ["Self-XSS", "Clickjacking", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-06-25",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "One mistake, Three bugs: Comprehensive android pentesting.",
               "Link": "https://medium.com/@kushjain0107/one-mistake-three-bugs-comprehensive-android-pentesting-a8fc68e36af5"
            }
         ],
         "Authors": ["Kushal Jain"],
         "Programs": ["-"],
         "Bugs": ["Android", "Bruteforce", "Buffer Overflow", "Memory corruption"],
         "Bounty": "600",
         "PublicationDate": "2023-06-24",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Pulling SYSTEM out of Windows GINA",
               "Link": "https://github.com/pedrib/PoC/blob/master/advisories/ManageEngine/adselfpwnplus/adselfpwnplus.md"
            }
         ],
         "Authors": ["Pedro Ribeiro (@pedrib1337)", "João Bigotte", "Ashley King"],
         "Programs": ["Zoho (ManageEngine ADSelfService Plus)"],
         "Bugs": ["Authentication bypass", "Windows", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-06-23",
         "AddedDate": "2023-07-11"
      },
      {
         "Links": [
            {
               "Title": "GraphQL API Hacking!",
               "Link": "https://medium.com/@mahmud0x/graphql-api-hacking-7cf6cd46ce4f"
            }
         ],
         "Authors": ["Mahmuduzzaman Kamol"],
         "Programs": ["-"],
         "Bugs": ["GraphQL", "IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-06-23",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "How I found a SQL Injection bug in using my cellphone.",
               "Link": "https://medium.com/@0xnaeem/how-i-found-a-sql-injection-bug-in-using-my-cellphone-5b5193fdc314"
            }
         ],
         "Authors": ["Naeem Ahmed Sayed (@0xNaeem)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "500",
         "PublicationDate": "2023-06-23",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "My First Bug is RCE via SQL injection!",
               "Link": "https://medium.com/@karimelsayed0x1/my-first-bug-is-rce-via-sql-injection-dfee9c4d4c01"
            }
         ],
         "Authors": ["z3r0xk (@z3r01k)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-06-23",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "Multiple Vulnerabilities in Fortra Globalscape EFT Administration Server [FIXED]",
               "Link": "https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/"
            }
         ],
         "Authors": ["Ron Bowes (@iagox86)"],
         "Programs": ["Fortra (Globalscape)"],
         "Bugs": ["Out-of-bounds Read", "Memory corruption", "DoS", "Information disclosure", "Credentials sent over unencrypted channel"],
         "Bounty": "-",
         "PublicationDate": "2023-06-23",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "Netskope Client Service Local Privilege Escalation",
               "Link": "https://hdwsec.fr/blog/20230622-netskope/"
            }
         ],
         "Authors": ["Jean-Jamil Khalife"],
         "Programs": ["Netskope"],
         "Bugs": ["Local Privilege Escalation", "DLL Hijacking", "Zip Slip attack"],
         "Bounty": "-",
         "PublicationDate": "2023-06-22",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Gaps in Azure Service Fabric’s Security Call for User Vigilance",
               "Link": "https://www.trendmicro.com/en_ae/research/23/f/gaps-in-azure-service-fabric-s-security-call-for-user-vigilance.html"
            }
         ],
         "Authors": ["David Fiser"],
         "Programs": ["-"],
         "Bugs": ["Cloud", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-06-21",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "UNCONTAINED: Uncovering Container Confusion in the Linux Kernel",
               "Link": "https://www.vusec.net/projects/uncontained/"
            }
         ],
         "Authors": ["Jakob Koschel", "Pietro Borrello", "Daniele Cono D'Elia", "Herbert Bos", "Cristiano Giuffrida"],
         "Programs": ["Linux Kernel Organization"],
         "Bugs": ["Kernel hacking", "Type confusion"],
         "Bounty": "-",
         "PublicationDate": "2023-06-21",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "My first bounty on Synack Red Team",
               "Link": "https://octa-mihail.medium.com/my-first-bounty-on-synack-red-team-4ef53329c960"
            }
         ],
         "Authors": ["Octavian Mihail Romanescu"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS"],
         "Bounty": "923.50",
         "PublicationDate": "2023-06-21",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "How I hacked NASA and got 8 bugs ?",
               "Link": "https://medium.com/@elsayedmohammed/how-i-hacked-nasa-and-get-8-bugs-e5cd397a6af9"
            }
         ],
         "Authors": ["EL Sayed Mohammed (@ElsayedMo77amed)"],
         "Programs": ["NASA"],
         "Bugs": ["Open redirect", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-06-21",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "AWS WAF Clients Left Vulnerable to SQL Injection Due to Unorthodox MSSQL Design Choice",
               "Link": "https://www.gosecure.net/blog/2023/06/21/aws-waf-clients-left-vulnerable-to-sql-injection-due-to-unorthodox-mssql-design-choice/"
            }
         ],
         "Authors": ["Marc Olivier Bergeron"],
         "Programs": ["Microsoft", "AWS"],
         "Bugs": ["SQL injection", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-21",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "Advisory: IDOR in Microsoft Teams Allows for External Tenants to Introduce Malware",
               "Link": "https://labs.jumpsec.com/advisory-idor-in-microsoft-teams-allows-for-external-tenants-to-introduce-malware/"
            }
         ],
         "Authors": ["Max Corbridge (@CorbridgeMax)", "Tom Ellson (@tde_sec)"],
         "Programs": ["Microsoft (Teams)"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-06-21",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "Leaking secrets through caching with Bunny CDN",
               "Link": "https://httptoolkit.com/blog/bunny-cdn-caching-vulnerability/"
            }
         ],
         "Authors": ["Tim Perry (@pimterry)"],
         "Programs": ["bunny.net"],
         "Bugs": ["Web cache poisoning"],
         "Bounty": "-",
         "PublicationDate": "2023-06-20",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Okta SSO=> HTTPS/HTTP",
               "Link": "https://rashahacks.com/bypassing-okta-sso-https-http/"
            }
         ],
         "Authors": ["Inderjeet Singh (@3nc0d3dGuY)"],
         "Programs": ["Yahoo! / Verizon Media"],
         "Bugs": ["SSO", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-20",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "nOAuth: How Microsoft OAuth Misconfiguration Can Lead to Full Account Takeover",
               "Link": "https://www.descope.com/blog/post/noauth"
            }
         ],
         "Authors": ["Descope (@descopeinc)"],
         "Programs": ["Microsoft (Azure AD)"],
         "Bugs": ["OAuth", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-06-20",
         "AddedDate": "2023-06-21"
      },
      {
         "Links": [
            {
               "Title": "Leveraging Android Permissions: A Solver Approach",
               "Link": "https://blog.thalium.re/posts/leveraging-android-permissions/"
            }
         ],
         "Authors": ["Jérémy Breton"],
         "Programs": ["Google (Android)"],
         "Bugs": ["Android", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-06-20",
         "AddedDate": "2023-06-21"
      },
      {
         "Links": [
            {
               "Title": "RCE via Path Traversal vulnerability in Onlyoffice CommunityServer < 12.5.2 (CVE-2023-34939)",
               "Link": "https://github.com/firsov/onlyoffice/blob/main/CVE-2023-34939-PoC.md"
            }
         ],
         "Authors": ["Kirill Firsov (@k_firsov)"],
         "Programs": ["OnlyOffice"],
         "Bugs": ["Path traversal", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-06-19",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "How I Unveiled a Critical Vulnerability: Exposing All Buyers’ Invoices PII with a Single Trick",
               "Link": "https://0xa1mn.medium.com/how-i-unveiled-a-critical-vulnerability-exposing-all-buyers-invoices-pii-with-a-single-trick-691fd410fd7a"
            }
         ],
         "Authors": ["Ayman"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "Hardcoded API keys"],
         "Bounty": "-",
         "PublicationDate": "2023-06-19",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Unleashing the Cloud: A Journey into Hacking College Servers and Uncovering Security Vulnerabilities",
               "Link": "https://medium.com/@smukx/how-i-hacked-my-college-cloud-servers-and-find-dos-ato-google-authentication-priv-esc-676b2db98938"
            }
         ],
         "Authors": ["Smukx (@Smukx07)"],
         "Programs": ["-"],
         "Bugs": ["Authentication bypass", "Account takeover", "DoS", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-06-19",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "DLL Hijacking – Finding Vulnerabilities In pestudio 9.52",
               "Link": "https://securitycafe.ro/2023/06/19/dll-hijacking-finding-vulnerabilities-in-pestudio-9-52/"
            }
         ],
         "Authors": ["Matei Josephs"],
         "Programs": ["pestudio"],
         "Bugs": ["DLL Hijacking", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-06-19",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "chonked pt.1: minidlna 1.3.2 http chunk parsing heap overflow (cve-2023-33476) root cause analysis",
               "Link": "https://blog.coffinsec.com/0day/2023/05/31/minidlna-heap-overflow-rca.html"
            },
            {
               "Title": "chonked pt.2: exploiting cve-2023-33476 for remote code execution",
               "Link": "https://blog.coffinsec.com/0day/2023/06/19/minidlna-cve-2023-33476-exploits.html"
            }
         ],
         "Authors": ["hyper (@hyprdude)"],
         "Programs": ["MiniDLNA"],
         "Bugs": ["Memory corruption", "Heap overflow", "Buffer Overflow", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-06-19",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "LibreOffice Arbitrary File Write (CVE-2023-1883)",
               "Link": "https://secfault-security.com/blog/libreoffice.html"
            }
         ],
         "Authors": ["Gregor Kopf"],
         "Programs": ["LibreOffice"],
         "Bugs": ["Arbitrary file write", "Thick client"],
         "Bounty": "-",
         "PublicationDate": "2023-06-19",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "The Unexpected “0” Master ID for Account Data Manipulation",
               "Link": "http://www.firstsight.me/2023/06/the-unexpected-0-master-id-for-account-data-manipulation/"
            }
         ],
         "Authors": ["YoKo Kho (@YokoAcc)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Broken Access Control"],
         "Bounty": "2,500",
         "PublicationDate": "2023-06-19",
         "AddedDate": "2023-06-21"
      },
      {
         "Links": [
            {
               "Title": "How we tried to book a train ticket and ended up with a databreach with 245,000 records",
               "Link": "https://zerforschung.org/posts/freundschaftspass-en/"
            }
         ],
         "Authors": ["zerforschung (@zerforschung)"],
         "Programs": ["DiscoverEU"],
         "Bugs": ["Subdomain takeover", "Password reset", "Logic flaw", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-06-19",
         "AddedDate": "2023-06-21"
      },
      {
         "Links": [
            {
               "Title": "[CVE-2023-32695] Socket.IO DoS Trought Javascript Property Manipulation on WebSockets",
               "Link": "https://rafa.hashnode.dev/cve-2023-32695"
            }
         ],
         "Authors": ["Rafael da Costa Santos (@rafabyte_)"],
         "Programs": ["Socket.IO"],
         "Bugs": ["DoS", "Websockets", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-18",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "FortiNAC - Just a few more RCEs",
               "Link": "https://frycos.github.io/vulns4free/2023/06/18/fortinac.html"
            }
         ],
         "Authors": ["Florian Hauser (@frycos)"],
         "Programs": ["Fortinet"],
         "Bugs": ["RCE", "XXE", "Insecure deserialization", "OS command injection", "Argument injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-18",
         "AddedDate": "2023-06-21"
      },
      {
         "Links": [
            {
               "Title": "Exploiting HTTP Parsers Inconsistencies",
               "Link": "https://rafa.hashnode.dev/exploiting-http-parsers-inconsistencies"
            }
         ],
         "Authors": ["Rafael da Costa Santos (@rafabyte_)"],
         "Programs": ["Nginx", "AWS", "Spring Boot", "Flask", "PHP"],
         "Bugs": ["Parsing issue", "WAF bypass", "SSRF", "Desync attack", "Cache poisoning attack"],
         "Bounty": "-",
         "PublicationDate": "2023-06-17",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "From Bug Bounty Hunter to Risk Analyst: My Cybersecurity Journey at Deloitte",
               "Link": "https://hunter-55.medium.com/from-bug-bounty-hunter-to-risk-analyst-my-cybersecurity-journey-at-deloitte-56e7835619e4"
            }
         ],
         "Authors": ["himanshu pdy (@himanshu_pdy)"],
         "Programs": ["Deloitte"],
         "Bugs": ["Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-06-17",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "One Electron to Rule Them All",
               "Link": "https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf"
            }
         ],
         "Authors": ["Uriel Kosayev(@MalFuzzer)", "Hai Vaknin(@VakninHai)", "Tamir Yehuda (@Tamirye94)", "Matan Bahar (@Bl4ckShad3)"],
         "Programs": ["-"],
         "Bugs": ["Electron"],
         "Bounty": "-",
         "PublicationDate": "2023-06-16",
         "AddedDate": "2023-06-21"
      },
      {
         "Links": [
            {
               "Title": "Admin Panel Bypass without the credentials",
               "Link": "https://medium.com/@sayim0x3105/admin-panel-bypass-without-the-credentials-e867eee7c81b"
            }
         ],
         "Authors": ["Sayim0x (@sayim0x)"],
         "Programs": ["Pfizer"],
         "Bugs": ["Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-15",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Brute-forcing ButterflyMX Virtual Keys and Hacking Time Limits",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/brute-forcing-butterflymx-virtual-keys-and-hacking-time-limits/"
            }
         ],
         "Authors": ["Robert Foggia"],
         "Programs": ["ButterflyMX"],
         "Bugs": ["Bruteforce"],
         "Bounty": "-",
         "PublicationDate": "2023-06-15",
         "AddedDate": "2023-06-21"
      },
      {
         "Links": [
            {
               "Title": "PII Data Leakage and US$1500 Bounty",
               "Link": "https://medium.com/@ferferof/pii-data-leakage-and-us-1500-bounty-af676350fb76"
            }
         ],
         "Authors": ["ferferof (@ferferof_)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "IDOR"],
         "Bounty": "1,500",
         "PublicationDate": "2023-06-14",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "SQL Injection in The HTTP Custom Header",
               "Link": "https://infosecwriteups.com/sql-injection-in-the-http-custom-header-fd117ba1435e"
            }
         ],
         "Authors": ["yoshi m lutfi (@yoshiahmadlutfi)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-06-14",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Pwning Admin Panel To Change Movie Ticket Prices at Disney",
               "Link": "https://rashahacks.com/pwning-admin-panel-to-change-movie-ticket-prices-at-disney/"
            }
         ],
         "Authors": ["Inderjeet Singh (@3nc0d3dGuY)"],
         "Programs": ["Disney"],
         "Bugs": ["Bruteforce", "Weak credentials"],
         "Bounty": "-",
         "PublicationDate": "2023-06-14",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "Two XSS Vulnerabilities in Azure with Embedded postMessage IFrames",
               "Link": "https://orca.security/resources/blog/examining-two-xss-vulnerabilities-in-azure-services/"
            }
         ],
         "Authors": ["Lidor Ben Shitrit"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["XSS", "postMessage"],
         "Bounty": "-",
         "PublicationDate": "2023-06-14",
         "AddedDate": "2023-06-21"
      },
      {
         "Links": [
            {
               "Title": "The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022",
               "Link": "https://starlabs.sg/blog/2023/06-the-old-the-new-and-the-bypass-one-clickopen-redirect-to-own-samsung-s22-at-pwn2own-2022/"
            }
         ],
         "Authors": ["Nguyễn Tiến Giang (@testanull)"],
         "Programs": ["Samsung"],
         "Bugs": ["Open redirect", "Insecure deeplink", "Android"],
         "Bounty": "-",
         "PublicationDate": "2023-06-14",
         "AddedDate": "2023-06-21"
      },
      {
         "Links": [
            {
               "Title": "Learning iOS App Pentesting and Security Part 1",
               "Link": "https://www.cobalt.io/blog/learning-ios-app-pentesting-and-security-part-1"
            }
         ],
         "Authors": ["Swaroop Yermalkar (@swaroopsy)"],
         "Programs": ["-"],
         "Bugs": ["iOS"],
         "Bounty": "-",
         "PublicationDate": "2023-06-13",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "Patch Diffing Progress MOVEIt Transfer",
               "Link": "https://blog.assetnote.io/2023/06/07/moveit-transfer-patch-diff-adventure/"
            },
            {
               "Title": "MOVEIt Transfer RCE Part Two (CVE-2023-34362)",
               "Link": "https://blog.assetnote.io/2023/06/13/moveit-transfer-part-two/"
            }
         ],
         "Authors": ["Dylan Pindur"],
         "Programs": ["Progress (MOVEit Transfer)"],
         "Bugs": ["RCE", "SQL injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-13",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "IDOR, unpin posts for fun.",
               "Link": "https://medium.com/@omarahmed_13016/idor-unpin-posts-for-fun-18f628eaef24"
            }
         ],
         "Authors": ["Omar Ahmed (@spaceboy2O)"],
         "Programs": ["LinkedIn"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-06-13",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Reflected XSS Injection & Permanent Open Redirection",
               "Link": "https://medium.com/@0day_exploit/stored-xss-injection-permanent-open-redirection-e14ffa11573c"
            }
         ],
         "Authors": ["0 day exploit (@0day_exploit_)"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS", "Open redirect"],
         "Bounty": "2,000",
         "PublicationDate": "2023-06-13",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Jasper Reports Library Code Injection",
               "Link": "https://insinuator.net/2023/06/jasper-reports-library-code-injection/"
            }
         ],
         "Authors": ["Dennis Heinze"],
         "Programs": ["Jasper Reports"],
         "Bugs": ["RCE", "SSTI", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-13",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "Pre-Authenticated RCE In VMware VRealize Network Insight - CVE-2023-20887",
               "Link": "https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-20887/"
            }
         ],
         "Authors": ["Sina Kheirkhah (@SinSinology)"],
         "Programs": ["VMware"],
         "Bugs": ["RCE", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-13",
         "AddedDate": "2023-06-13"
      },
      {
         "Links": [
            {
               "Title": "XORtigate: Pre-authentication Remote Code Execution on Fortigate VPN (CVE-2023-27997)",
               "Link": "https://blog.lexfo.fr/xortigate-cve-2023-27997.html"
            }
         ],
         "Authors": ["Charles Fol (@cfreal_)"],
         "Programs": ["Fortinet (Fortigate VPN)"],
         "Bugs": ["RCE", "Heap overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-06-13",
         "AddedDate": "2023-06-13"
      },
      {
         "Links": [
            {
               "Title": "Dynamic Linq Injection Remote Code Execution Vulnerability (CVE-2023-32571)",
               "Link": "https://research.nccgroup.com/2023/06/13/dynamic-linq-injection-remote-code-execution-vulnerability-cve-2023-32571/"
            }
         ],
         "Authors": ["Ross Bradley"],
         "Programs": ["Dynamic LINQ"],
         "Bugs": ["RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-13",
         "AddedDate": "2023-06-13"
      },
      {
         "Links": [
            {
               "Title": "Obtaining Domain Admin from Azure AD by abusing Cloud Kerberos Trust",
               "Link": "https://dirkjanm.io/obtaining-domain-admin-from-azure-ad-via-cloud-kerberos-trust/"
            }
         ],
         "Authors": ["Dirk-jan Mollema (@_dirkjan)"],
         "Programs": ["-"],
         "Bugs": ["Azure AD", "Kerberos", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-06-13",
         "AddedDate": "2023-06-13"
      },
      {
         "Links": [
            {
               "Title": "can I speak to your manager? hacking root EPP servers to take control of zones",
               "Link": "https://hackcompute.com/hacking-epp-servers/"
            }
         ],
         "Authors": ["Sam Curry (@samwcyo)", "Brett Buerhaus (@bbuerhaus)", "Rhys Elsmore (@rhyselsmore)", "Shubham Shah (@infosec_au)"],
         "Programs": ["CoCCA"],
         "Bugs": ["XXE", "LFI", "EPP protocol"],
         "Bounty": "-",
         "PublicationDate": "2023-06-12",
         "AddedDate": "2023-06-13"
      },
      {
         "Links": [
            {
               "Title": "Taking Over an Entire Organization - A Journey Through Multiple Bugs",
               "Link": "https://hacktus.tech/taking-over-an-entire-organization"
            }
         ],
         "Authors": ["Hacktus (@H4cktus)", "DreyAnd (@dreyand_)"],
         "Programs": ["-"],
         "Bugs": ["Broken Access Control", "Privilege escalation", "IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-06-12",
         "AddedDate": "2023-06-13"
      },
      {
         "Links": [
            {
               "Title": "googlesource.com access_token leak (Awarded $7500)",
               "Link": "https://ndevtk.github.io/writeups/2023/06/11/googlesource/"
            }
         ],
         "Authors": ["NDevTK (@ndevtk)"],
         "Programs": ["Google"],
         "Bugs": ["URL validation bypass", "Regex", "Token leak"],
         "Bounty": "$7,500",
         "PublicationDate": "2023-06-11",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "Kubernetes pentest — Bypassing load balancer",
               "Link": "https://infosecwriteups.com/kubernetes-pentest-bypassing-load-balancer-9bcfae2ce84a"
            }
         ],
         "Authors": ["hosein vita (@HoseinVita)"],
         "Programs": ["-"],
         "Bugs": ["Security code review", "Load balancer bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-10",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "XSS in GMAIL Dynamic Email (AMP for Email)",
               "Link": "https://asdqw3.medium.com/xss-in-gmail-dynamic-email-amp-for-email-3872d6052a0d"
            }
         ],
         "Authors": ["asdqw3"],
         "Programs": ["Google"],
         "Bugs": ["XSS", "HTML injection"],
         "Bounty": "$6,000",
         "PublicationDate": "2023-06-09",
         "AddedDate": "2023-10-03"
      },
      {
         "Links": [
            {
               "Title": "My First Bug: A Unique $500 XSS.",
               "Link": "https://medium.com/@f3tch/my-first-bug-a-unique-500-xss-eb5caccb628f"
            }
         ],
         "Authors": ["f3tch"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "$750",
         "PublicationDate": "2023-06-09",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "Sony Bravia Remote Code Execution Disclosure",
               "Link": "https://www.whiteoaksecurity.com/blog/sony-bravia-remote-code-execution-disclosure/"
            }
         ],
         "Authors": ["Brett DeWall (@xbadbiddyx)", "Michael Rand"],
         "Programs": ["Sony"],
         "Bugs": ["RCE", "Unrestricted file upload", "RFI"],
         "Bounty": "-",
         "PublicationDate": "2023-06-09",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "Hunting for Bitwarden master passwords stored in memory",
               "Link": "https://redmaple.tech/blogs/2023/extract-bitwarden-vault-passwords/"
            }
         ],
         "Authors": ["Naz Markuta (@NazMarkuta)"],
         "Programs": ["Bitwarden"],
         "Bugs": ["Information disclosure", "Memory leak", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-06-08",
         "AddedDate": "2023-07-04"
      },
      {
         "Links": [
            {
               "Title": "Confused Deputy Vulnerability in Cloudflare CASB",
               "Link": "https://albertpedersen.com/blog/cloudflare-casb-confused-deputy/"
            }
         ],
         "Authors": ["Albert Pedersen (@AlbertSPedersen)"],
         "Programs": ["Cloudflare"],
         "Bugs": ["Confused deputy"],
         "Bounty": "3,300",
         "PublicationDate": "2023-06-08",
         "AddedDate": "2023-06-13"
      },
      {
         "Links": [
            {
               "Title": "Less SmartScreen More Caffeine: (Ab)Using ClickOnce for Trusted Code Execution",
               "Link": "https://posts.specterops.io/less-smartscreen-more-caffeine-ab-using-clickonce-for-trusted-code-execution-1446ea8051c5"
            }
         ],
         "Authors": ["Nick Powers (@zyn3rgy)", "Steven Flores (@0xthirteen)"],
         "Programs": ["-"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2023-06-08",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "How I Hacked 100K+ Godaddy Users And Help To Secure For Free",
               "Link": "https://medium.com/pentesternepal/how-i-hacked-100k-godaddy-users-and-help-to-secure-for-free-65f172bd726a"
            }
         ],
         "Authors": ["Bishal Shrestha (@bishal0x01)"],
         "Programs": ["GoDaddy"],
         "Bugs": [".git folder disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-06-08",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "Spotted: How we discovered Privilege Escalation, missing CloudTrail data and a race condition in AWS Directory Service",
               "Link": "https://cloudar.be/awsblog/spotted-privilege-escalation-in-aws-directory-service/"
            }
         ],
         "Authors": ["Ben Bridts (@benbridts)"],
         "Programs": ["AWS"],
         "Bugs": ["Cloud", "Privilege escalation", "Race condition"],
         "Bounty": "-",
         "PublicationDate": "2023-06-07",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Abusing Client-Side Desync on Werkzeug",
               "Link": "https://mizu.re/post/abusing-client-side-desync-on-werkzeug"
            }
         ],
         "Authors": ["Mizu (@kevin_mizu)"],
         "Programs": ["Werzeug"],
         "Bugs": ["Client-Side Desync attack", "HTTP request smuggling", "Account takeover", "Open redirect", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-06-07",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "KeePass Triggers Are Dead, Long Live KeePass Triggers!",
               "Link": "https://d3lb3.github.io/keepass_triggers_arent_dead/"
            }
         ],
         "Authors": ["Julien Bedel (@d3lb3_)"],
         "Programs": ["KeePass"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-06-07",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "MSSQL linked servers: abusing ADSI for password retrieval",
               "Link": "https://www.tarlogic.com/blog/linked-servers-adsi-passwords/"
            }
         ],
         "Authors": ["Pablo Martínez (@xassiz)"],
         "Programs": ["-"],
         "Bugs": ["ADSI", "Active Directory", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-06-07",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "OneDrive To Enum Them All",
               "Link": "https://www.trustedsec.com/blog/onedrive-to-enum-them-all/"
            }
         ],
         "Authors": ["nyxgeek (@nyxgeek)"],
         "Programs": ["Microsoft (OneDrive)"],
         "Bugs": ["Username enumeration"],
         "Bounty": "-",
         "PublicationDate": "2023-06-06",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "How I was able to get account takeover via IDOR form JWT",
               "Link": "https://medium.com/@M0X0101/how-i-was-able-to-get-account-takeover-via-idor-form-jwt-caaf7ea58aa"
            }
         ],
         "Authors": ["Mohamed Reda (@M0x0101)"],
         "Programs": ["-"],
         "Bugs": ["JWT", "IDOR", "Bruteforce", "Self-XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-06-06",
         "AddedDate": "2023-06-06"
      },
      {
         "Links": [
            {
               "Title": "Compromising Honda’s power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API",
               "Link": "https://eaton-works.com/2023/06/06/honda-ecommerce-hack/"
            }
         ],
         "Authors": ["Eaton Z. (@XeEaton)"],
         "Programs": ["Honda"],
         "Bugs": ["Password reset", "Broken Access Control", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-06-06",
         "AddedDate": "2023-06-06"
      },
      {
         "Links": [
            {
               "Title": "Turning a 50$ Tab-Nabbing vulnerability into a 1000$ Account takeover",
               "Link": "https://medium.com/@malekmahmed55/turning-a-50-tab-nabbing-vulnerability-into-a-1000-account-takeover-9c3f32cb2d84"
            }
         ],
         "Authors": ["Malek Mohamed (@MalekMohamed0)"],
         "Programs": ["-"],
         "Bugs": ["Reverse tabnabbing", "Stored XSS", "Self-XSS", "Account takeover"],
         "Bounty": "1,000",
         "PublicationDate": "2023-06-06",
         "AddedDate": "2023-06-06"
      },
      {
         "Links": [
            {
               "Title": "Kanboard - Spraying Malicious Tasks Across all Projects",
               "Link": "https://castilho.onrender.com/kanboard"
            }
         ],
         "Authors": ["Castilho (@castilho101)"],
         "Programs": ["Kanboard"],
         "Bugs": ["Broken Access Control", "Stored XSS", "CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-06",
         "AddedDate": "2023-06-06"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory –  Roundcube MarkAsJunk RCE",
               "Link": "https://ssd-disclosure.com/ssd-advisory-roundcube-markasjunk-rce/"
            }
         ],
         "Authors": ["Selim Enes Karaduman (@Enesdex)"],
         "Programs": ["Roundcube"],
         "Bugs": ["RCE", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-06",
         "AddedDate": "2023-06-06"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-32902: Patch One Issue and Introduce Two",
               "Link": "https://jhftss.github.io/CVE-2022-32902-Patch-One-Issue-and-Introduce-Two/"
            }
         ],
         "Authors": ["Mickey Jin (@patch1t)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["TCC bypass", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-06-06",
         "AddedDate": "2023-06-06"
      },
      {
         "Links": [
            {
               "Title": "Storing Passwords - A Journey Of Common Pitfalls",
               "Link": "https://blog.redteam-pentesting.de/2023/storing-passwords/"
            }
         ],
         "Authors": ["RedTeam Pentesting (@RedTeamPT)"],
         "Programs": ["STARFACE"],
         "Bugs": ["Broken authentication", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-05",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "Multiple vulnerabilities in Delmia Apriso 2017 to 2022",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-06/Synacktiv-3DS-Delmia_Apriso_2017_to_2022-Multiple-Vulnerabilities.pdf"
            }
         ],
         "Authors": ["Mehdi Elyassa", "Vincent Herbulot"],
         "Programs": ["Dassault Systèmes (Delmia Apriso)"],
         "Bugs": ["Insecure deserialization", "RCE", "SSRF", "Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-06-05",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "A short white box code audit of avo",
               "Link": "https://evait.medium.com/a-short-white-box-code-audit-of-avo-2083b08f3a95"
            }
         ],
         "Authors": ["Paul Werther", "Anton Strilez (@mergon2089)"],
         "Programs": ["Avo"],
         "Bugs": ["Stored XSS", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-06-05",
         "AddedDate": "2023-06-06"
      },
      {
         "Links": [
            {
               "Title": "Storing Passwords - A Journey Of Common Pitfalls",
               "Link": "https://blog.redteam-pentesting.de/2023/storing-passwords/"
            }
         ],
         "Authors": ["RedTeam Pentesting (@RedTeamPT)"],
         "Programs": ["STARFACE"],
         "Bugs": ["Pass-the-Hash", "Broken authentication", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-05",
         "AddedDate": "2023-06-06"
      },
      {
         "Links": [
            {
               "Title": "Bypassing CSP via DOM clobbering",
               "Link": "https://portswigger.net/research/bypassing-csp-via-dom-clobbering"
            }
         ],
         "Authors": ["Gareth Heyes (@garethheyes)"],
         "Programs": ["-"],
         "Bugs": ["DOM Clobbering", "CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-05",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Send email from anyone to any(user outlook Microsoft)",
               "Link": "https://infosecwriteups.com/send-email-from-anyone-to-any-user-outlook-microsoft-69fce333066d"
            }
         ],
         "Authors": ["Abbas Heybati (@abbas_heybati)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Open mail relay", "Email spoofing", "SMTP", "SPF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-04",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Breaking TikTok: Our Journey to Finding an Account Takeover Vulnerability",
               "Link": "https://medium.com/@mrhavit/breaking-tiktok-our-journey-to-finding-an-account-takeover-vulnerability-b0646aba1c4b"
            }
         ],
         "Authors": ["mrhavit", "const"],
         "Programs": ["TikTok"],
         "Bugs": ["XSS", "Account takeover", "OAuth"],
         "Bounty": "-",
         "PublicationDate": "2023-06-04",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "AWS Chain Attack- Thousands of Vulnerable EKS Clusters",
               "Link": "https://medium.com/@chenshiri/aws-chain-attack-thousands-of-vulnerable-eks-clusters-701cbd963907"
            }
         ],
         "Authors": ["Chen Shiri (@ChenShiri73)"],
         "Programs": ["-"],
         "Bugs": ["AWS Kubernetes", "EKS", "Container escape", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-06-04",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "How a misconfigured Lotus Domino Server can lead to Disclosure of PII Data of Employees, Configuration Details about the Active Directory, etc",
               "Link": "https://medium.com/@ar_hawk/how-a-misconfigured-lotus-domino-server-can-lead-to-disclosure-of-pii-data-of-employees-badad691dad"
            }
         ],
         "Authors": ["Aayush Vishnoi (@AayushVishnoi10)"],
         "Programs": ["-"],
         "Bugs": ["Lotus Domino", "Security misconfiguration", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-06-04",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Rate Limit Bypass Leads to 0 Click ATO",
               "Link": "https://zeroxuf.medium.com/rate-limit-bypass-leads-to-0-click-ato-9f1b29daec42"
            }
         ],
         "Authors": ["ZeroXUF (@ZeroXUF)"],
         "Programs": ["-"],
         "Bugs": ["Rate limiting bypass", "Bruteforce", "Password reset", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-06-04",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Prototype Pollution Akamai",
               "Link": "https://github.com/Sudistark/BB-Writeups/blob/main/2023/prototype-pollution-akamai.md"
            }
         ],
         "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
         "Programs": ["-"],
         "Bugs": ["Client-side prototype pollution", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-03",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "RCE via LDAP truncation on hg.mozilla.org",
               "Link": "https://0day.click/recipe/pash/"
            }
         ],
         "Authors": ["joernchen (@joernchen)"],
         "Programs": ["Mozilla"],
         "Bugs": ["RCE", "LDAP truncation", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-06-03",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Critical vulnerability on TP-Link service or how I got 0$",
               "Link": "https://infosecwriteups.com/critical-finding-on-tp-link-service-or-how-i-got-0-fc86a0e52eaf"
            }
         ],
         "Authors": ["Serj Novoselov (@novoselov_s)"],
         "Programs": ["TP-Link"],
         "Bugs": ["Account verification bypass", "IDOR", "Information disclosure", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-06-01",
         "AddedDate": "2024-02-01"
      },
      {
         "Links": [
            {
               "Title": "HTTP Request Splitting vulnerabilities exploitation",
               "Link": "https://offzone.moscow/upload/iblock/11a/sagouc86idiapdb8f29w41yaupqv6fwv.pdf"
            }
         ],
         "Authors": ["Sergey Bobrov (@black2fan)"],
         "Programs": ["AWS", "Yandex"],
         "Bugs": ["HTTP request splitting", "CRLF injection", "Nginx misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-06-01",
         "AddedDate": "2024-01-18"
      },
      {
         "Links": [
            {
               "Title": "Bypassing An Industry-Leading WAF and Exploiting SQLi",
               "Link": "https://blog.stratumsecurity.com/2023/06/01/sqli-the-road-to-bypassing-an-industry-leading-waf/"
            }
         ],
         "Authors": ["Adeeb Shah"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-06-01",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-24941: Microsoft Network File System Remote Code Execution",
               "Link": "https://www.zerodayinitiative.com/blog/2023/5/31/cve-2023-24941-microsoft-network-file-system-remote-code-execution"
            }
         ],
         "Authors": ["Quinton Crist", "Guy Lederfein (@glederfein)", "Lucas Miller"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["RCE", "NFS"],
         "Bounty": "-",
         "PublicationDate": "2023-06-01",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Anatomy of an IoT Exploit, from Hands-On to RCE",
               "Link": "https://www.klogixsecurity.com/scorpion-labs-blog/anatomy-of-an-iot-exploit-from-hands-on-to-rce"
            }
         ],
         "Authors": ["David Baker"],
         "Programs": ["Wavlink"],
         "Bugs": ["IoT", "RCE", "Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-06-01",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Ghost Sites: Stealing Data From Deactivated Salesforce Communities",
               "Link": "https://www.varonis.com/blog/salesforce-ghost-sites"
            }
         ],
         "Authors": ["Nitay Bachrach"],
         "Programs": ["-"],
         "Bugs": ["Salesforce", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-05-31",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Reverse Engineering Coin Hunt World’s Binary Protocol",
               "Link": "https://research.nccgroup.com/2023/05/31/reverse-engineering-coin-hunt-worlds-binary-protocol/"
            }
         ],
         "Authors": ["qkchambers"],
         "Programs": ["Coin Hunt World"],
         "Bugs": ["Reverse engineering", "Spoofing"],
         "Bounty": "-",
         "PublicationDate": "2023-05-31",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Kramer VIA GO² – Multiple issues",
               "Link": "https://zxsecurity.co.nz/research/advisories/kramer-via-go-2-rce-and-other-vulns/"
            }
         ],
         "Authors": ["Jim Rush (@JimSRush)", "Tomais Williamson (@softpoison_)"],
         "Programs": ["Kramer"],
         "Bugs": ["RCE", "SQL injection", "Arbitrary file upload", "Arbitrary file read"],
         "Bounty": "-",
         "PublicationDate": "2023-05-31",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-33733 reportlab RCE",
               "Link": "https://github.com/c53elyas/CVE-2023-33733"
            }
         ],
         "Authors": ["c53elyas"],
         "Programs": ["ReportLab"],
         "Bugs": ["Code injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-05-30",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "an offensive look at docker desktop extensions",
               "Link": "https://sensepost.com/blog/2023/an-offensive-look-at-docker-desktop-extensions/"
            }
         ],
         "Authors": ["Leon Jacobs (@leonjza)"],
         "Programs": ["Docker"],
         "Bugs": ["OS command injection", "Container security"],
         "Bounty": "-",
         "PublicationDate": "2023-05-30",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "Vulnerabilities In Apache Commons-Text 1.10.0",
               "Link": "https://mc0wn.blogspot.com/2023/05/vulnerabilities-in-apache-commons-text.html"
            }
         ],
         "Authors": ["Chris (@mc_0wn)"],
         "Programs": ["Apache Commons Text"],
         "Bugs": ["Path traversal", "XXE"],
         "Bounty": "-",
         "PublicationDate": "2023-05-30",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "New macOS vulnerability, Migraine, could bypass System Integrity Protection",
               "Link": "https://www.microsoft.com/en-us/security/blog/2023/05/30/new-macos-vulnerability-migraine-could-bypass-system-integrity-protection/"
            }
         ],
         "Authors": ["Jonathan Bar Or (@yo_yo_yo_jbo)", "Michael Pearse", "Anurag Bohra"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["SIP bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-05-30",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "VSCode Remote Code Execution advisory",
               "Link": "https://blog.ammaraskar.com/vscode-rce/"
            }
         ],
         "Authors": ["Ammar Askar"],
         "Programs": ["Microsoft VSCode)"],
         "Bugs": ["RCE", "Thick client", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-05-30",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Hunting For Password Reset Tokens By Spraying And Using HTTP Pipelining",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/hunting-for-password-reset-tokens-by-spraying-and-using-http-pipelining/"
            }
         ],
         "Authors": ["Tom Neaves"],
         "Programs": ["-"],
         "Bugs": ["Password reset", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-05-30",
         "AddedDate": "2023-06-01"
      },
      {
         "Links": [
            {
               "Title": "Exploit an unexploitable XSS via an open redirect — A Real-Life Scenario from a Hacker’s Mindset",
               "Link": "https://medium.com/@ajzead660/exploit-an-unexploitable-xss-via-an-open-redirect-a-real-life-scenario-from-a-hackers-mindset-32b71041c5fe"
            }
         ],
         "Authors": ["Ziad Ali"],
         "Programs": ["-"],
         "Bugs": ["XSS", "Open redirect"],
         "Bounty": "-",
         "PublicationDate": "2023-05-29",
         "AddedDate": "2023-06-01"
      },
      {
         "Links": [
            {
               "Title": "XSS in WordPress via open embed auto discovery",
               "Link": "https://research.securitum.com/xss-in-wordpress-via-open-embed-auto-discovery/"
            }
         ],
         "Authors": ["Jakub Żoczek (@zoczus)"],
         "Programs": ["WordPress"],
         "Bugs": ["XSS", "postMessage"],
         "Bounty": "-",
         "PublicationDate": "2023-05-29",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "The 30000$ Bounty Affair.",
               "Link": "https://medium.com/@gokulsspace/the-30000-bounty-affair-3f025ee6b834"
            }
         ],
         "Authors": ["Gokulsspace (@GokTest)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Missing authentication", "Exposed Jenkins instance"],
         "Bounty": "30,000",
         "PublicationDate": "2023-05-28",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "Anonymised Penetration Test Report",
               "Link": "https://handbook.volkis.com.au/assets/doc/Volkis%20-%20Anonymous%20Client%20-%20Penetration%20Test%20May%202023.pdf"
            }
         ],
         "Authors": ["Volkis (@VolkisAU)"],
         "Programs": ["-"],
         "Bugs": ["Internal pentest", "RCE", "ADCS", "Active Directory", "Kerberos",  "DHCPv6", "LLMNR"],
         "Bounty": "-",
         "PublicationDate": "2023-05-28",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "Find out the IP address through a call to Telegram…",
               "Link": "https://medium.com/@ibederov_en/find-out-the-ip-address-through-a-call-to-telegram-a899441b1bac"
            }
         ],
         "Authors": ["Igor S. Bederov"],
         "Programs": ["Telegram"],
         "Bugs": ["Privacy issue", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-05-28",
         "AddedDate": "2023-05-29"
      }, 
      {
         "Links": [
            {
               "Title": "Utilizing Historical URLs of an Organization to successfully execute SQL queries — Blind SQLi",
               "Link": "https://medium.com/@ar_hawk/utilizing-historical-urls-of-an-organization-to-successfully-execute-sql-queries-blind-sqli-3526d9c3863d"
            }
         ],
         "Authors": ["Aayush Vishnoi (@AayushVishnoi10)"],
         "Programs": ["-"],
         "Bugs": ["Blind SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-05-26",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Exploring Three Remote Code Execution Vulnerabilities in RPC Runtime",
               "Link": "https://www.akamai.com/blog/security-research/rpc-runtime-exploring-three-vulnerabilities"
            }
         ],
         "Authors": ["Ben Barnea (@nachoskrnl)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["RCE", "MS-RPC", "Integer overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-05-26",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-2825 Analysis And Exploit",
               "Link": "https://occamsec.com/exploit-for-cve-2023-2825/"
            }
         ],
         "Authors": ["OccamSec (@occamsec)"],
         "Programs": ["GitLab"],
         "Bugs": ["Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2023-05-25",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Exploiting The Sonos One Speaker Three Different Ways: A Pwn2Own Toronto Highlight",
               "Link": "https://www.zerodayinitiative.com/blog/2023/5/24/exploiting-the-sonos-one-speaker-three-different-ways-a-pwn2own-toronto-highlight"
            }
         ],
         "Authors": ["The ZDI Research Team (@thezdi)"],
         "Programs": ["Sonos"],
         "Bugs": ["Memory corruption", "RCE", "Out-of-bounds Read"],
         "Bounty": "105,000",
         "PublicationDate": "2023-05-25",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Ericsson Sensitive Data Exposure via Trace.axd",
               "Link": "https://checkmarx.com/blog/ericsson-sensitive-data-exposure-via-trace-axd/"
            }
         ],
         "Authors": ["David Sopas (@dsopas)"],
         "Programs": ["Ericsson"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-05-25",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "XSS Via Qr Code",
               "Link": "https://medium.com/@A0g/xss-via-qr-code-8022a1a0309f"
            }
         ],
         "Authors": ["Ahmed Osama (A0G)"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-05-25",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "Hacking my “smart” toothbrush",
               "Link": "https://kuenzi.dev/toothbrush/"
            }
         ],
         "Authors": ["Cyrill Künzi"],
         "Programs": ["-"],
         "Bugs": ["IoT", "Reverse engineering", "NFC"],
         "Bounty": "-",
         "PublicationDate": "2023-05-24",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "how I found a tricky XSS",
               "Link": "https://medium.com/@ajzead660/how-i-found-a-tricky-xss-1adf25850d33"
            }
         ],
         "Authors": ["Ziad Ali"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-05-24",
         "AddedDate": "2023-06-01"
      },
      {
         "Links": [
            {
               "Title": "Unintended Path to Exam Domination - AWS EC2 Meta-Data",
               "Link": "https://www.rootcat.de/blog/ec2-meta_may23/"
            }
         ],
         "Authors": ["Dr. Michael Gschwender (@rootcathacking)"],
         "Programs": ["-"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-05-24",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure",
               "Link": "https://www.dig.security/post/gcp-cloudsql-vulnerability-leads-to-internal-container-access-and-data-exposure"
            }
         ],
         "Authors": ["Ofir Balassiano (@ofir_balassiano)", "Ofir Shaty (@Nu11p01Nt)"],
         "Programs": ["Google (GCP)"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-05-24",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "Salt Labs exposes a new vulnerability in popular OAuth framework, used in hundreds of online services",
               "Link": "https://salt.security/blog/a-new-oauth-vulnerability-that-may-impact-hundreds-of-online-services"
            }
         ],
         "Authors": ["Aviad Carmel (@AviadCarmel)"],
         "Programs": ["Expo", "Codeacademy.com"],
         "Bugs": ["OAuth", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-05-24",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "From Response To Request, Adding Your Own Variables Inside Of GraphQL Queries For Account Take Over",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/from-response-to-request-adding-your-own-variables-inside-of-graphql-queries-for-account-take-over/"
            }
         ],
         "Authors": ["Tom Neaves"],
         "Programs": ["-"],
         "Bugs": ["GraphQL", "IDOR", "Mass assignment"],
         "Bounty": "-",
         "PublicationDate": "2023-05-23",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Tampering with Conditional Access Policies Using Azure AD Graph API",
               "Link": "https://www.secureworks.com/research/tampering-with-conditional-access-policies-using-azure-ad-graph-api"
            }
         ],
         "Authors": ["Secureworks Counter Threat Unit (@Secureworks)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-05-23",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "Multiple vulnerabilities in Danfoss Storeview Web",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-05/Synacktiv-Danfoss-Storeview-Multiple-Vulnerabilities.pdf"
            }
         ],
         "Authors": ["Florent Sicchio", "Mehdi Elyassa"],
         "Programs": ["Danfoss"],
         "Bugs": ["OS command injection", "Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-05-22",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "CVE 2023 25690 - Proof of Concept",
               "Link": "https://github.com/dhmosfunk/CVE-2023-25690-POC"
            }
         ],
         "Authors": ["dhmosfunk (@DSkfunk)"],
         "Programs": ["Apache HTTP Server"],
         "Bugs": ["HTTP request smuggling", "HTTP request splitting", "CRLF injection"],
         "Bounty": "-",
         "PublicationDate": "2023-05-22",
         "AddedDate": "2023-06-01"
      },
      {
         "Links": [
            {
               "Title": "Red team: Journey from RCE to have total control of cloud infrastructure",
               "Link": "https://mr-r3bot.github.io/red/team/2023/05/22/From-RCE-to-owning-entire-cloud-infrastructure.html"
            }
         ],
         "Authors": ["Quang Vo (@mr_r3bot)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "SSTI", "Container escape", "Kubernetes", "Components with known vulnerabilities", "CI/CD"],
         "Bounty": "-",
         "PublicationDate": "2023-05-22",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Azure DNS Takeover @ Swisscom",
               "Link": "https://medium.com/@husein.ayoub/azure-dns-takeover-swisscom-7c6aacb38e8"
            }
         ],
         "Authors": ["Hussein Ayoub"],
         "Programs": ["Swisscom"],
         "Bugs": ["DNS takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-05-22",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "I helped a top Indian health benefits management platform from major PII leak by hacking their SQL Servers, AWS instance, DCs etc.",
               "Link": "https://nav1n.medium.com/i-helped-a-top-indian-health-benefits-management-platform-from-major-pii-leak-by-hacking-their-sql-b42caeca9729"
            }
         ],
         "Authors": ["nav1n (@nav1n0x)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-05-22",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "2FA Bypass Using Custom Cookie Parameter",
               "Link": "https://medium.com/@sharp488/2fa-bypass-using-custom-cookie-parameter-cb270c8557d2"
            }
         ],
         "Authors": ["Sharat Kaikolamthuruthil (@sharp488)"],
         "Programs": ["-"],
         "Bugs": ["2FA / MFA bypass", "Android"],
         "Bounty": "-",
         "PublicationDate": "2023-05-22",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "AEM Bug in Adobe",
               "Link": "https://realm3ter.medium.com/aem-bug-in-adobe-416763d3ad04"
            }
         ],
         "Authors": ["Muhammad Mater (@micro0x00)"],
         "Programs": ["Adobe"],
         "Bugs": ["AEM", "Missing authentication", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-05-20",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Exploiting SQL Error SQLSTATE[42000] To Own MariaDB of A Large Online Media Leader",
               "Link": "https://nav1n.medium.com/exploiting-sql-error-sqlstate-42000-to-own-mariadb-of-a-large-eu-based-online-media-and-cf7396c43bbf"
            }
         ],
         "Authors": ["nav1n (@nav1n0x)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "3,000",
         "PublicationDate": "2023-05-20",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Why You Should Always Check The Audit Log [Medium] — $500",
               "Link": "https://emanuel-beni.medium.com/why-you-should-always-check-the-audit-log-medium-500-80a778bfbcd6"
            }
         ],
         "Authors": ["Emanuel Beni Harijanto"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "500",
         "PublicationDate": "2023-05-20",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Exposing iCloud user’s Name, phone numbers, and email addresses.",
               "Link": "https://infosecwriteups.com/exposing-icloud-users-name-phone-numbers-and-email-addresses-d1f4a3786092"
            }
         ],
         "Authors": ["Renganathan (@IamRenganathan)"],
         "Programs": ["Apple (iCloud)"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-05-20",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "DNS Recursion Leads to DoS Attack Vivo Play (IPTV) — CVE-2023–31893",
               "Link": "https://medium.com/@lukinha05farias/dns-recursion-leads-to-dos-attack-vivo-play-iptv-cve-2023-31893-b5ac45f38f"
            }
         ],
         "Authors": ["Shooter"],
         "Programs": ["Vivo"],
         "Bugs": ["DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-05-20",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Official extension spoofing attacks: when trusted add-ons are not so trusted",
               "Link": "https://strike.sh/blog/official-extension-attacks"
            }
         ],
         "Authors": ["Yesenia Trejo (@Yess_2021xD)"],
         "Programs": ["-"],
         "Bugs": ["Extension spoofing", "Account takeover", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-05-19",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Blind OS Command Injection via Activation Request",
               "Link": "https://www.zerodayinitiative.com/blog/2023/5/17/cve-2023-2086920870-exploiting-vmware-workstation-at-pwn2own-vancouver"
            }
         ],
         "Authors": ["Nguyễn Hoàng Thạch (@hi_im_d4rkn3ss)"],
         "Programs": ["VMware"],
         "Bugs": ["Memory corruption", "Buffer Overflow", "Out-of-bounds Read"],
         "Bounty": "80,000",
         "PublicationDate": "2023-05-18",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "Blind OS Command Injection via Activation Request",
               "Link": "https://medium.com/@alb-soul/blind-os-command-injection-via-activation-request-66dc25377bf4"
            }
         ],
         "Authors": ["Arumusutakimu (@arumusutakimu)"],
         "Programs": ["-"],
         "Bugs": ["OS command injection"],
         "Bounty": "-",
         "PublicationDate": "2023-05-18",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Stored Iframe Injection & Permanent Open Redirection - Zero Day",
               "Link": "https://shahjerry33.medium.com/stored-iframe-injection-permanent-open-redirection-zero-day-ce7cd15903ac"
            }
         ],
         "Authors": ["Jerry Shah (@Jerry)"],
         "Programs": ["Discourse"],
         "Bugs": ["HTML injection", "Open redirect"],
         "Bounty": "-",
         "PublicationDate": "2023-05-18",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "How Misconfigured and Vulnerable Devices Could Expose Your Company to Physical and Cyber Threats",
               "Link": "https://blog.pretera.com/how-misconfigured-and-vulnerable-devices-could-expose-your-company-to-physical-and-cyber-threats-37d0e0d8d158"
            }
         ],
         "Authors": ["Arben Shala (@arbennsh)"],
         "Programs": ["-"],
         "Bugs": ["IoT", "Default credentials", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2023-05-18",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "A $1,000,000 bounty? The KuCoin User Information Leak",
               "Link": "https://corben.io/blog/hacking-kucoin"
            }
         ],
         "Authors": ["Corben Leo (@hacker_)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "Zendesk", "Broken authorization", "Security misconfiguration"],
         "Bounty": "5,000",
         "PublicationDate": "2023-05-18",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "KeePass Master Password Exploit - CVE-2023-32784 - Proof Of Concept (POC)",
               "Link": "https://bleekseeks.com/blog/keepass-master-password-exploit-cve-2023-32784-poc"
            }
         ],
         "Authors": ["Luke Kavanagh"],
         "Programs": ["KeePass"],
         "Bugs": ["Plaintext Storage of a Password", "Thick client"],
         "Bounty": "-",
         "PublicationDate": "2023-05-17",
         "AddedDate": "2023-06-05"
      },
      {
         "Links": [
            {
               "Title": "Arbitrary email forgery in Webflow",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-05/Synacktiv-Webflow-Arbitrary-Email-Forgery.pdf"
            }
         ],
         "Authors": ["Antoine Carrincazeaux"],
         "Programs": ["Webflow"],
         "Bugs": ["Email spoofing", "Phishing"],
         "Bounty": "-",
         "PublicationDate": "2023-05-17",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "DLL Hijacking Strikes Back: Exploiting Windows on ARM RDP Client (CVE-2023-24905)",
               "Link": "https://cyolo.io/blog/dll-hijacking-strikes-back-exploiting-windows-on-arm-rdp-client-cve-2023-24905/"
            }
         ],
         "Authors": ["Dor Dali"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["DLL Hijacking", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-05-17",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "LOLBINed — Finding “LOLBINs” In AV Uninstallers",
               "Link": "https://nasbench.medium.com/lolbined-finding-lolbins-in-av-uninstallers-bf29427d3cd8"
            }
         ],
         "Authors": ["Nasreddine Bencherchali (@nas_bench)"],
         "Programs": ["Kaspersky", "F-Secure", "Trend Micro", "McAfee"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-05-17",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "DOS via cache poisoning",
               "Link": "https://medium.com/@zhero_/dos-via-cache-poisoning-38f3a87f997c"
            },
            {
               "Title": "Alternative link",
               "Link": "https://zhero-web-sec.github.io/dos-via-cache-poisoning/"
            }
         ],
         "Authors": ["Allam Rachid (@blank_cold)"],
         "Programs": ["-"],
         "Bugs": ["Web cache deception", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-05-17",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "From DA to EA with ESC5",
               "Link": "https://posts.specterops.io/from-da-to-ea-with-esc5-f9f045aa105c"
            }
         ],
         "Authors": ["Andy Robbins (@_wald0)"],
         "Programs": ["-"],
         "Bugs": ["Active Directory Privilege Escalation", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2023-05-17",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "From GitHub To Account Takeover: Misconfigured Actions Place GCP & AWS Accounts At Risk",
               "Link": "https://www.rezonate.io/blog/github-misconfigurations-put-gcp-aws-in-account-takeover-risk/"
            }
         ],
         "Authors": ["Rezonate"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Cloud", "OIDC", "CI/CD"],
         "Bounty": "-",
         "PublicationDate": "2023-05-16",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Hardcore RCE via directory name for $3.000",
               "Link": "https://medium.com/@levshmelevv/hardcore-rce-via-directory-name-for-3-000-225ed58b41a9"
            }
         ],
         "Authors": ["Lev Shmelev"],
         "Programs": ["-"],
         "Bugs": ["RCE", "OS command injection", "Security code review"],
         "Bounty": "3,000",
         "PublicationDate": "2023-05-16",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "Unauthenticated Remote Command Execution in Multiple WAGO Products",
               "Link": "https://onekey.com/blog/security-advisory-wago-unauthenticated-remote-command-execution/"
            }
         ],
         "Authors": ["Quentin Kaiser (@QKaiser)"],
         "Programs": ["WAGO"],
         "Bugs": ["RCE", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-05-16",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "‘FriendlyName’ Buffer Overflow Vulnerability in Wemo Smart Plug V2",
               "Link": "https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/"
            }
         ],
         "Authors": ["Amit Serper (@0xAmit)", "Reuven Yakar"],
         "Programs": ["Belkin (Wemo)"],
         "Bugs": ["IoT", "Buffer Overflow", "Memory corruption", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2023-05-16",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "Bypassing open redirect protection site-wide on web2py applications",
               "Link": "https://web.archive.org/web/20230515045300/https://www.kaytaq.com/uncategorized/bypassing-open-redirect-protection-site-wide-on-web2py-applications/"
            }
         ],
         "Authors": ["Mohamed Dief (@DemoniaSlash)"],
         "Programs": ["Web2py"],
         "Bugs": ["Open redirect", "Regex"],
         "Bounty": "-",
         "PublicationDate": "2023-05-15",
         "AddedDate": "2023-05-29"
      },
      {
         "Links": [
            {
               "Title": "Avast Anti-Virus privileged arbitrary file create on virus restore (CVE-2023-1586)",
               "Link": "https://the-deniss.github.io/posts/avast-privileged-arbitrary-file-create-on-restore/"
            }
         ],
         "Authors": ["Denis Skvortcov (@Denis_Skvortcov)"],
         "Programs": ["Avast", "NortonLifeLock"],
         "Bugs": ["TOCTOU", "Arbitrary file write", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-05-15",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Triple Threat: Breaking Teltonika Routers Three Ways",
               "Link": "https://claroty.com/team82/research/triple-threat-breaking-teltonika-routers-three-ways"
            }
         ],
         "Authors": ["Roni Gavrilov", "Noam Moshe"],
         "Programs": ["Teltonika"],
         "Bugs": ["IoT", "RCE", "OS command injection", "SSRF", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-05-15",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Finding and reporting a Gatekeeper bypass exploit with help from Mac Monitor",
               "Link": "https://redcanary.com/blog/gatekeeper-bypass-vulnerabilities/"
            }
         ],
         "Authors": ["Brandon Dalton (@PartyD0lphin)", "Csaba Fitzl (@theevilbit)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["GateKeeper bypass", "Local Privilege Escalation", "MacOS"],
         "Bounty": "-",
         "PublicationDate": "2023-05-15",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Linux IPv6 \"Route of Death\" 0day",
               "Link": "https://www.interruptlabs.co.uk/articles/linux-ipv6-route-of-death"
            }
         ],
         "Authors": ["Max VA (@maxpl0it)"],
         "Programs": ["Linux Kernel Organization"],
         "Bugs": ["DoS", "Kernel hacking", "IPv6"],
         "Bounty": "-",
         "PublicationDate": "2023-05-15",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "Pimcore: One click, two security vulnerabilities",
               "Link": "https://www.sonarsource.com/blog/pimcore-one-click-two-security-vulnerabilities/"
            }
         ],
         "Authors": ["Yaniv Nizry (@YNizry)"],
         "Programs": ["Pimcore"],
         "Bugs": ["Path traversal", "SQL injection", "Arbitrary file write", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-05-15",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-26818 - Bypass TCC with Telegram in macOS",
               "Link": "https://danrevah.github.io/2023/05/15/CVE-2023-26818-Bypass-TCC-with-Telegram/"
            }
         ],
         "Authors": ["Dan Revah (@danrevah)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["TCC bypass", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-05-15",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "CS:GO: From Zero to 0-day",
               "Link": "https://neodyme.io/blog/csgo_from_zero_to_0day/"
            }
         ],
         "Authors": ["Felipe", "Alain"],
         "Programs": ["Valve (CS:GO)"],
         "Bugs": ["Game hacking", "RCE", "Memory corruption", "Arbitrary file download", "Arbitrary file write", "DLL Hijacking", "Privilege escalation"],
         "Bounty": "22,500",
         "PublicationDate": "2023-05-13",
         "AddedDate": "2023-05-15"
      },
      {
         "Links": [
            {
               "Title": "Container security: Infecting images to establish backdoors",
               "Link": "https://www.mnemonic.io/resources/blog/container-security-infecting-images-to-establish-backdoors/"
            }
         ],
         "Authors": ["Emilien Socchi (@emiliensocchi)"],
         "Programs": ["-"],
         "Bugs": ["Container security", "Kubernetes"],
         "Bounty": "-",
         "PublicationDate": "2023-05-12",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "The Printer Goes Brrrrr, Again!",
               "Link": "https://www.synacktiv.com/en/publications/the-printer-goes-brrrrr-again.html"
            }
         ],
         "Authors": ["Rémi Jullian (@netsecurity1)", "Mehdi Talbi (@abu_y0ussef)", "Thomas Jeunet  (@cleptho)"],
         "Programs": ["Canon"],
         "Bugs": ["Printer hacking", "Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-05-12",
         "AddedDate": "2023-05-15"
      },
      {
         "Links": [
            {
               "Title": "One Bug at a Time: I failed my quiz on purpose to get $1,000!",
               "Link": "https://medium.com/@atomiczsec/one-bug-at-a-time-my-first-paid-bug-1-000-idor-4b89b63b2b4b"
            }
         ],
         "Authors": ["atomiczsec (@atomiczsec)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "1,000",
         "PublicationDate": "2023-05-12",
         "AddedDate": "2023-05-15"
      },
      {
         "Links": [
            {
               "Title": "Discovering a Hidden Security Loophole: Rent luxury Cars for a Single Dollar",
               "Link": "https://medium.com/@yashsancheti24/discovering-a-hidden-security-loophole-rent-luxury-cars-for-a-single-dollar-706b4a7bf101"
            }
         ],
         "Authors": ["Yash Sancheti"],
         "Programs": ["-"],
         "Bugs": ["Payment tampering"],
         "Bounty": "-",
         "PublicationDate": "2023-05-12",
         "AddedDate": "2023-05-15"
      },
      {
         "Links": [
            {
               "Title": "Hacking HackerOne: How computer vision helped uncover hidden vulnerabilities?",
               "Link": "https://3bodymo.medium.com/hacking-hackerone-how-computer-vision-helped-uncover-hidden-vulnerabilities-858d03a6a67"
            }
         ],
         "Authors": ["Abdullah Mohamed (@3bodymo_)"],
         "Programs": ["HackerOne"],
         "Bugs": ["Information disclosure", "AI"],
         "Bounty": "-",
         "PublicationDate": "2023-05-11",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "Rendezvous with a Chatbot: Chaining Contextual Risk Vulnerabilities",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/rendezvous-with-a-chatbot-chaining-contextual-risk-vulnerabilities/"
            }
         ],
         "Authors": ["Abeer Banerjee (@bugasur)"],
         "Programs": ["-"],
         "Bugs": ["Chatbot", "Websockets", "Cross-Site WebSocket Hijacking (CSWH)", "Captcha bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-05-11",
         "AddedDate": "2023-05-15"
      },
      {
         "Links": [
            {
               "Title": "Hacking Chess.com: My Journey to Unlock Premium Bots on the Android App",
               "Link": "https://medium.com/@icebre4ker/hacking-chess-com-my-journey-to-unlock-premium-bots-on-the-android-app-d8cac9d25094"
            }
         ],
         "Authors": ["Fr4 (@_icebre4ker_)"],
         "Programs": ["Chess.com"],
         "Bugs": ["Android", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-05-10",
         "AddedDate": "2023-05-15"
      },
      {
         "Links": [
            {
               "Title": "What is kong & why we’re relying on it",
               "Link": "https://thinkloveshare.com/hacking/kong-konga-exploitation-and-hardening/"
            }
         ],
         "Authors": ["Laluka (@TheLaluka)"],
         "Programs": ["Konga"],
         "Bugs": ["RCE", "Sandbox escape", "Authentication bypass", "Hardcoded credentials", "Broken Access Control", "Privilege escalation", "JWT"],
         "Bounty": "-",
         "PublicationDate": "2023-05-10",
         "AddedDate": "2023-05-12"
      },
      {
         "Links": [
            {
               "Title": "Bypass IIS Authorisation with this One Weird Trick - Three RCEs and Two Auth Bypasses in Sitecore 9.3",
               "Link": "https://blog.assetnote.io/2023/05/10/sitecore-round-two/"
            }
         ],
         "Authors": ["Dylan Pindur"],
         "Programs": ["Sitecore"],
         "Bugs": ["RCE", "Authorization bypass", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-05-10",
         "AddedDate": "2023-05-11"
      },
      {
         "Links": [
            {
               "Title": "From One Vulnerability to Another: Outlook Patch Analysis Reveals Important Flaw in Windows API",
               "Link": "https://www.akamai.com/blog/security-research/important-outlook-vulnerability-bypass-windows-api"
            }
         ],
         "Authors": ["Ben Barnea (@nachoskrnl)"],
         "Programs": ["Microsoft (Outlook)"],
         "Bugs": ["Privilege escalation", "NTLM"],
         "Bounty": "-",
         "PublicationDate": "2023-05-10",
         "AddedDate": "2023-05-11"
      },
      {
         "Links": [
            {
               "Title": "RCE due to Dependency Confusion — $5000 bounty!",
               "Link": "https://chevonphillip.medium.com/rce-due-to-dependency-confusion-5000-bounty-fd1b294d645f"
            }
         ],
         "Authors": ["Chevon Phillip (@ChevonPhillip)"],
         "Programs": ["-"],
         "Bugs": ["Dependency confusion", "RCE"],
         "Bounty": "5,000",
         "PublicationDate": "2023-05-10",
         "AddedDate": "2023-05-11"
      },
      {
         "Links": [
            {
               "Title": "Testing a new encrypted messaging app's extraordinary claims",
               "Link": "https://crnkovic.dev/testing-converso/"
            }
         ],
         "Authors": ["Crnković"],
         "Programs": ["Converso"],
         "Bugs": ["Android", "Firebase", "Cryptographic issues", "Privacy issue", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-05-10",
         "AddedDate": "2023-05-11"
      },
      {
         "Links": [
            {
               "Title": "Discovery of an XSS on Opera",
               "Link": "https://infosecwriteups.com/discovery-of-an-xss-on-opera-f029f6522ec5"
            }
         ],
         "Authors": ["Arman (@M7arm4n)"],
         "Programs": ["Opera"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-05-10",
         "AddedDate": "2023-05-11"
      },
      {
         "Links": [
            {
               "Title": "PwnAssistant - Controlling /home's Via A Home Assistant RCE",
               "Link": "https://www.elttam.com/blog/pwnassistant/"
            }
         ],
         "Authors": ["elttam (@elttam)"],
         "Programs": ["Home Assistant"],
         "Bugs": ["Authentication bypass", "RCE", "Security code review", "IoT"],
         "Bounty": "-",
         "PublicationDate": "2023-05-09",
         "AddedDate": "2023-05-11"
      },
      {
         "Links": [
            {
               "Title": "Subdomain Takeover leading to Full Account Takeover",
               "Link": "https://hacktus.tech/subdomain-takeover-leading-to-full-account-takeover"
            }
         ],
         "Authors": ["Hacktus (@H4cktus)", "DreyAnd (@dreyand_)"],
         "Programs": ["-"],
         "Bugs": ["Subdomain takeover", "Account takeover", "ASP.NET"],
         "Bounty": "3,000",
         "PublicationDate": "2023-05-08",
         "AddedDate": "2023-07-17"
      },
      {
         "Links": [
            {
               "Title": "A deep-dive on Pluck CMS vulnerability CVE-2023-25828",
               "Link": "https://www.synopsys.com/blogs/software-security/a-deep-dive-on-pluck-cms-vulnerability-cve-2023-25828/"
            }
         ],
         "Authors": ["Matthew Hogg"],
         "Programs": ["Pluck CMS"],
         "Bugs": ["Unrestricted file upload", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-05-08",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Escaping Parallels Desktop with Plist Injection",
               "Link": "https://pwn.win/2023/05/08/parallels-escape.html"
            }
         ],
         "Authors": ["kn32"],
         "Programs": ["Parallels"],
         "Bugs": ["Local Privilege Escalation", "Plist injection", "TOCTOU"],
         "Bounty": "-",
         "PublicationDate": "2023-05-08",
         "AddedDate": "2023-05-11"
      },
      {
         "Links": [
            {
               "Title": "Sorting Your Way to Stolen Passwords",
               "Link": "https://blog.prodefense.io/sorting-your-way-to-stolen-passwords-43ff5cfeeabd"
            }
         ],
         "Authors": ["Matthew Keeley (@Nightbanes)"],
         "Programs": ["-"],
         "Bugs": ["Bruteforce", "Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2023-05-08",
         "AddedDate": "2023-05-11"
      },
      {
         "Links": [
            {
               "Title": "IPv6 DNS Takeover via mitm6 (Write Up)",
               "Link": "http://blog.evanricafort.com/2023/05/ipv6-dns-takeover-via-mitm6-write-up.html"
            }
         ],
         "Authors": ["Evan Ricafort (@evanricafort)"],
         "Programs": ["-"],
         "Bugs": ["MiTM", "IPv6", "DNS takeover", "Misconfigured LDAP server", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2023-05-08",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "How a simple Directory Listing leads to PII Data Leakage, Remote Code Execution and many more vulnerabilities on a HR management subdomain",
               "Link": "https://medium.com/@ar_hawk/how-a-simple-directory-listing-leads-to-pii-data-leakage-remote-code-execution-and-many-more-104b09e644f4"
            }
         ],
         "Authors": ["Aayush Vishnoi (@AayushVishnoi10)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Unrestricted file upload", "Stored XSS","Information disclosure",  "Directory listing"],
         "Bounty": "-",
         "PublicationDate": "2023-05-07",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "How I discovered XSS via triple URL encode",
               "Link": "https://medium.com/@mohammed01550038865/how-i-discovred-xss-via-url-encode-3-times-86ccd5354081"
            }
         ],
         "Authors": ["Muhammed Mubarak"],
         "Programs": ["-"],
         "Bugs": ["XSS", "WAF bypass"],
         "Bounty": "500",
         "PublicationDate": "2023-05-07",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Size matters! When capital letters introduce vulnerabilities",
               "Link": "https://www.secforce.com/blog/size-matters-when-capital-letters-introduce-vulnerabilities/"
            }
         ],
         "Authors": ["Mario Stathakopoulos", "Pieter Van Schaik"],
         "Programs": ["Microsoft"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-05-06",
         "AddedDate": "2023-05-13"
      },
      {
         "Links": [
            {
               "Title": "Dependabot Confusion: Gaining Access to Private GitHub Repositories using Dependabot",
               "Link": "https://giraffesecurity.dev/posts/dependabot-confusion/"
            }
         ],
         "Authors": ["Giraffe Security"],
         "Programs": ["GitHub"],
         "Bugs": ["Dependency confusion"],
         "Bounty": "2,500",
         "PublicationDate": "2023-05-06",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "CSS Injection via PostMessages to stealing Credit Card Info",
               "Link": "https://castilho.onrender.com/"
            }
         ],
         "Authors": ["Castilho (@castilho101)"],
         "Programs": ["-"],
         "Bugs": ["postMessage", "CSS injection"],
         "Bounty": "-",
         "PublicationDate": "2023-05-05",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Mass Assignment leads to the victim’s account being inaccessible forever",
               "Link": "https://infosecwriteups.com/mass-assignment-leads-to-the-victims-account-being-inaccessible-forever-52e48c6a8a4d"
            }
         ],
         "Authors": ["Arman (@M7arm4n)"],
         "Programs": ["-"],
         "Bugs": ["Mass assignment", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2023-05-05",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Bullied by Bugcrowd over Kape CyberGhost disclosure",
               "Link": "https://www.pentestpartners.com/security-blog/bullied-by-bugcrowd-over-kape-cyberghost-disclosure/"
            }
         ],
         "Authors": ["Ceri Coburn (@_ethicalchaos_)"],
         "Programs": ["Kape (CyberGhost)"],
         "Bugs": ["Local Privilege Escalation", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-05-05",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Cookie Bugs - Smuggling & Injection",
               "Link": "https://blog.ankursundara.com/cookie-bugs/"
            }
         ],
         "Authors": ["Ankur Sundara (@ankursundara)"],
         "Programs": ["Eclipse Foundation (Jetty)"],
         "Bugs": ["Cookie smuggling", "Cookie injection"],
         "Bounty": "-",
         "PublicationDate": "2023-05-05",
         "AddedDate": "2023-05-06"
      },
      {
         "Links": [
            {
               "Title": "A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF…",
               "Link": "https://jub0bs.com/posts/2023-05-05-smorgasbord-of-a-bug-chain/"
            }
         ],
         "Authors": ["Julien Cretel (@jub0bs)"],
         "Programs": ["-"],
         "Bugs": ["postMessage", "JSONP", "DOM XSS", "CORS misconfiguration", "CSRF", "WAF bypass"],
         "Bounty": "200",
         "PublicationDate": "2023-05-05",
         "AddedDate": "2023-05-06"
      },
      {
         "Links": [
            {
               "Title": "When Good APIs Go Bad: Uncovering 3 Azure API Management Vulnerabilities",
               "Link": "https://ermetic.com/blog/azure/when-good-apis-go-bad-uncovering-3-azure-api-management-vulnerabilities/"
            }
         ],
         "Authors": ["Liv Matan (@terminatorLM)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["SSRF", "Unrestricted file upload", "Path traversal", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-05-04",
         "AddedDate": "2023-05-06"
      },
      {
         "Links": [
            {
               "Title": "Privilege Escalations through Integrations",
               "Link": "https://blog.stratumsecurity.com/2023/05/04/integration-fails/"
            }
         ],
         "Authors": ["Colin McQueen"],
         "Programs": ["-"],
         "Bugs": ["Privilege escalation", "Amazon cognito misconfiguration", "JWT", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-05-04",
         "AddedDate": "2023-05-06"
      },
      {
         "Links": [
            {
               "Title": "OpenAI Allowed “Unlimited” Credit on New Accounts",
               "Link": "https://checkmarx.com/blog/openai-allowed-unlimited-credit-on-new-accounts/"
            }
         ],
         "Authors": ["David Sopas (@dsopas)"],
         "Programs": ["OpenAI (ChatGPT)"],
         "Bugs": ["AI", "LLM", "Logic flaw", "Account verification bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-05-04",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Imperva Red Team Discovers Vulnerability in TikTok That Can Reveal User Activity and Information",
               "Link": "https://www.imperva.com/blog/imperva-red-team-discovers-vulnerability-in-tiktok-that-can-reveal-user-activity-and-information/"
            }
         ],
         "Authors": ["Ron Masas (@RonMasas)"],
         "Programs": ["TikTok"],
         "Bugs": ["postMessage"],
         "Bounty": "-",
         "PublicationDate": "2023-05-03",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-25394 - VideoStream Local Privilege Escalation",
               "Link": "https://danrevah.github.io/2023/05/03/CVE-2023-25394-VideoStream-LPE/"
            }
         ],
         "Authors": ["Dan Revah (@danrevah)"],
         "Programs": ["Videostream"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-05-03",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "The Art of Information Disclosure: A Deep Dive into CVE-2022-37985, a Unique Information Disclosure Vulnerability in Windows Graphics Component",
               "Link": "https://www.trellix.com/en-us/about/newsroom/stories/research/the-art-of-information-disclosure.html"
            }
         ],
         "Authors": ["Bing Sun"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Out-of-bounds Read", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-05-03",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Accessing Admin Dashboard in 5 seconds: Hall of Fame.",
               "Link": "https://sumedh00.medium.com/accessing-admin-dashboard-in-5-seconds-acee737eacfb"
            }
         ],
         "Authors": ["Sumedh Dawadi"],
         "Programs": ["-"],
         "Bugs": ["Default credentials"],
         "Bounty": "-",
         "PublicationDate": "2023-05-03",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Automating SQL Injection On Encrypted Request",
               "Link": "https://medium.com/@janirudransh/automating-sql-injection-on-encrypted-request-21a43aa2e7ef"
            }
         ],
         "Authors": ["Janirudransh"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "Client-side encryption bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-05-03",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "When you're so bored, you start debugging someone else's code: bug hunting in a random Cloud-Native project",
               "Link": "https://blog.onsec.io/when-youre-so-bored-you-start-debugging-someone-elses-code/"
            }
         ],
         "Authors": ["ONSEC.io Research Team"],
         "Programs": ["Foreman"],
         "Bugs": ["SSTI", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-05-03",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Exploiting misconfigured Google Cloud Service Accounts from GitHub Actions",
               "Link": "https://www.revblock.dev/exploiting-misconfigured-google-cloud-service-accounts-from-github-actions/"
            }
         ],
         "Authors": ["Revblock (@revbl0ck)"],
         "Programs": ["-"],
         "Bugs": ["OIDC", "Cloud", "CI/CD"],
         "Bounty": "-",
         "PublicationDate": "2023-05-02",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "Securing Databricks cluster init scripts",
               "Link": "https://sec-consult.com/blog/detail/securing-databricks-cluster-init-scripts/"
            }
         ],
         "Authors": ["Elia Florio", "Florian Roth (@cyb3rops)", "Marius Bartholdy"],
         "Programs": ["Databricks"],
         "Bugs": ["Privilege escalation", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-05-02",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "How do I Bypass Payment when a Subscription ends so I don’t have to pay for my subscription",
               "Link": "https://aidilarf.medium.com/how-do-i-bypass-payment-when-a-subscription-ends-so-i-dont-have-to-pay-for-my-subscription-3889ab3f7484"
            }
         ],
         "Authors": ["Aidil Arief"],
         "Programs": ["-"],
         "Bugs": ["Payment bypass", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2023-05-02",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-28231: RCE In The Microsoft Windows DHCPv6 Service",
               "Link": "https://www.zerodayinitiative.com/blog/2023/5/1/cve-2023-28231-rce-in-the-microsoft-windows-dhcpv6-service"
            }
         ],
         "Authors": ["Guy Lederfein (@glederfein)", "Lucas Miller"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["RCE", "Buffer Overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-05-02",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory –  KerioControl Remote Code Execution",
               "Link": "https://ssd-disclosure.com/ssd-advisory-keriocontrol-remote-code-execution/"
            }
         ],
         "Authors": ["Simon Janz"],
         "Programs": ["GFI Software (KerioControl)"],
         "Bugs": ["RCE", "TAR path traversal"],
         "Bounty": "-",
         "PublicationDate": "2023-05-02",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "AWS Identity Center (formerly known as AWS SSO): A Guide to Privilege Escalation and Identity and Access Management",
               "Link": "https://www.cloudquery.io/blog/aws-priv-esc-identity-center"
            }
         ],
         "Authors": ["Jason Kao"],
         "Programs": ["AWS"],
         "Bugs": ["Privilege escalation", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-05-01",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Placeholder for Dayzzz: Abusing placeholders to extract customer informations",
               "Link": "https://ophionsecurity.com/blog/placeholder-for-dayzzz"
            }
         ],
         "Authors": ["Ophion Security (@OphionSecurity)"],
         "Programs": ["GitHub"],
         "Bugs": ["SSTI", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-05-01",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Apache Solr 8.3.1 RCE from exposed administration interface",
               "Link": "https://blog.scrt.ch/2023/05/01/solr-rce-from-exposed-administration-interface/"
            }
         ],
         "Authors": ["Nicolas Brunner"],
         "Programs": ["Apache Solr"],
         "Bugs": ["RCE", "Unrestricted file upload", "XSLT injection", "Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2023-05-01",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Azure Devops CICD Pipelines - Command Injection With Parameters, Variables And A Discussion On Runner Hijacking",
               "Link": "https://pulsesecurity.co.nz/advisories/Azure-Devops-Command-Injection"
            }
         ],
         "Authors": ["Sana Oshika (@bigshika)"],
         "Programs": ["Microsoft (Azure DevOps Pipelines)"],
         "Bugs": ["CI/CD", "OS command injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-05-01",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Unauthorized access to the admin panel via leaked credentials on the WayBackMachine",
               "Link": "https://infosecwriteups.com/unauthorized-access-to-the-admin-panel-via-leaked-credentials-on-the-waybackmachine-55c3307141c6"
            }
         ],
         "Authors": ["Arman (@M7arm4n)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-05-01",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Bug Bounty Writeup: Stored XSS Vulnerability WAF Bypass",
               "Link": "https://medium.com/@lopseg/bug-bounty-writeup-stored-xss-vulnerability-waf-bypass-f38aae7ff9eb"
            }
         ],
         "Authors": ["Rafael Silva \"lopseg\""],
         "Programs": ["-"],
         "Bugs": ["Stored XSS", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-05-01",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "TENDA–N301-v6–(CVE-2023–29680,CVE-2023–29681)",
               "Link": "https://medium.com/@0ta/tenda-n301-v6-cve-2023-29680-cve-2023-29681-a40f7ae6dc62"
            }
         ],
         "Authors": ["Mateus Pantoja"],
         "Programs": ["Tenda"],
         "Bugs": ["Sensitive Information Sent Over an Unencrypted Channel"],
         "Bounty": "-",
         "PublicationDate": "2023-04-30",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Exploiting an Order of Operations Bug to Achieve RCE in Oracle Opera",
               "Link": "https://blog.assetnote.io/2023/04/30/rce-oracle-opera/"
            }
         ],
         "Authors": ["Shubham Shah (@infosec_au)", "Sean Yeoh (@seanyeoh)", "Brendan Scarvell (@bscarvell)", "Jason Haddix (@Jhaddix)"],
         "Programs": ["Oracle (Opera)"],
         "Bugs": ["RCE", "Unrestricted file upload", "Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-04-30",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Netflix — Bypassing Multi-Factor Authentication (MFA)",
               "Link": "https://ltsirkov.medium.com/netflix-bypassing-multi-factor-authentication-mfa-53135c9d6d50"
            }
         ],
         "Authors": ["Lyubomir Tsirkov (@lyubo_tsirkov)"],
         "Programs": ["Netflix"],
         "Bugs": ["2FA / MFA bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-04-30",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "How I Chained an Information Disclosure Bug with SQL Injection",
               "Link": "https://goziem.medium.com/how-i-chained-an-information-disclosure-bug-to-sql-injection-bca936d90fb1"
            }
         ],
         "Authors": ["Mba-oji Chiagoziem (@g0ziem)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", ".git folder disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-04-30",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Privilege Escalation in Microsoft Windows",
               "Link": "https://herolab.usd.de/security-advisories/usd-2022-0034/"
            }
         ],
         "Authors": ["Tobias Neitzel (@qtc_de)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-04-28",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "Ambushed by AngularJS: a hidden CSP bypass in Piwik PRO",
               "Link": "https://portswigger.net/research/ambushed-by-angularjs-a-hidden-csp-bypass-in-piwik-pro"
            }
         ],
         "Authors": ["Gareth Heyes (@garethheyes)"],
         "Programs": ["PortSwigger", "Piwik"],
         "Bugs": ["CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-04-28",
         "AddedDate": "2023-04-29"
      },
      {
         "Links": [
            {
               "Title": "Redash SAML Authentication Bypass",
               "Link": "https://blog.calif.io/p/redash-saml-authentication-bypass"
            }
         ],
         "Authors": ["An Trinh (@_tint0)", "Gia Bui (@yabeow)"],
         "Programs": ["Redash"],
         "Bugs": ["SAML", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-04-28",
         "AddedDate": "2023-04-28"
      },
      {
         "Links": [
            {
               "Title": "Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707)",
               "Link": "https://starlabs.sg/blog/2023/04-microsoft-exchange-powershell-remoting-deserialization-leading-to-rce-cve-2023-21707/"
            }
         ],
         "Authors": ["Nguyễn Tiến Giang (@testanull)"],
         "Programs": ["Microsoft (Exchange)"],
         "Bugs": ["RCE", "Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2023-04-28",
         "AddedDate": "2023-04-28"
      },
           {
            "Links": [
               {
                  "Title": "State of DNS Rebinding in 2023",
                  "Link": "https://research.nccgroup.com/2023/04/27/state-of-dns-rebinding-in-2023/"
               }
            ],
            "Authors": ["Roger Meyer (@sanktjodel)"],
            "Programs": ["-"],
            "Bugs": ["DNS rebinding"],
            "Bounty": "-",
            "PublicationDate": "2023-04-27",
            "AddedDate": "2024-01-18"
         },
      {
         "Links": [
            {
               "Title": "Avast Anti-Virus privileged arbitrary file create on virus quarantine (CVE-2023-1585 and CVE-2023-1587)",
               "Link": "https://the-deniss.github.io/posts/2023/04/26/avast-privileged-arbitrary-file-create-on-quarantine.html"
            }
         ],
         "Authors": ["Denis Skvortcov (@Denis_Skvortcov)"],
         "Programs": ["Avast"],
         "Bugs": ["TOCTOU", "NULL pointer dereference", "Arbitrary file write", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-04-26",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Alias file to rule them all — One click code execution with alias file in macOS",
               "Link": "https://mikko-kenttala.medium.com/alias-file-to-rule-them-all-one-click-code-execution-with-alias-file-in-macos-1eeb0a730b88"
            }
         ],
         "Authors": ["Mikko Kenttälä (@Turmio_)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["Arbitrary Code Execution", "TCC bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-04-26",
         "AddedDate": "2023-04-28"
      },
      {
         "Links": [
            {
               "Title": "Git Arbitrary Configuration Injection (CVE-2023-29007)",
               "Link": "https://blog.ethiack.com/en/blog/git-arbitrary-configuration-injection-cve-2023-29007"
            }
         ],
         "Authors": ["André Baptista (@0xacb)", "Vítor Pinho"],
         "Programs": ["Git"],
         "Bugs": ["Logic flaw", "Arbitrary Code Execution", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-04-26",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "Finding XSS in a million websites (cPanel CVE-2023-29489)",
               "Link": "https://blog.assetnote.io/2023/04/26/xss-million-websites-cpanel/"
            }
         ],
         "Authors": ["Shubham Shah (@infosec_au)"],
         "Programs": ["cPanel"],
         "Bugs": ["Reflected XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-04-26",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "Never Connect to RDP Servers Over Untrusted Networks",
               "Link": "https://www.gosecure.net/blog/2023/04/26/never-connect-to-rdp-servers-over-untrusted-networks/"
            }
         ],
         "Authors": ["Olivier Bilodeau (@obilodeau)"],
         "Programs": ["Microsoft"],
         "Bugs": ["RDP"],
         "Bounty": "-",
         "PublicationDate": "2023-04-26",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "API Misconfiguration - Algolia API Key",
               "Link": "https://shahjerry33.medium.com/api-misconfiguration-algolia-api-key-b3f4a9f04f0d"
            }
         ],
         "Authors": ["Jerry Shah (@Jerry)"],
         "Programs": ["-"],
         "Bugs": ["Hardcoded API keys"],
         "Bounty": "-",
         "PublicationDate": "2023-04-26",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "Methodological approach to find business logic bugs",
               "Link": "https://strike.sh/blog/business-bugs-approach"
            }
         ],
         "Authors": ["Fady Othman (@Fady_Othman)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw", "Payment tampering", "IP address validation bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-04-25",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "New high-severity vulnerability (CVE-2023-29552) discovered in the Service Location Protocol (SLP)",
               "Link": "https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp"
            },
            {
               "Title": "Curesec article",
               "Link": "https://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Denial-of-Service-Amplification-Attack-212.html"
            }
         ],
         "Authors": ["Pedro Umbelino", "Marco Lux"],
         "Programs": ["Service Location Protocol (SLP)"],
         "Bugs": ["DoS", "UDP spoofing"],
         "Bounty": "-",
         "PublicationDate": "2023-04-25",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-27524: Insecure Default Configuration in Apache Superset Leads to Remote Code Execution",
               "Link": "https://www.horizon3.ai/cve-2023-27524-insecure-default-configuration-in-apache-superset-leads-to-remote-code-execution/"
            }
         ],
         "Authors": ["Naveen Sunkavally"],
         "Programs": ["Apache Superset"],
         "Bugs": ["RCE", "Default Flask Secret Key", "Hardcoded credentials"],
         "Bounty": "-",
         "PublicationDate": "2023-04-25",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "Odoo: Get your Content Type right, or else!",
               "Link": "https://www.sonarsource.com/blog/odoo-get-your-content-type-right-or-else/"
            }
         ],
         "Authors": ["Dennis Brinkrolf (@DBrinkrolf)", "Thomas Chauchefoin (@swapgs)"],
         "Programs": ["Odoo"],
         "Bugs": ["XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-04-24",
         "AddedDate": "2023-04-28"
      },
      {
         "Links": [
            {
               "Title": "Vocera Report Server Pwnage",
               "Link": "https://www.securifera.com/blog/2023/04/24/vocera_report_server_pwnage/"
            }
         ],
         "Authors": ["b0yd (@rwincey)"],
         "Programs": ["Stryker"],
         "Bugs": ["RCE", "Arbitrary file upload", "Path traversal", "Zip Slip attack"],
         "Bounty": "-",
         "PublicationDate": "2023-04-24",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "No Portals Needed",
               "Link": "https://medium.com/cyesec/no-portals-needed-79995d8f7e62"
            }
         ],
         "Authors": ["Chen Levy Ben Aroy"],
         "Programs": ["-"],
         "Bugs": ["2FA / MFA bypass", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-04-24",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "Discord Rich Presence LeonardSSH.vscord",
               "Link": "https://github.com/Sudistark/advisories/blob/main/vscode-extension/Discord-Rich-Presence-LeonardSSH.vscord.md"
            }
         ],
         "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
         "Programs": ["vscord"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-04-23",
         "AddedDate": "2023-05-22"
      },
      {
         "Links": [
            {
               "Title": "How careless default credentials impact to massive account takeover",
               "Link": "https://medium.com/@mmaulanaabdullah/how-careless-default-credentials-impact-to-massive-account-takeover-be6bfc85119a"
            }
         ],
         "Authors": ["M Maulana Abdullah"],
         "Programs": ["-"],
         "Bugs": ["Authentication bypass", "Account takeover", "Weak credentials"],
         "Bounty": "-",
         "PublicationDate": "2023-04-22",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "Stealing GitHub staff's access token via GitHub Actions",
               "Link": "https://blog.ryotak.net/post/github-actions-staff-access-token-en/"
            }
         ],
         "Authors": ["RyotaK (@ryotkak)"],
         "Programs": ["GitHub"],
         "Bugs": ["CI/CD", "Token leak", "Privilege escalation", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2023-04-22",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "Compromising Garmin’s Sport Watches: A Deep Dive into GarminOS and its MonkeyC Virtual Machine",
               "Link": "https://www.anvilsecure.com/blog/compromising-garmins-sport-watches-a-deep-dive-into-garminos-and-its-monkeyc-virtual-machine.html"
            }
         ],
         "Authors": ["Tao Sauvage"],
         "Programs": ["Garmin"],
         "Bugs": ["IoT", "Memory corruption", "Buffer Overflow", "Integer overflow", "Out-of-bounds Read", "Out-of-bounds Write", "Type confusion", "Permission bypass", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2023-04-21",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "Exploits Explained: Permission misconfiguration within Salesforce JavaScript Remoting tokens used for Apex Controllers",
               "Link": "https://www.synack.com/blog/permission-problem-salesforce-javascript-remoting-token/"
            }
         ],
         "Authors": ["Mahmoud Gamal (@Zombiehelp54)"],
         "Programs": ["-"],
         "Bugs": ["Salesforce", "Security misconfiguration", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-04-21",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "From BitLocker-Suspended to Virtual Machine",
               "Link": "https://sensepost.com/blog/2023/from-bitlocker-suspended-to-virtual-machine/"
            }
         ],
         "Authors": ["Reino Mostert"],
         "Programs": ["-"],
         "Bugs": ["Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2023-04-21",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "XS-Leak: Deanonymize Microsoft Skype Users by any 3rd-party websites",
               "Link": "https://infosecwriteups.com/xs-leak-deanonymize-microsoft-skype-users-by-any-3rd-party-website-69849e4501a8"
            }
         ],
         "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
         "Programs": ["Microsoft (Skype)"],
         "Bugs": ["XSLeaks"],
         "Bounty": "-",
         "PublicationDate": "2023-04-21",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "2 XSS on Microsoft",
               "Link": "https://medium.com/@nikouei_com/2-xss-on-microsoft-37b6a7efcc84"
            }
         ],
         "Authors": ["Mohammad Nikouei (@NikoueiMohammad)"],
         "Programs": ["Microsoft"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-04-20",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-23525: Get Root via A Fake Installer",
               "Link": "https://jhftss.github.io/CVE-2023-23525-Get-Root-via-A-Fake-Installer/"
            }
         ],
         "Authors": ["Mickey Jin (@patch1t)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-04-20",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Turning Vulnerability into Bounty: How CVE-2020–17453 XSS Earned Me a $500 Bounty",
               "Link": "https://infosecwriteups.com/turning-vulnerability-into-bounty-how-cve-2020-17453-xss-earned-me-a-500-bounty-dcabc737fded"
            }
         ],
         "Authors": ["Karthikeyan.V (@karthithehacker)"],
         "Programs": ["-"],
         "Bugs": ["Components with known vulnerabilities", "XSS"],
         "Bounty": "500",
         "PublicationDate": "2023-04-20",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts",
               "Link": "https://astrix.security/ghosttoken-exploiting-gcp-application-infrastructure-to-create-invisible-unremovable-trojan-app-on-google-accounts/"
            }
         ],
         "Authors": ["Astrix Security (@AstrixSecurity)"],
         "Programs": ["Google (GCP)"],
         "Bugs": ["Cloud", "OAuth", "Authorization bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-04-20",
         "AddedDate": "2023-04-29"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Link Sharing Protection in Messenger Kids Parent’s Control Feature | Meta Bug Bounty",
               "Link": "https://zerocode-ph.medium.com/bypassing-link-sharing-protection-in-messenger-kids-parents-control-feature-meta-bug-bounty-e53f2d148bd9"
            }
         ],
         "Authors": ["Syd Ricafort (@devsyd11)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["URL validation bypass"],
         "Bounty": "500",
         "PublicationDate": "2023-04-20",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "The Fuzzing Guide to the Galaxy: An Attempt with Android System Services",
               "Link": "https://blog.thalium.re/posts/fuzzing-samsung-system-services/"
            }
         ],
         "Authors": ["Anthony Remy"],
         "Programs": ["Samsung"],
         "Bugs": ["Android", "Fuzzing", "Heap overflow", "Integer overflow", "Out-of-bounds Write", "Memory corruption", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-04-20",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "Turning Vulnerability into Bounty: How CVE-2020–17453 XSS Earned Me a $500 Bounty",
               "Link": "https://medium.com/bugbountywriteup/turning-vulnerability-into-bounty-how-cve-2020-17453-xss-earned-me-a-500-bounty-dcabc737fded"
            }
         ],
         "Authors": ["Karthikeyan.V (@karthithehacker)"],
         "Programs": ["-"],
         "Bugs": ["Components with known vulnerabilities", "XSS"],
         "Bounty": "500",
         "PublicationDate": "2023-04-20",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "Uncovering a Critical Vulnerability: My Journey of Discovering CVE-2021–31589, a Reflected XSS in LinkedIn",
               "Link": "https://medium.com/bugbountywriteup/uncovering-a-critical-vulnerability-my-journey-of-discovering-cve-2021-31589-a-reflected-xss-in-1e13c0aa41b0"
            }
         ],
         "Authors": ["Karthikeyan.V (@karthithehacker)"],
         "Programs": ["LinkedIn"],
         "Bugs": ["Components with known vulnerabilities", "Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-04-20",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-29844: A Classic Buffer Overflow On The Western Digital My Cloud Pro Series PR4100",
               "Link": "https://www.zerodayinitiative.com/blog/2023/4/19/cve-2022-29844-a-classic-buffer-overflow-on-the-western-digital-my-cloud-pro-series-pr4100"
            }
         ],
         "Authors": ["Luca Moro (@johncool__)"],
         "Programs": ["Western Digital"],
         "Bugs": ["Buffer Overflow", "Memory corruption", "RCE"],
         "Bounty": "40,000",
         "PublicationDate": "2023-04-20",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "How I hacked hackers in Voorivex Hunt Event",
               "Link": "https://medium.com/@snoopy101/how-i-hacked-hackers-in-voorivex-hunt-event-9c572ce0005f"
            }
         ],
         "Authors": ["snoopy (@snoopy101101)"],
         "Programs": ["-"],
         "Bugs": ["Cloudflare bypass", "WAF bypass", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-04-19",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Vulnerability Spotlight: CVE-2023-0264",
               "Link": "https://mogwailabs.de/en/blog/2023/04/vulnerability-spotlight-cve-2023-0264/"
            }
         ],
         "Authors": ["Timo Müller (@mtimo44)"],
         "Programs": ["Keycloak"],
         "Bugs": ["OIDC", "OAuth", "Broken authentication", "Privilege escalation", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-04-19",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "How I Manipulated My Rank on the Bugcrowd Platform",
               "Link": "https://blog.securitybreached.org/2023/04/19/how-i-manipulated-my-rank-on-the-bugcrowd-platform/"
            }
         ],
         "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
         "Programs": ["Bugcrowd"],
         "Bugs": ["Logic flaw"],
         "Bounty": "900",
         "PublicationDate": "2023-04-19",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2",
               "Link": "https://www.cyberark.com/resources/threat-research-blog/breaking-docker-named-pipes-systematically-docker-desktop-privilege-escalation-part-2"
            }
         ],
         "Authors": ["Eviatar Gerzi"],
         "Programs": ["Docker"],
         "Bugs": ["Local Privilege Escalation", "TOCTOU", "Arbitrary file write"],
         "Bounty": "-",
         "PublicationDate": "2023-04-19",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "Weblogic CVE-2023-21931 vulnerability exploration technique: post-deserialization exploitation",
               "Link": "https://github.com/gobysec/Weblogic/blob/main/Research%20on%20WebLogic%20After-Deserialization.md"
            }
         ],
         "Authors": ["Goby (@GobySec)"],
         "Programs": ["Oracle (WebLogic)"],
         "Bugs": ["Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-04-19",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "#BrokenSesame: Accidental ‘write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services",
               "Link": "https://www.wiz.io/blog/brokensesame-accidental-write-permissions-to-private-registry-allowed-potential-r"
            }
         ],
         "Authors": ["Ronen Shustin (@ronenshh)", "Shir Tamari (@shirtamari)"],
         "Programs": ["Alibaba"],
         "Bugs": ["Cloud", "RCE", "Container escape", "Kubernetes", "Privilege escalation","Lateral movement", "Supply chain attack", "Cross-tenant vulnerability"],
         "Bounty": "-",
         "PublicationDate": "2023-04-19",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "How Material Security Uncovered a Vulnerability in the Gmail API",
               "Link": "https://material.security/blog/how-material-security-uncovered-a-vulnerability-in-gmail-api"
            }
         ],
         "Authors": ["Chris Long (@Centurion)"],
         "Programs": ["Google"],
         "Bugs": ["Broken Access Control", "Broken authorization"],
         "Bounty": "-",
         "PublicationDate": "2023-04-18",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "My First Case of SSRF Using Dirsearch",
               "Link": "https://goziem.medium.com/my-first-case-of-ssrf-using-dirsearch-b916f0f1e94b"
            }
         ],
         "Authors": ["Mba-oji Chiagoziem (@g0ziem)"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-04-18",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Popping Tags: Exploiting Template Injections in PRTG Network Monitor",
               "Link": "https://skylightcyber.com/2023/04/18/popping-tags/"
            }
         ],
         "Authors": ["Peter Szot"],
         "Programs": ["Paessler"],
         "Bugs": ["Reflected XSS", "CSTI"],
         "Bounty": "-",
         "PublicationDate": "2023-04-18",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
           {
              "Title": "Impersonating Other Players with UDP Spoofing in Mirror",
              "Link": "https://blog.includesecurity.com/2023/04/impersonating-local-unity-players-with-udp-spoofing-in-mirror/"
           }
          ],
         "Authors": ["IncludeSec (@IncludeSecurity)"],
         "Programs": ["Unity (Mirror)"],
         "Bugs": ["Game hacking", "UDP spoofing", "Reverse engineering"],
         "Bounty": "-",
         "PublicationDate": "2023-04-18",
         "AddedDate": "2023-04-27"
       },
      {
         "Links": [
            {
               "Title": "Break the Logic: Playing with product ratings on a shopping site(600$)",
               "Link": "https://infosecwriteups.com/break-the-logic-playing-with-product-ratings-on-a-shopping-site-600-c9a87fb66a73"
            }
         ],
         "Authors": ["Fırat"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw", "Parameter tampering"],
         "Bounty": "600",
         "PublicationDate": "2023-04-18",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "[Responsible Disclosure] How we could have deleted any Linkedin post",
               "Link": "https://www.pingsafe.com/blog/linkedin-vulnerability-delete-any-post"
            }
         ],
         "Authors": ["Anand Prakash (@anandpraka_sh)"],
         "Programs": ["LinkedIn"],
         "Bugs": ["IDOR"],
         "Bounty": "10,000",
         "PublicationDate": "2023-04-18",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "Identifying vulnerabilities in GitHub Actions & AWS OIDC Configurations",
               "Link": "https://medium.com/tinder/identifying-vulnerabilities-in-github-actions-aws-oidc-configurations-8067c400d5b8"
            }
         ],
         "Authors": ["Rojan Rijal (@uraniumhacker)", "Johnny Nipper (@ratherbeonline)", "Tanner Emek (@itscachemoney)"],
         "Programs": ["AWS"],
         "Bugs": ["CI/CD", "OIDC"],
         "Bounty": "-",
         "PublicationDate": "2023-04-18",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "How to narrow recon giving me $$$$ Bounty",
               "Link": "https://mmdz.ninja/2023/04/17/how-narrow-recon-giving-me-bounty/"
            }
         ],
         "Authors": ["Mohammad Zaheri (@mzaherii)"],
         "Programs": ["-"],
         "Bugs": ["Web cache deception"],
         "Bounty": "-",
         "PublicationDate": "2023-04-17",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Multiple Critical Vulnerabilities In Strapi Versions <=4.7.1",
               "Link": "https://www.ghostccamm.com/blog/multi_strapi_vulns/"
            }
         ],
         "Authors": ["GhostCcamm (@GhostCcamm)"],
         "Programs": ["Strapi"],
         "Bugs": ["Authentication bypass", "SSTI", "RCE", "Amazon cognito misconfiguration", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-04-17",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "A Big company Admin Panel takeover $4500",
               "Link": "https://medium.com/@nanwinata/a-big-company-admin-panel-takeover-4500-9520a6c83430"
            }
         ],
         "Authors": ["nanwn"],
         "Programs": ["-"],
         "Bugs": ["Authentication bypass", "40x bypass", "Account takeover"],
         "Bounty": "4,500",
         "PublicationDate": "2023-04-17",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "(CVE-2023-2017) Shopware 6 Server-side Template Injection (SSTI) via Twig Security Extension",
               "Link": "https://starlabs.sg/advisories/23/23-2017/"
            }
         ],
         "Authors": ["Ngo Wei Lin (@Creastery)"],
         "Programs": ["Shopware"],
         "Bugs": ["SSTI", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-04-17",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "Bypassing the 2FA /MFA — An Easy win",
               "Link": "https://medium.com/@mehtashobhit98/bypassing-the-2fa-mfa-an-easy-win-9b059bf0ac75"
            }
         ],
         "Authors": ["Shobhit Mehta"],
         "Programs": ["MathWorks"],
         "Bugs": ["2FA / MFA bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-04-16",
         "AddedDate": "2023-04-29"
      },
      {
         "Links": [
            {
               "Title": "From payload to 300$ bounty: A story of CRLF injection and responsible disclosure on HackerOne",
               "Link": "https://infosecwriteups.com/from-payload-to-300-bounty-a-story-of-crlf-injection-and-responsible-disclosure-on-hackerone-eeff74aff422"
            }
         ],
         "Authors": ["Karthikeyan.V (@karthithehacker)"],
         "Programs": ["-"],
         "Bugs": ["CRLF injection"],
         "Bounty": "300",
         "PublicationDate": "2023-04-16",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "How do I get cross site scripting(“xss”) in “Nokia”",
               "Link": "https://medium.com/@elsayedmohammed/how-do-i-get-cross-site-scripting-xss-in-nokia-3041c942b923"
            }
         ],
         "Authors": ["EL Sayed Mohammed (@ElsayedMo77amed)"],
         "Programs": ["Nokia"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-04-16",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "Prototype Pollution in xml2js",
               "Link": "https://github.com/Sudistark/advisories/blob/main/2023/npm-package/xml2js.md"
            }
         ],
         "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
         "Programs": ["xml2js"],
         "Bugs": ["Prototype pollution"],
         "Bounty": "-",
         "PublicationDate": "2023-04-14",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "From Django Debug Mode to PII Data Leak of more than 500+ Employees due Broken Access Control and IDOR",
               "Link": "https://medium.com/@ar_hawk/from-django-debug-mode-to-pii-data-leak-of-more-than-500-employees-due-broken-access-control-and-a3eb602a4207"
            }
         ],
         "Authors": ["Aayush Vishnoi (@AayushVishnoi10)"],
         "Programs": ["-"],
         "Bugs": ["Debug mode enabled", "IDOR", "Information disclosure", "JWT", "Broken Access Control", "Exposed registration page"],
         "Bounty": "-",
         "PublicationDate": "2023-04-14",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "User impersonation via stolen UUID code in KeyCloak (CVE-2023-0264)",
               "Link": "https://www.offensity.com/en/blog/user-impersonation-via-stolen-uuid-code-in-keycloak-cve-2023-0264/"
            }
         ],
         "Authors": ["Jordi Zayuelas i Muñoz"],
         "Programs": ["Keycloak"],
         "Bugs": ["OAuth", "OIDC", "Privilege escalation", "Broken authentication"],
         "Bounty": "-",
         "PublicationDate": "2023-04-14",
         "AddedDate": "2023-04-28"
      },
      {
         "Links": [
            {
               "Title": "Remote Code Execution Vulnerability in Google They Are Not Willing To Fix",
               "Link": "https://giraffesecurity.dev/posts/google-remote-code-execution/"
            }
         ],
         "Authors": ["Giraffe Security"],
         "Programs": ["Google"],
         "Bugs": ["Dependency confusion", "RCE"],
         "Bounty": "500",
         "PublicationDate": "2023-04-14",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "How I got RCE in + 10 websites…",
               "Link": "https://medium.com/@crd0x49/how-i-got-rce-in-10-websites-26dd87441f22"
            }
         ],
         "Authors": ["m4cddr (@m4cddr)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-04-13",
         "AddedDate": "2023-04-15"
      },
      {
         "Links": [
            {
               "Title": "TOPdesk vulnerable to XML Signature Wrapping Attacks",
               "Link": "https://char49.com/articles/topdesk-vulnerable-to-xml-signature-wrapping-attacks"
            }
         ],
         "Authors": ["Paulo A. Silva (@pauloasilva_com)"],
         "Programs": ["TOPdesk"],
         "Bugs": ["XML Signature Wrapping", "SAML", "SSO"],
         "Bounty": "-",
         "PublicationDate": "2023-04-12",
         "AddedDate": "2023-05-18"
      },
      {
         "Links": [
            {
               "Title": "Rooting A Common-criteria Certified Printer To Improve Opsec",
               "Link": "https://blog.redteam-pentesting.de/2023/rooting-printer/"
            }
         ],
         "Authors": ["RedTeam Pentesting (@RedTeamPT)"],
         "Programs": ["Canon"],
         "Bugs": ["Printer hacking"],
         "Bounty": "-",
         "PublicationDate": "2023-04-12",
         "AddedDate": "2023-04-28"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-29383: Abusing Linux chfn to Misrepresent /etc/passwd",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-29383-abusing-linux-chfn-to-misrepresent-etc-passwd/"
            }
         ],
         "Authors": ["Tom Neaves"],
         "Programs": ["shadow-utils"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-04-12",
         "AddedDate": "2023-04-15"
      },
      {
         "Links": [
            {
               "Title": "SecurePwn Part 2: Leaking Remote Memory Contents (CVE-2023-22897)",
               "Link": "https://www.rcesecurity.com/2023/04/securepwn-part-2-leaking-remote-memory-contents-cve-2023-22897/"
            }
         ],
         "Authors": ["Julien Ahrens (@MrTuxracer)"],
         "Programs": ["SecurePoint"],
         "Bugs": ["Memory leak"],
         "Bounty": "-",
         "PublicationDate": "2023-04-12",
         "AddedDate": "2023-04-15"
      },
      {
         "Links": [
            {
               "Title": "How ChatGPT helped me find a bug",
               "Link": "https://abhishekgk.medium.com/how-chatgpt-helped-me-find-a-bug-b5a3795c722"
            }
         ],
         "Authors": ["Abhishekgk"],
         "Programs": ["-"],
         "Bugs": ["XSS", "File upload"],
         "Bounty": "200",
         "PublicationDate": "2023-04-11",
         "AddedDate": "2023-04-29"
      },
      {
         "Links": [
            {
               "Title": "Losing control over Schneider's EcoStruxure Control Expert",
               "Link": "https://www.reversemode.com/2023/04/losing-control-over-schneiders.html"
            }
         ],
         "Authors": ["Ruben Santamarta (@reversemode)"],
         "Programs": ["Schneider Electric"],
         "Bugs": ["RCE", "Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-04-11",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "Java Exploitation Restrictions in Modern JDK Times",
               "Link": "https://codewhitesec.blogspot.com/2023/04/java-exploitation-restrictions-in.html"
            }
         ],
         "Authors": ["Florian Hauser (@frycos)"],
         "Programs": ["-"],
         "Bugs": ["Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2023-04-11",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "SecurePwn Part 1: Bypassing SecurePoint UTM’s Authentication (CVE-2023-22620)",
               "Link": "https://www.rcesecurity.com/2023/04/securepwn-part-1-bypassing-securepoint-utms-authentication-cve-2023-22620/"
            }
         ],
         "Authors": ["Julien Ahrens (@MrTuxracer)"],
         "Programs": ["SecurePoint"],
         "Bugs": ["Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-04-11",
         "AddedDate": "2023-04-15"
      },
      {
         "Links": [
            {
               "Title": "Pretalx Vulnerabilities: How to get accepted at every conference",
               "Link": "https://www.sonarsource.com/blog/pretalx-vulnerabilities-how-to-get-accepted-at-every-conference/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["Pretalx"],
         "Bugs": ["Arbitrary file read", "Arbitrary file write", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-04-11",
         "AddedDate": "2023-04-15"
      },
      {
         "Links": [
            {
               "Title": "Shell in the Ghost: Ghostscript CVE-2023-28879 writeup",
               "Link": "https://offsec.almond.consulting/ghostscript-cve-2023-28879.html"
            }
         ],
         "Authors": ["sigabrt9 (@sigabrt9)"],
         "Programs": ["Artifex Ghostscript"],
         "Bugs": ["Buffer Overflow", "Memory corruption", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-04-11",
         "AddedDate": "2023-04-15"
      },
      {
         "Links": [
            {
               "Title": "From listKeys to Glory: How We Achieved a Subscription Privilege Escalation and RCE by Abusing Azure Storage Account Keys",
               "Link": "https://orca.security/resources/blog/azure-shared-key-authorization-exploitation/"
            }
         ],
         "Authors": ["Roi Nisimi (@roinisimi)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-04-11",
         "AddedDate": "2023-04-15"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-1767 - Stored XSS on Snyk Advisor service can allow full fabrication of npm packages health score",
               "Link": "https://weizman.github.io/2023/04/10/snyk-xss/"
            }
         ],
         "Authors": ["Gal Weizman (@WeizmanGal)"],
         "Programs": ["Snyk"],
         "Bugs": ["Stored XSS", "Markdown XSS", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2023-04-10",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories",
               "Link": "https://blog.nietaanraken.nl/posts/aur-packages-github-repo-jacking/"
            }
         ],
         "Authors": ["Joren Vrancken"],
         "Programs": ["-"],
         "Bugs": ["Repojacking", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2023-04-10",
         "AddedDate": "2023-04-29"
      },
      {
         "Links": [
            {
               "Title": "Account Take Over (Via an API)",
               "Link": "https://medium.com/@thabisomokoena/account-take-over-via-an-api-2eea4fe49532"
            }
         ],
         "Authors": ["Thabiso Mokoena"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Information disclosure", "Broken Access Control", "Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2023-04-10",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "A successful prototype pollution chained to a DOM XSS",
               "Link": "https://medium.com/@zhero_/a-successful-prototype-pollution-chained-to-a-dom-xss-9887087b56a4"
            }
         ],
         "Authors": ["Allam Rachid (@blank_cold)"],
         "Programs": ["-"],
         "Bugs": ["Prototype pollution", "DOM XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-04-10",
         "AddedDate": "2023-04-15"
      },
      {
         "Links": [
            {
               "Title": "How I was able to change password of any corporate user",
               "Link": "https://medium.com/@ch3tanbug/how-i-was-able-to-change-password-of-any-corporate-user-c68b9509840"
            }
         ],
         "Authors": ["CH3TAN"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Password reset", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-04-09",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "Steal authentication token with one-click on misconfigured WebView.",
               "Link": "https://0xwise.medium.com/are-clicking-links-safe-f7cfcae2e421"
            }
         ],
         "Authors": ["Kerolos A. Saber (@0xWise)"],
         "Programs": ["-"],
         "Bugs": ["Android", "Webview", "Account takeover"],
         "Bounty": "3,000",
         "PublicationDate": "2023-04-08",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "SQL Wildcard DoS - Hang Till Death",
               "Link": "https://shahjerry33.medium.com/sql-wildcard-dos-hang-till-death-adbae66d1f7b"
            }
         ],
         "Authors": ["Jerry Shah (@Jerry)"],
         "Programs": ["-"],
         "Bugs": ["DoS", "File upload"],
         "Bounty": "-",
         "PublicationDate": "2023-04-08",
         "AddedDate": "2023-04-24"
      },
      {
         "Links": [
            {
               "Title": "Stored Cross-Site Scripting (XSS) in Zimbra version 8.8.15_GA_4059 CVE-2022-41348",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-04/Synacktiv-ZimbraConnect-CVE-2022-41348.pdf"
            }
         ],
         "Authors": ["Guillaume Jacques", "Melvil Guillaume", "Kévin Tellier"],
         "Programs": ["Zimbra"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-04-07",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-1906 - Heap-based Buffer Overflow in ImageMagick",
               "Link": "https://blog.agilehunt.com/blogs/security/cve-2023-1906-heap-based-buffer-overflow-in-imagemagick"
            }
         ],
         "Authors": ["Vikas Anil Sharma (@vikzsharma)"],
         "Programs": ["ImageMagick"],
         "Bugs": ["Heap buffer overflow", "Memory corruption", "Fuzzing"],
         "Bounty": "-",
         "PublicationDate": "2023-04-06",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "SharePoint Webpart Property Traversal Vulnerability Analysis (CVE-2022–38053, CVE-2023–21742, CVE-2023–21717)",
               "Link": "https://testbnull.medium.com/phân-t%C3%ADch-lỗ-hổng-sharepoint-webpart-property-traversal-cve-2022-38053-cve-2023-21742-bc6931698a5f"
            }
         ],
         "Authors": ["Nguyễn Tiến Giang (@testanull)"],
         "Programs": ["Microsoft (Sharepoint)"],
         "Bugs": ["Property traversal"],
         "Bounty": "-",
         "PublicationDate": "2023-04-06",
         "AddedDate": "2023-04-07"
      },
      {
         "Links": [
            {
               "Title": "A web security story from 2008: silently securing JSON.parse",
               "Link": "https://dev.to/mikesamuel/2008-silently-securing-jsonparse-5cbb"
            }
         ],
         "Authors": ["Mike Samuel (@mvsamuel)"],
         "Programs": ["JSON.parse"],
         "Bugs": ["Parsing issue", "XSS", "Arbitrary Code Execution"],
         "Bounty": "-",
         "PublicationDate": "2023-04-06",
         "AddedDate": "2023-04-07"
      },
      {
         "Links": [
            {
               "Title": "Escaping Adobe Sandbox: Exploiting an Integer Overflow in Microsoft Windows Crypto Provider",
               "Link": "https://blog.exodusintel.com/2023/04/06/escaping-adobe-sandbox-exploiting-an-integer-overflow-in-microsoft-windows/"
            }
         ],
         "Authors": ["Michele Campa (@s1ckb017)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Integer overflow", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-04-06",
         "AddedDate": "2023-04-07"
      },
      {
         "Links": [
            {
               "Title": "Let me Unmask my next 👻",
               "Link": "https://crypt0g30rgy.github.io/post/TinderBug"
            }
         ],
         "Authors": ["g30rgy th3 d4rk (@Crypt0g30rgy)"],
         "Programs": ["Tinder"],
         "Bugs": ["IDOR", "Payment bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-04-06",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Simple Bugs 0x02: Overwritting Uploaded Files",
               "Link": "https://vitorfalcao.com/posts/simple-bugs/overwritting-files/"
            }
         ],
         "Authors": ["Vitor Falcao (@egl_falcao)"],
         "Programs": ["-"],
         "Bugs": ["Normalization"],
         "Bounty": "-",
         "PublicationDate": "2023-04-06",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Bash Privileged-mode Vulnerabilities In Parallels Desktop And CDPATH Handling In MacOS",
               "Link": "https://www.zerodayinitiative.com/blog/2023/4/5/bash-privileged-mode-vulnerabilities-in-parallels-desktop-and-cdpath-handling-in-macos"
            }
         ],
         "Authors": ["Reno Robert (@renorobertr)"],
         "Programs": ["Parallels"],
         "Bugs": ["MacOS", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-04-06",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-1877 / RCE with Server-Side Template Injection in Microweber",
               "Link": "https://cupc4k3.medium.com/cve-2023-1877-rce-with-server-side-template-injection-in-microweber-89da6a0e2603"
            }
         ],
         "Authors": ["cupc4k3"],
         "Programs": ["Microweber"],
         "Bugs": ["SSTI", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-04-05",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Exploiting insecure exception logging",
               "Link": "https://www.invicti.com/blog/web-security/exploiting-insecure-exception-logging/"
            }
         ],
         "Authors": ["Bogdan Calin"],
         "Programs": ["-"],
         "Bugs": ["Blind XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-04-05",
         "AddedDate": "2023-04-15"
      },
      {
         "Links": [
            {
               "Title": "Discovering Headroll (CVE-2023–0704) in Chromium",
               "Link": "https://canvatechblog.com/discovering-headroll-cve-2023-0704-in-chromium-2e7f66fc130c"
            }
         ],
         "Authors": ["Rhys Elsmore (@rhyselsmore)", "Zac Sims"],
         "Programs": ["Google (Chromium)"],
         "Bugs": ["SOP bypass", "Browser hacking"],
         "Bounty": "2,000",
         "PublicationDate": "2023-04-05",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Microsoft Intune, Version 1.55.48.0 Advisory",
               "Link": "https://bishopfox.com/blog/microsoft-intune-version-1-55-48-0-advisory"
            }
         ],
         "Authors": ["Ben Lincoln (@0x00C651E0)"],
         "Programs": ["Microsoft (Intune)"],
         "Bugs": ["Unquoted search path", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-04-04",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Windows Task Scheduler Application, Version 19044.1706 Advisory",
               "Link": "https://bishopfox.com/blog/windows-task-scheduler-19044-advisory"
            }
         ],
         "Authors": ["Ben Lincoln (@0x00C651E0)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Unquoted search path", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-04-04",
         "AddedDate": "2023-05-04"
      },
      {
         "Links": [
            {
               "Title": "Post Account Takeover? Account Takeover of Internal Tesla Accounts",
               "Link": "https://medium.com/@evan.connelly/post-account-takeover-account-takeover-of-internal-tesla-accounts-bc720603e67d"
            },
            {
               "Title": "Alternative link",
               "Link": "https://evanconnelly.github.io/post/tesla-account-takeover/"
            }
         ],
         "Authors": ["Evan Connelly (@Evan_Connelly)"],
         "Programs": ["Tesla"],
         "Bugs": ["Account takeover", "SSO"],
         "Bounty": "-",
         "PublicationDate": "2023-04-04",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Amazon Kids+ Parental Controls",
               "Link": "https://www.n00py.io/2023/01/bypassing-amazon-kids-parental-controls/"
            }
         ],
         "Authors": ["n00py (@n00py1)"],
         "Programs": ["Amazon"],
         "Bugs": ["Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2023-04-04",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Pentah0wnage: Pre-Auth RCE in Pentaho Business Analytics Server",
               "Link": "https://research.aurainfosec.io/pentest/pentah0wnage/"
            }
         ],
         "Authors": ["Harry Withington"],
         "Programs": ["Hitachi Vantara (Pentaho)"],
         "Bugs": ["RCE", "SSTI", "Authorization bypass", "Groovy scripting"],
         "Bounty": "-",
         "PublicationDate": "2023-04-04",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Holiday Hunting With Aquatone",
               "Link": "https://kuldeep.io/posts/holiday-hunting-with-aquatone/"
            }
         ],
         "Authors": ["Kuldeep Pandya (@kuldeepdotexe)"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "Missing authentication", "Information disclosure"],
         "Bounty": "3,605",
         "PublicationDate": "2023-04-03",
         "AddedDate": "2023-04-10"
      },
      {
         "Links": [
            {
               "Title": "CyberGhostVPN - the story of finding MITM, RCE, LPE in the Linux client",
               "Link": "https://mmmds.pl/cyberghostvpn-mitm-rce-lpe/"
            }
         ],
         "Authors": ["mmmds"],
         "Programs": ["CyberGhost"],
         "Bugs": ["RCE", "MiTM", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-04-03",
         "AddedDate": "2023-04-07"
      },
      {
         "Links": [
            {
               "Title": "Blind XSS via SMS Support Chat — $1100 Bug Bounty!",
               "Link": "https://chevonphillip.medium.com/blind-xss-via-sms-support-chat-1100-bug-bounty-779a1e19cc51"
            }
         ],
         "Authors": ["Chevon Phillip (@ChevonPhillip)"],
         "Programs": ["-"],
         "Bugs": ["Blind XSS", "Chatbot"],
         "Bounty": "1,100",
         "PublicationDate": "2023-04-03",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Simple Bugs 0x01: Password Changing to Account Takeover!",
               "Link": "https://vitorfalcao.com/posts/simple-bugs/password-changing-to-ato/"
            }
         ],
         "Authors": ["Vitor Falcao (@egl_falcao)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "CSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-04-03",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Two Minor Cross-Tenant Vulnerabilities in AWS App Runner",
               "Link": "https://frichetten.com/blog/minor-cross-tenant-vulns-app-runner/"
            }
         ],
         "Authors": ["Nick Frichette (@frichette_n)"],
         "Programs": ["AWS"],
         "Bugs": ["Cross-tenant vulnerability", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-04-03",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Lenovo database of root user credentials exposed",
               "Link": "https://medium.com/@prakashchand72/lenovo-database-of-root-user-credentials-exposed-22aab5382c"
            }
         ],
         "Authors": ["ASTUTE"],
         "Programs": ["Lenovo"],
         "Bugs": [".git folder disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-04-03",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Let’s Hack Citizens Bank",
               "Link": "https://infosecwriteups.com/lets-hacking-citizens-bank-9520e9c05cf9"
            }
         ],
         "Authors": ["Arman (@M7arm4n)"],
         "Programs": ["Citizens Bank"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-04-03",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Bug Bounty: como encontrei o bug Unrestricted File Upload",
               "Link": "https://medium.com/@paulo_mota/bug-bounty-como-encontrei-o-bug-unrestricted-file-upload-dd1a61adc9fd"
            }
         ],
         "Authors": ["Paulo Mota"],
         "Programs": ["-"],
         "Bugs": ["Unrestricted file upload"],
         "Bounty": "100",
         "PublicationDate": "2023-04-02",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Finding RCE in NodeJS templating engine 'Eta' - CVE-2022-25967",
               "Link": "https://rayhan0x01.github.io/ctf/2023/04/01/finding-rce-in-eta-cve-2022-25967.html"
            }
         ],
         "Authors": ["Rayhan Ahmed Niloy (@Rayhan0x01)"],
         "Programs": ["Eta"],
         "Bugs": ["RCE", "Server-side prototype pollution", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-04-01",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Beware of Java's String.getBytes",
               "Link": "https://www.reversemode.com/2023/03/beware-of-javas-stringgetbytes.html"
            }
         ],
         "Authors": ["Ruben Santamarta (@reversemode)"],
         "Programs": ["Swiss E-Voting"],
         "Bugs": ["Hash collision", "Cryptographic issues", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-31",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Protected Users: you thought you were safe uh?",
               "Link": "https://sensepost.com/blog/2023/protected-users-you-thought-you-were-safe-uh/"
            }
         ],
         "Authors": ["Aurélien Chalot (@Defte_)", "Thomas SEIGNEURET (@_zblurx)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Active Directory", "Kerberos", "NTLM", "Internal pentest"],
         "Bounty": "-",
         "PublicationDate": "2023-03-31",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Unveiling the Secrets: My Journey of Hacking Google’s OSS",
               "Link": "https://7h3h4ckv157.medium.com/unveiling-the-secrets-my-journey-of-hacking-googles-oss-cdd9ef3c7aa"
            }
         ],
         "Authors": ["7𝖍3𝖍4𝖈kv157 (@7h3h4ckv157)"],
         "Programs": ["Google"],
         "Bugs": ["CSRF", "Self-XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-03-31",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Exposed Docker Registries Server as Critical Reminder on Container Security",
               "Link": "https://emad0x90.medium.com/exposed-docker-registries-server-as-critical-reminder-on-container-security-a9bba13b403d"
            }
         ],
         "Authors": ["Emad Shawky"],
         "Programs": ["-"],
         "Bugs": ["Docker Registry"],
         "Bounty": "-",
         "PublicationDate": "2023-03-31",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "From an Innocent api-key to PII data",
               "Link": "https://crypt0g30rgy.github.io/post/Journey2pII"
            }
         ],
         "Authors": ["g30rgy th3 d4rk (@Crypt0g30rgy)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "Hardcoded API keys"],
         "Bounty": "200",
         "PublicationDate": "2023-03-30",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Hibernate Injection in \"Order by\" Clause (Oracle database)",
               "Link": "https://www.mannulinux.org/2023/03/exploiting-hibernate-injection-in-order.html"
            }
         ],
         "Authors": ["Mannu Linux (@IndiShell1046)"],
         "Programs": ["-"],
         "Bugs": ["HQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-03-30",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "How to avoid the aCropalypse",
               "Link": "https://blog.trailofbits.com/2023/03/30/acropalypse-polytracker-blind-spots/"
            }
         ],
         "Authors": ["Henrik Brodin"],
         "Programs": ["Google", "Microsoft"],
         "Bugs": ["Privacy issue", "Information disclosure", "Android"],
         "Bounty": "-",
         "PublicationDate": "2023-03-30",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Super FabriXss: From XSS to an RCE in Azure Service Fabric Explorer by Abusing an Event Tab Cluster Toggle (CVE-2023-23383)",
               "Link": "https://orca.security/resources/blog/super-fabrixss-azure-vulnerability/"
            }
         ],
         "Authors": ["Lidor Ben Shitrit"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["RCE", "XSS", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-03-30",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Remote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack",
               "Link": "https://www.legitsecurity.com/blog/remote-code-execution-vulnerability-in-azure-pipelines-can-lead-to-software-supply-chain-attack"
            }
         ],
         "Authors": ["Nadav Noy"],
         "Programs": ["Microsoft (Azure DevOps Pipelines)"],
         "Bugs": ["RCE", "CI/CD", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2023-03-30",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Found SSRF and LFI in Just 10 minutes of using burp!",
               "Link": "https://xelkomy.medium.com/found-ssrf-and-lfi-in-just-10-minutes-of-using-burp-492fddef3f3e"
            }
         ],
         "Authors": ["Khaled Mohamed (@0xElkomy)"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "LFI"],
         "Bounty": "-",
         "PublicationDate": "2023-03-30",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Riding the Azure Service Bus (Relay) into Power Platform",
               "Link": "https://www.netspi.com/blog/technical/vulnerability-research/azure-service-bus-power-platform/"
            }
         ],
         "Authors": ["Nick Landers (@monoxgas)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["RCE", "Cross-tenant vulnerability", "Cloud", "Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2023-03-30",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-37734: graphql-java Denial-of-Service",
               "Link": "https://checkmarx.com/blog/cve-2022-37734-graphql-java-denial-of-service/"
            }
         ],
         "Authors": ["Artem Logutov"],
         "Programs": ["graphql-java"],
         "Bugs": ["GraphQL", "DoS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-30",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Hacking Admin Panel & Getting free subscription",
               "Link": "https://z-sec.co/hacking-admin-panel-getting-free-subscription"
            }
         ],
         "Authors": ["Zeeshan Mustafa (@by6153)"],
         "Programs": ["-"],
         "Bugs": ["Exposed registration API", "Privilege escalation", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-03-29",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "It’s a (SNMP) Trap: Gaining Code Execution on LibreNMS",
               "Link": "https://www.sonarsource.com/blog/it-s-a-snmp-trap-gaining-code-execution-on-librenms/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["LibreNMS"],
         "Bugs": ["RCE", "Stored XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-29",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "BingBang: The AAD misconfiguration that led to Bing.com results manipulation and account takeover explained",
               "Link": "https://www.wiz.io/blog/azure-active-directory-bing-misconfiguration"
            }
         ],
         "Authors": ["Hillai Ben-Sasson (@hillai)"],
         "Programs": ["Microsoft (Bing)"],
         "Bugs": ["Account takeover", "Azure AD", "Cloud", "XSS", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-03-29",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "I’d TAP That Pass",
               "Link": "https://posts.specterops.io/id-tap-that-pass-8f79fff839ac"
            }
         ],
         "Authors": ["Daniel Heinsen (@hotnops)"],
         "Programs": ["-"],
         "Bugs": ["Azure AD", "Cloud", "OAuth"],
         "Bounty": "-",
         "PublicationDate": "2023-03-29",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Attacking Android Antivirus Applications",
               "Link": "https://blog.scrt.ch/2023/03/29/attacking-android-antivirus-applications/"
            }
         ],
         "Authors": ["2Dai (@mabenz68)"],
         "Programs": ["McAfee"],
         "Bugs": ["Android", "Improper Export of Android Application Components"],
         "Bounty": "-",
         "PublicationDate": "2023-03-29",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "A short tell of LFI from PDF link → Professor the Hunter",
               "Link": "https://medium.com/@bughuntar/a-short-tell-of-lfi-from-pdf-link-professor-the-hunter-43a8be853e"
            }
         ],
         "Authors": ["Professor the Hunter (@bughuntar)"],
         "Programs": ["-"],
         "Bugs": ["LFI"],
         "Bounty": "-",
         "PublicationDate": "2023-03-29",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Attacking Visual Studio for Initial Access",
               "Link": "https://www.outflank.nl/blog/2023/03/28/attacking-visual-studio-for-initial-access/"
            }
         ],
         "Authors": ["Stan Hegt (@StanHacked)"],
         "Programs": ["Microsoft (Visual Studio)"],
         "Bugs": ["Phishing", "1-click RCE", "Watering hole attack"],
         "Bounty": "-",
         "PublicationDate": "2023-03-28",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "High severity vulnerability fixed in WordPress Elementor Pro plugin.",
               "Link": "https://blog.nintechnet.com/high-severity-vulnerability-fixed-in-wordpress-elementor-pro-plugin/"
            }
         ],
         "Authors": ["Jerome Bruandet"],
         "Programs": ["Elementor"],
         "Bugs": ["Broken Access Control", "Privilege escalation", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-28",
         "AddedDate": "2023-05-15"
      },
      {
         "Links": [
            {
               "Title": "The curl quirk that exposed Burp Suite & Google Chrome",
               "Link": "https://portswigger.net/research/the-curl-quirk-that-exposed-burp-suite-amp-google-chrome"
            }
         ],
         "Authors": ["Paul Mutton (@paulmutton)"],
         "Programs": ["PortSwigger", "Google (Chrome)"],
         "Bugs": ["LFI"],
         "Bounty": "-",
         "PublicationDate": "2023-03-28",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Dynamic Linking Injection and LOLBAS Fun",
               "Link": "https://www.praetorian.com/blog/dynamic-linking-injection/"
            }
         ],
         "Authors": ["Joseph Henry"],
         "Programs": ["-"],
         "Bugs": ["DLL Hijacking", "Dynamic-linking injection", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-03-28",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "My First Bug, Open redirect at Epic Games → $500 Bounty",
               "Link": "https://medium.com/@bughuntar/my-first-bug-open-redirect-at-epic-games-500-bounty-d0c03de60fa7"
            }
         ],
         "Authors": ["Professor the Hunter (@bughuntar)"],
         "Programs": ["Epic Games"],
         "Bugs": ["Open redirect"],
         "Bounty": "500",
         "PublicationDate": "2023-03-27",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Using an Undocumented Amplify API to Leak AWS Account IDs",
               "Link": "https://frichetten.com/blog/undocumented-amplify-api-leak-account-id/"
            }
         ],
         "Authors": ["Nick Frichette (@frichette_n)"],
         "Programs": ["AWS"],
         "Bugs": ["Cloud", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-03-27",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "My Journey to Nokia Hall of Fame in just 10 minutes",
               "Link": "https://medium.com/@rajdipdeysarkar7/my-journey-to-nokia-hall-of-fame-in-just-10-minutes-4869c78c37e7"
            }
         ],
         "Authors": ["Rajdip"],
         "Programs": ["Nokia"],
         "Bugs": ["DOM XSS", "Open redirect"],
         "Bounty": "-",
         "PublicationDate": "2023-03-27",
         "AddedDate": "2023-03-28"
      },
      {
         "Links": [
            {
               "Title": "How I escalated default credentials to Remote Code Execution",
               "Link": "https://pawanchhabria.medium.com/how-i-escalated-default-credentials-to-remote-code-execution-1c34504be7a5"
            }
         ],
         "Authors": ["Pawan Chhabria (@heybenchmarkkk)"],
         "Programs": ["-"],
         "Bugs": ["Default credentials", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-03-26",
         "AddedDate": "2023-03-28"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023–1410 : Stored XSS in the Graphite Function Description tooltip",
               "Link": "https://infosecwriteups.com/cve-2023-1410-stored-xss-in-the-graphite-function-description-tooltip-165bdc32154c"
            }
         ],
         "Authors": ["Aswin K V (@deep_marketer_)"],
         "Programs": ["Grafana Labs"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-03-25",
         "AddedDate": "2023-03-28"
      },
      {
         "Links": [
            {
               "Title": "Hacking AI: System and Cloud Takeover via MLflow Exploit",
               "Link": "https://protectai.com/blog/hacking-ai-system-takeover-exploit-in-mlflow"
            }
         ],
         "Authors": ["Dan McInerney (@DanHMcInerney)"],
         "Programs": ["MLflow"],
         "Bugs": ["LFI", "RFI", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-03-25",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Joomla! CVE-2023-23752 to Code Execution",
               "Link": "https://vulncheck.com/blog/joomla-for-rce"
            }
         ],
         "Authors": ["Jacob Baines (@Junior_Baines)"],
         "Programs": ["Joomla!"],
         "Bugs": ["Broken Access Control", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-03-23",
         "AddedDate": "2023-03-31"
      },
      {
         "Links": [
            {
               "Title": "Exploiting prototype pollution in Node without the filesystem",
               "Link": "https://portswigger.net/research/exploiting-prototype-pollution-in-node-without-the-filesystem"
            }
         ],
         "Authors": ["Gareth Heyes (@garethheyes)"],
         "Programs": ["-"],
         "Bugs": ["Server-side prototype pollution", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-03-23",
         "AddedDate": "2023-03-28"
      },
      {
         "Links": [
            {
               "Title": "Escalating Privileges with Azure Function Apps",
               "Link": "https://www.netspi.com/blog/technical/cloud-penetration-testing/azure-function-apps/"
            }
         ],
         "Authors": ["Karl Fosaaen (@kfosaaen)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Privilege escalation", "Cloud", "Container escape", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-03-23",
         "AddedDate": "2023-03-28"
      },
      {
         "Links": [
            {
               "Title": "Finding Initial Access on a real life Penetration Test",
               "Link": "https://medium.com/@warrenbutterworth/finding-initial-access-on-a-real-life-penetration-test-86ed5503ae48"
            }
         ],
         "Authors": ["Warren Butterworth (@w88ugs)"],
         "Programs": ["-"],
         "Bugs": ["Old components with known vulnerabilities", "Internal pentest", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-03-23",
         "AddedDate": "2023-03-28"
      },
      {
         "Links": [
            {
               "Title": "Story of a Beautiful Account Takeover.",
               "Link": "https://medium.com/@ambushneupane4/story-of-a-beautiful-account-takeover-869ef61ac6c8"
            }
         ],
         "Authors": ["Ambush Neupane (@N_ambush)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "OTP bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-23",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Getting Root - A Technical Walkthrough",
               "Link": "https://occamsec.com/getting-root-a-technical-walkthrough/"
            }
         ],
         "Authors": ["OccamSec (@occamsec)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "LFI", "RCE", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-03-22",
         "AddedDate": "2023-06-27"
      },
      {
         "Links": [
            {
               "Title": "Expression DoS Vulnerability Found In Spring - CVE-2023-20861",
               "Link": "https://www.code-intelligence.com/blog/expression-dos-spring"
            }
         ],
         "Authors": ["Dan Glendowne"],
         "Programs": ["Spring"],
         "Bugs": ["DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-03-22",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Improper Privilege Management in Grails Spring Security Core <= 5.1.0 (CVE-2022-41923)",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-03/Synacktiv-Grails-Spring-Security-CVE-2022-41923.pdf"
            }
         ],
         "Authors": ["Benjamin Sepe (@Butanal_C4H8O)", "Adrien Peter (@Taryax)"],
         "Programs": ["Grails"],
         "Bugs": ["Privilege escalation", "Authorization bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-21",
         "AddedDate": "2023-03-28"
      },
      {
         "Links": [
            {
               "Title": "PHP Filter Chains: File Read From Error-based Oracle",
               "Link": "https://www.synacktiv.com/publications/php-filter-chains-file-read-from-error-based-oraclel"
            }
         ],
         "Authors": ["Rémi Matasse (@_remsio_)"],
         "Programs": ["-"],
         "Bugs": ["Arbitrary file read", "LFI", "PHP filter chain"],
         "Bounty": "-",
         "PublicationDate": "2023-03-21",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Windows Installer EOP (CVE-2023-21800)",
               "Link": "https://blog.doyensec.com//2023/03/21/windows-installer.html"
            }
         ],
         "Authors": ["Adrian Denkiewicz"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-03-21",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "How I got access to Essilor International company customer PII INFO by AWS metadata access through SSRF",
               "Link": "https://notifybugme.medium.com/how-i-got-access-to-essilor-international-company-customer-pii-info-by-aws-metadata-access-through-3da02f4c79f0"
            }
         ],
         "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-03-21",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Bypassing CloudTrail in AWS Service Catalog, and Other Logging Research",
               "Link": "https://securitylabs.datadoghq.com/articles/bypass-cloudtrail-aws-service-catalog-and-other/"
            }
         ],
         "Authors": ["Nick Frichette (@frichette_n)"],
         "Programs": ["AWS"],
         "Bugs": ["Cloud", "CloudTrail bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-20",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Parallels Desktop Toolgate Vulnerability",
               "Link": "https://blog.impalabs.com/2303_advisory_parallels-desktop_toolgate.html"
            }
         ],
         "Authors": ["Alexandre Adamski (@NeatMonster_)"],
         "Programs": ["Parallels"],
         "Bugs": ["Path traversal", "Arbitrary file write", "Security code review", "Thick client"],
         "Bounty": "-",
         "PublicationDate": "2023-03-20",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Credit card statement disclosure vulnerability in Viseca's eXpense portal",
               "Link": "https://www.pentagrid.ch/de/blog/viseca-expense-credit-card-statement-disclosure/"
            }
         ],
         "Authors": ["Pentagrid (@pentagridsec)"],
         "Programs": ["Viseca"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-03-20",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "JMX Exploitation Revisited",
               "Link": "https://codewhitesec.blogspot.com/2023/03/jmx-exploitation-revisited.html"
            }
         ],
         "Authors": ["Markus Wulftange (@mwulftange)", "Tobias Neitzel (@qtc_de)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "JMX"],
         "Bounty": "-",
         "PublicationDate": "2023-03-20",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "SSTI leads to RCE on PyroCMS",
               "Link": "https://cupc4k3.lol/ssti-leads-to-rce-on-pyrocms-7515be27c811"
            }
         ],
         "Authors": ["cupc4k3"],
         "Programs": ["PyroCMS"],
         "Bugs": ["SSTI", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-03-20",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Exploiting aCropalypse: Recovering Truncated PNGs",
               "Link": "https://www.da.vidbuchanan.co.uk/blog/exploiting-acropalypse.html"
            }
         ],
         "Authors": ["David Buchanan (@David3141593)"],
         "Programs": ["Google"],
         "Bugs": ["Privacy issue", "Information disclosure", "Android"],
         "Bounty": "-",
         "PublicationDate": "2023-03-18",
         "AddedDate": "2023-04-06"
      },
      {
         "Links": [
            {
               "Title": "Easy $$$ via API params manipulation leading to bypassing the email verification block",
               "Link": "https://medium.com/@bag0zathev2/easy-via-api-params-manipulation-leading-to-bypassing-the-email-verification-block-a45dad2db60c"
            }
         ],
         "Authors": ["Fares Walid (@SirBagoza)"],
         "Programs": ["-"],
         "Bugs": ["Mass assignment", "Email verification bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-18",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover with rate limit bypass",
               "Link": "https://medium.com/@shamimahamed666070/account-takeover-with-rate-limit-bypass-f28c5089a1eb"
            }
         ],
         "Authors": ["Shamim Ahamed (@itm4n)"],
         "Programs": ["-"],
         "Bugs": ["Rate limiting bypass", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-03-18",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "OpenSIPS Security Audit Report is fully disclosed and out there",
               "Link": "https://www.rtcsec.com/post/2023/03/opensips-security-audit-report/"
            }
         ],
         "Authors": ["Sandro Gauci (@sandrogauci)"],
         "Programs": ["OpenSIPS", "Kamailio"],
         "Bugs": ["SIP", "Memory corruption", "Memory leak", "Buffer Overflow", "Buffer over-read"],
         "Bounty": "-",
         "PublicationDate": "2023-03-17",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Remote code execution in BIRT Viewer ≤ 4.12.0 (CVE-2023-0100)",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-03/Synacktiv-BIRTViewer-CVE-2023-0100_1.pdf"
            }
         ],
         "Authors": ["Louis Wolfers (@TG91aXMK)"],
         "Programs": ["Eclipse Foundation"],
         "Bugs": ["RCE", "RFI", "URL validation bypass", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-17",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Bypassing PPL in Userland (again)",
               "Link": "https://blog.scrt.ch/2023/03/17/bypassing-ppl-in-userland-again/"
            }
         ],
         "Authors": ["Clément Labro (@itm4n)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Kernel hacking", "PPL bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-17",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Directory Traversal and LFI worth $400",
               "Link": "https://medium.com/@hritkmjth/directory-traversal-and-lfi-worth-400-c4422785d3bd"
            }
         ],
         "Authors": ["Hritik Thapa"],
         "Programs": ["-"],
         "Bugs": ["Path traversal"],
         "Bounty": "400",
         "PublicationDate": "2023-03-17",
         "AddedDate": "2023-03-18"
      },
      {
         "Links": [
            {
               "Title": "Anatomy of a Reflected XSS: My Discovery on a Microsoft’s Subdomain",
               "Link": "https://infosecwriteups.com/anatomy-of-a-reflected-xss-my-discovery-on-a-microsofts-subdomain-7a237aba4392"
            }
         ],
         "Authors": ["Sawrav Chowdhury"],
         "Programs": ["Microsoft"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-03-17",
         "AddedDate": "2023-03-18"
      },
      {
         "Links": [
            {
               "Title": "How I chained multiple High-impact vulnerabilities to create a critical one.",
               "Link": "https://princej-76.medium.com/how-i-chained-multiple-high-impact-vulnearbilities-to-create-a-critical-one-476950a3bb9f"
            }
         ],
         "Authors": ["Vinay Jagetiya (@princej_76)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "IDOR", "OTP bypass", "HTTP response manipulation"],
         "Bounty": "-",
         "PublicationDate": "2023-03-17",
         "AddedDate": "2023-03-18"
      },
      {
         "Links": [
            {
               "Title": "SSRF Cross Protocol Redirect Bypass",
               "Link": "https://blog.doyensec.com/2023/03/16/ssrf-remediation-bypass.html"
            }
         ],
         "Authors": ["Szymon Drosdzol"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-03-16",
         "AddedDate": "2023-03-21"
      },
      {
         "Links": [
            {
               "Title": "Facebook Creator Studio Misconfiguration $$$$",
               "Link": "https://medium.com/@abdulparkar9554/facebook-creator-studio-misconfiguration-348b0ee38c31"
            }
         ],
         "Authors": ["Abdul Rehman Parkar"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["Session expiration issue"],
         "Bounty": "-",
         "PublicationDate": "2023-03-16",
         "AddedDate": "2023-03-18"
      },
      {
         "Links": [
            {
               "Title": "CHECKMATE",
               "Link": "https://research.checkpoint.com/2023/checkmate/"
            }
         ],
         "Authors": ["Oded Vaanunu", "Roman Zaikin (@R0m4nZ41k1n)", "Dan Lasker"],
         "Programs": ["Chess.com"],
         "Bugs": ["Websockets", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2023-03-16",
         "AddedDate": "2023-03-18"
      },
      {
         "Links": [
            {
               "Title": "OAuth 2.0 Authentication Misconfiguration",
               "Link": "https://medium.com/@minometidji/oauth-authentication-misconfiguration-cb43c3b3ec24"
            }
         ],
         "Authors": ["Mohamed Lakhdar Metidji (@minometidjii)"],
         "Programs": ["-"],
         "Bugs": ["OAuth", "Account takeover", "Open redirect", "Token leak"],
         "Bounty": "-",
         "PublicationDate": "2023-03-16",
         "AddedDate": "2023-03-18"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Character Limit - XSS Using Spanned Payload",
               "Link": "https://infosecwriteups.com/bypassing-character-limit-xss-using-spanned-payload-7301ffac226e"
            }
         ],
         "Authors": ["SMHTahsin33 (@SMHTahsin33)"],
         "Programs": ["-"],
         "Bugs": ["XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-03-15",
         "AddedDate": "2023-03-16"
      },
      {
         "Links": [
            {
               "Title": "Emotional Rollercoaster: A Unique Case Study of Bypassing Antivirus and Firewall by Abusing PostgreSQL",
               "Link": "https://medium.com/@yousefamery/emotional-rollercoaster-a-unique-case-study-of-bypassing-antivirus-and-firewall-by-abusing-2b36d8f6553c"
            }
         ],
         "Authors": ["Yousef Amery (@YousefAmery)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Old components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2023-03-15",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "LFI - An Interesting Tweak",
               "Link": "https://shahjerry33.medium.com/lfi-an-interesting-tweak-9c5638dbdd1b"
            }
         ],
         "Authors": ["Jerry Shah (@Jerry)"],
         "Programs": ["-"],
         "Bugs": ["LFI"],
         "Bounty": "-",
         "PublicationDate": "2023-03-15",
         "AddedDate": "2023-03-15"
      },      
      {
         "Links": [
            {
               "Title": "IP spoofing and SQL injection in Textcube",
               "Link": "https://www.sjoerdlangkemper.nl/2023/03/15/textcube-sql-injection-session-ip-spoofing/"
            }
         ],
         "Authors": ["Sjoerd Langkemper"],
         "Programs": ["Textcube"],
         "Bugs": ["SQL injection", "IP spoofing", "HTTP header attack", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-15",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Backend Parameter Injection --> RCE",
               "Link": "http://blog.sysdum.net/parameter-injection-to-rce"
            }
         ],
         "Authors": ["Austin (@systemdumb)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "HTTP parameter pollution", "OS command injection"],
         "Bounty": "-",
         "PublicationDate": "2023-03-14",
         "AddedDate": "2023-06-13"
      },
      {
         "Links": [
            {
               "Title": "AD Security Research: Breaking Trust Transitivity",
               "Link": "https://www.semperis.com/blog/ad-security-research-breaking-trust-transitivity/"
            },
            {
               "Title": "External Trusts Are Evil",
               "Link": "https://exploit.ph/external-trusts-are-evil.html"
            }
         ],
         "Authors": ["Charlie Clark (@exploitph)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Active Directory Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-03-14",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Finding Hundreds of SSRF Vulnerabilities on AWS",
               "Link": "https://trickest.com/blog/hundreds-of-ssrfs/"
            }
         ],
         "Authors": ["Carlos Polop"],
         "Programs": ["AWS"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-03-14",
         "AddedDate": "2023-03-16"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023–24625 / IDOR in Faveo Service Desk",
               "Link": "https://cupc4k3.lol/cve-2023-24625-idor-in-faveo-service-desk-37a63f53d896"
            }
         ],
         "Authors": ["cupc4k3"],
         "Programs": ["Faveo"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-03-14",
         "AddedDate": "2023-03-16"
      },
      {
         "Links": [
            {
               "Title": "Producing a POC for CVE-2022-42475 (Fortinet RCE)",
               "Link": "https://blog.scrt.ch/2023/03/14/producing-a-poc-for-cve-2022-42475-fortinet-rce/"
            }
         ],
         "Authors": ["Alain Mowat (@plopz0r)"],
         "Programs": ["Fortinet"],
         "Bugs": ["Memory corruption", "RCE", "Integer overflow", "Heap overflow"],
         "Bounty": "-",
         "PublicationDate": "2023-03-14",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Vulnerabilities in the TPM 2.0 reference implementation code",
               "Link": "https://blog.quarkslab.com/vulnerabilities-in-the-tpm-20-reference-implementation-code.html"
            }
         ],
         "Authors": ["Francisco Falcon (@fdfalcon)"],
         "Programs": ["Microsoft", "VMware", "Google", "IBM", "Lenovo", "Qemu", "Nuvoton", "Trusted Computing Group", "STMicroelectronics", "Aruba Networks", "CERT/CC", "libtpms"],
         "Bugs": ["Memory corruption", "Out-of-bounds Read", "Out-of-bounds Write"],
         "Bounty": "20,000",
         "PublicationDate": "2023-03-14",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability",
               "Link": "https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/"
            }
         ],
         "Authors": ["Dominic Chell (@domchell)"],
         "Programs": ["Microsoft (Outlook)"],
         "Bugs": ["Privilege escalation", "NTLM"],
         "Bounty": "-",
         "PublicationDate": "2023-03-14",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Your Browser is Not a Safe Space",
               "Link": "https://www.blackhillsinfosec.com/your-browser-is-not-a-safe-space/"
            }
         ],
         "Authors": ["Corey Ham"],
         "Programs": ["-"],
         "Bugs": ["Local Privilege Escalation", "Lateral movement"],
         "Bounty": "-",
         "PublicationDate": "2023-03-14",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Hacking the Docker Registry with Burp Suite",
               "Link": "https://medium.com/@H1Xploit/hacking-the-docker-registry-with-burp-suite-18112cbfb6dd"
            }
         ],
         "Authors": ["H1Xploit (@H1Xploit)"],
         "Programs": ["-"],
         "Bugs": ["Docker Registry"],
         "Bounty": "-",
         "PublicationDate": "2023-03-14",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Microsoft Defender for Cloud Management Port Exposure Confusion",
               "Link": "https://www.rapid7.com/blog/post/2023/03/14/microsoft-defender-for-cloud-management-port-exposure-confusion/"
            }
         ],
         "Authors": ["Aaron Sawitsky"],
         "Programs": ["Microsoft"],
         "Bugs": ["Cloud", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-03-14",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Veeam Backup and Replication CVE-2023-27532 Deep Dive",
               "Link": "https://www.horizon3.ai/veeam-backup-and-replication-cve-2023-27532-deep-dive/"
            }
         ],
         "Authors": ["James Horseman (@JamesHorseman2)"],
         "Programs": ["Veeam"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-03-13",
         "AddedDate": "2023-03-28"
      },
      {
         "Links": [
            {
               "Title": "The Time I Hacked Google’s Manual Actions Database",
               "Link": "https://www.tomanthony.co.uk/blog/googles-manual-actions-hack/"
            }
         ],
         "Authors": ["Tom Anthony (@TomAnthonySEO)"],
         "Programs": ["Google"],
         "Bugs": ["Broken Access Control", "Broken authorization"],
         "Bounty": "5,000",
         "PublicationDate": "2023-03-13",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "How I Leak Other’s Access Token by Exploiting Evil Deeplink Flaw",
               "Link": "https://infosecwriteups.com/how-i-leak-others-access-token-by-exploiting-evil-deeplink-flaw-a0a566677639"
            }
         ],
         "Authors": ["Crisdeo Nuel Siahaan"],
         "Programs": ["-"],
         "Bugs": ["Insecure deeplink", "Android", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-03-13",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Dolibarr : unauthenticated contacts database theft",
               "Link": "https://www.dsecbypass.com/en/dolibarr-pre-auth-contact-database-dump/"
            }
         ],
         "Authors": ["Vladimir"],
         "Programs": ["Dolibarr"],
         "Bugs": ["SQL injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-13",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "P1 Vulnerability by Bypassing the membership payment page",
               "Link": "https://medium.com/@mares.viktor/p1-vulnerability-by-bypassing-the-membership-payment-page-3289e09262c1"
            }
         ],
         "Authors": ["Viktor Mares"],
         "Programs": ["-"],
         "Bugs": ["Payment bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-12",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "The story of how I was able to chain SSRF with Command Injection Vulnerability",
               "Link": "https://medium.com/@rajqureshi07/the-story-of-how-i-was-able-to-chain-ssrf-with-command-injection-vulnerability-ef31feb30ea9"
            }
         ],
         "Authors": ["Raj Qureshi (@RajQureshi9)"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "OS command injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-03-12",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "CCAI",
               "Link": "https://ndevtk.github.io/writeups/2023/03/11/ccai/"
            }
         ],
         "Authors": ["NDevTK (@ndevtk)"],
         "Programs": ["Google"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-03-11",
         "AddedDate": "2023-06-12"
      },
      {
         "Links": [
            {
               "Title": "[Netflix][Smart TV] — Chaining Self-XSS with Session poisoning.",
               "Link": "https://ltsirkov.medium.com/netflix-smart-tv-chaining-self-xss-with-session-poisoning-3eb7c78c7914"
            }
         ],
         "Authors": ["Lyubomir Tsirkov (@lyubo_tsirkov)"],
         "Programs": ["Netflix"],
         "Bugs": ["Self-XSS", "Cookie injection", "Session management issue"],
         "Bounty": "-",
         "PublicationDate": "2023-03-11",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover: An Epic Bug Bounty Story",
               "Link": "https://infosecwriteups.com/account-takeover-an-epic-bug-bounty-story-dd5468d5773d"
            }
         ],
         "Authors": ["Jaydev Ahire (@cybor_j)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Self-XSS", "Pre-account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-03-11",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-36413 Unauthorized Reset Password of Zoho ManageEngine ADSelfService Plus",
               "Link": "https://noahblog.360.cn/cve-2022-36413-unauthorized-reset-password-of-zoho-manageengine-adselfservice-plus/"
            }
         ],
         "Authors": ["Sky"],
         "Programs": ["Zoho (ManageEngine)"],
         "Bugs": ["Password reset", "OTP bruteforce", "Account takeover", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-10",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Bugging Out: My Experience of Earning $300 for Reporting an Unexpected Bug",
               "Link": "https://medium.com/@thelinuxboy/bugging-out-my-experience-of-earning-300-for-reporting-an-unexpected-bug-ec9f9b0054bc"
            }
         ],
         "Authors": ["Charlie : The Hacker"],
         "Programs": ["-"],
         "Bugs": ["Subdomain takeover"],
         "Bounty": "300",
         "PublicationDate": "2023-03-10",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "Improper Authentication in Android App",
               "Link": "https://medium.com/@oXnoOneXo/improper-authentication-in-android-app-aa855227e6f1"
            }
         ],
         "Authors": ["oXnoOneXo"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw", "Broken authentication", "HTTP response manipulation"],
         "Bounty": "-",
         "PublicationDate": "2023-03-10",
         "AddedDate": "2023-03-21"
      },
      {
         "Links": [
            {
               "Title": "Default Credentials on Sony- Swag Time",
               "Link": "https://m7arm4n.medium.com/default-credentials-on-sony-swag-time-8e35681ad39e"
            }
         ],
         "Authors": ["Arman (@M7arm4n)"],
         "Programs": ["Sony"],
         "Bugs": ["Hardcoded credentials", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-03-10",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Rxss inside href attribute - Bypassing lots of weird checks to takeover accounts!",
               "Link": "https://infosecwriteups.com/rxss-inside-href-attribute-bypassing-lots-of-weird-checks-to-takeover-accounts-b4c8b4e70877"
            }
         ],
         "Authors": ["Ashutosh Dutta (@maniacmarvel_)"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS", "WAF bypass"],
         "Bounty": "2,000",
         "PublicationDate": "2023-03-10",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "I Earned $3500 and 40 Points for A GraphQL Blind SQL Injection Vulnerability.",
               "Link": "https://nav1n.medium.com/i-earned-3500-and-40-points-for-a-graphql-blind-sql-injection-vulnerability-5b7e428c477d"
            }
         ],
         "Authors": ["nav1n (@nav1n0x)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "GraphQL"],
         "Bounty": "3,500",
         "PublicationDate": "2023-03-10",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Clipchamp ( Microsoft Office Product) - Google IAP Authorization bypass allowed access to Internal Environment Leading to Zero Interaction Account takeover",
               "Link": "https://blog.agilehunt.com/blogs/security/msrc-critical-google-iap-authorization-bypass-allows-access-to-internal-envirnment-leading-to-zero-interaction-account-takeover"
            }
         ],
         "Authors": ["Vikas Anil Sharma (@vikzsharma)"],
         "Programs": ["Microsoft (ClipChamp)"],
         "Bugs": ["Authorization bypass", "JWT", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-03-10",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "Wait Time Bypass for fun and Profit",
               "Link": "https://vijetareigns.medium.com/wait-time-bypass-for-fun-and-profit-c3837e6bb8ed"
            }
         ],
         "Authors": ["the_unluck_guy (@7he_unlucky_guy)"],
         "Programs": ["Automattic"],
         "Bugs": ["Rate limiting bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-10",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "Deanonymizing OpenSea NFT Owners via Cross-Site Search Vulnerability",
               "Link": "https://www.imperva.com/blog/deanonymizing-opensea-nft-owners-via-xs-leaks-vulnerability/"
            }
         ],
         "Authors": ["Ron Masas (@RonMasas)"],
         "Programs": ["OpenSea"],
         "Bugs": ["XS-Search"],
         "Bounty": "-",
         "PublicationDate": "2023-03-09",
         "AddedDate": "2024-07-15"
      },
      {
         "Links": [
            {
               "Title": "Leveraging ssh-keygen for Arbitrary Execution (and Privilege Escalation)",
               "Link": "https://seanpesce.blogspot.com/2023/03/leveraging-ssh-keygen-for-arbitrary.html"
            }
         ],
         "Authors": ["Sean Pesce (@SeanPesce)"],
         "Programs": ["-"],
         "Bugs": ["Local Privilege Escalation", "IoT"],
         "Bounty": "-",
         "PublicationDate": "2023-03-09",
         "AddedDate": "2023-03-23"
      },
      {
         "Links": [
            {
               "Title": "EJS - Server Side Prototype Pollution gadgets to RCE",
               "Link": "https://mizu.re/post/ejs-server-side-prototype-pollution-gadgets-to-rce"
            }
         ],
         "Authors": ["Mizu (@kevin_mizu)"],
         "Programs": ["Node.js third-party modules (EJS)"],
         "Bugs": ["Server-side prototype pollution", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-09",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "The Silent Spy Among Us: Modern Attacks Against Smart Intercoms",
               "Link": "https://claroty.com/team82/research/the-silent-spy-among-us-modern-attacks-against-smart-intercoms"
            }
         ],
         "Authors": ["Claroty's Team82 (@Claroty)"],
         "Programs": ["Akuvox"],
         "Bugs": ["IoT", "OS command injection", "Missing authentication", "MiTM", "SIP"],
         "Bounty": "-",
         "PublicationDate": "2023-03-09",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "Self XSS To Stored Through IDOR/",
               "Link": "https://arben.sh/bugbounty/SelfXSS-To-Stored-Through-IDOR/"
            }
         ],
         "Authors": ["Arben Shala (@arbennsh)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Self-XSS", "Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-03-08",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "CorePlague: Severe Vulnerabilities in Jenkins Server Lead to RCE",
               "Link": "https://blog.aquasec.com/jenkins-server-vulnerabilities"
            }
         ],
         "Authors": ["Ilay Goldman (@GoldmanIlay)", "Yakir Kadkoda"],
         "Programs": ["Jenkins"],
         "Bugs": ["RCE", "XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-08",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "How I got Owned A Multi-Billion Dollar Retailer’s MySQL Databases Using Simple SQL Injection",
               "Link": "https://nav1n.medium.com/how-i-got-owned-a-multi-billion-dollar-retailers-mysql-databases-using-simple-sql-injection-30f8b0dfd9ce"
            }
         ],
         "Authors": ["nav1n (@nav1n0x)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-03-08",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749",
               "Link": "https://mahaloz.re/2023/02/25/pwnagent-netgear.html"
            }
         ],
         "Authors": ["Zion Basque (@mahal0z)", "Wil Gibbs (@cl4sm)"],
         "Programs": ["Netgear"],
         "Bugs": ["RCE", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-08",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "The story of becoming a Super Admin",
               "Link": "https://medium.com/@omerkepenek/the-story-of-becoming-a-super-admin-ab32db7dd1b3"
            }
         ],
         "Authors": ["Ömer Kepenek (@omer_kepenek)"],
         "Programs": ["-"],
         "Bugs": ["Hardcoded credentials", "Account takeover", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-03-08",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Subdomain Takeover: How a Misconfigured DNS Record Could Lead to a Huge Supply Chain Attack",
               "Link": "https://www.shockwave.cloud/blog/subdomain-takeover-how-a-misconfigured-dns-record-could-lead-to-a-huge-supply-chain-attack"
            }
         ],
         "Authors": ["Gal Nagli (@naglinagli)"],
         "Programs": ["GitHub"],
         "Bugs": ["Subdomain takeover", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2023-03-08",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Unauthorized access to Codespace secrets in GitHub",
               "Link": "https://ophionsecurity.com/blog/access-organization-secrets-in-github"
            }
         ],
         "Authors": ["Ophion Security (@OphionSecurity)"],
         "Programs": ["GitHub"],
         "Bugs": ["Logic flaw", "Broken Access Control", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-03-07",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "[Account Takeover] Don’t Send a Message to anyone Before Reading This [External Audit]",
               "Link": "https://infosecwriteups.com/dont-send-a-message-to-anyone-before-reading-this-account-takeover-vulnerability-external-audit-cf584a0c983c"
            }
         ],
         "Authors": ["Vipul Sahu"],
         "Programs": ["-"],
         "Bugs": ["HTTP response manipulation", "Authentication bypass", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-03-07",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "WordPress BuddyForms Plugin — Unauthenticated Insecure Deserialization (CVE-2023–26326)",
               "Link": "https://medium.com/tenable-techblog/wordpress-buddyforms-plugin-unauthenticated-insecure-deserialization-cve-2023-26326-3becb5575ed8"
            }
         ],
         "Authors": ["Joshua Martinelle (@J0_mart)"],
         "Programs": ["-"],
         "Bugs": ["Insecure deserialization", "Security code review", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-03-07",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Feeding Tasty Objects to Visual Studio's App Center SDK for Apple",
               "Link": "https://secfault-security.com/blog/ms-app-center.html"
            }
         ],
         "Authors": ["Jenny (@OldM4nHunting)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Insecure deserialization", "MacOS"],
         "Bounty": "-",
         "PublicationDate": "2023-03-07",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Attacking .NET Web Services",
               "Link": "https://www.securifera.com/blog/2023/03/06/attacking-net-web-services/"
            }
         ],
         "Authors": ["b0yd (@rwincey)"],
         "Programs": ["Siemens"],
         "Bugs": ["Security code review", "Arbitrary file read", "Arbitrary file write", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-03-06",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "Caveat Implementor! Key Recovery Attacks on MEGA",
               "Link": "https://mega-caveat.github.io"
            }
         ],
         "Authors": ["Martin R. Albrecht (@martinralbrecht)", "Miro Haller (@M__Haller)", "Lenka Mareková", "Kenneth G. Paterson (@Yogehi)"],
         "Programs": ["MEGA"],
         "Bugs": ["Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2023-03-06",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "A Vulnerability in Implementations of SHA-3, SHAKE, EdDSA, and Other NIST-Approved Algorithms",
               "Link": "https://eprint.iacr.org/2023/331.pdf"
            }
         ],
         "Authors": ["Nicky Mouha", "Christopher Celi"],
         "Programs": ["Python", "PHP", "PyPy", "SHA3 for Ruby", "Keccak Team"],
         "Bugs": ["Cryptographic issues", "Buffer Overflow"],
         "Bounty": "-",
         "PublicationDate": "2023-03-06",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Remote Stealth Brute-force of Oracle Database Passwords",
               "Link": "https://blog.bitcrack.net/oracle-databases-remote-stealth-password-bruteforce/"
            }
         ],
         "Authors": ["Viktor Markopoulos"],
         "Programs": ["-"],
         "Bugs": ["Bruteforce", "Information disclosure", "Authentication bypass", "Components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2023-03-06",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Manipulating Encrypted Traffic for Manual and Automation",
               "Link": "https://medium.com/@Ano_F_/manipulating-encrypted-traffic-using-pycript-b637612528bb"
            }
         ],
         "Authors": ["Sourav Kalal (@Ano_F_)"],
         "Programs": ["-"],
         "Bugs": ["Client-side encryption bypass", "Bruteforce"],
         "Bounty": "-",
         "PublicationDate": "2023-03-06",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Insecure Toyota CRM exposed Mexican customer information",
               "Link": "https://eaton-works.com/2023/03/06/toyota-c360-hack/"
            }
         ],
         "Authors": ["Eaton Z. (@XeEaton)"],
         "Programs": ["Toyota"],
         "Bugs": ["Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-06",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Authentication Bypass Vulnerability in Mura CMS and Masa CMS (CVE-2022-47003 and CVE-2022-47002)",
               "Link": "https://hoyahaxa.blogspot.com/2023/03/authentication-bypass-mura-masa.html"
            }
         ],
         "Authors": ["Brian (@hoyahaxa)"],
         "Programs": ["Mura CMS", "Masa CMS"],
         "Bugs": ["Authentication bypass", "Security code review", "ColdFusion"],
         "Bounty": "-",
         "PublicationDate": "2023-03-06",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Accessing to Data Sources of any Facebook Business account via IDOR in GraphQL",
               "Link": "https://medium.com/@mukundbhuva/accessing-the-data-sources-of-any-facebook-business-account-via-idor-in-graphql-1fc963ad3ecd"
            }
         ],
         "Authors": ["Mukund Bhuva (@MukundBhuva)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR", "GraphQL"],
         "Bounty": "-",
         "PublicationDate": "2023-03-06",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Exposing Users Table From a Leaky GraphQL Query",
               "Link": "https://rashahacks.com/exposing-users-table-from-a-leaky-graphql-query/"
            }
         ],
         "Authors": ["Inderjeet Singh - encodedguy (@3nc0d3dGuY)"],
         "Programs": ["-"],
         "Bugs": ["GraphQL", "Broken authorization", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-03-06",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Protecting Android clipboard content from unintended exposure",
               "Link": "https://www.microsoft.com/en-us/security/blog/2023/03/06/protecting-android-clipboard-content-from-unintended-exposure/"
            }
         ],
         "Authors": ["Microsoft 365 Defender Research Team"],
         "Programs": ["SHEIN"],
         "Bugs": ["Android"],
         "Bounty": "-",
         "PublicationDate": "2023-03-06",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "IDOR on bitdefender.com",
               "Link": "https://hopesamples.blogspot.com/2023/03/idor-on-bitdefendercom.html"
            }
         ],
         "Authors": ["Vivek M"],
         "Programs": ["Bitdefender"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-03-05",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "500$ Bounty in just 5 minutes through Recon!!!!",
               "Link": "https://hunter-55.medium.com/500-bounty-in-just-5-minutes-through-recon-5eeb6c299c3c"
            }
         ],
         "Authors": ["Himanshu Pdy (@himanshu_pdy)"],
         "Programs": ["-"],
         "Bugs": ["AWS misconfiguration", "Cloud storage misconfiguration"],
         "Bounty": "500",
         "PublicationDate": "2023-03-05",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Microsoft Word RTF Font Table Heap Corruption",
               "Link": "https://qoop.org/publications/cve-2023-21716-rtf-fonttbl.md"
            }
         ],
         "Authors": ["Joshua J. Drake (@jduck)"],
         "Programs": ["Microsoft (Office)"],
         "Bugs": ["Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-03-05",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "JS file enumeration for bug bounty hunters",
               "Link": "https://screamy7.github.io/posts/Javascript/"
            }
         ],
         "Authors": ["Aadarsh Anand (@ScreamZoro)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-03-04",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "30-Minute Heist: How I Bagged a $1500 Bounty in Just few Minutes!",
               "Link": "https://medium.com/@thelinuxboy/30-minute-heist-how-i-bagged-a-1500-bounty-in-just-few-minutes-48753eb2028e"
            }
         ],
         "Authors": ["Charlie : The Hacker"],
         "Programs": ["-"],
         "Bugs": ["Broken Access Control", "Logic flaw"],
         "Bounty": "1,500",
         "PublicationDate": "2023-03-04",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Bug in Netflix with my automation",
               "Link": "https://medium.com/@mrxdevil404/bug-in-netflix-with-my-automation-1382d087078"
            }
         ],
         "Authors": ["Ali Mansour (@Ali45598547)"],
         "Programs": ["Netflix"],
         "Bugs": ["Information disclosure"],
         "Bounty": "400",
         "PublicationDate": "2023-03-04",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Unauthorized Access To Admin Panel via Swagger",
               "Link": "https://m7arm4n.medium.com/unauthorized-access-to-admin-panel-via-swagger-c242e8341045"
            }
         ],
         "Authors": ["Arman (@M7arm4n)"],
         "Programs": ["Coca-Cola"],
         "Bugs": ["Missing authentication", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-03-04",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Bypass TCC via iCloud",
               "Link": "https://wojciechregula.blog/post/bypass-tcc-via-icloud/"
            }
         ],
         "Authors": ["Wojciech Reguła (@_r3ggi)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["TCC bypass", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-03-04",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Safe-Redirect in Rails 7.0",
               "Link": "https://bountyplz.xyz/bugbounty/2023/03/03/Bypassing-Safe-Redirect-in-Rails-7.0.html"
            }
         ],
         "Authors": ["Ryan (@healthyoutlet)"],
         "Programs": ["Ruby on Rails"],
         "Bugs": ["Open redirect", "URL validation bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-03",
         "AddedDate": "2023-08-08"
      },
      {
         "Links": [
            {
               "Title": "GitHub Security Lab audited DataHub: Here’s what they found",
               "Link": "https://github.blog/2023-03-03-github-security-lab-audited-datahub-heres-what-they-found/"
            }
         ],
         "Authors": ["Alvaro Muñoz (@pwntester)", "Michael Stepankin (@artsploit)", "Peter Stöckli (@ulldma)", "Kevin Stubbings", "Jorge Rosillo (@jorge_ctf)", "Sylwia Budzynska"],
         "Programs": ["DataHub"],
         "Bugs": ["SSRF", "Insecure deserialization", "Cypher injection", "Authentication bypass", "Authorization bypass", "XSS", "Open redirect", "JWT", "JSON injection", "Cryptographic issues", "Session expiration issue", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-03",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Web Cache Poisoning - Capability to disable/deface the app.██████████.com (A tale of poisoning through the layers of caching)",
               "Link": "https://github.com/AnkitCuriosity/Write-Ups/blob/main/Web%20Cache%20Poisoning%20-%20Capability%20to%20disable%E2%88%95deface%20the%20app.vulnerable.com%20(A%20tale%20of%20poisoning%20through%20the%20layers%20of%20caching).md"
            }
         ],
         "Authors": ["Ankit Singh (@AnkitCuriosity)"],
         "Programs": ["-"],
         "Bugs": ["Web cache poisoning"],
         "Bounty": "1,000",
         "PublicationDate": "2023-03-03",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "CS-Cart PDF Plugin Unauthenticated Command Injection",
               "Link": "https://starlabs.sg/blog/2023/03-cs-cart-pdf-plugin-unauthenticated-command-injection/"
            }
         ],
         "Authors": ["Ngo Wei Lin (@Creastery)"],
         "Programs": ["CS-Cart"],
         "Bugs": ["RCE", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-03-03",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "How Your NFTs Could Have Been Stolen in Just One Click",
               "Link": "https://www.permasecure.io/2023/03/03/how-your-nfts-could-have-been-stolen-in-just-one-click/"
            }
         ],
         "Authors": ["PermaSecure (@PermaSecure)"],
         "Programs": ["-"],
         "Bugs": ["postMessage", "GraphQL"],
         "Bounty": "-",
         "PublicationDate": "2023-03-03",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Upgrade plan from Free to Paid via Response Manipulation",
               "Link": "https://ibraradi.gitbook.io/write-up/upgrade-plan-from-free-to-paid-via-response-manipulation"
            }
         ],
         "Authors": ["Ibrahim Radi (@ibraradi9)"],
         "Programs": ["-"],
         "Bugs": ["Payment bypass", "HTTP response manipulation"],
         "Bounty": "-",
         "PublicationDate": "2023-03-03",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "How I Earned $$$ for Excessive Data Exposure Through Directory Traversal Leads to Product Price Manipulation",
               "Link": "https://mshibilmp.medium.com/how-i-earned-for-excessive-data-exposure-through-directory-traversal-leads-to-product-price-4582e5371774"
            }
         ],
         "Authors": ["Mohamed Shibil"],
         "Programs": ["-"],
         "Bugs": ["Path traversal", "Information disclosure", "Payment bypass"],
         "Bounty": "500",
         "PublicationDate": "2023-03-03",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "The Story of My First Reflected XSS",
               "Link": "https://medium.com/@ahmedelbolaqy/the-story-of-my-first-reflected-xss-c24fbfef2dc6"
            }
         ],
         "Authors": ["Ahmed Kamal Abu_Elwafa (@AhmedKa01184061)"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-03-03",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Email Verification Bypass Worth $$$",
               "Link": "https://vijetareigns.medium.com/email-verification-bypass-worth-cbb65a68a34f"
            }
         ],
         "Authors": ["the_unluck_guy (@7he_unlucky_guy)"],
         "Programs": ["-"],
         "Bugs": ["Email verification bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-03-03",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Hacking the Nintendo DSi Browser",
               "Link": "https://farlow.dev/2023/03/02/hacking-the-nintendo-dsi-browser"
            }
         ],
         "Authors": ["Nathan Farlow (@0x1337cafe)"],
         "Programs": ["Nintendo"],
         "Bugs": ["Memory corruption", "Use-After-Free", "Browser hacking"],
         "Bounty": "-",
         "PublicationDate": "2023-03-02",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Traveling with OAuth - Account Takeover on Booking.com",
               "Link": "https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com"
            }
         ],
         "Authors": ["Aviad Carmel (@AviadCarmel)"],
         "Programs": ["Booking.com", "KAYAK"],
         "Bugs": ["OAuth", "Account takeover", "Authentication bypass", "Open redirect"],
         "Bounty": "-",
         "PublicationDate": "2023-03-02",
         "AddedDate": "2023-03-03"
      },
      {
         "Links": [
            {
               "Title": "Mining Takeovers for Fun and Profit",
               "Link": "https://fireshellsecurity.team/mining-takeovers-for-fun-and-profit/"
            }
         ],
         "Authors": ["Artur Marzano (@MacmodSec)"],
         "Programs": ["-"],
         "Bugs": ["Subdomain takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-03-01",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "How a simple IDOR impacted the data of thousands of customers of an Indian automotive giant",
               "Link": "https://medium.com/@kushjain0107/how-simple-idor-impacted-the-data-of-thousands-of-customers-of-an-indian-automotive-giant-fdbd2ef1c2c6"
            }
         ],
         "Authors": ["Kushal Jain", "Ashutosh Mahajan"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Information disclosure", "IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-03-01",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Web Cache Deception Attack on a private bug bounty program",
               "Link": "https://medium.com/@snoopy101/web-cache-deception-attack-on-a-private-bug-bounty-program-52872cbdeedc"
            }
         ],
         "Authors": ["snoopy (@snoopy101101)"],
         "Programs": ["-"],
         "Bugs": ["Web cache deception"],
         "Bounty": "-",
         "PublicationDate": "2023-03-01",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Introducing Aladdin",
               "Link": "https://labs.nettitude.com/blog/introducing-aladdin/"
            }
         ],
         "Authors": ["Lefteris Panos (@lefterispan)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2023-03-01",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Gitpod remote code execution 0-day vulnerability via WebSockets",
               "Link": "https://snyk.io/blog/gitpod-remote-code-execution-vulnerability-websockets/"
            }
         ],
         "Authors": ["Elliot Ward"],
         "Programs": ["Gitpod"],
         "Bugs": ["RCE", "Websockets", "Cross-Site WebSocket Hijacking (CSWH)", "Cloud", "Samesite cookie bypass", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-03-01",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "Abusing Hop-by-Hop Header to Chain A CRLF Injection Vulnerability",
               "Link": "https://redshark1802.com/blog/2023/03/01/abusing-hopy-by-hop-header-crlf-injection/"
            }
         ],
         "Authors": ["Simon Bräuer (@redshark1802)"],
         "Programs": ["-"],
         "Bugs": ["CRLF injection", "Hop-by-hop header", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-03-01",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "Exfiltrating AWS Credentials via PDF Rendering of Unsanitized Input",
               "Link": "https://cristivlad.medium.com/exfiltrating-aws-credentials-via-pdf-rendering-of-unsanitized-input-63f39d60d963"
            }
         ],
         "Authors": ["Cristi Vlad (@CristiVlad25)"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "HTML injection", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-03-01",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "How I Earned $1800 for finding a (Business Logic) Account Takeover Vulnerability?",
               "Link": "https://medium.com/@0xd3vil/how-i-earned-1800-for-finding-a-business-logic-account-takeover-vulnerability-c84c78e6ade0"
            }
         ],
         "Authors": ["Vivek Kumar Yadav (@0xd3vil)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Authentication bypass"],
         "Bounty": "1,800",
         "PublicationDate": "2023-03-01",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "Broken links hijacking and CDN takeover",
               "Link": "https://bergee.it/blog/broken-links-hijacking-and-cdn-takeover/"
            }
         ],
         "Authors": ["Bartłomiej Bergier (@_bergee_)"],
         "Programs": ["-"],
         "Bugs": ["Broken link hijacking", "Subdomain takeover"],
         "Bounty": "200",
         "PublicationDate": "2023-02-28",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "A New Vector For “Dirty” Arbitrary File Write to RCE",
               "Link": "https://blog.doyensec.com/2023/02/28/new-vector-for-dirty-arbitrary-file-write-2-rce.html"
            }
         ],
         "Authors": ["Maxence Schmitt (@maxenceschmitt)", "Lorenzo Stella (@lorenzostella)"],
         "Programs": ["-"],
         "Bugs": ["Arbitrary file write", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-28",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "Empowering weak primitives: file truncation to code execution with Git",
               "Link": "https://www.sonarsource.com/blog/empowering-weak-primitives-file-truncation-to-code-execution-with-git/"
            }
         ],
         "Authors": ["Thomas Chauchefoin (@swapgs)"],
         "Programs": ["-"],
         "Bugs": ["Argument injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-28",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-38108: RCE In Solarwinds Network Performance Monitor",
               "Link": "https://www.zerodayinitiative.com/blog/2023/2/27/cve-2022-38108-rce-in-solarwinds-network-performance-monitor"
            }
         ],
         "Authors": ["Piotr Bazydło (@chudyPB)", "Justin Hong", "Lucas Miller"],
         "Programs": ["SolarWinds"],
         "Bugs": ["Insecure deserialization", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-28",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "A student's dream: hacking (then fixing) Gradescope's autograder",
               "Link": "https://saligrama.io/blog/post/gradescope-autograder-security/"
            }
         ],
         "Authors": ["Aditya Saligrama (@saligrama_a)"],
         "Programs": ["Gradescope"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-28",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "[Tips & Tricks] Exfiltrating User's Data Through CSV Injection",
               "Link": "https://blog.rehack.xyz/2023/02/tips-tricks-exfiltrating-users-data.html"
            }
         ],
         "Authors": ["RE:HACK (@rehackxyz)"],
         "Programs": ["-"],
         "Bugs": ["CSV injection"],
         "Bounty": "-",
         "PublicationDate": "2023-02-28",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "My First Un-Expected $$$$ Digit Bounty for an Un-Expected Vulnerability",
               "Link": "https://medium.com/@mehtashobhit98/my-first-un-expected-digit-bounty-for-an-un-expected-vulnerability-b44933d6ebda"
            }
         ],
         "Authors": ["Shobhit Mehta"],
         "Programs": ["-"],
         "Bugs": ["Lack of rate limiting", "Bruteforce"],
         "Bounty": "1,000",
         "PublicationDate": "2023-02-28",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Gitpod remote code execution 0-day vulnerability via WebSockets",
               "Link": "https://snyk.io/blog/gitpod-remote-code-execution-vulnerability-websockets/"
            }
         ],
         "Authors": ["Elliot Ward"],
         "Programs": ["Gitpod"],
         "Bugs": ["RCE", "Cross-Site WebSocket Hijacking (CSWH)", "Samesite cookie bypass", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-02-27",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Abusing Maven’s pom.xml",
               "Link": "https://security.humanativaspa.it/abusing-mavens-pom-xml/"
            }
         ],
         "Authors": ["Gianluca Baldi (@0x_nope)"],
         "Programs": ["Apache Maven"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-27",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "VMware Workspace One Access",
               "Link": "https://trenchant.io/vmware-workspace-one-access/"
            }
         ],
         "Authors": ["Steven Seeley (@steventseeley)"],
         "Programs": ["VMware"],
         "Bugs": ["RCE", "Java Beans", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-27",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "The Vulnerability That Exposed an UN Website to Remote Code Execution",
               "Link": "https://medium.com/@mullangisashank/the-vulnerability-that-exposed-an-un-website-to-remote-code-execution-dfe377b82049"
            }
         ],
         "Authors": ["Mullangisashank (@manisashankm)"],
         "Programs": ["United Nations"],
         "Bugs": ["Components with known vulnerabilities", "OGNL injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-27",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "$10.000 bounty for exposed .git to RCE",
               "Link": "https://medium.com/@levshmelevv/10-000-bounty-for-exposed-git-to-rce-304c7e1f54"
            }
         ],
         "Authors": ["Lev Shmelev"],
         "Programs": ["-"],
         "Bugs": [".git folder disclosure", "RCE", "OS command injection"],
         "Bounty": "10,000",
         "PublicationDate": "2023-02-27",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Grand Theft Auto - A peek of BLE relay attack",
               "Link": "https://rollingpwn.github.io/BLE-Relay-Aattck/"
            }
         ],
         "Authors": ["@Kevin2600"],
         "Programs": ["-"],
         "Bugs": ["Bluetooth", "BLE", "Car hacking"],
         "Bounty": "-",
         "PublicationDate": "2023-02-27",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Interesting Stored XSS in sandboxed environment to Full Account Takeover",
               "Link": "https://varmaanu001.medium.com/interesting-stored-xss-in-sandboxed-environment-to-full-account-takeover-32e541062938"
            }
         ],
         "Authors": ["Anurag__Verma"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-02-27",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "How did I found RCE on SHAREit which rewarded $$$ bounty",
               "Link": "https://infosecwriteups.com/how-did-i-found-rce-on-shareit-which-rewarded-bounty-7d4196bf1b52"
            }
         ],
         "Authors": ["Suprit Pandurangi"],
         "Programs": ["SHAREit"],
         "Bugs": ["Log4shell", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-26",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Using efficient tooling to hunt GraphQL security issues",
               "Link": "https://nishantjain.tech/#/blog"
            }
         ],
         "Authors": ["Nishant Jain (@realArcherL)"],
         "Programs": ["-"],
         "Bugs": ["GraphQL"],
         "Bounty": "-",
         "PublicationDate": "2023-02-26",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "The Tale of a Command Injection by Changing the Logo",
               "Link": "https://medium.com/@omidxrz/command-injection-by-changing-the-logo-2d730887ab6c"
            }
         ],
         "Authors": ["0xrz (@omidxrz)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "OS command injection", "Unrestricted file upload", "Directory listing", "HTTP response manipulation"],
         "Bounty": "2,400",
         "PublicationDate": "2023-02-26",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover worth of $5",
               "Link": "https://gonzxph.medium.com/account-takeover-worth-of-5-dba784b32383"
            }
         ],
         "Authors": ["Jefferson Gonzales (@gonzxph)"],
         "Programs": ["-"],
         "Bugs": ["OAuth", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-02-26",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "How I got a $2000 bounty with RXSS",
               "Link": "https://hacklido.com/blog/320-how-i-got-a-2000-bounty-with-rxss"
            },
            {
               "Title": "Alternative link",
               "Link": "https://p4n7h3rx.medium.com/how-i-got-a-2000-bounty-with-rxss-e6f45f987793"
            }
         ],
         "Authors": ["Hashir Sami Khan (@P4n7h3Rx)"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "2,000",
         "PublicationDate": "2023-02-26",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Unauthenticated GraphQL Introspection and API calls",
               "Link": "https://medium.com/@osamaavvan/unauthenticated-graphql-introspection-and-api-calls-92f1d9d86bcf"
            }
         ],
         "Authors": ["Osama Avvan (@osamaavvan)"],
         "Programs": ["-"],
         "Bugs": ["GraphQL", "Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2023-02-26",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Give me a browser, I’ll give you a Shell",
               "Link": "https://systemweakness.com/give-me-a-browser-ill-give-you-a-shell-de19811defa0"
            }
         ],
         "Authors": ["Rend"],
         "Programs": ["-"],
         "Bugs": ["Local Privilege Escalation", "Kiosk hacking"],
         "Bounty": "-",
         "PublicationDate": "2023-02-25",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "My P1 — Account Takeover",
               "Link": "https://medium.com/@metikalakullai.gtl/my-p1-account-takeover-3293fc59e10"
            }
         ],
         "Authors": ["Kullai (@Kullai12)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "IDOR", "Password reset"],
         "Bounty": "-",
         "PublicationDate": "2023-02-25",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "From CVE-2022-33679 to Unauthenticated Kerberoasting",
               "Link": "https://www.horizon3.ai/from-cve-2022-33679-to-unauthenticated-kerberoasting/"
            }
         ],
         "Authors": ["Trampas Howe (@trampashowe)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Kerberos", "MiTM", "Local Privilege Escalation", "Downgrade attack"],
         "Bounty": "-",
         "PublicationDate": "2023-02-25",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Authenticated XXE vulnerability in IBM Tivoli Workload Scheduler CVE-2022-38389",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-02/Synacktiv-IBM-TWS-CVE-2022-38389.pdf"
            }
         ],
         "Authors": ["Geoffrey Bertoli (@YofBalibump)"],
         "Programs": ["IBM"],
         "Bugs": ["XXE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-24",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "draw.io CVEs",
               "Link": "https://lude.rs/h4ck1ng/draw.io_cves.html"
            }
         ],
         "Authors": ["@caioluders"],
         "Programs": ["draw.io"],
         "Bugs": ["SSRF", "OAuth", "Open redirect", "Token leak", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-24",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Exploits Explained: Using APIs to Execute a Server-Side Request Forgery",
               "Link": "https://www.synack.com/blog/exploits-explained-using-apis-to-execute-a-server-side-request-forgery/"
            }
         ],
         "Authors": ["@cor3min3r"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-02-24",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Microsoft Azure Account Takeover via DOM-based XSS in Cosmos DB Explorer",
               "Link": "https://starlabs.sg/blog/2023/02-microsoft-azure-account-takeover-via-dom-based-xss-in-cosmos-db-explorer/"
            },
            {
               "Title": "Alternative link",
               "Link": "https://www.creastery.com/blog/microsoft-azure-ato-via-xss-in-cosmos-db-explorer/"
            }
         ],
         "Authors": ["Ngo Wei Lin (@Creastery)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Account takeover", "DOM XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-02-24",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Little bug, Big impact. 25k bounty",
               "Link": "https://blog.prodefense.io/little-bug-big-impact-25k-bounty-9e47773f959f"
            }
         ],
         "Authors": ["Matthew Keeley (@Nightbanes)"],
         "Programs": ["-"],
         "Bugs": ["Hardcoded API keys"],
         "Bounty": "25,000",
         "PublicationDate": "2023-02-24",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Blind XSS fired on Admin panel worth $2000",
               "Link": "https://medium.com/@feribytex/blind-xss-fired-on-admin-panel-worth-2000-abe2c83279b5"
            }
         ],
         "Authors": ["Feri Susanto (@feribytex)"],
         "Programs": ["-"],
         "Bugs": ["Blind XSS"],
         "Bounty": "2,000",
         "PublicationDate": "2023-02-24",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Escaping well-configured VSCode extensions (for profit)",
               "Link": "https://blog.trailofbits.com/2023/02/23/escaping-well-configured-vscode-extensions-for-profit/"
            }
         ],
         "Authors": ["Vasco Franco"],
         "Programs": ["Microsoft"],
         "Bugs": ["Electron", "Webview", "Path traversal"],
         "Bounty": "7,500",
         "PublicationDate": "2023-02-23",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "How I Used JS files inspection and Fuzzing to do admins/supports stuff",
               "Link": "https://medium.com/@bag0zathev2/how-i-used-js-files-inspection-and-fuzzing-to-do-admins-supports-stuff-dd4f700605a"
            }
         ],
         "Authors": ["Fares Walid (@SirBagoza)"],
         "Programs": ["-"],
         "Bugs": ["Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-02-23",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "How I found DOM-Based XSS on Microsoft MSRC and How they fixed it",
               "Link": "https://m3ez.medium.com/how-i-found-dom-based-xss-on-microsoft-msrc-and-how-they-fixed-it-8b71a6020c82"
            }
         ],
         "Authors": ["Supakiad S. (@Supakiad_Mee)"],
         "Programs": ["Microsoft"],
         "Bugs": ["DOM XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-02-23",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "How do I take over another user subdomain name worth $$$$",
               "Link": "https://parkerzanta.medium.com/how-do-i-take-over-another-user-subdomain-name-worth-c66bb0c3f2f7"
            }
         ],
         "Authors": ["Parkerzanta (@parkerzanta)"],
         "Programs": ["-"],
         "Bugs": ["Subdomain takeover"],
         "Bounty": "1250",
         "PublicationDate": "2023-02-23",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "LogicalDOC Vulnerability Disclosure",
               "Link": "https://www.whiteoaksecurity.com/blog/logicaldoc-vulnerability-disclosure/"
            }
         ],
         "Authors": ["Brett DeWall (@xbadbiddyx)", "Michael Rand"],
         "Programs": ["LogicalDOC"],
         "Bugs": ["XXE", "RCE", "Command injection", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-23",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Exploit Airlines that use T-Mobile for Free WiFi",
               "Link": "https://cylect.io/blog/cybr-2/exploit-airlines-to-get-free-wifi-airline-vulnerability-8"
            }
         ],
         "Authors": ["cylect.io (@cylect_io)"],
         "Programs": ["T-Mobile"],
         "Bugs": ["Wifi", "Payment bypass", "MAC address spoofing", "Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2023-02-23",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "The code that wasn’t there: Reading memory on an Android device by accident",
               "Link": "https://github.blog/2023-02-23-the-code-that-wasnt-there-reading-memory-on-an-android-device-by-accident/"
            }
         ],
         "Authors": ["Man Yue Mo (@mmolgtm)"],
         "Programs": ["Qualcomm"],
         "Bugs": ["Kernel hacking", "Android", "Memory leak", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-02-23",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Decoding BlazorPack",
               "Link": "https://sensepost.com/blog/2023/decoding-blazorpack/"
            }
         ],
         "Authors": ["Rogan Dawes (@RoganDawes)"],
         "Programs": ["-"],
         "Bugs": ["Websockets"],
         "Bounty": "-",
         "PublicationDate": "2023-02-22",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "How I got into Nokia HOF in 5 Mins",
               "Link": "https://sl4x0.medium.com/how-i-got-into-nokia-hof-in-5-mins-99ce16583bd4"
            }
         ],
         "Authors": ["Abdelrhman Allam (@sl4x0)"],
         "Programs": ["Nokia"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-02-22",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "Insufficient GraphQL API vulnerability due to lack of validation of Authorization Bearer token",
               "Link": "https://0x1int.gitbook.io/blogs/insufficient-graphql-api-vulnerability-due-to-lack-of-validation-of-authorization-bearer-token"
            }
         ],
         "Authors": ["Int (@intlulz)"],
         "Programs": ["-"],
         "Bugs": ["GraphQL", "IDOR"],
         "Bounty": "700",
         "PublicationDate": "2023-02-22",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Unauthenticated RCE in Goanywhere",
               "Link": "https://www.vicarius.io/vsociety/blog/unauthenticated-rce-in-goanywhere"
            }
         ],
         "Authors": ["Youssef Muhammad (@yosef0x1)"],
         "Programs": ["Fortra (GoAnywhere)"],
         "Bugs": ["Insecure deserialization", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-22",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Vulnerability write-up - \"Dangerous assumptions\"",
               "Link": "https://www.codean.io/blog/vulnerability-write-up---%22dangerous-assumptions%22"
            }
         ],
         "Authors": ["Thomas Rinsma (@thomasrinsma)", "Kevin Valk (@krvalk)"],
         "Programs": ["DIVD"],
         "Bugs": ["Prototype pollution", "SQL injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-22",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Parameter Pollution in Golang Web Apps",
               "Link": "https://medium.com/@rramgattie/exploiting-parameter-pollution-in-golang-web-apps-daca72b28ce2"
            }
         ],
         "Authors": ["Rick Ramgattie (@RRamgattie)"],
         "Programs": ["Concourse", "VMware"],
         "Bugs": ["Broken authorization", "HTTP parameter pollution"],
         "Bounty": "-",
         "PublicationDate": "2023-02-22",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "With a single request, you can kill any Gitea server",
               "Link": "https://medium.com/@knassar702/with-a-single-request-you-can-kill-any-gitea-server-1275c5f3b226"
            }
         ],
         "Authors": ["Khaled Nassar (@knassar702)"],
         "Programs": ["Gitea"],
         "Bugs": ["Application-level DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-02-22",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Access Twitter blue features using deeplink without a subscription.",
               "Link": "https://servicenger.com/mobile/android/access-twitter-blue-features-using-deeplink-without-a-paid-subscription/"
            }
         ],
         "Authors": ["Rahul Kankrale (@RahulKankrale)"],
         "Programs": ["Twitter"],
         "Bugs": ["Insecure deeplink", "Android"],
         "Bounty": "-",
         "PublicationDate": "2023-02-22",
         "AddedDate": "2023-02-22"
      },
      {
         "Links": [
            {
               "Title": "Information Disclosure Vulnerability in Adobe Experience Manager affecting multiple companies including Microsoft, Apple, Amazon, McDonald’s and many more.",
               "Link": "https://medium.com/@fattselimi/information-disclosure-vulnerability-in-adobe-experience-manager-affecting-multiple-companies-2fb0558cd957"
            }
         ],
         "Authors": ["Fat Selimi (@fattselimi)"],
         "Programs": ["Apple", "Microsoft", "Amazon", "McDonalds"],
         "Bugs": ["Information disclosure", "AEM"],
         "Bounty": "-",
         "PublicationDate": "2023-02-22",
         "AddedDate": "2023-02-22"
      },
      {
         "Links": [
            {
               "Title": "Taking over “Google Cloud Shell” by utilizing capabilities and Kubelet",
               "Link": "https://medium.com/@chenshiri/taking-over-google-cloud-shell-by-utilizing-capabilities-and-kubelet-fd5e2417f286"
            }
         ],
         "Authors": ["Chen Shiri (@ChenShiri73)"],
         "Programs": ["-"],
         "Bugs": ["Container escape", "RCE", "Kubernetes"],
         "Bounty": "-",
         "PublicationDate": "2023-02-21",
         "AddedDate": "2023-05-15"
      },
      {
         "Links": [
            {
               "Title": "Exploiting an HTML injection with dangling markup",
               "Link": "https://www.vaadata.com/blog/exploiting-an-html-injection-with-dangling-markup/"
            }
         ],
         "Authors": ["Yoan Montoya"],
         "Programs": ["-"],
         "Bugs": ["HTML injection", "Dangling Markup Injection"],
         "Bounty": "-",
         "PublicationDate": "2023-02-21",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Multiple vulnerabilities in Dell Unisphere for PowerMax vApp, VASA Provider vApp and Solutions Enabler vApp CVE-2022-45103 / CVE-2022-45104",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-02/Synacktiv-Security_Advisory-Dell_EMC_vApp_Manager-Multiple_Vulnerabilities.pdf"
            }
         ],
         "Authors": ["Antoine Carrincazeaux"],
         "Programs": ["Dell"],
         "Bugs": ["Parameter injection", "Arbitrary file read", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-21",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Trellix Advanced Research Center Discovers a New Privilege Escalation Bug Class on macOS and iOS",
               "Link": "https://www.trellix.com/en-us/about/newsroom/stories/research/trellix-advanced-research-center-discovers-a-new-privilege-escalation-bug-class-on-macos-and-ios.html"
            }
         ],
         "Authors": ["Austin Emmitt (@alkalinesec)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-21",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "What the Vuln: Zimbra",
               "Link": "https://bishopfox.com/blog/what-the-vuln-zimbra"
            }
         ],
         "Authors": ["Carlos Yanez"],
         "Programs": ["-"],
         "Bugs": ["Zip Slip attack", "Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2023-02-21",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "ClamAV Critical Patch Review",
               "Link": "https://onekey.com/blog/clamav-critical-patch-review/"
            }
         ],
         "Authors": ["ONEKEY (@onekey_sec)"],
         "Programs": ["ClamAV"],
         "Bugs": ["RCE", "Memory corruption", "Buffer Overflow", "XXE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-21",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Multiple vulnerabilities in Nokia BTS Airscale ASIKA",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-02/Synacktiv-Nokia-BTS-AirScale-Asika-Multiple-Vulnerabilities.pdf"
            }
         ],
         "Authors": ["Geoffrey Bertoli (@YofBalibump)", "Lena David (@_lemeda)"],
         "Programs": ["Nokia"],
         "Bugs": ["Base transceiver station", "Path traversal", "Hardcoded private key", "Local Privilege Escalation", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-02-21",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Reflected Cross site scripting on reddit website (bounty awards $5000)",
               "Link": "https://jjainam16.medium.com/reflected-cross-site-scripting-on-reddit-website-bounty-awards-5000-99fa639cdd7"
            }
         ],
         "Authors": ["ShuttlerTech"],
         "Programs": ["Reddit"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "5,000",
         "PublicationDate": "2023-02-21",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Escaping misconfigured VSCode extensions",
               "Link": "https://blog.trailofbits.com/2023/02/21/vscode-extension-escape-vulnerability/"
            }
         ],
         "Authors": ["Vasco Franco"],
         "Programs": ["Microsoft (SARIF viewer & Live Preview)"],
         "Bugs": ["Path traversal", "DNS rebinding", "XSS", "HTML injection", "Webview", "CSP bypass"],
         "Bounty": "7,500",
         "PublicationDate": "2023-02-21",
         "AddedDate": "2023-02-22"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Akamai’s Web Application Firewall Using an Injected Content-Encoding Header",
               "Link": "https://www.praetorian.com/blog/using-crlf-injection-to-bypass-akamai-web-app-firewall/"
            }
         ],
         "Authors": ["Adam Crosser"],
         "Programs": ["Akamai"],
         "Bugs": ["WAF bypass", "CRLF injection", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-02-21",
         "AddedDate": "2023-02-22"
      },
      {
         "Links": [
            {
               "Title": "Bypassing SSO Authentication from the Login Without Password Feature Lead to Account Takeover",
               "Link": "https://aidilarf.medium.com/bypassing-sso-authentication-from-the-login-without-password-feature-lead-to-account-takeover-d2322a33a208"
            }
         ],
         "Authors": ["Aidil Arief"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "SSO", "OTP", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-02-20",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Exposing 185M+ Indians’ Personal Information and much more",
               "Link": "https://blog.robinjust.in/gov-in/2023/02/Exposing-Indian-Citizens-Sensitive-PII-and-more/"
            }
         ],
         "Authors": ["Robin Justin (@_robinjustin_)"],
         "Programs": ["Aadhaar", "CERT-In"],
         "Bugs": ["Broken Access Control", "IDOR", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-02-20",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "Reflected Cross Site Scripting (Awards 3500$ bounty)",
               "Link": "https://jjainam16.medium.com/reflected-cross-site-scripting-awards-3500-bounty-c8a619f129a1"
            }
         ],
         "Authors": ["ShuttlerTech"],
         "Programs": ["Shopify"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "3,500",
         "PublicationDate": "2023-02-20",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "[1500$ Worth — Slack] vulnerability, bypass invite accept process",
               "Link": "https://medium.com/@siratsami71/1500-worth-slack-vulnerability-bypass-invite-accept-process-8204e5431d52"
            }
         ],
         "Authors": ["Sirat Sami (@siratsami71)"],
         "Programs": ["Slack"],
         "Bugs": ["Broken Access Control", "Logic flaw"],
         "Bounty": "1,500",
         "PublicationDate": "2023-02-20",
         "AddedDate": "2023-02-22"
      },
      {
         "Links": [
            {
               "Title": "Shockwave Identifies Web Cache Deception and Account Takeover Vulnerability affecting OpenAI's ChatGPT",
               "Link": "https://www.shockwave.cloud/blog/shockwave-works-with-openai-to-fix-critical-chatgpt-vulnerability"
            }
         ],
         "Authors": ["Gal Nagli (@naglinagli)"],
         "Programs": ["OpenAI (ChatGPT)"],
         "Bugs": ["AI", "LLM", "Web cache deception", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-02-19",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Disabling ClamAV as an Unprivileged User",
               "Link": "https://www.archcloudlabs.com/projects/disabling-clamav-as-unprivileged-user/"
            }
         ],
         "Authors": ["Arch Cloud Labs (@DLL_Cool_J)"],
         "Programs": ["ClamAV"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-19",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Found an URL in the android application source code which lead to an IDOR",
               "Link": "https://vengeance.medium.com/found-an-url-in-the-android-application-source-code-which-lead-to-an-idor-1b8768708756"
            }
         ],
         "Authors": ["Vengeance"],
         "Programs": ["-"],
         "Bugs": ["Android", "Information disclosure", "IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-02-18",
         "AddedDate": "2023-02-22"
      },
      {
         "Links": [
            {
               "Title": "Hacking the Search Bar: The Story of Discovering and Reporting an XSS Vulnerability on Bing.com",
               "Link": "https://medium.com/@niraj1mahajan/hacking-the-search-bar-the-story-of-discovering-and-reporting-an-xss-vulnerability-on-bing-com-cac2f241835"
            }
         ],
         "Authors": ["Niraj Mahajan"],
         "Programs": ["Microsoft (Bing)"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-02-18",
         "AddedDate": "2023-02-22"
      },
      {
         "Links": [
           {
              "Title": "Readline crime: exploiting a SUID logic bug",
              "Link": "https://blog.trailofbits.com/2023/02/16/suid-logic-bug-linux-readline/"
           }
          ],
         "Authors": ["roddux"],
         "Programs": ["Arch Linux", "util-linux"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-16",
         "AddedDate": "2023-03-06"
       },
      {
         "Links": [
           {
              "Title": "Facebook bug: A Journey from Code Execution to S3 Data Leak",
              "Link": "https://medium.com/@win3zz/facebook-bug-a-journey-from-code-execution-to-s3-data-leak-698b7d2b02ef"
           }
          ],
         "Authors": ["Bipin Jitiya (@win3zz)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["RCE", "OS command injection"],
         "Bounty": "-",
         "PublicationDate": "2023-02-16",
         "AddedDate": "2023-02-26"
       },
      {
         "Links": [
           {
              "Title": "The Inside Story of Finding a Reverse Transaction Vulnerability in a Financial Application",
              "Link": "https://medium.com/@rajauzairabdullah/the-inside-story-of-finding-a-reverse-transaction-vulnerability-in-a-financial-application-d73f9cd40f6f"
           }
          ],
         "Authors": ["Raja Uzair Abdullah (@UzaiRaja)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw", "Payment tampering"],
         "Bounty": "-",
         "PublicationDate": "2023-02-16",
         "AddedDate": "2023-02-26"
       },
      {
         "Links": [
           {
              "Title": "Hacking Apple: Two Successful Exploits and Positive Thoughts on their Bug Bounty Program",
              "Link": "https://blog.infiltrateops.io/hacking-apple-two-successful-exploits-and-positive-thoughts-on-their-bug-bounty-program-963efe7518f6"
           }
          ],
         "Authors": ["Joe Gregg (@infiltrateops)", "Mike Piekarski (@pect0ral)"],
         "Programs": ["Apple"],
         "Bugs": ["RCE", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-02-16",
         "AddedDate": "2023-02-22"
       },
       {
         "Links": [
           {
              "Title": "EoP via Arbitrary File Write/Overwite in Group Policy Client “gpsvc” – CVE-2022-37955",
              "Link": "https://decoder.cloud/2023/02/16/eop-via-arbitrary-file-write-overwite-in-group-policy-client-gpsvc-cve-2022-37955/"
           }
          ],
         "Authors": ["ap (@decoder_it)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-16",
         "AddedDate": "2023-02-22"
       },
       {
         "Links": [
           {
              "Title": "Server-side prototype pollution: Black-box detection without the DoS",
              "Link": "https://portswigger.net/research/server-side-prototype-pollution"
           }
          ],
         "Authors": ["Gareth Heyes (@garethheyes)"],
         "Programs": ["-"],
         "Bugs": ["Server-side prototype pollution", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-15",
         "AddedDate": "2023-02-26"
       },
       {
         "Links": [
           {
              "Title": "Server side prototype pollution, how to detect and exploit",
              "Link": "https://blog.yeswehack.com/talent-development/server-side-prototype-pollution-how-to-detect-and-exploit/"
           }
          ],
         "Authors": ["BitK (@BitK_)"],
         "Programs": ["-"],
         "Bugs": ["Server-side prototype pollution", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-15",
         "AddedDate": "2023-02-26"
       },
       {
         "Links": [
           {
              "Title": "Detecting Server-Side Prototype Pollution",
              "Link": "https://www.intruder.io/research/server-side-prototype-pollution"
           }
          ],
         "Authors": ["Daniel Thatcher (@_danielthatcher)"],
         "Programs": ["-"],
         "Bugs": ["Server-side prototype pollution"],
         "Bounty": "-",
         "PublicationDate": "2023-02-15",
         "AddedDate": "2023-02-26"
       },
       {
         "Links": [
           {
              "Title": "Technical Advisory – Azure B2C – Crypto Misuse and Account Compromise",
              "Link": "https://www.praetorian.com/blog/azure-b2c-crypto-misuse-and-account-compromise/"
           }
          ],
         "Authors": ["John Novak"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Cryptographic issues", "JWT", "Account takeover", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-02-15",
         "AddedDate": "2023-02-22"
       },
       {
         "Links": [
           {
              "Title": "Abusing Azure App Service Managed Identity Assignments",
              "Link": "https://posts.specterops.io/abusing-azure-app-service-managed-identity-assignments-c3adefccff95"
           }
          ],
         "Authors": ["Andy Robbins (@_wald0)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-02-15",
         "AddedDate": "2023-02-22"
       },
       {
         "Links": [
           {
              "Title": "Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape vulnerability (CVE-2022-44666) (0day).",
              "Link": "https://github.com/j00sean/CVE-2022-44666"
           }
          ],
         "Authors": ["j00sean (@j00sean)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-15",
         "AddedDate": "2023-02-22"
       },
       {
         "Links": [
            {
               "Title": "XSS on The MOST Popular Movie Ticket website.",
               "Link": "https://medium.com/@tarang.parmar/xss-on-most-popular-entertaining-website-2fbf5a88df0f"
            }
         ],
         "Authors": ["Tarang Parmar"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-02-15",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "I Got United Nation’s Hall Of Fame With This Simple Technique!",
               "Link": "https://faiyazhacks.medium.com/i-got-united-nations-hall-of-fame-with-this-simple-technique-3d9a021e4a5d"
            }
         ],
         "Authors": ["Faiyaz Ahmad"],
         "Programs": ["United Nations"],
         "Bugs": ["HTML injection"],
         "Bounty": "-",
         "PublicationDate": "2023-02-15",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Assumed Breach Assessment Case Study: Uncovering WeSecureApp’s Approach",
               "Link": "https://wesecureapp-smm.medium.com/assumed-breach-assessment-case-study-uncovering-wesecureapps-approach-45a512c0bd63"
            }
         ],
         "Authors": ["WeSecureApp (@wesecureapp)"],
         "Programs": ["-"],
         "Bugs": ["Internal pentest", "Missing authentication", "Hardcoded credentials", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-02-14",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "http: properly reject empty http header field names",
               "Link": "https://github.com/haproxy/haproxy/commit/a8598a2eb11b6c989e81f0dbf10be361782e8d32"
            }
         ],
         "Authors": ["Bahruz Jabiyev (@BahruzJabiyev)", "Anthony Gavazzi", "Engin Kirda", "Kaan Onarlioglu", "Adi Peleg", "Harvey Tuch"],
         "Programs": ["HAProxy"],
         "Bugs": ["HTTP header attack", "HTTP request smuggling", "Access control bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-02-14",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Securing Open-Source Solutions: A Study of osTicket Vulnerabilities",
               "Link": "https://checkmarx.com/blog/securing-open-source-solutions-a-study-of-osticket-vulnerabilities/"
            }
         ],
         "Authors": ["Miguel Correia", "Davide Teixeira"],
         "Programs": ["Enhancesoft (osTicket)"],
         "Bugs": ["Stored XSS", "Reflected XSS", "SQL injection", "Session fixation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-14",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "cURL audit: How a joke led to significant findings",
               "Link": "https://blog.trailofbits.com/2023/02/14/curl-audit-fuzzing-libcurl-command-line-interface/"
            }
         ],
         "Authors": ["Maciej Domanski"],
         "Programs": ["Internet Bug Bounty (curl)"],
         "Bugs": ["Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-02-14",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "LPE via StorSvc",
               "Link": "https://github.com/blackarrowsec/redteam-research/tree/master/LPE%20via%20StorSvc"
            }
         ],
         "Authors": ["Antón Ortigueira (@antuache)", "Kurosh Dabbagh (@_Kudaes_)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Local Privilege Escalation", "DLL Hijacking"],
         "Bounty": "-",
         "PublicationDate": "2023-02-13",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "SQL Injection: Utilizing XML Functions in Oracle and PostgreSQL to bypass WAFs",
               "Link": "https://mahmoudsec.blogspot.com/2023/02/sql-injection-utilizing-xml-functions.html"
            }
         ],
         "Authors": ["Mahmoud Gamal (@Zombiehelp54)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-02-13",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Bypassing CORS configurations to produce an Account Takeover for Fun and Profit",
               "Link": "https://pullerjsecu.medium.com/bypassing-cors-configurations-to-produce-an-account-takeover-for-fun-and-profit-3e50c3f2a124"
            }
         ],
         "Authors": ["Josh Fam (@Pullerze)"],
         "Programs": ["-"],
         "Bugs": ["CORS misconfiguration", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-02-13",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Blind Time-based SQL injection vulnerability in an Indian government website",
               "Link": "https://medium.com/@kartikhunt3r/blind-time-based-sql-injection-vulnerability-in-an-indian-government-website-6bf3bb7daf25"
            }
         ],
         "Authors": ["Kartikhunt3r"],
         "Programs": ["NCIIPC"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-02-13",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Bypassing SameSite=lax cookie restrictions to preform CSRF resulting to a horizontal privilege escalation via poor email verification mechanism",
               "Link": "https://medium.com/@deadoverflow/bypassing-samesite-lax-cookie-restrictions-to-preform-csrf-resulting-to-a-horizontal-privilege-1dfc8fb17b0a"
            }
         ],
         "Authors": ["Imad Husanovic (@deadoverflow_)"],
         "Programs": ["-"],
         "Bugs": ["CSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-02-13",
         "AddedDate": "2023-02-22"
      },
      {
         "Links": [
            {
               "Title": "Hacking our way into internal DBs with hardcoded authentication keys",
               "Link": "https://ophionsecurity.com/blog/hacking-our-way-into-an-internal-db"
            }
         ],
         "Authors": ["Ophion Security (@OphionSecurity)"],
         "Programs": ["-"],
         "Bugs": ["JWT", "SSO", "Authentication bypass", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-02-13",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Exploiting A Remote Heap Overflow With A Custom TCP Stack",
               "Link": "https://www.synacktiv.com/publications/exploiting-a-remote-heap-overflow-with-a-custom-tcp-stack.html"
            }
         ],
         "Authors": ["Etienne Helluy-Lafont" , "Luca Moro (@johncool__)"],
         "Programs": ["Western Digital"],
         "Bugs": ["Memory corruption", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-13",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-22655 - TCC - Location Services Bypass",
               "Link": "https://theevilbit.github.io/posts/cve-2022-22655/"
            }
         ],
         "Authors": ["Csaba Fitzl (@theevilbit)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["MacOS", "TCC bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-02-13",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Zip bomb attack",
               "Link": "https://medium.com/@ramkumarnadar47/zip-bomb-attack-88d84a98be9f"
            }
         ],
         "Authors": ["Ramkumar Nadar"],
         "Programs": ["-"],
         "Bugs": ["Zip bomb", "DoS", "Unrestricted file upload"],
         "Bounty": "-",
         "PublicationDate": "2023-02-12",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "SSRF That Allowed Us to Access Whole Infra Web Services and Many More",
               "Link": "https://basu-banakar.medium.com/ssrf-that-allowed-us-to-access-whole-infra-web-services-and-many-more-3424f8efa0e4"
            }
         ],
         "Authors": ["Basavaraj Banakar (@basu_banakar)", "Lohith Gowda M (@lohigowda_in)"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-02-12",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "XXE with Auto-Update in install4j",
               "Link": "https://frycos.github.io/vulns4free/2023/02/12/install4j-xxe.html"
            }
         ],
         "Authors": ["Florian Hauser (@frycos)"],
         "Programs": ["Prosys OPC"],
         "Bugs": ["XXE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-12",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "IDOR Leads to MASS Account Takeover",
               "Link": "https://yaseenzubair.medium.com/idor-leads-to-mass-account-takeover-7548a03f5672"
            }
         ],
         "Authors": ["Yaseen Zubair"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-02-12",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Vulnerabilities due to XML files processing: XXE in C# applications in theory and in practice",
               "Link": "https://pvs-studio.com/en/blog/posts/csharp/0918/"
            }
         ],
         "Authors": ["Sergey Vasiliev (@_SergVasiliev_)"],
         "Programs": ["BlogEngine.NET"],
         "Bugs": ["XXE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-11",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "A tale of a full Business Takeover — Red Team Diaries",
               "Link": "https://infosecwriteups.com/a-tale-of-a-full-business-takeover-red-team-diaries-fe7a6a7acaef"
            }
         ],
         "Authors": ["Dhanesh Dodia - HeyDanny (@Dhanesh_Dodia)"],
         "Programs": ["-"],
         "Bugs": ["MITM", "Credential stuffing", "Password spraying"],
         "Bounty": "-",
         "PublicationDate": "2023-02-11",
         "AddedDate": "2023-02-11"
      },
      {
         "Links": [
            {
               "Title": "We Hacked GitHub for a Month: Here’s What We Found",
               "Link": "https://blog.cyberxplore.com/we-hacked-github-for-a-month-heres-what-we-found/"
            }
         ],
         "Authors": ["Shivam Kumar Singh (@MrRajputHacker)", "Vansh Devgan (@Th3Pr0xyB0y)"],
         "Programs": ["GitHub"],
         "Bugs": ["Pre-account takeover", "Broken Access Control", "Email verification bypass", "Logic flaw"],
         "Bounty": "10,000",
         "PublicationDate": "2023-02-11",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "HubSpot Full Account Takeover in Bug Bounty",
               "Link": "https://omar0x01.medium.com/hubspot-full-account-takeover-in-bug-bounty-4e2047914ab5"
            }
         ],
         "Authors": ["Omar Hashem (@OmarHashem666)"],
         "Programs": ["HubSpot"],
         "Bugs": ["Account takeover", "Hyperlink injection", "Password reset"],
         "Bounty": "-",
         "PublicationDate": "2023-02-11",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Disabling js for the win",
               "Link": "https://infosecwriteups.com/disabling-js-for-the-win-9d13c606f910"
            }
         ],
         "Authors": ["Vuk Ivanovic"],
         "Programs": ["-"],
         "Bugs": ["Unrestricted file upload", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-10",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "LocalPotato - When Swapping The Context Leads You To SYSTEM",
               "Link": "https://decoder.cloud/2023/02/13/localpotato-when-swapping-the-context-leads-you-to-system/"
            },
            {
               "Title": "Alternative link",
               "Link": "https://www.localpotato.com/localpotato_html/LocalPotato.html"
            }
         ],
         "Authors": ["Andrea Pierini (@decoder_it)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Windows", "NTLM", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-10",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Information disclosure or GDPR breach? A Google tale…",
               "Link": "https://medium.com/@lukeberner/information-disclosure-to-gdpr-breach-a-google-tale-f9e99fd5d648"
            }
         ],
         "Authors": ["Luke Berner"],
         "Programs": ["Google"],
         "Bugs": ["Privacy issue", "Information disclosure", "Missing authentication"],
         "Bounty": "500",
         "PublicationDate": "2023-02-10",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023–0759 / Privilege Escalation in the Cockpit CMS",
               "Link": "https://cupc4k3.medium.com/cve-2023-0759-privilege-escalation-in-the-cockpit-cms-6a4a28685f8e"
            }
         ],
         "Authors": ["cupc4k3"],
         "Programs": ["Cockpit CMS"],
         "Bugs": ["Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-09",
         "AddedDate": "2024-02-27"
      },
      {
         "Links": [
            {
               "Title": "Elevation of privileges from Everyone through Avast Sandbox to System AmPPL (CVE-2021-45335, CVE-2021-45336 and CVE-2021-45337)",
               "Link": "https://the-deniss.github.io/posts/2023/02/09/elevation-of-privileges-from-everyone-through-avast-av-sandbox-to-system-amppl.html"
            }
         ],
         "Authors": ["Denis Skvortcov (@Denis_Skvortcov)"],
         "Programs": ["Avast"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-09",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "A-Salt: attacking SaltStack",
               "Link": "https://skylightcyber.com/2023/02/09/a-salt-attacking-saltstack/"
            }
         ],
         "Authors": ["Alex Hill"],
         "Programs": ["-"],
         "Bugs": ["SSTI", "Security misconfiguration", "Information disclosure", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-09",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Cracking The Odd Case Of Randomness In Java",
               "Link": "https://www.elttam.com/blog/cracking-randomness-in-java/"
            }
         ],
         "Authors": ["Joseph (@josep68_)"],
         "Programs": ["-"],
         "Bugs": ["Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2023-02-09",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "How I got $$$$ Bounty within 5 mins",
               "Link": "https://p4n7h3rx.medium.com/how-i-got-bounty-within-5-mins-f1448f6db9b5"
            }
         ],
         "Authors": ["Hashir Khan (@P4n7h3Rx)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2023-02-09",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Azure Ad Kerberos Tickets: Pivoting To The Cloud",
               "Link": "https://www.trustedsec.com/blog/azure-ad-kerberos-tickets-pivoting-to-the-cloud/"
            }
         ],
         "Authors": ["Edwin David"],
         "Programs": ["-"],
         "Bugs": ["Active Directory", "Cloud", "Lateral movement"],
         "Bounty": "-",
         "PublicationDate": "2023-02-09",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Exploits Explained: Default Credentials Still a Problem Today",
               "Link": "https://www.synack.com/blog/default-credentials-still-a-problem-today/"
            }
         ],
         "Authors": ["Popeax"],
         "Programs": ["-"],
         "Bugs": ["Default credentials"],
         "Bounty": "-",
         "PublicationDate": "2023-02-09",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Exploit Development – A Sincere Form of Flattery",
               "Link": "https://www.blackhillsinfosec.com/exploit-development-a-sincere-form-of-flattery/"
            }
         ],
         "Authors": ["moth"],
         "Programs": ["-"],
         "Bugs": ["MS-RPC", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-09",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Pwn2Owning Two Hosts At The Same Time: Abusing Inductive Automation Ignition’s Custom Deserialization",
               "Link": "https://www.zerodayinitiative.com/blog/2023/2/6/pwn2owning-two-hosts-at-the-same-time-abusing-inductive-automation-ignitions-custom-deserialization"
            }
         ],
         "Authors": ["Piotr Bazydło (@chudyPB)"],
         "Programs": ["Inductive Automation Ignition"],
         "Bugs": ["Insecure deserialization", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-08",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Chaining Bugs to get my First Bug Bounty",
               "Link": "https://infosecwriteups.com/chaining-bugs-to-get-my-first-bug-bounty-7e94afb704e7"
            }
         ],
         "Authors": ["ag3n7 (@ag3n7apk)"],
         "Programs": ["-"],
         "Bugs": ["CSRF", "Open redirect", "Clickjacking", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-02-08",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "Reflected XSS on Target with tough WAF ( WAF Bypass )",
               "Link": "https://jowin922.medium.com/reflected-xss-on-target-with-tough-waf-waf-bypass-3b7efd1ef2bc"
            }
         ],
         "Authors": ["Eagle_92"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-02-08",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Dota 2 Under Attack: How a V8 Bug Was Exploited in the Game",
               "Link": "https://decoded.avast.io/janvojtesek/dota-2-under-attack-how-a-v8-bug-was-exploited-in-the-game/"
            }
         ],
         "Authors": ["Jan Vojtěšek"],
         "Programs": ["Valve"],
         "Bugs": ["V8 JavaScript engine", "Memory corruption", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-08",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Bypassing API Restrictions for Fun and Profit",
               "Link": "https://arnavtripathy98.medium.com/bypassing-api-restrictions-for-fun-and-profit-c9ab746b67be"
            }
         ],
         "Authors": ["Arnav Tripathy"],
         "Programs": ["-"],
         "Bugs": ["Payment bypass", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2023-02-07",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "How I Got +1000$ by Clickjacking",
               "Link": "https://medium.com/@mydudehello91/how-i-got-1000-by-clickacking-233e89d76ffd"
            }
         ],
         "Authors": ["Aryan W13DOM (@NeuRosis23)"],
         "Programs": ["-"],
         "Bugs": ["Clickjacking"],
         "Bounty": "1,000",
         "PublicationDate": "2023-02-07",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "[CVE-2023-22855] Kardex MLOG - Insecure path join to RCE via SSTI",
               "Link": "https://hesec.de/posts/cve-2023-22855/"
            }
         ],
         "Authors": ["Patrick Hener (@C1sc01)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "SSTI", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-07",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Code Injection via Python Sandbox Escape — how I got a shell inside a network.",
               "Link": "https://medium.com/@mares.viktor/code-injection-via-python-sandbox-escape-how-i-got-a-shell-inside-a-network-c977c35a82de"
            }
         ],
         "Authors": ["Viktor Mares"],
         "Programs": ["-"],
         "Bugs": ["Code injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-07",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Post-Exploitation: Abusing the KeePass Plugin Cache",
               "Link": "https://blog.quarkslab.com/post-exploitation-abusing-the-keepass-plugin-cache.html"
            }
         ],
         "Authors": ["Kevin Minacori"],
         "Programs": ["KeePass"],
         "Bugs": ["Local Privilege Escalation", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2023-02-07",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "The Linux Kernel and the Cursed Driver",
               "Link": "https://www.cyberark.com/resources/threat-research-blog/the-linux-kernel-and-the-cursed-driver"
            }
         ],
         "Authors": ["Alon Zahavi (@Alon_Z4)"],
         "Programs": ["Linux Kernel Organization"],
         "Bugs": ["Kernel hacking", "NULL pointer dereference"],
         "Bounty": "-",
         "PublicationDate": "2023-02-07",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "A zero day for the government’s “demo servers” and internal networks",
               "Link": "https://read.martiandefense.llc/a-zero-day-for-demo-servers-and-internal-government-networks-96acda9e83ed"
            }
         ],
         "Authors": ["fopwn"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-02-06",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Hacking into Toyota’s global supplier management network",
               "Link": "https://eaton-works.com/2023/02/06/toyota-gspims-hack/"
            }
         ],
         "Authors": ["Eaton Z. (@XeEaton)"],
         "Programs": ["Toyota"],
         "Bugs": ["Authentication bypass", "Backdoor"],
         "Bounty": "-",
         "PublicationDate": "2023-02-06",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Discovering a weakness leading to a partial bypass of the login rate limiting in the AWS Console",
               "Link": "https://securitylabs.datadoghq.com/articles/aws-console-rate-limit-bypass/"
            }
         ],
         "Authors": ["Christophe Tafani-Dereeper (@christophetd)"],
         "Programs": ["AWS"],
         "Bugs": ["Rate limiting bypass", "Bruteforce"],
         "Bounty": "-",
         "PublicationDate": "2023-02-06",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Apache SCXML Remote Code Execution",
               "Link": "https://pyn3rd.github.io/2023/02/06/Apache-Commons-SCXML-Remote-Code-Execution/"
            }
         ],
         "Authors": ["pyn3rd (@pyn3rd)"],
         "Programs": ["Apache SCXML"],
         "Bugs": ["RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-06",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "GoAnywhere MFT - A Forgotten Bug",
               "Link": "https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html"
            }
         ],
         "Authors": ["Florian Hauser (@frycos)"],
         "Programs": ["Fortra (GoAnywhere)"],
         "Bugs": ["Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-06",
         "AddedDate": "2023-02-09"
      },
      {
         "Links": [
            {
               "Title": "How we made $120k bug bounty in a year with good automation",
               "Link": "https://www.vidocsecurity.com/blog/2022-summary-how-we-made-120k-bug-bounty-in-a-year/"
            }
         ],
         "Authors": ["Dawid Moczadło (@kannthu1)", "Klaudia Kloc"],
         "Programs": ["-"],
         "Bugs": ["XSS", "Security misconfiguration", "Log4shell", "Debug mode enabled"],
         "Bounty": "120,000",
         "PublicationDate": "2023-02-06",
         "AddedDate": "2023-02-07"
      },
      {
         "Links": [
            {
               "Title": "Easy Account Takeover on dell subdomain",
               "Link": "https://medium.com/@2os5/easy-account-takeover-on-dell-subdomain-6297460741fd"
            }
         ],
         "Authors": ["Mohamed Fares (@_2os5)"],
         "Programs": ["Dell"],
         "Bugs": ["Password reset", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-02-05",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "I was able to see likes count even though it was hidden by the victim | YouTube App 16.15.35",
               "Link": "https://bloggerrando.blogspot.com/2023/02/06-2.html"
            }
         ],
         "Authors": ["R ando (@Rando02355205)"],
         "Programs": ["Google (Youtube)"],
         "Bugs": ["Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2023-02-05",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Memcached Command Injections at Pylibmc",
               "Link": "https://btlfry.gitlab.io/notes/posts/memcached-command-injections-at-pylibmc/"
            }
         ],
         "Authors": ["Zakhar Fedotkin / d4d (@d4d89704243)"],
         "Programs": ["Flask-Session"],
         "Bugs": ["CRLF injection", "Memcached command injection", "Insecure deserialization", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-04",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "SSO Gadgets: Escalate (Self-)XSS to ATO",
               "Link": "https://security.lauritz-holtmann.de/post/xss-ato-gadgets/"
            }
         ],
         "Authors": ["Lauritz Holtmann (@_lauritz_)"],
         "Programs": ["-"],
         "Bugs": ["SSO", "OAuth", "Account takeover", "Self-XSS", "Login CSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-02-04",
         "AddedDate": "2023-02-07"
      },
      {
         "Links": [
            {
               "Title": "postMessage DOM XSS vulnerability in Gartner Peer Insights widget",
               "Link": "https://kindergartner.computerhacker.ring0.lol"
            }
         ],
         "Authors": ["Justin Steven (@justinsteven)"],
         "Programs": ["Gartner", "Gradle", "LogRhythm", "SentinelOne", "Synopsys", "Veeam", "Vodafone", "Black Kite", "ReversingLabs", "Tata Communications"],
         "Bugs": ["postMessage", "DOM XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-02-04",
         "AddedDate": "2023-02-07"
      },
      {
         "Links": [
            {
               "Title": "A weird bug that leaked PII",
               "Link": "https://medium.com/@jawadmahdi/a-weird-bug-that-leaked-pii-9e2e91a8b8c8"
            }
         ],
         "Authors": ["Jawad Mahdi (@hunter0x1)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-02-03",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "Authentication Bypass in Izanami Docker image 1.10.22 CVE-2023-22495",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-02/Synacktiv-Advisory-Izanami-CVE-2023-22495.pdf"
            }
         ],
         "Authors": ["Raphaël Lob"],
         "Programs": ["Izanami"],
         "Bugs": ["Authentication bypass", "JWT", "Security code review", "Container security"],
         "Bounty": "-",
         "PublicationDate": "2023-02-03",
         "AddedDate": "2023-03-06"
      },
      {
         "Links": [
            {
               "Title": "Play with Google, Twitter, Apple, Dell",
               "Link": "https://medium.com/@rezaduty/play-with-google-twitter-apple-dell-a90777faa779"
            }
         ],
         "Authors": ["rezaduty (@rezaduty)"],
         "Programs": ["Google", "Twitter", "Apple", "Dell"],
         "Bugs": ["XSS", "HTML injection", "IDOR", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-02-03",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Azure security — Internal recon leveraging lack of access control",
               "Link": "https://molx32.github.io/blog/2023/Azure-access-panel-lack-of-access-control/"
            }
         ],
         "Authors": ["Molx32"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Azure AD", "Cloud", "Security misconfiguration", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-04-27"
      },
      {
         "Links": [
            {
               "Title": "WEEKEND DESTROYER - RCE in Western Digital PR4100 NAS",
               "Link": "https://www.flashback.sh/blog/weekend-destroyer-wd-pr4100-rce"
            }
         ],
         "Authors": ["Pedro Ribeiro (@pedrib1337)", "Radek Domanski (@RabbitPro)"],
         "Programs": ["Western Digital"],
         "Bugs": ["RCE", "Hardcoded credentials", "Privilege escalation", "Cryptographic issues", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "Discovering 5 XSS Vulnerabilities In a Simple Way With Xssor.go",
               "Link": "https://medium.com/@bag0zathev2/discovering-5-xss-vulnerabilities-in-a-simple-way-with-xssor-go-a0a761631012"
            }
         ],
         "Authors": ["Fares Walid (@SirBagoza)"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "Host Header Injection to Complete Organization takeover",
               "Link": "https://medium.com/@_yldrm/host-header-injection-to-complete-organization-takeover-67a8a2ddb188"
            }
         ],
         "Authors": ["Muhammad Umer Adeem"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "Host header injection", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "IDOR - Inside the Session Storage",
               "Link": "https://shahjerry33.medium.com/idor-inside-the-session-storage-88af485fc899"
            }
         ],
         "Authors": ["Jerry Shah (@Jerry)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 1",
               "Link": "https://www.cyberark.com/resources/threat-research-blog/breaking-docker-named-pipes-systematically-docker-desktop-privilege-escalation-part-1"
            }
         ],
         "Authors": ["Eviatar Gerzi"],
         "Programs": ["Docker"],
         "Bugs": ["Local Privilege Escalation", "Windows", "Thick client"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "WEEKEND DESTROYER - RCE in Western Digital PR4100 NAS",
               "Link": "https://www.flashback.sh/blog/weekend-destroyer-wd-pr4100-rce"
            }
         ],
         "Authors": ["Pedro Ribeiro (@pedrib1337)", "Radek Domanski (@RabbitPro)"],
         "Programs": ["Western Digital"],
         "Bugs": ["RCE", "Hardcoded credentials", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Pre-Auth RCE in Aspera Faspex: Case Guide for Auditing Ruby on Rails",
               "Link": "https://blog.assetnote.io/2023/02/02/pre-auth-rce-aspera-faspex/"
            }
         ],
         "Authors": ["Maxwell Garrett (@TheGrandPew)", "Shubham Shah (@infosec_au)"],
         "Programs": ["IBM"],
         "Bugs": ["RCE", "Security code review", "Missing authentication", "Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-02-03"
      },
      {
         "Links": [
            {
               "Title": "Exploits Explained: Java JMX’s Exploitation Problems and Resolutions",
               "Link": "https://www.synack.com/blog/exploits-explained-java-jmxs-exploitation-problems-and-resolutions/"
            }
         ],
         "Authors": ["Nicolas Krassas (@Dinosn)"],
         "Programs": ["-"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-02-03"
      },
      {
         "Links": [
            {
               "Title": "Vulnerability Causing Deletion of All Users in CrushFTP Admin Area",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/vulnerability-causing-deletion-of-all-users-in-crushftp-admin-area/"
            }
         ],
         "Authors": ["Jean Calvin Mugabo"],
         "Programs": ["CrushFTP"],
         "Bugs": ["Application-level DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-02-03"
      },
      {
         "Links": [
            {
               "Title": "CentreStack Disclosure",
               "Link": "https://www.whiteoaksecurity.com/blog/centrestack-disclosure/"
            }
         ],
         "Authors": ["Michael Rand"],
         "Programs": ["Gladinet (CentreStack)"],
         "Bugs": ["Authentication bypass", "Password reset", "Unrestricted file upload", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-02-02",
         "AddedDate": "2023-02-03"
      },
      {
         "Links": [
            {
               "Title": "ImageMagick: The hidden vulnerability behind your online images",
               "Link": "https://www.metabaseq.com/imagemagick-zero-days/"
            }
         ],
         "Authors": ["Bryan Gonzalez"],
         "Programs": ["ImageMagick"],
         "Bugs": ["Application-level DoS", "Arbitrary file read", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-01",
         "AddedDate": "2023-02-07"
      },
      {
         "Links": [
            {
               "Title": "An IDOR vulnerability often hides many others",
               "Link": "https://infosecwriteups.com/an-idor-vulnerability-often-hides-many-others-2893ddd0a0d7"
            }
         ],
         "Authors": ["Allam Rachid (@blank_cold)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "GraphQL"],
         "Bounty": "500",
         "PublicationDate": "2023-02-01",
         "AddedDate": "2023-02-07"
      },
      {
         "Links": [
            {
               "Title": "RCE in Avaya Aura Device Services",
               "Link": "https://blog.assetnote.io/2023/02/01/rce-in-avaya-aura/"
            }
         ],
         "Authors": ["Dylan Pindur"],
         "Programs": ["Avaya"],
         "Bugs": ["RCE", "Security code review", "XSS", "WebDAV"],
         "Bounty": "-",
         "PublicationDate": "2023-02-01",
         "AddedDate": "2023-02-03"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-22374: F5 BIG-IP Format String Vulnerability",
               "Link": "https://www.rapid7.com/blog/post/2023/02/01/cve-2023-22374-f5-big-ip-format-string-vulnerability/"
            }
         ],
         "Authors": ["Ron Bowes (@iagox86)"],
         "Programs": ["F5"],
         "Bugs": ["Format string vulnerability", "Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2023-02-01",
         "AddedDate": "2023-02-03"
      },
      {
         "Links": [
            {
               "Title": "Broken Function Level Authorization leads to disclosing PII Information of all company users",
               "Link": "https://webresearcher007.medium.com/broken-function-level-authorization-leads-to-disclosing-pii-information-of-all-company-users-35aee60b287b"
            }
         ],
         "Authors": ["Mirza Muhammad Fauzan"],
         "Programs": ["-"],
         "Bugs": ["Broken Function Level Authorization", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-01-31",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Mass Account takeover by bypassing 2 FA",
               "Link": "https://z-sec.co/mass-account-takeover"
            }
         ],
         "Authors": ["Zeeshan Mustafa (@by6153)"],
         "Programs": ["-"],
         "Bugs": ["2FA / MFA bypass", "IDOR", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-01-31",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Reversing UK mobile rail tickets",
               "Link": "https://eta.st/2023/01/31/rail-tickets.html"
            }
         ],
         "Authors": ["Zeeshan Mustafa (@by6153)"],
         "Programs": ["-"],
         "Bugs": ["Reverse engineering", "Android"],
         "Bounty": "-",
         "PublicationDate": "2023-01-31",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "Remote Command Execution in binwalk",
               "Link": "https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk/"
            }
         ],
         "Authors": ["Quentin Kaiser (@QKaiser)"],
         "Programs": ["ReFirm Labs (binwalk)", "ubi_reader", "jefferson", "yaffshiv"],
         "Bugs": ["RCE", "Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-01-31",
         "AddedDate": "2023-02-07"
      },
      {
         "Links": [
            {
               "Title": "Can't Wait to Shut You Down — Remote DoS Using Wininit.exe",
               "Link": "https://www.akamai.com/blog/security-research/cant-wait-to-shut-you-down-msrpc-wininit"
            }
         ],
         "Authors": ["Stiv Kupchik (@kupsul)"],
         "Programs": ["Microsoft"],
         "Bugs": ["DoS", "MS-RPC", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2023-01-31",
         "AddedDate": "2023-02-07"
      },
      {
         "Links": [
            {
               "Title": "Unserializable, But Unreachable: Remote Code Execution On vBulletin",
               "Link": "https://www.ambionics.io/blog/vbulletin-unserializable-but-unreachable"
            }
         ],
         "Authors": ["Charles Fol (@cfreal_)"],
         "Programs": ["vBulletin"],
         "Bugs": ["RCE", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-01-31",
         "AddedDate": "2023-02-03"
      },
      {
         "Links": [
            {
               "Title": "How I bypassed the registration validation and logged-in with the company email",
               "Link": "https://khaledyassen.medium.com/how-i-bypassed-the-registration-validation-and-logged-in-with-the-company-email-14eb12c45fb5"
            }
         ],
         "Authors": ["Khaledyassen"],
         "Programs": ["-"],
         "Bugs": ["Email verification bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-01-30",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "How i hacked all Zendesk sites 265,000 site by one line",
               "Link": "https://mazoka777.medium.com/how-i-hacked-all-zendesk-sites-265-000-site-by-one-line-c6b6485a7a6"
            }
         ],
         "Authors": ["Ahmed Salah Abdalhfaz (@Elsfa7-110)"],
         "Programs": ["Zendesk"],
         "Bugs": ["Web cache poisoning"],
         "Bounty": "-",
         "PublicationDate": "2023-01-30",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
            {
               "Title": "How I Found an Insecure Direct Object Reference in TikTok",
               "Link": "https://medium.com/@mrhavit/how-i-found-an-insecure-direct-object-reference-in-tiktok-c7303addf223"
            }
         ],
         "Authors": ["mrhavit"],
         "Programs": ["TikTok"],
         "Bugs": ["IDOR"],
         "Bounty": "5,500",
         "PublicationDate": "2023-01-29",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Discovered a Critical IDOR and Earned $900 for My First P1 Vulnerability!",
               "Link": "https://medium.com/@abhisekr/discovered-a-critical-idor-and-earned-900-for-my-first-p1-vulnerability-57c1e72f42c1"
            }
         ],
         "Authors": ["Abhisek R (@abh1sek_r)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "900",
         "PublicationDate": "2023-01-29",
         "AddedDate": "2023-02-07"
      },
      {
         "Links": [
            {
               "Title": "The 100+ Million Person Data Disclosure",
               "Link": "https://www.jhaddix.com/post/the-100-million-person-data-disclosure"
            }
         ],
         "Authors": ["Jason Haddix (@Jhaddix)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2023-01-29",
         "AddedDate": "2023-02-07"
      },
      {
         "Links": [
            {
               "Title": "How I was able to find 4 Cross-site scripting (XSS) on vulnerability disclosure program ?",
               "Link": "https://medium.com/@DrakenKun/how-i-was-able-to-find-4-cross-site-scripting-xss-on-vulnerability-disclosure-program-e2f39199ae16"
            }
         ],
         "Authors": ["DrakenKun"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-29",
         "AddedDate": "2023-02-07"
      },
      {
         "Links": [
            {
               "Title": "Blind XSS To SSRF",
               "Link": "https://akashc99.medium.com/blind-xss-to-ssrf-e2bc579976d"
            }
         ],
         "Authors": ["Akash c"],
         "Programs": ["-"],
         "Bugs": ["Blind XSS", "SSRF"],
         "Bounty": "500",
         "PublicationDate": "2023-01-29",
         "AddedDate": "2023-02-03"
      },
      {
         "Links": [
            {
               "Title": "DOM-XSS in Instant Games due to improper verification of supplied URLs",
               "Link": "https://ysamm.com/?p=779"
            }
         ],
         "Authors": ["Youssef Sammouda (@samm0uda)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["DOM XSS"],
         "Bounty": "62,500",
         "PublicationDate": "2023-01-29",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation",
               "Link": "https://ysamm.com/?p=783"
            }
         ],
         "Authors": ["Youssef Sammouda (@samm0uda)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["Account takeover", "postMessage"],
         "Bounty": "62,500",
         "PublicationDate": "2023-01-29",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
            {
               "Title": "Account takeover of Facebook/Oculus accounts due to First-Party access_token stealing",
               "Link": "https://ysamm.com/?p=777"
            }
         ],
         "Authors": ["Youssef Sammouda (@samm0uda)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["Account takeover", "OAuth", "Open redirect"],
         "Bounty": "44,250",
         "PublicationDate": "2023-01-29",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
            {
               "Title": "Froxlor v2.0.6 Remote Command Execution (CVE-2023-0315)",
               "Link": "https://shells.systems/froxlor-v2-0-6-remote-command-execution-cve-2023-0315/"
            },
            {
               "Title": "Exploit",
               "Link": "https://github.com/mhaskar/CVE-2023-0315"
            }
         ],
         "Authors": ["Askar (@mohammadaskar2)"],
         "Programs": ["Froxlor"],
         "Bugs": ["RCE", "Arbitrary file write", "SSTI", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-01-29",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
           {
              "Title": "Bypassing account lockout through password reset functionality",
              "Link": "https://akashc99.medium.com/bypassing-account-lockout-through-password-reset-functionality-8ff5c256f380"
           }
          ],
         "Authors": ["Akash c"],
         "Programs": ["-"],
         "Bugs": ["Rate limiting bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-01-28",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
           {
              "Title": "Adobe Acrobat Reader - resetForm - CAgg UaF - RCE Exploit - CVE-2023-21608",
              "Link": "https://hacksys.io/blogs/adobe-reader-resetform-cagg-rce-cve-2023-21608"
           }
          ],
         "Authors": ["Ashfaq Ansari (@HackSysTeam)", "Krishnakant Patil (@shsirk)"],
         "Programs": ["Adobe"],
         "Bugs": ["Memory corruption", "Use-After-Free", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-01-28",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-44789",
               "Link": "https://github.com/alalng/CVE-2022-44789"
            }
         ],
         "Authors": ["Alvin Ng (@alngpwn)"],
         "Programs": ["Artifex MuJS"],
         "Bugs": ["Memory corruption", "Use-After-Free", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-01-28",
         "AddedDate": "2023-02-22"
      },
      {
         "Links": [
            {
               "Title": "PHP Development Server <= 7.4.21 - Remote Source Disclosure",
               "Link": "https://blog.projectdiscovery.io/php-http-server-source-disclosure/"
            }
         ],
         "Authors": ["Rahul Maini (@iamnoooob)", "Harsh Jaiswal (@rootxharsh)"],
         "Programs": ["PHP"],
         "Bugs": ["Source code disclosure", "Information disclosure", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-01-28",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
            {
               "Title": "Disclosing Facebook page admins by playing a game",
               "Link": "https://medium.com/@sudipshah_66336/disclosing-facebook-page-admins-by-playing-a-game-2b0f4ed082e4"
            }
         ],
         "Authors": ["Sudip Shah"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["Logic flaw", "Information disclosure"],
         "Bounty": "2,075",
         "PublicationDate": "2023-01-28",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
            {
               "Title": "Bypassing OGNL sandboxes for fun and charities",
               "Link": "https://github.blog/2023-01-27-bypassing-ognl-sandboxes-for-fun-and-charities/"
            }
         ],
         "Authors": ["Alvaro Muñoz (@pwntester)"],
         "Programs": ["Atlassian", "Apache Struts"],
         "Bugs": ["OGNL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-01-27",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "How I Found My First Bug in Android App",
               "Link": "https://medium.com/@severustalin/how-i-found-my-first-bug-in-android-41153093ba57"
            }
         ],
         "Authors": ["Barath Stalin"],
         "Programs": ["-"],
         "Bugs": ["Android", "Authentication bypass", "Insecure intent"],
         "Bounty": "-",
         "PublicationDate": "2023-01-26",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "Ransacking your password reset tokens",
               "Link": "https://positive.security/blog/ransack-data-exfiltration"
            }
         ],
         "Authors": ["Lukas Euler"],
         "Programs": ["Ransack library"],
         "Bugs": ["Account takeover", "Password reset", "Bruteforce"],
         "Bounty": "-",
         "PublicationDate": "2023-01-26",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
            {
               "Title": "OpenEMR - Remote Code Execution in your Healthcare System",
               "Link": "https://www.sonarsource.com/blog/openemr-remote-code-execution-in-your-healthcare-system/"
            }
         ],
         "Authors": ["Dennis Brinkrolf (@DBrinkrolf)"],
         "Programs": ["OpenEMR"],
         "Bugs": ["RCE", "XSS", "LFI", "Arbitrary file read", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-01-26",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
            {
               "Title": "Kamailio’s exec module considered harmful",
               "Link": "https://www.rtcsec.com/article/kamailio-exec-module-considered-harmful/"
            }
         ],
         "Authors": ["Ali Norouzi", "Sandro Gauci (@sandrogauci)"],
         "Programs": ["Kamailio"],
         "Bugs": ["OS command injection", "SIP"],
         "Bounty": "-",
         "PublicationDate": "2023-01-26",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
            {
               "Title": "Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI",
               "Link": "https://www.akamai.com/blog/security-research/exploiting-critical-spoofing-vulnerability-microsoft-cryptoapi"
            }
         ],
         "Authors": ["Tomer Peled (@tomerpeled92)", "Yoni Rozenshein"],
         "Programs": ["Microsoft"],
         "Bugs": ["Windows", "Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2023-01-25",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "MyBB <= 1.8.31: Remote Code Execution Chain",
               "Link": "https://swarm.ptsecurity.com/mybb-1-8-31-remote-code-execution-chain/"
            }
         ],
         "Authors": ["Aleksey Solovev"],
         "Programs": ["MyBB"],
         "Bugs": ["RCE", "SQL injection", "Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-25",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "Easy 2000$ Race Condition",
               "Link": "https://medium.com/@_deshine_/easy-2000-race-condition-b4d093c9bc3c"
            }
         ],
         "Authors": ["Deshine"],
         "Programs": ["-"],
         "Bugs": ["Race condition"],
         "Bounty": "2,000",
         "PublicationDate": "2023-01-25",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "Unleashing the power of CSS injection: The access key to an internal API",
               "Link": "https://sanderwind.medium.com/unleashing-the-power-of-css-injection-the-access-key-to-an-internal-api-789b166d0527"
            }
         ],
         "Authors": ["Sander Wind (@SanderWind)"],
         "Programs": ["-"],
         "Bugs": ["CSS injection"],
         "Bounty": "-",
         "PublicationDate": "2023-01-24",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Jumping into SOCKS",
               "Link": "https://sensepost.com/blog/2023/jumping-into-socks/"
            }
         ],
         "Authors": ["Jacques Coertze (@JCoertze)"],
         "Programs": ["-"],
         "Bugs": ["Lateral movement"],
         "Bounty": "-",
         "PublicationDate": "2023-01-24",
         "AddedDate": "2023-02-13"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI",
               "Link": "https://blog.assetnote.io/2023/01/24/yellowfin-auth-bypass-to-rce/"
            }
         ],
         "Authors": ["Maxwell Garrett (@TheGrandPew)", "Shubham Shah (@infosec_au)"],
         "Programs": ["Yellowfin BI"],
         "Bugs": ["RCE", "Authentication bypass", "Security code review", "JWT"],
         "Bounty": "-",
         "PublicationDate": "2023-01-24",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "Using 0days to Protect the United Nations",
               "Link": "https://frycos.github.io/vulns4free/2023/01/24/0days-united-nations.html"
            }
         ],
         "Authors": ["Florian Hauser (@frycos)"],
         "Programs": ["United Nations"],
         "Bugs": ["RCE", "Authentication bypass", "Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2023-01-24",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "CrossTalk and Secret Agent: Two Attack Vectors on Okta's Identity Suite",
               "Link": "https://www.varonis.com/blog/okta-attack-vectors"
            }
         ],
         "Authors": ["Tal Peleg", "Nitay Bachrach"],
         "Programs": ["Okta"],
         "Bugs": ["Insecure storage of sensitive information", "Phishing"],
         "Bounty": "-",
         "PublicationDate": "2023-01-23",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "CVE from 2018 Strikes Again",
               "Link": "https://blog.stratumsecurity.com/2023/01/23/remote-code-execution-through-deserializtion/"
            }
         ],
         "Authors": ["Colin McQueen"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Insecure deserialization", "Thick client"],
         "Bounty": "-",
         "PublicationDate": "2023-01-23",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "Activation Context Cache Poisoning: Exploiting CSRSS For Privilege Escalation",
               "Link": "https://www.zerodayinitiative.com/blog/2023/1/23/activation-context-cache-poisoning-exploiting-csrss-for-privilege-escalation"
            }
         ],
         "Authors": ["Simon Zuckerbraun"],
         "Programs": ["Microsoft"],
         "Bugs": ["Local Privilege Escalation", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2023-01-23",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "How i Hacked Scopely with “Sign in with Google”",
               "Link": "https://ph-hitachi.medium.com/how-i-hacked-scopely-using-sign-in-with-google-298a9c166ad"
            }
         ],
         "Authors": ["Ph.Hitachi"],
         "Programs": ["Scopely"],
         "Bugs": ["Account takeover", "CORS misconfiguration", "Client-side enforcement of server-side security", "OAuth"],
         "Bounty": "-",
         "PublicationDate": "2023-01-23",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "CVE-2023-24068 && CVE-2023-24069: Abusing Signal Desktop Client for fun and for Espionage",
               "Link": "https://johnjhacking.com/blog/cve-2023-24068-cve-2023-24069/"
            }
         ],
         "Authors": ["John Jackson (@johnjhacking)"],
         "Programs": ["Signal"],
         "Bugs": ["Thick client", "Insecure data storage", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-01-22",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "How i was able to get critical bug on google by get full access on [Google Cloud BI Hackathon]",
               "Link": "https://orwaatyat.medium.com/how-i-was-able-to-get-critical-bug-on-google-by-get-full-access-on-google-cloud-bi-hackathon-f779fce29900"
            }
         ],
         "Authors": ["Orwa Atyat (@GodfatherOrwa)"],
         "Programs": ["Google"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-01-22",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "Reflected XSS Leads to 3,000$ Bug Bounty Rewards from Microsoft Forms",
               "Link": "https://infosecwriteups.com/reflected-xss-leads-to-3-000-bug-bounty-rewards-from-microsoft-forms-efe34fc6b261"
            }
         ],
         "Authors": ["Supakiad S. (@Supakiad_Mee)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "3,000",
         "PublicationDate": "2023-01-22",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "How I found XSS on Admin Page without login!",
               "Link": "https://sl4x0.medium.com/how-i-found-xss-on-admin-page-without-login-fe165a5f89c2"
            }
         ],
         "Authors": ["Abdelrhman Allam (@sl4x0)"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-22",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "Bypassing Cloudflare WAF: XSS via SQL Injection",
               "Link": "https://www.ukusormus.com/bypassing-cloudflare-waf-xss-via-sql-injection/"
            }
         ],
         "Authors": ["Uku Sõrmus"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS", "SQL injection", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-01-21",
         "AddedDate": "2023-01-31"
      },
      {
         "Links": [
            {
               "Title": "Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP”",
               "Link": "https://securityintelligence.com/posts/dissecting-exploiting-tcp-ip-rce-vulnerability-evilesp/?"
            }
         ],
         "Authors": ["Valentina Palmiotti (@chompie1337)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Kernel hacking",  "Windows", "RCE","Memory corruption", "Buffer Overflow"],
         "Bounty": "-",
         "PublicationDate": "2023-01-20",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "Vulnerabilities in ManageEngine ADSelfService Plus 6.1 build 6117",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-01/advisory_manageengine_adss_2023.pdf"
            }
         ],
         "Authors": ["Antoine Cervoise (@acervoise)", "Wilfried Bécard (@tiyeuse)"],
         "Programs": ["Zoho (ManageEngine)"],
         "Bugs": ["RCE", "OS command injection", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-01-20",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "CSRF + Stored XSS Leading to Full Account Takeover",
               "Link": "https://medium.com/@bag0zathev2/csrf-stored-xss-to-leading-to-full-account-takeover-39e9a79533e3"
            }
         ],
         "Authors": ["Fares Walid (@SirBagoza)"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS", "CSRF", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-01-20",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "Bypassing E2E encryption leads to multiple high vulnerabilities.",
               "Link": "https://melotover.medium.com/bypassing-e2e-encryption-leads-to-multiple-high-vulnerabilities-65b708e5ad84"
            }
         ],
         "Authors": ["Asem Eleraky (@melotover)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-01-20",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "Technical Advisory – Multiple Vulnerabilities in the Galaxy App Store (CVE-2023-21433, CVE-2023-21434)",
               "Link": "https://research.nccgroup.com/2023/01/20/technical-advisory-multiple-vulnerabilities-in-the-galaxy-app-store-cve-2023-21433-cve-2023-21434/"
            }
         ],
         "Authors": ["Ken Gannon (@Yogehi)"],
         "Programs": ["Samsung"],
         "Bugs": ["Android", "Insecure intent", "Insecure deeplink", "URL validation bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-01-20",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "Two Factor Authentication Bypass On Facebook",
               "Link": "https://medium.com/pentesternepal/two-factor-authentication-bypass-on-facebook-3f4ac3ea139c"
            }
         ],
         "Authors": ["Gtm Mänôz (@Gtm0x01)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["2FA / MFA bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-01-20",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "AWS Cognito pitfalls: Default settings attackers love (and you should know about)",
               "Link": "https://www.secforce.com/blog/aws-cognito-pitfalls-default-settings-attackers-love-and-you-should-know-about/"
            }
         ],
         "Authors": ["Lorenzo Vogelsang (@ptrac3)"],
         "Programs": ["-"],
         "Bugs": ["Amazon cognito misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-01-19",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-35690: Unauthenticated RCE In Adobe ColdFusion",
               "Link": "https://www.zerodayinitiative.com/blog/2023/1/18/cve-2022-35690-unauthenticated-rce-in-adobe-coldfusion"
            }
         ],
         "Authors": ["rgod"],
         "Programs": ["Adobe"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-01-19",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-47966 SAML ShowStopper",
               "Link": "https://blog.viettelcybersecurity.com/saml-show-stopper/"
            }
         ],
         "Authors": ["Khoa Dinh (@_l0gg)"],
         "Programs": ["Zoho (ManageEngine)"],
         "Bugs": ["SAML", "XSLT injection"],
         "Bounty": "-",
         "PublicationDate": "2023-01-19",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "The easiest way I used to bypass an admin panel",
               "Link": "https://medium.com/@siratsami71/the-easiest-way-i-used-to-bypass-an-admin-panel-93d4297ed4a6"
            }
         ],
         "Authors": ["Sirat Sami (@siratsami71)"],
         "Programs": ["-"],
         "Bugs": ["HTTP request smuggling", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-01-19",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "EmojiDeploy: Smile! Your Azure web service just got RCE’d ._.",
               "Link": "https://ermetic.com/blog/azure/emojideploy-smile-your-azure-web-service-just-got-rced/"
            }
         ],
         "Authors": ["Liv Matan (@terminatorLM)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["RCE", "Cloud", "CSRF", "CORS misconfiguration"],
         "Bounty": "30,000",
         "PublicationDate": "2023-01-19",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "API Misconfiguration - No Swag of SwaggerUI",
               "Link": "https://shahjerry33.medium.com/api-misconfiguration-no-swag-of-swaggerui-9b43135346be"
            }
         ],
         "Authors": ["Jerry Shah (@Jerry)"],
         "Programs": ["-"],
         "Bugs": ["Security misconfiguration", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-01-19",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "Azure Active Directory Flaw Allowed SAML Persistence",
               "Link": "https://www.secureworks.com/research/azure-active-directory-flaw-allowed-saml-persistence"
            }
         ],
         "Authors": ["Secureworks Counter Threat Unit (@Secureworks)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Azure AD", "SAML", "SSO"],
         "Bounty": "-",
         "PublicationDate": "2023-01-18",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "Nothing new under the Sun – Discovering and exploiting a CDE bug chain",
               "Link": "https://security.humanativaspa.it/nothing-new-under-the-sun/"
            }
         ],
         "Authors": ["Marco Ivaldi / Raptor (@0xdea)"],
         "Programs": ["Oracle"],
         "Bugs": ["Printer hacking", "Local Privilege Escalation", "Memory corruption", "Buffer Overflow"],
         "Bounty": "-",
         "PublicationDate": "2023-01-18",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "The MarkdownTime Vulnerability: How to Avoid This DoS Attack on Business Critical Services",
               "Link": "https://www.legitsecurity.com/blog/dos-via-software-supply-chain-innumerable-projects-exposed-to-a-markdown-library-vulnerability"
            }
         ],
         "Authors": ["Tor Beer (@tor19951)"],
         "Programs": ["GitLab", "GitHub", "commonmarker RubyGem"],
         "Bugs": ["DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-18",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "How I identified and reported vulnerabilities in Oracle and the rewards of responsible disclosure:From Backup Leak to Hall of Fame",
               "Link": "https://medium.com/@Parag_Bagul/how-i-identified-and-reported-vulnerabilities-in-oracle-and-the-rewards-of-responsible-43ee5fea457f"
            }
         ],
         "Authors": ["ParagBagul"],
         "Programs": ["Oracle"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-01-18",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "Sudoedit bypass in Sudo <= 1.9.12p1 (CVE-2023-22809)",
               "Link": "https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf"
            }
         ],
         "Authors": ["Matthieu Barjole (@aevy__)", "Victor Cutillas (@v1csec)"],
         "Programs": ["Sudo"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-01-18",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "From Error_Log File(P4) To Company Account Takeover(P1) and Unauthorized Actions On API",
               "Link": "https://medium.com/@mohanad.hussam23/from-error-log-file-p4-to-company-account-takeover-p1-and-unauthorized-actions-on-api-35e45e43273a"
            }
         ],
         "Authors": ["Muhanad Israiwi (@IsrewyMohand)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-01-17",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "Security Audit of Git",
               "Link": "https://x41-dsec.de/security/research/news/2023/01/17/git-security-audit-ostif/"
            }
         ],
         "Authors": ["Markus Vervier (@marver)", "Eric Sesterhenn", "Joern Schneeweisz (@joernchen)", "Patrick Steinhardt"],
         "Programs": ["Git"],
         "Bugs": ["Memory corruption", "Out-of-bounds Write", "Out-of-bounds Read"],
         "Bounty": "-",
         "PublicationDate": "2023-01-17",
         "AddedDate": "2023-01-28"
      },
      {
         "Links": [
            {
               "Title": "XML Security in Java",
               "Link": "https://semgrep.dev/blog/2022/xml-security-in-java"
            }
         ],
         "Authors": ["Pieter De Cremer (@0xDC0DE)", "Vasilii Ermilov (@ermil0v)"],
         "Programs": ["-"],
         "Bugs": ["XXE", "Billion laugh attack", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-17",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "Centreon map vulnerability",
               "Link": "https://www.dsecbypass.com/en/centreon-map-vulnerability/"
            }
         ],
         "Authors": ["Vladimir"],
         "Programs": ["Centreon"],
         "Bugs": ["Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-01-17",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "How Orca Found Server-Side Request Forgery (SSRF) Vulnerabilities in Four Different Azure Services",
               "Link": "https://orca.security/resources/blog/ssrf-vulnerabilities-in-four-azure-services/"
            }
         ],
         "Authors": ["Lidor Ben Shitrit"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["SSRF", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2023-01-17",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "DOM-Based XSS for fun and profit $$$! | Bug Bounty POC",
               "Link": "https://medium.com/@haroonhameed_76621/dom-based-xss-for-fun-and-profit-bug-bounty-poc-f4b9554e95d"
            }
         ],
         "Authors": ["Haroon Hameed (@HaroonHameed40)", "Hannan Haseeb (@HannanHaseeb11)"],
         "Programs": ["-"],
         "Bugs": ["DOM XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-17",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "AWS CloudTrail vulnerability: Undocumented API allows CloudTrail bypass",
               "Link": "https://securitylabs.datadoghq.com/articles/iamadmin-cloudtrail-bypass/"
            }
         ],
         "Authors": ["Nick Frichette (@frichette_n)"],
         "Programs": ["AWS"],
         "Bugs": ["Cloud", "Logic flaw", "CloudTrail bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-01-17",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "Unauthenticated Configuration Export in Multiple WAGO Products",
               "Link": "https://onekey.com/blog/security-advisory-wago-unauthenticated-config-export-vulnerability/"
            }
         ],
         "Authors": ["ONEKEY (@onekey_sec)"],
         "Programs": ["WAGO"],
         "Bugs": ["Path traversal", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-02-16",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "2022 Microsoft Teams RCE",
               "Link": "https://blog.pksecurity.io/2023/01/16/2022-microsoft-teams-rce.html"
            }
         ],
         "Authors": ["@adm1nkyj1", "@jinmo123"],
         "Programs": ["Microsoft"],
         "Bugs": ["RCE", "Insecure deeplink", "Webview"],
         "Bounty": "-",
         "PublicationDate": "2023-01-16",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-21587 (Oracle E-Business Suite Unauthenticated RCE)",
               "Link": "https://blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/"
            }
         ],
         "Authors": ["@vudq16", "Q5Ca (@_q5ca)", "@hoangnx99"],
         "Programs": ["Oracle"],
         "Bugs": ["RCE", "Unrestricted file upload", "Zip Slip attack"],
         "Bounty": "-",
         "PublicationDate": "2023-01-16",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "Full Account Take Over by very simple trick.",
               "Link": "https://medium.com/@xerox0x1/full-account-take-over-by-very-simple-trick-b4025a53047c"
            }
         ],
         "Authors": ["XeRox01 (@xerox0x1)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-01-16",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "Account Take Over Due To AWS Cognito Misconfiguration",
               "Link": "https://medium.com/@_deshine_/account-take-over-due-to-aws-cognito-misconfiguration-7b092c667ee3"
            }
         ],
         "Authors": ["Deshine"],
         "Programs": ["-"],
         "Bugs": ["Amazon cognito misconfiguration", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-01-16",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "thisclosed_#2 - PostgreSQL Database Exfiltration through the abuse of PostgREST requests",
               "Link": "https://blog.hckrt.com/blog/thisclosed_2/"
            }
         ],
         "Authors": ["Samuele Gugliotta (@indevi0us)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2023-01-16",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "Critical Vulnerability through OSINT only",
               "Link": "https://medium.com/@mares.viktor/critical-vulnerability-through-osint-only-56e56eb97516"
            }
         ],
         "Authors": ["Viktor Mares"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-01-15",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "XSS using postMessage in Google Cloud Theia notebooks [Google VRP]",
               "Link": "https://blog.geekycat.in/xss-using-postmessage-in-google-cloud-theia-notebooks/"
            }
         ],
         "Authors": ["Sreeram KL (@kl_sree)", "Sivanesh Ashok (@sivaneshashok)"],
         "Programs": ["Google"],
         "Bugs": ["XSS", "postMessage"],
         "Bounty": "3,133.70",
         "PublicationDate": "2023-01-15",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "YAFPC — Unauthenticated Remote Code Execution",
               "Link": "https://blog.paradoxis.nl/yafpc-unauthenticated-remote-code-execution-755bf9e4d7c1"
            }
         ],
         "Authors": ["Luke Paris"],
         "Programs": ["-"],
         "Bugs": ["Authentication bypass", "Hardcoded credentials", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-01-14",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "How Browser’s Save As Feature might lead to Code Execution (CVE-2022–45415)",
               "Link": "https://infosecwriteups.com/how-browsers-save-as-feature-might-lead-to-code-execution-cve-2022-45415-ebaa8711692"
            }
         ],
         "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
         "Programs": ["Mozilla (Firefox)"],
         "Bugs": ["RCE", "Browser hacking"],
         "Bounty": "-",
         "PublicationDate": "2023-01-14",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Application Logic to Phish Internal Mailing Lists",
               "Link": "https://medium.com/@cachemoney/exploiting-application-logic-to-phish-internal-mailing-lists-486b94fc2ef1"
            }
         ],
         "Authors": ["Tanner Emek (@itscachemoney)"],
         "Programs": ["-"],
         "Bugs": ["Phishing"],
         "Bounty": "-",
         "PublicationDate": "2023-01-13",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "Bypassing authorization in Google Cloud Workstations [Google VRP]",
               "Link": "https://blog.stazot.com/auth-bypass-in-google-cloud-workstations/"
            }
         ],
         "Authors": ["Sivanesh Ashok (@sivaneshashok)", "Sreeram KL (@kl_sree)"],
         "Programs": ["Google"],
         "Bugs": ["Account takeover", "OAuth", "URL validation bypass"],
         "Bounty": "3,133.70",
         "PublicationDate": "2023-01-13",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "Bad things come in large packages: .pkg signature verification bypass on macOS",
               "Link": "https://sector7.computest.nl/post/2023-01-xar/"
            }
         ],
         "Authors": ["Sector 7 (@sector7_nl)"],
         "Programs": ["Apple"],
         "Bugs": ["Local Privilege Escalation", "GateKeeper bypass", "SIP bypass", "MacOS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-13",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "SSH key injection in Google Cloud Compute Engine [Google VRP]",
               "Link": "https://blog.stazot.com/ssh-key-injection-google-cloud/"
            }
         ],
         "Authors": ["Sivanesh Ashok (@sivaneshashok)", "Sreeram KL (@kl_sree)"],
         "Programs": ["Google"],
         "Bugs": ["OS command injection", "RCE"],
         "Bounty": "6,000",
         "PublicationDate": "2023-01-12",
         "AddedDate": "2023-01-23"
      },
      {
         "Links": [
            {
               "Title": "DER Entitlements: The (Brief) Return of the Psychic Paper",
               "Link": "https://googleprojectzero.blogspot.com/2023/01/der-entitlements-brief-return-of.html"
            }
         ],
         "Authors": ["Ivan Fratric (@ifsecure)"],
         "Programs": ["Apple"],
         "Bugs": ["iOS", "MacOS", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-01-12",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "Client-Side SSRF to Google Cloud Project Takeover [Google VRP]",
               "Link": "https://blog.geekycat.in/client-side-ssrf-to-google-cloud-project-takeover/"
            }
         ],
         "Authors": ["Dohyun Lee"],
         "Programs": ["Google"],
         "Bugs": ["SSRF","CSRF", "Open redirect"],
         "Bounty": "5,000",
         "PublicationDate": "2023-01-12",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "Google Chrome “SymStealer” Vulnerability: How to Protect Your Files from Being Stolen",
               "Link": "https://www.imperva.com/blog/google-chrome-symstealer-vulnerability/"
            }
         ],
         "Authors": ["Ron Masas (@RonMasas)"],
         "Programs": ["Google (Chrome & Chromium)"],
         "Bugs": ["Local Privilege Escalation", "Browser hacking", "Symbolic link following"],
         "Bounty": "-",
         "PublicationDate": "2023-01-11",
         "AddedDate": "2023-02-16"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – MacOS Mozilla Firefox Download Protections Were Bypassed By .atloc / .ftploc Files",
               "Link": "https://ssd-disclosure.com/ssd-advisory-macos-mozilla-firefox-download-protections-were-bypassed-by-atloc-ftploc-files/"
            }
         ],
         "Authors": ["Dohyun Lee"],
         "Programs": ["Mozilla (Firefox)"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-01-11",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "How I Earned $1000 From Business Logic Vulnerability (account takeover)",
               "Link": "https://andika-here.medium.com/how-i-earned-1000-from-business-logic-vulnerability-account-takeover-f03547950c82"
            }
         ],
         "Authors": ["andika"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw", "Account takeover"],
         "Bounty": "1,000",
         "PublicationDate": "2023-01-10",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Full Team Takeover",
               "Link": "https://infosecwriteups.com/full-team-takeover-678c79842065"
            }
         ],
         "Authors": ["Tuhin Bose (@tuhin1729_)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2023-01-09",
         "AddedDate": "2023-02-28"
      },
      {
         "Links": [
            {
               "Title": "Practical Example Of Client Side Path Manipulation",
               "Link": "https://erasec.be/blog/client-side-path-manipulation/"
            }
         ],
         "Authors": ["Antoine Roly (@aroly)"],
         "Programs": ["-"],
         "Bugs": ["Client-side Path Traversal"],
         "Bounty": "-",
         "PublicationDate": "2023-01-09",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "“2022: A Year of Fascinating Discoveries”",
               "Link": "https://dhakalbibek.medium.com/2022-a-year-of-fascinating-discoveries-d3277dfb006f"
            }
         ],
         "Authors": ["dhakal_bibek (@dhakal__bibek)"],
         "Programs": ["-"],
         "Bugs": ["CSRF", "SSRF", "Blind XSS", "Password reset", "Hyperlink injection", "IDOR", "Weak credentials", "AWS misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-01-09",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Full Team Takeover",
               "Link": "https://tuhin1729.medium.com/full-team-takeover-678c79842065"
            }
         ],
         "Authors": ["Tuhin Bose (@tuhin1729_)"],
         "Programs": ["-"],
         "Bugs": ["Broken Access Control", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2023-01-09",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Hacking Hackers for fun and profit",
               "Link": "https://krevetk0.medium.com/hacking-hackers-for-fun-and-profit-784e6c7897e8"
            }
         ],
         "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
         "Programs": ["-"],
         "Bugs": ["Self-XSS", "Blind XSS"],
         "Bounty": "5,000",
         "PublicationDate": "2023-01-09",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Lexmark MC3224adwe RCE exploit",
               "Link": "https://github.com/blasty/lexmark/blob/main/writeup/writeup.md"
            }
         ],
         "Authors": ["blasty (@bl4sty)"],
         "Programs": ["Lexmark"],
         "Bugs": ["RCE", "SSRF", "Printer hacking", "Unrestricted file upload", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2023-01-09",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Meta Quest: Attacker could make any Oculus user to follow (subscribe) him without any approval",
               "Link": "https://www.vulnano.com/2023/01/meta-quest-attacker-could-make-any.html"
            }
         ],
         "Authors": ["Dzmitry Lukyanenka (@vulnano)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR", "Broken authorization"],
         "Bounty": "1,726",
         "PublicationDate": "2023-01-09",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Uploading the Webshell using filename of Content-Disposition Header Story!",
               "Link": "https://ymohagheghi.medium.com/uploading-the-webshell-using-filename-of-content-disposition-header-story-59ba87752311"
            }
         ],
         "Authors": ["Yashar Mohagheghi"],
         "Programs": ["-"],
         "Bugs": ["Unrestricted file upload", "Arbitrary file write"],
         "Bounty": "-",
         "PublicationDate": "2023-01-09",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Bug hunting: Open access to S3 bucket",
               "Link": "https://engrinside.medium.com/bug-hunting-open-access-to-s3-bucket-79f262a86a78"
            }
         ],
         "Authors": ["Raghul Raj"],
         "Programs": ["-"],
         "Bugs": ["AWS misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-01-09",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "The SSRF that Brought down a Server",
               "Link": "https://crypt0g30rgy.github.io/post/SSRFtoDos"
            }
         ],
         "Authors": ["g30rgy th3 d4rk (@Crypt0g30rgy)"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-07",
         "AddedDate": "2023-03-09"
      },
      {
         "Links": [
            {
               "Title": "The Bug That Kept On Giving :: PaymentBypass :: QR CODE",
               "Link": "https://crypt0g30rgy.github.io/post/PaymentBypassOne"
            }
         ],
         "Authors": ["g30rgy th3 d4rk (@Crypt0g30rgy)"],
         "Programs": ["-"],
         "Bugs": ["Payment bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-01-07",
         "AddedDate": "2023-01-18"
      },
      {
         "Links": [
            {
               "Title": "Advanced CSRF Exploitation",
               "Link": "https://medium.com/@sandro.einfeldt/advanced-csrf-exploitation-via-xss-4cd00c895ba"
            }
         ],
         "Authors": ["Sandro Einfeldt"],
         "Programs": ["-"],
         "Bugs": ["CSRF", "Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-07",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability",
               "Link": "https://medium.com/@LogicalHunter/identity-aware-proxy-misconfiguration-google-cloud-vulnerability-813d2a07a4ed"
            }
         ],
         "Authors": ["Borna Nematzadeh (@LogicalHunter)"],
         "Programs": ["Google"],
         "Bugs": ["CORS misconfiguration"],
         "Bounty": "2,337",
         "PublicationDate": "2023-01-06",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "I scanned every package on PyPi and found 57 live AWS keys",
               "Link": "https://tomforb.es/i-scanned-every-package-on-pypi-and-found-57-live-aws-keys/"
            }
         ],
         "Authors": ["Tom Forbes"],
         "Programs": ["Amazon", "Intel", "Stanford", "The Australian Government"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-01-06",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "PandoraFMS - Pre-Auth Remote Code Execution",
               "Link": "https://3sjay.github.io/2023/01/06/pandoraFMS-Pre-Auth-RCE.html"
            }
         ],
         "Authors": ["esj4y (@esj4y)"],
         "Programs": ["PandoraFMS"],
         "Bugs": ["RCE", "Path traversal", "Arbitrary file upload", "LFI", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-01-06",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Leaking Secrets From GitHub Actions: Reading Files And Environment Variables, Intercepting Network/Process Communication, Dumping Memory",
               "Link": "https://karimrahal.com/2023/01/05/github-actions-leaking-secrets/"
            }
         ],
         "Authors": ["Karim Rahal (@KarimPwnz)"],
         "Programs": ["GitHub"],
         "Bugs": ["CI/CD", "OS command injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2023-01-05",
         "AddedDate": "2024-01-29"
      },
      {
         "Links": [
            {
               "Title": "Blind XSS in Email Field; 1000$ bounty",
               "Link": "https://yaseenzubair.medium.com/blind-xss-in-email-field-1000-bounty-b19b25a23236"
            }
         ],
         "Authors": ["Yaseen Zubair"],
         "Programs": ["-"],
         "Bugs": ["Blind XSS"],
         "Bounty": "1,000",
         "PublicationDate": "2023-01-05",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Prototype Pollution in Python",
               "Link": "https://blog.abdulrah33m.com/prototype-pollution-in-python/"
            }
         ],
         "Authors": ["Abdulraheem Khaled (@Abdulrah33mK)"],
         "Programs": ["-"],
         "Bugs": ["Prototype pollution", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-04",
         "AddedDate": "2023-03-08"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-25026 & CVE-2022-25027: Vulnerabilities in Rocket TRUfusion Enterprise",
               "Link": "https://labs.nettitude.com/blog/cve-2022-25026-cve-2022-25027-vulnerabilities-in-rocket-trufusion-enterprise/"
            }
         ],
         "Authors": ["Tom Wedgbury"],
         "Programs": ["Rocket Software"],
         "Bugs": ["Authentication bypass", "SSRF"],
         "Bounty": "-",
         "PublicationDate": "2023-01-04",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Cacti: Unauthenticated Remote Code Execution",
               "Link": "https://www.sonarsource.com/blog/cacti-unauthenticated-remote-code-execution/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["Cacti"],
         "Bugs": ["RCE", "Authentication bypass", "OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2023-01-03",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More",
               "Link": "https://samcurry.net/web-hackers-vs-the-auto-industry/"
            }
         ],
         "Authors": ["Sam Curry (@samwcyo)", "Neiko Rivera (@_specters)", "Brett Buerhaus (@bbuerhaus)", "Maik Robert (@xEHLE_)", "Ian Carroll (@iangcarroll)", "Justin Rhinehart (@sshell_)", "Shubham Shah (@infosec_au)"],
         "Programs": ["Kia", "Honda", "Infiniti", "Nissan", "Acura", "Mercedes-Benz", "Hyundai", "Genesis", "BMW", "Rolls Royce", "Ferrari", "Spireon", "Ford", "Reviver", "Porsche", "Toyota", "Jaguar", "Land Rover", "SiriusXM"],
         "Bugs": ["Account takeover", "SSO", "RCE", "Authorization bypass", "SQL injection", "Mass assignment", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-01-03",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Fetch Diversion",
               "Link": "https://acut3.pages.dev/posts/2023-01-03-fetch-diversion/"
            }
         ],
         "Authors": ["Nicolas Christin (@acut3hack)"],
         "Programs": ["-"],
         "Bugs": ["DOM XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-03",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Vue JS Reflected XSS",
               "Link": "https://medium.com/@sid0krypt/vue-js-reflected-xss-fae04c9872d2"
            }
         ],
         "Authors": ["sid0krypt (@Siddhar07949650)"],
         "Programs": ["-"],
         "Bugs": ["Reflected XSS", "Blind XSS", "CORS misconfiguration", "UI redressing"],
         "Bounty": "-",
         "PublicationDate": "2023-01-03",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Access to page with default credentials that require authenticate $$$.",
               "Link": "https://medium.com/@adhaamsayed3/access-to-page-with-default-credentials-that-require-authenticate-e59cebf0bced"
            }
         ],
         "Authors": ["Adham sayed (doosec101)"],
         "Programs": ["-"],
         "Bugs": ["Default credentials"],
         "Bounty": "-",
         "PublicationDate": "2023-01-03",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Bypass firewalls with of-CORs and typo-squatting",
               "Link": "https://trufflesecurity.com/blog/of-cors/index.html"
            }
         ],
         "Authors": ["Chris Grayson", "Truffle Security (@trufflesec)"],
         "Programs": ["Tesla"],
         "Bugs": ["CORS misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2023-01-02",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Instagram vulnerability : Turn off all type of message requests using deeplink (Android)",
               "Link": "https://servicenger.com/mobile/instagram-vulnerability-turn-off-message-requests-deeplink/"
            }
         ],
         "Authors": ["Rahul Kankrale (@RahulKankrale)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["Insecure deeplink", "Android"],
         "Bounty": "-",
         "PublicationDate": "2023-01-02",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Exploiting thousands of Domains for XSS",
               "Link": "https://kailashbohara.com.np/blog/2023/01/02/exploiting-thousands-of-domains-for-XSS/"
            }
         ],
         "Authors": ["Kailash (@Corrupted_brain)"],
         "Programs": ["GoDaddy"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2023-01-02",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Web-Cache Poisoning $$$? Worth it?",
               "Link": "https://yaseenzubair.medium.com/web-cache-poisoning-worth-it-e7c6d88797b1"
            }
         ],
         "Authors": ["Yaseen Zubair"],
         "Programs": ["-"],
         "Bugs": ["Web cache poisoning", "XSS"],
         "Bounty": "200",
         "PublicationDate": "2023-01-02",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "An amazing way to turn a xss into an ATO",
               "Link": "https://medium.com/@nakah_/an-amazing-way-to-turn-a-xss-into-an-ato-40bc92772195"
            }
         ],
         "Authors": ["Naka"],
         "Programs": ["-"],
         "Bugs": ["XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-01-02",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "India’s Aadhar card source code disclosure via exposed .svn/wc.db",
               "Link": "https://0xlittlespidy.medium.com/indias-aadhar-card-source-code-disclosure-via-exposed-svn-wc-db-c05519ea7761"
            }
         ],
         "Authors": ["0xLittleSpidy (@0xLittleSpidy)"],
         "Programs": ["Aadhaar"],
         "Bugs": ["Source code disclosure", ".svn folder disclosure"],
         "Bounty": "-",
         "PublicationDate": "2023-01-02",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Bypass Premium Account Payment (GetPocket)",
               "Link": "https://medium.com/@querylab/bypass-premium-account-payment-getpocket-d813b249687c"
            }
         ],
         "Authors": ["querylab"],
         "Programs": ["Mozilla (GetPocket)"],
         "Bugs": ["Payment bypass"],
         "Bounty": "-",
         "PublicationDate": "2023-01-01",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "$500 in 5 minutes",
               "Link": "https://medium.com/@coffeeaddict_exe/500-in-5-minutes-45977e89a337"
            }
         ],
         "Authors": ["CoffeeAddict"],
         "Programs": ["Dropbox"],
         "Bugs": ["Broken link hijacking"],
         "Bounty": "500",
         "PublicationDate": "2023-01-01",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "How I took over an admin panel and got $500",
               "Link": "https://medium.com/@mohammed01550038865/hello-hackers-a229fb5c821b"
            }
         ],
         "Authors": ["Muhammed Mubarak"],
         "Programs": ["-"],
         "Bugs": ["Blind XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-01-01",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "Subdomain Hijacking Of Any Qwilr’s Customer",
               "Link": "https://0xprial.com/subdomain-hijacking-of-any-qwilrs-customer/"
            }
         ],
         "Authors": ["Prial Islam Khan (@prial261)"],
         "Programs": ["-"],
         "Bugs": ["Subdomain takeover"],
         "Bounty": "-",
         "PublicationDate": "2023-01-01",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-38627: A journey through SQLite Injection to compromise the whole enterprise building",
               "Link": "https://infosecwriteups.com/cve-2022-38627-a-journey-through-sqlite-injection-to-compromise-the-whole-enterprise-building-15cebd072ed6"
            }
         ],
         "Authors": ["Omar Hashem (@OmarHashem666)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2022-12-30",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "Exploring the World of ESI Injection",
               "Link": "https://sudhanshur705.medium.com/exploring-the-world-of-esi-injection-b86234e66f91"
            }
         ],
         "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)", "nytr0gen (@nytr0gen_)"],
         "Programs": ["-"],
         "Bugs": ["ESI injection", "WAF bypass", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-12-29",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "How I got a Bug At Apple that lead’s to takeover accounts of any user who view my profile",
               "Link": "https://hamzadzworm.medium.com/how-i-got-a-bug-that-leads-to-takeover-accounts-of-any-user-who-view-my-profile-913c8704f6cd"
            }
         ],
         "Authors": ["Abdelkader Mouaz (@hamzadzworm)"],
         "Programs": ["Apple"],
         "Bugs": ["XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2022-12-29",
         "AddedDate": "2022-12-30"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover Due to Cognito Misconfiguration Earns Me €xxxx",
               "Link": "https://medium.com/@mukundbhuva/account-takeover-due-to-cognito-misconfiguration-earns-me-xxxx-3a7b8bb9a619"
            }
         ],
         "Authors": ["Mukund Bhuva (@MukundBhuva)"],
         "Programs": ["-"],
         "Bugs": ["Amazon cognito misconfiguration", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2022-12-29",
         "AddedDate": "2022-12-30"
      },
      {
         "Links": [
            {
               "Title": "Getting Secret Key to Building Custom Burp Extension",
               "Link": "https://medium.com/@ashlyn.lau_17206/hooking-secret-key-to-building-custom-burp-extension-c6aeb6fd312a"
            }
         ],
         "Authors": ["Ashlyn Lau (@ashlyn_lau)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2022-12-29",
         "AddedDate": "2022-12-30"
      },
      {
         "Links": [
            {
               "Title": "Feedback Analyzer Exploitation",
               "Link": "https://medium.com/@kandar.souvik6/feedback-analyzer-exploitation-dc44a91b7fcc"
            }
         ],
         "Authors": ["hacker_might"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-28",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "Unauthorized Sign-up on Subdomain of Subdomain leading to Organization takeover worth $2000",
               "Link": "https://infosecwriteups.com/unauthorized-sign-up-on-subdomain-of-subdomain-leading-to-organization-takeover-worth-2000-a7199952d80b"
            }
         ],
         "Authors": ["Manav Bankatwala (@ManavBankatwala)"],
         "Programs": ["-"],
         "Bugs": ["Exposed registration page"],
         "Bounty": "2,000",
         "PublicationDate": "2022-12-28",
         "AddedDate": "2022-12-30"
      },
      {
         "Links": [
            {
               "Title": "LDAP anonymous login story of my 3 simple P3 findings",
               "Link": "https://tamimhasan404.medium.com/ldap-anonymous-login-story-of-my-3-simple-p3-findings-d5b4a991b345"
            }
         ],
         "Authors": ["Tamim Hasan (@tamimhasan404)"],
         "Programs": ["Department of Homeland Security"],
         "Bugs": ["LDAP anonymous login"],
         "Bounty": "-",
         "PublicationDate": "2022-12-28",
         "AddedDate": "2022-12-30"
      },
      {
         "Links": [
            {
               "Title": "Hunting for Amazon Cognito Security misconfigurations",
               "Link": "https://www.yassineaboukir.com//blog/hunting-for-amazon-cognito-security-misconfigurations/"
            }
         ],
         "Authors": ["Yassine Aboukir (@Yassineaboukir)"],
         "Programs": ["-"],
         "Bugs": ["Amazon cognito misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2022-12-27",
         "AddedDate": "2022-12-30"
      },
      {
         "Links": [
            {
               "Title": "Hacking a .NET API in the real world",
               "Link": "https://danaepp.com/hacking-a-net-api-in-the-real-world"
            }
         ],
         "Authors": ["Dana Epp (@DanaEpp)"],
         "Programs": ["-"],
         "Bugs": ["LFI"],
         "Bounty": "-",
         "PublicationDate": "2022-12-27",
         "AddedDate": "2022-12-30"
      },
      {
         "Links": [
            {
               "Title": "Stored XSS vulnerability in Microsoft booking",
               "Link": "https://mtechghost.medium.com/stored-xss-vulnerability-in-microsoft-booking-e593de3344e0"
            }
         ],
         "Authors": ["Mrtechghost"],
         "Programs": ["Microsoft"],
         "Bugs": ["Stored XSS", "CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-27",
         "AddedDate": "2022-12-27"
      },
      {
         "Links": [
            {
               "Title": "[ GCP 2022 ] Few bugs in the google cloud shell",
               "Link": "https://obmiblog.blogspot.com/2022/12/gcp-2022-few-bugs-in-google-cloud-shell.html"
            }
         ],
         "Authors": ["Obmi"],
         "Programs": ["Google"],
         "Bugs": ["CSRF", "Stored XSS", "File upload", "OAuth"],
         "Bounty": "20,000",
         "PublicationDate": "2022-12-26",
         "AddedDate": "2023-07-12"
      },
      {
         "Links": [
            {
               "Title": "The OWASSRF + TabShell exploit chain",
               "Link": "https://blog.viettelcybersecurity.com/tabshell-owassrf/"
            }
         ],
         "Authors": ["Rskvp93 (@rskvp93)", "Q5Ca (@_q5ca)", "nxhoang99 (@nxhoang99)"],
         "Programs": ["Microsoft"],
         "Bugs": ["SSRF", "Path traversal", "Sandbox escape"],
         "Bounty": "-",
         "PublicationDate": "2022-12-26",
         "AddedDate": "2023-01-26"
      },
      {
         "Links": [
            {
               "Title": "Turning Google smart speakers into wiretaps for $100k",
               "Link": "https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html"
            }
         ],
         "Authors": ["Matt"],
         "Programs": ["Google"],
         "Bugs": ["IoT", "Wifi hacking"],
         "Bounty": "107,500",
         "PublicationDate": "2022-12-26",
         "AddedDate": "2022-12-30"
      },
      {
         "Links": [
            {
               "Title": "How I found multiple critical bugs in Red Bull",
               "Link": "https://bergee.it/blog/how-i-found-multiple-critical-bugs-in-red-bull/"
            }
         ],
         "Authors": ["Bartłomiej Bergier (@_bergee_)"],
         "Programs": ["Red Bull"],
         "Bugs": ["Authentication bypass", "HTTP response manipulation", "Path traversal", "LFI", "XSS", "SQL injection", "RCE", "Unrestricted file upload", "RFI", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-12-26",
         "AddedDate": "2022-12-30"
      },
      {
         "Links": [
            {
               "Title": "Uncovering a Bug I Found in Outlook: How Could an Account Has Been Compromised?",
               "Link": "https://cems.fun/2022/12/26/CVE-2017-8758.html"
            }
         ],
         "Authors": ["Cem Onat Karagun"],
         "Programs": ["Microsoft"],
         "Bugs": ["XSS"],
         "Bounty": "5,000",
         "PublicationDate": "2022-12-26",
         "AddedDate": "2022-12-27"
      },
      {
         "Links": [
            {
               "Title": "Authentication Bypass in Nexus manager (version 3.37.3–02)",
               "Link": "https://sharanthehunter.medium.com/authentication-bypass-in-nexus-manager-version-3-37-3-02-712f0bdb2fb4"
            }
         ],
         "Authors": ["SHARAN.K"],
         "Programs": ["-"],
         "Bugs": ["Components with known vulnerabilities", "Authentication bypass", "HTTP response manipulation"],
         "Bounty": "-",
         "PublicationDate": "2022-12-26",
         "AddedDate": "2022-12-27"
      },
      {
         "Links": [
            {
               "Title": "How I Pwned 10 Admin Panels and got rewarded 8000$+?",
               "Link": "https://rashahacks.com/how-i-pwned-10-admin-panels-and-rewarded-8000/"
            }
         ],
         "Authors": ["Inderjeet Singh (@3nc0d3dGuY)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "Credential stuffing"],
         "Bounty": "8,000",
         "PublicationDate": "2022-12-25",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Unusual 403 Bypass to a full website takeover [External Pentest]",
               "Link": "https://medium.com/@mares.viktor/unusual-403-bypass-to-a-full-website-takeover-external-pentest-4970c788c6bf"
            }
         ],
         "Authors": ["Viktor Mares"],
         "Programs": ["-"],
         "Bugs": ["403 bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-25",
         "AddedDate": "2022-12-27"
      },
      {
         "Links": [
            {
               "Title": "Bypassing SSRF Protections",
               "Link": "https://medium.com/@tobydavenn/bypassing-ssrf-protections-45e5e3ac31e9"
            }
         ],
         "Authors": ["Tobydavenn"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2022-12-24",
         "AddedDate": "2022-12-27"
      },
      {
         "Links": [
            {
               "Title": "Bypass Apple’s redirection process with the dot (“.”) character",
               "Link": "https://infosecwriteups.com/bypass-apples-redirection-process-with-the-dot-character-c47d40537202"
            }
         ],
         "Authors": ["can1337 (@canmustdie)"],
         "Programs": ["Apple"],
         "Bugs": ["Open redirect"],
         "Bounty": "-",
         "PublicationDate": "2022-12-24",
         "AddedDate": "2022-12-27"
      },
      {
         "Links": [
            {
               "Title": "CRLF Injection — xxx$ — How was it possible for me to earn a bounty with the Cloudflare WAF?",
               "Link": "https://infosecwriteups.com/crlf-injection-xxx-how-was-it-possible-for-me-to-earn-a-bounty-with-the-cloudflare-waf-f581506f97f5"
            }
         ],
         "Authors": ["Proviesec (@proviesec)"],
         "Programs": ["-"],
         "Bugs": ["CRLF injection"],
         "Bounty": "500",
         "PublicationDate": "2022-12-24",
         "AddedDate": "2022-12-27"
      },
      {
         "Links": [
            {
               "Title": "Microsoft bug reports lead to ranking on Microsoft MSRC Quarterly Leaderboard (Q3 2022)",
               "Link": "https://medium.com/supakiad-s-m3ez/microsoft-bug-reports-lead-to-ranking-on-microsoft-msrc-quarterly-leaderboard-q3-2022-c6c9f70e2ccd"
            }
         ],
         "Authors": ["Supakiad S. (@Supakiad_Mee)"],
         "Programs": ["Microsoft"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-12-23",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "$350 XSS in 15 minutes",
               "Link": "https://therceman.medium.com/350-xss-in-15-minutes-dcb74ad93d5f"
            }
         ],
         "Authors": ["Anton (@therceman)"],
         "Programs": ["-"],
         "Bugs": ["DOM XSS", "JSONP"],
         "Bounty": "350",
         "PublicationDate": "2022-12-23",
         "AddedDate": "2022-12-26"
      },
      {
         "Links": [
            {
               "Title": "Flickr Stored XSS",
               "Link": "https://keerok.github.io/2022/12/22/Flickr-Stored-XSS/"
            }
         ],
         "Authors": ["Guilherme Keerok (@k33r0k)"],
         "Programs": ["Flickr"],
         "Bugs": ["Stored XSS"],
         "Bounty": "3,263",
         "PublicationDate": "2022-12-22",
         "AddedDate": "2023-06-25"
      },
      {
         "Links": [
            {
               "Title": "ENLBufferPwn (CVE-2022-47949)",
               "Link": "https://github.com/PabloMK7/ENLBufferPwn"
            }
         ],
         "Authors": ["PabloMK7 (@Pablomf6)"],
         "Programs": ["Nintendo"],
         "Bugs": ["Buffer Overflow", "Memory corruption", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-12-22",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "ACSESSED: Cross-tenant network bypass in Azure Cognitive Search",
               "Link": "https://www.mnemonic.io/resources/blog/acsessed-cross-tenant-network-bypass-in-azure-cognitive-search/"
            }
         ],
         "Authors": ["Emilien Socchi (@emiliensocchi)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Cloud", "Cross-tenant vulnerability", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-12-22",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "Puckungfu: A NETGEAR WAN Command Injection",
               "Link": "https://research.nccgroup.com/2022/12/22/puckungfu-a-netgear-wan-command-injection/"
            }
         ],
         "Authors": ["McCaulay Hudson (@_mccaulay)"],
         "Programs": ["Netgear"],
         "Bugs": ["OS command injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-12-22",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "Multiple authenticated blind SQL Injections in Sage XRT Business Exchange application",
               "Link": "https://www.synacktiv.com/sites/default/files/2022-12/sage_xrt_multiple_sqli_1.pdf"
            }
         ],
         "Authors": ["Mickaël Benassouli (@mickaelweb)", "Antoine Gicquel (@blueshhit)"],
         "Programs": ["Sage"],
         "Bugs": ["Blind SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2022-12-21",
         "AddedDate": "2023-03-02"
      },
      {
         "Links": [
            {
               "Title": "How Race Condition helped me break Business Logic of the application",
               "Link": "https://web.archive.org/web/20221224215757/https://rashahacks.com/how-race-condition-helped-me-break-business-logic/"
            }
         ],
         "Authors": ["Inderjeet Singh (@3nc0d3dGuY)"],
         "Programs": ["-"],
         "Bugs": ["Race condition"],
         "Bounty": "-",
         "PublicationDate": "2022-12-21",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Passwordless Persistence and Privilege Escalation in Azure",
               "Link": "https://posts.specterops.io/passwordless-persistence-and-privilege-escalation-in-azure-98a01310be3f"
            }
         ],
         "Authors": ["Andy Robbins (@_wald0)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Privilege escalation", "Cloud", "Azure AD"],
         "Bounty": "-",
         "PublicationDate": "2022-12-21",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "0 click Facebook Account Takeover and Two-Factor Authentication Bypass",
               "Link": "https://medium.com/@yaala/account-takeover-and-two-factor-authentication-bypass-de56ed41d7f9"
            }
         ],
         "Authors": ["abdellah yaala (@yaalaab)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["Authentication bypass", "GraphQL", "Account takeover", "Android", "2FA / MFA bypass"],
         "Bounty": "3,000",
         "PublicationDate": "2022-12-21",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "Delete any Video or Reel on Facebook (11,250$)",
               "Link": "https://bugreader.com/social/write-ups-general-delete-any-video-or-reel-on-facebook-11-250--100965"
            }
         ],
         "Authors": ["Bassem M Bazzoun (@bassemmbazzoun)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["IDOR"],
         "Bounty": "11,250",
         "PublicationDate": "2022-12-21",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "Zero Click To Account Takeover (IDOR + XSS)",
               "Link": "https://m7arm4n.medium.com/zero-click-to-account-takeover-idor-xss-98dd6cce63c4"
            }
         ],
         "Authors": ["Arman (@M7arm4n)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "XSS", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2022-12-21",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "RCE on admin panel of web3 website",
               "Link": "https://medium.com/@vamshivaran110/rce-on-admin-panel-of-web3-website-2d0acf34d6ea"
            }
         ],
         "Authors": ["T VAMSHI"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2022-12-21",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "Cisco BroadWorks CommPilot Application Software Unauthenticated Server-Side Request Forgery (CVE-2022-20951)",
               "Link": "https://www.shielder.com/advisories/cisco-broadworks-commpilot-ssrf/"
            }
         ],
         "Authors": ["smaury (@smaury92)", "Andrea Cappa (@zi0Black)", "Th3Zer0 (@Th3Zer0)"],
         "Programs": ["Cisco"],
         "Bugs": ["SSRF", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-12-21",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "My First Bug In Bugcrowd Platform",
               "Link": "https://medium.com/@EX_097/my-first-bug-in-bugcrowd-76decc1f9901"
            }
         ],
         "Authors": ["EX_097"],
         "Programs": ["-"],
         "Bugs": ["Race condition"],
         "Bounty": "-",
         "PublicationDate": "2022-12-21",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "A Technical Analysis of CVE-2022-22583 and CVE-2022-32800",
               "Link": "https://www.trendmicro.com/en_us/research/22/l/a-technical-analysis-of-cve-2022-22583-and-cve-2022-32800.html"
            }
         ],
         "Authors": ["Mickey Jin (@patch1t)", "Ron Hass (@ronhass7)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["MacOS", "Local Privilege Escalation", "SIP bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-21",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Owning half of a government assets through AWS",
               "Link": "https://crypt0g30rgy.github.io/post/AWSTakeover"
            }
         ],
         "Authors": ["g30rgy th3 d4rk (@Crypt0g30rgy)"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "Hardcoded API keys"],
         "Bounty": "-",
         "PublicationDate": "2022-12-20",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities",
               "Link": "https://www.trendmicro.com/en_us/research/22/l/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypas.html"
            }
         ],
         "Authors": ["Mickey Jin (@patch1t)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["MacOS", "Local Privilege Escalation", "SIP bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-20",
         "AddedDate": "2023-01-06"
      },
      {
         "Links": [
            {
               "Title": "From PostAuth RCE to PreAuth RCE on Liferay Portal",
               "Link": "https://dappsec.substack.com/p/an-advisory-for-cve-2019-16891-from"
            }
         ],
         "Authors": ["RV Sharma"],
         "Programs": ["Liferay"],
         "Bugs": ["RCE", "Insecure deserialization"],
         "Bounty": "-",
         "PublicationDate": "2022-12-20",
         "AddedDate": "2022-12-26"
      },
      {
         "Links": [
            {
               "Title": "How I got a 4 digits(₹) bounty from an Indian company",
               "Link": "https://rv09.medium.com/in-this-article-ill-tell-you-how-i-got-a-4-digits-bounty-from-an-indian-company-38e39a29f99e"
            }
         ],
         "Authors": ["RV Sharma"],
         "Programs": ["-"],
         "Bugs": ["Broken link hijacking"],
         "Bounty": "-",
         "PublicationDate": "2022-12-20",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "[GraphQL IDOR]Leaking credit card information of 1000s of users",
               "Link": "https://infosecwriteups.com/graphql-idor-leaking-credit-card-information-of-1000s-of-users-d07eec732979"
            }
         ],
         "Authors": ["Vipul Sahu"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "GraphQL"],
         "Bounty": "1,500",
         "PublicationDate": "2022-12-20",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "How I found my first XSS on a Bug Bounty Program",
               "Link": "https://kingcoolvikas.medium.com/how-i-found-my-first-xss-on-a-bug-bounty-program-c41107617ce1"
            }
         ],
         "Authors": ["Vikas Anand (@kingcoolvikas)"],
         "Programs": ["Coinbase"],
         "Bugs": ["XSS"],
         "Bounty": "200",
         "PublicationDate": "2022-12-20",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "Cengage LTI Session Management Leakage",
               "Link": "https://www.rapid7.com/blog/post/2022/12/20/cengage-lti-session-management-leakage/"
            }
         ],
         "Authors": ["Tony Porterfield"],
         "Programs": ["Cengage"],
         "Bugs": ["SSO", "Session management issue"],
         "Bounty": "-",
         "PublicationDate": "2022-12-20",
         "AddedDate": "2022-12-23"
      },
      {
         "Links": [
            {
               "Title": "Better Make Sure Your Password Manager Is Secure",
               "Link": "https://www.modzero.com/modlog/archives/2022/12/19/better_make_sure_your_password_manager_is_secure/index.html"
            }
         ],
         "Authors": ["kuekerino (@kuekerino)", "ubahnverleih (@ubahnverleih)", "parzel (@parzel2)"],
         "Programs": ["Click Studios"],
         "Bugs": ["Hardcoded credentials", "XSS", "Cryptographic issues", "Broken authorization", "Authentication bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-19",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "How I was able to steal users credentials via Swagger UI DOM-XSS",
               "Link": "https://medium.com/@M0X0101/how-i-was-able-to-steal-users-credentials-via-swagger-ui-dom-xss-e84255eb8c96"
            }
         ],
         "Authors": ["Mohamed Reda (@M0x0101)"],
         "Programs": ["-"],
         "Bugs": ["DOM XSS", "Old components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2022-12-18",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "Directory Traversal Vulnerability in Huawei HG255s Products",
               "Link": "https://infosecwriteups.com/directory-ttraversal-vulnerability-in-huawei-hg255s-products-dce941a1d015"
            }
         ],
         "Authors": ["Ismail Tasdelen"],
         "Programs": ["Huawei"],
         "Bugs": ["Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2022-12-17",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "Gatekeeper’s Achilles heel: Unearthing a macOS vulnerability",
               "Link": "https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/"
            }
         ],
         "Authors": ["Jonathan Bar Or (@yo_yo_yo_jbo)"],
         "Programs": ["Apple (macOS)"],
         "Bugs": ["Local Privilege Escalation", "GateKeeper bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-17",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "I Hope This Sticks: Analyzing ClipboardEvent Listeners for Stored XSS",
               "Link": "https://spaceraccoon.dev/analyzing-clipboardevent-listeners-stored-xss/"
            }
         ],
         "Authors": ["Eugene Lim (@spaceraccoonsec)"],
         "Programs": ["Zoom"],
         "Bugs": ["Stored XSS", "Self-XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-12-17",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "The Bug That Kept On Giving :: PaymentBypass :: Response Manipulation",
               "Link": "https://crypt0g30rgy.github.io/post/PaymentBypassTwo"
            }
         ],
         "Authors": ["g30rgy th3 d4rk (@Crypt0g30rgy)"],
         "Programs": ["-"],
         "Bugs": ["Payment bypass", "Logic flaw"],
         "Bounty": "500",
         "PublicationDate": "2022-12-16",
         "AddedDate": "2023-02-26"
      },
      {
         "Links": [
            {
               "Title": "Simple CORS misconfig leads to disclose the sensitive token worth of $$$",
               "Link": "https://0xraminfosec.medium.com/simple-cors-misconfig-leads-to-disclose-the-sensitive-token-worth-of-91433763f4d6"
            }
         ],
         "Authors": ["Ramalingasamy"],
         "Programs": ["Linear"],
         "Bugs": ["CORS misconfiguration", "Token leak"],
         "Bounty": "-",
         "PublicationDate": "2022-12-16",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-42710: A journey through XXE to Stored-XSS",
               "Link": "https://omar0x01.medium.com/cve-2022-42710-a-journey-through-xxe-to-stored-xss-851d74dfe917"
            }
         ],
         "Authors": ["Omar Hashem (@OmarHashem666)"],
         "Programs": ["Linear"],
         "Bugs": ["Stored XSS", "XXE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-12-16",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "Param Hunting to Injections",
               "Link": "https://infosecwriteups.com/param-hunting-to-injections-4365da5447cf"
            }
         ],
         "Authors": ["302 Found"],
         "Programs": ["-"],
         "Bugs": ["HTML injection", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-12-16",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
           {
              "Title": "Foxit PDF Reader - Use after Free - Remote Code Execution Exploit - CVE-2022-28672",
              "Link": "https://hacksys.io/blogs/foxit-reader-uaf-rce-jit-spraying-cve-2022-28672"
           }
          ],
         "Authors": ["Ashfaq Ansari (@HackSysTeam)", "Krishnakant Patil (@shsirk)"],
         "Programs": ["Foxit"],
         "Bugs": ["Memory corruption", "Use-After-Free"],
         "Bounty": "-",
         "PublicationDate": "2022-12-16",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "Missing Bricks: Finding Security Holes in LEGO APIs",
               "Link": "https://salt.security/blog/missing-bricks-finding-security-holes-in-lego-apis"
            }
         ],
         "Authors": ["Shiran Yodev"],
         "Programs": ["LEGO"],
         "Bugs": ["XSS", "XXE"],
         "Bounty": "-",
         "PublicationDate": "2022-12-15",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "FlowscreenComponents Basepack, Version 3.0.7 Advisory",
               "Link": "https://bishopfox.com/blog/flowscreencomponents-advisory"
            }
         ],
         "Authors": ["Matthew Rutledge"],
         "Programs": ["UnofficialSF"],
         "Bugs": ["XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-12-15",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "Unprotected API endpoint at HAwebsso.nl leads to data leak of +15k medical doctor usernames & password hashes",
               "Link": "https://medium.com/@jonathanbouman/unprotected-api-endpoint-at-hawebsso-nl-5f1951e212fe"
            }
         ],
         "Authors": ["Jonathan Bouman (@JonathanBouman)"],
         "Programs": ["HAwebsso.nl"],
         "Bugs": ["SSO", "IDOR", "Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2022-12-14",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution",
               "Link": "https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/"
            }
         ],
         "Authors": ["Iain Wallace (@strawp)"],
         "Programs": ["OnlyOffice"],
         "Bugs": ["Websockets", "XSS", "RCE", "Arbitrary file write", "Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2022-12-14",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "Unusual Cache Poisoning between Akamai and S3 buckets",
               "Link": "https://spyclub.tech/2022/12/14/unusual-cache-poisoning-akamai-s3/"
            }
         ],
         "Authors": ["SpyD3r (@TarunkantG)"],
         "Programs": ["Akamai"],
         "Bugs": ["Web cache poisoning", "Host header injection"],
         "Bounty": "-",
         "PublicationDate": "2022-12-14",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution",
               "Link": "https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/"
            }
         ],
         "Authors": ["Iain Wallace (@strawp)"],
         "Programs": ["OnlyOffice"],
         "Bugs": ["Websockets", "RCE", "Arbitrary file write", "Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2022-12-14",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "You’ve Crossed the Line — Disturbing a Host’s Rest",
               "Link": "https://www.akamai.com/blog/security-research/msrpc-lsm-cve-disturbing-hosts-rest"
            }
         ],
         "Authors": ["Ben Barnea (@nachoskrnl)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Windows", "MS-RPC", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2022-12-14",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "Privilege escalation leads to deleting other user’s account and company Workspace [Access Control]",
               "Link": "https://medium.com/@h4ck3rp4tik/privilege-escalation-leads-to-deleting-other-users-account-and-company-workspace-access-control-7b709eb88ef"
            }
         ],
         "Authors": ["Pratik Gaikwad"],
         "Programs": ["-"],
         "Bugs": ["Privilege escalation", "Broken Access Control"],
         "Bounty": "400",
         "PublicationDate": "2022-12-14",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "How I Hacked A Company (My First Red Team Engagement 🚩)Permalink",
               "Link": "https://aidenpearce369.github.io/offsec/My-First-RedTeam-Engagement/"
            }
         ],
         "Authors": ["Monish Kumar (@aidenpearce369)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2022-12-13",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "Doing it the researcher’s way: How I Managed to Get SSTI (Server Side Template Injection) which lead to arbitrary file reading on One of the Leading Payment Systems in Asia",
               "Link": "https://medium.com/@jazdprince/doing-it-the-researchers-way-how-i-managed-to-get-ssti-server-side-template-injection-which-66b239ca0104"
            }
         ],
         "Authors": ["JzeeRx"],
         "Programs": ["-"],
         "Bugs": ["SSTI", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-13",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "Exploiting an SQL injection with WAF bypass",
               "Link": "https://www.vaadata.com/blog/exploiting-an-sql-injection-with-waf-bypass/"
            }
         ],
         "Authors": ["Benoit Philippe"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-13",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "AWS ECR Public Vulnerability",
               "Link": "https://blog.lightspin.io/aws-ecr-public-vulnerability"
            }
         ],
         "Authors": ["Gafnit Amiga (@gafnitav)"],
         "Programs": ["AWS"],
         "Bugs": ["Cloud", "Privilege escalation", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2022-12-13",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "CVE-2019–6238: Apple XAR directory traversal vulnerability",
               "Link": "https://yilmazcanyigit.medium.com/cve-2019-6238-apple-xar-directory-traversal-vulnerability-9a32ba8b3b7d"
            }
         ],
         "Authors": ["Yiğit Can Yılmaz"],
         "Programs": ["Apple"],
         "Bugs": ["Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-12-13",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-20942: It's not old functionality, it's vintage",
               "Link": "https://www.secforce.com/blog/cve-2022-20942-its-not-old-functionality-its-vintage/"
            }
         ],
         "Authors": ["Silver Security (@SugarFiendSec)"],
         "Programs": ["Cisco"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-13",
         "AddedDate": "2023-01-02"
      },
      {
         "Links": [
            {
               "Title": "Not usual CSP bypass case",
               "Link": "https://karol-mazurek95.medium.com/not-usual-csp-bypass-case-b538263e09d6"
            }
         ],
         "Authors": ["Karol Mazurek"],
         "Programs": ["-"],
         "Bugs": ["Unrestricted file upload", "XSS", "CSP bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-12",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "PII data exfiltration within minutes",
               "Link": "https://0xmayankgarg.medium.com/pii-data-exfiltration-within-minutes-f06d4587d201"
            }
         ],
         "Authors": ["Mayank Garg"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-12",
         "AddedDate": "2022-12-15"
      },
      {
         "Links": [
            {
               "Title": "How I became a millionaire in 3h | Fintech Bug Bounty — Part 1",
               "Link": "https://0x4kd.medium.com/how-i-became-a-millionaire-in-3h-fintech-bug-bounty-part-1-90193c5bd86f"
            },
            {
             "Title": "Part 2",
             "Link": "https://0x4kd.medium.com/graphql-exploitation-techniques-fintech-bug-bounty-part-2-b05b9cb7d64b"
            }
         ],
         "Authors": ["0x4KD (@0x4kd)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Lack of rate limiting", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2022-12-12",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "How “I hacked the Dutch government and got the lousy t-shirt”",
               "Link": "https://medium.com/@Iam5345/how-i-hacked-the-dutch-government-and-got-the-lousy-t-shirt-81fd0a0dd84d"
            }
         ],
         "Authors": ["IamDEAD"],
         "Programs": ["Dutch Government"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-12-11",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "IDOR allows to assign deleted tasks to other members in Google Chat Space",
               "Link": "https://hopesamples.blogspot.com/2022/12/idor-allows-to-assign-deleted-tasks-to.html"
            }
         ],
         "Authors": ["Vivek M"],
         "Programs": ["Google"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2022-12-11",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "Source code leakage due to exposed sourcemap",
               "Link": "https://hopesamples.blogspot.com/2022/12/source-code-leakage-due-to-exposed.html"
            }
         ],
         "Authors": ["Vivek M"],
         "Programs": ["Google"],
         "Bugs": ["Source code disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-11",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "User names and email addresses are exposed to unprivileged admins in the Google Marketing Platform",
               "Link": "https://hopesamples.blogspot.com/2022/12/user-names-and-email-addresses-are.html"
            }
         ],
         "Authors": ["Vivek M"],
         "Programs": ["Google"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-11",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "Custom role details are exposed in Google groups.",
               "Link": "https://hopesamples.blogspot.com/2022/12/custom-role-details-are-exposed-in.html"
            }
         ],
         "Authors": ["Vivek M"],
         "Programs": ["Google"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-11",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "Users of other organizations can be confirmed on the Google Marketing Platform - User enumeration Error based",
               "Link": "https://hopesamples.blogspot.com/2022/12/users-of-other-organizations-can-be.html"
            }
         ],
         "Authors": ["Vivek M"],
         "Programs": ["Google"],
         "Bugs": ["Username enumeration", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-11",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "Scoring $$$ for a very simple bug : You don’t always need proxy tools",
               "Link": "https://medium.com/@mrd17x/scoring-for-a-very-simple-bug-you-dont-always-need-proxy-tools-872a832f83ea"
            }
         ],
         "Authors": ["MRD7 (@_mrd7_)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2022-12-10",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "Automate Cross-Site Scripting (XSS) exploitation with unusal events and Burp Intruder",
               "Link": "https://web.archive.org/web/20221212095559/https://medium.com/@seeu-inspace/automate-cross-site-scripting-xss-exploitation-with-unusal-events-and-burp-intruder-9dfed4369fff"
            }
         ],
         "Authors": ["Riccardo Malatesta (@seeu_inspace)"],
         "Programs": ["-"],
         "Bugs": ["XSS", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-10",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "Public Report – VPN by Google One Security Assessment",
               "Link": "https://research.nccgroup.com/2022/12/09/public-report-vpn-by-google-one-security-assessment/"
            }
         ],
         "Authors": ["Daniel Romero (@daniel_rome)", "Laura Garcia", "Mario Rivas", "Rafael Alfaro March", "Shawn Fitzgerald"],
         "Programs": ["Google"],
         "Bugs": ["Android", "iOS", "DoS", "Windows", "MacOS", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-12-09",
         "AddedDate": "2022-03-09"
      },
      {
         "Links": [
            {
               "Title": "The first step to PWN2OWN - A sad one",
               "Link": "https://blog.viettelcybersecurity.com/the-first-step-to-pwn2own-but-a-sad-one/"
            }
         ],
         "Authors": ["Vương Quốc Huy"],
         "Programs": ["Netgear"],
         "Bugs": ["Command injection"],
         "Bounty": "-",
         "PublicationDate": "2022-12-09",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "Privilege Escalation to remove the owner from the organization",
               "Link": "https://medium.com/@kashyapherry147/privilege-escalation-to-remove-the-owner-from-the-organization-c029292a5d55"
            }
         ],
         "Authors": ["Hemant Kumar"],
         "Programs": ["-"],
         "Bugs": ["Privilege escalation", "Mass assignment"],
         "Bounty": "-",
         "PublicationDate": "2022-12-09",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "STRIPE Live Key Exposed:: Bounty: $1000",
               "Link": "https://infosecwriteups.com/stripe-live-key-exposed-bounty-1000-dc670f2c5d9c"
            }
         ],
         "Authors": ["Vipul Sahu"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "1,000",
         "PublicationDate": "2022-12-09",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "{JS-ON: Security-OFF}: Abusing JSON-Based SQL to Bypass WAF",
               "Link": "https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf"
            },
            {
               "Title": "Slides",
               "Link": "https://i.blackhat.com/EU-22/Thursday-Briefings/EU-22-Noam-Moshe-JS-ON-Security-off.pdf"
            }
         ],
         "Authors": ["Noam Moshe"],
         "Programs": ["Palo Alto Networks", "AWS", "Cloudflare", "F5", "Imperva"],
         "Bugs": ["WAF bypass", "SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2022-12-08",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "CORS Misconfig on Out of scope domain Bug Bounty Writeup (300 USD Reward )",
               "Link": "https://jowin922.medium.com/cors-misconfig-on-out-of-scope-domain-bug-bounty-writeup-300-usd-reward-8a9e420d21e0"
            }
         ],
         "Authors": ["Eagle_92"],
         "Programs": ["-"],
         "Bugs": ["CORS misconfiguration"],
         "Bounty": "300",
         "PublicationDate": "2022-12-08",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "Race Condition vulnerability in Azure Video Indexer allowed trial account users use Advance / Premium feature",
               "Link": "https://blog.agilehunt.com/blogs/security/race-condition-vulnerability-in-azure-video-indexer-allowed-trial-account-users-use-advance-premium-feature"
            }
         ],
         "Authors": ["Vikas Anil Sharma (@vikzsharma)"],
         "Programs": ["Microsoft (Azure)"],
         "Bugs": ["Race condition"],
         "Bounty": "-",
         "PublicationDate": "2022-12-07",
         "AddedDate": "2023-03-15"
      },
      {
         "Links": [
            {
               "Title": "DataBinding2Shell: Novel Pathways to RCE Web Frameworks",
               "Link": "https://www.blackhat.com/eu-22/briefings/schedule/#databindingshell-novel-pathways-to-rce-web-frameworks-28583"
            }
         ],
         "Authors": ["Haowen Mu (@meizjm3i)", "Biao He (@codeplutos)"],
         "Programs": ["Spring", "Grails"],
         "Bugs": ["RCE", "Spring4Shell"],
         "Bounty": "-",
         "PublicationDate": "2022-12-07",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "A03:2021 — [Injection] SQL Injection through internal directory disclose",
               "Link": "https://tusharvaidya16.medium.com/a03-2021-injection-sql-injection-through-internal-directory-disclose-ecdef5230131"
            }
         ],
         "Authors": ["Tushar"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-07",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "How you can find your first bug using google",
               "Link": "https://medium.com/@shellyshubh/how-you-can-find-your-first-bug-using-google-c9327f82632e"
            }
         ],
         "Authors": ["shbugger1"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-07",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "Cool Vulns Don't Live Long - Netgear And Pwn2Own",
               "Link": "https://www.synacktiv.com/publications/cool-vulns-dont-live-long-netgear-and-pwn2own.html"
            }
         ],
         "Authors": ["Kevin Denis"],
         "Programs": ["Netgear"],
         "Bugs": ["Code injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-12-06",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022",
               "Link": "https://starlabs.sg/blog/2022/12-the-last-breath-of-our-netgear-rax30-bugs-a-tragic-tale-before-pwn2own-toronto-2022/"
            }
         ],
         "Authors": ["Vu Thi Lan (@lanleft_)", "Nguyễn Hoàng Thạch (@hi_im_d4rkn3ss)"],
         "Programs": ["Netgear"],
         "Bugs": ["Command injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-12-06",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "How we breached ZDFheute live on television",
               "Link": "https://medium.com/@cybercitizen.tech/how-we-breached-zdfheute-live-on-television-7530509b91be"
            }
         ],
         "Authors": ["CyberCitizen"],
         "Programs": ["Zweites Deutsches Fernsehen"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-06",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "TheHole New World - how a small leak will sink a great browser (CVE-2021-38003)",
               "Link": "https://starlabs.sg/blog/2022/12-the-hole-new-world-how-a-small-leak-will-sink-a-great-browser-cve-2021-38003/"
            }
         ],
         "Authors": ["Bruce Chen (@bruce30262)"],
         "Programs": ["Google (Chrome)"],
         "Bugs": ["Memory corruption", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-12-06",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "[BAC/IDOR] How my father credit card help me to find this access control issue",
               "Link": "https://xcoder074.medium.com/bac-idor-how-my-father-credit-card-help-me-to-find-this-access-control-issue-7ff7c1ae463e"
            }
         ],
         "Authors": ["Xcoder(Joy ahmed) (@xcoder074)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Lack of rate limiting"],
         "Bounty": "350",
         "PublicationDate": "2022-12-05",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "OTP Leaking Through Cookie Leads to Account Takeover",
               "Link": "https://ag3n7.medium.com/otp-leaking-through-cookie-leads-to-account-takeover-4fb96f255e2f"
            }
         ],
         "Authors": ["ag3n7"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2022-12-05",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "Bug Writeup: RCE via SSTI on Spring Boot Error Page with Akamai WAF Bypass",
               "Link": "https://www.pmnh.site/post/writeup_spring_el_waf_bypass/"
            }
         ],
         "Authors": ["Peter M (@pmnh_)", "Usman Mansha (@UsmanMansha420)"],
         "Programs": ["GitHub"],
         "Bugs": ["SSTI", "RCE", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-04",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "Hijacking GitHub Repositories by Deleting and Restoring Them",
               "Link": "https://blog.nietaanraken.nl/posts/gitub-popular-repository-namespace-retirement-bypass/"
            }
         ],
         "Authors": ["Joren Vrancken"],
         "Programs": ["GitHub"],
         "Bugs": ["Repojacking"],
         "Bounty": "4,000",
         "PublicationDate": "2022-12-04",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "The most underrated injection of all time — CYPHER INJECTION. How I found and exploited it ?",
               "Link": "https://marvelmaniac.medium.com/the-most-underrated-injection-of-all-time-cypher-injection-fa2018ba0de8"
            }
         ],
         "Authors": ["Ashutosh Dutta (@maniacmarvel_)"],
         "Programs": ["-"],
         "Bugs": ["Cypher injection", "SSRF"],
         "Bounty": "2,000",
         "PublicationDate": "2022-12-04",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "URL Validation Bypass Using Browser URI Normalization",
               "Link": "https://marxchryz.medium.com/url-validation-bypass-using-browser-uri-normalization-cf545d33d13f"
            }
         ],
         "Authors": ["Marx Chryz Del Mundo"],
         "Programs": ["-"],
         "Bugs": ["URL validation bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-04",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "Drupal H5P Module <= 2.0.0 (isValidPackage) Zip Slip Vulnerability",
               "Link": "https://karmainsecurity.com/KIS-2022-06"
            }
         ],
         "Authors": ["Egidio Romano / EgiX"],
         "Programs": ["Drupal"],
         "Bugs": ["Zip Slip attack", "Path traversal", "Source code disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-03",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys",
               "Link": "https://blog.dixitaditya.com/manipulating-aes-traffic-using-a-chain-of-proxies-and-hardcoded-keys"
            }
         ],
         "Authors": ["Aditya Dixit (@zombie007o)"],
         "Programs": ["-"],
         "Bugs": ["Android", "Hardcoded credentials", "Client-side encryption bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-12-03",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover - Inside The Tenant",
               "Link": "https://shahjerry33.medium.com/account-takeover-inside-the-tenant-6101a3cafbee"
            }
         ],
         "Authors": ["Jerry Shah (@Jerry)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Information disclosure"],
         "Bounty": "150",
         "PublicationDate": "2022-12-03",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "A $$$ worth of cookies! | Reflected DOM-Based XSS | Bug Bounty POC",
               "Link": "https://medium.com/@haroonhameed_76621/a-775-worth-of-cookies-reflected-dom-based-xss-bug-bounty-poc-3e7720c78fbe"
            }
         ],
         "Authors": ["Haroon Hameed (@HaroonHameed40)", "Hannan Haseeb (@HannanHaseeb11)"],
         "Programs": ["-"],
         "Bugs": ["DOM XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-12-03",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "3 Step IDOR in HackerResume",
               "Link": "https://medium.com/@swapmaurya20/3-step-idor-in-hackerresume-a365f2632996"
            }
         ],
         "Authors": ["Swapnil Maurya (@swapmaurya20)"],
         "Programs": ["HackerResume"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2022-12-03",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "SysmonEoP",
               "Link": "https://github.com/Wh04m1001/SysmonEoP"
            }
         ],
         "Authors": ["Filip Dragovic (@filip_dragovic)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Local Privilege Escalation", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2022-12-03",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "Hacking on a plane: Leaking data of millions and taking over any account",
               "Link": "http://rez0.blog/hacking/2022/12/02/hacking-on-a-plane.html"
            }
         ],
         "Authors": ["rez0 (@rez0__)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2022-12-02",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "Pre-Auth RCE with CodeQL in Under 20 Minutes",
               "Link": "https://frycos.github.io/vulns4free/2022/12/02/rce-in-20-minutes.html"
            }
         ],
         "Authors": ["Florian Hauser (@frycos)"],
         "Programs": ["pgAdmin"],
         "Bugs": ["Security code review", "RCE", "Command injection", "Broken authorization"],
         "Bounty": "-",
         "PublicationDate": "2022-12-02",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "CertPotato – Using ADCS to privesc from virtual and network service accounts to local system",
               "Link": "https://sensepost.com/blog/2022/certpotato-using-adcs-to-privesc-from-virtual-and-network-service-accounts-to-local-system/"
            }
         ],
         "Authors": ["Hocine Mahtout (@Sant0rryu)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Local Privilege Escalation", "ADCS"],
         "Bounty": "-",
         "PublicationDate": "2022-12-02",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "Multiple Vulnerabilities in Proxmox VE & Proxmox Mail Gateway",
               "Link": "https://starlabs.sg/blog/2022/12-multiple-vulnerabilites-in-proxmox-ve--proxmox-mail-gateway/"
            }
         ],
         "Authors": ["JianTao Li (@cursered)"],
         "Programs": ["Proxmox"],
         "Bugs": ["XSS", "CRLF injection", "SSRF", "LFI", "Local Privilege Escalation", "Arbitrary file read"],
         "Bounty": "-",
         "PublicationDate": "2022-12-02",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "[WRITE-UP] Irremovable comments on the FB Lite app | A story of a simple FB Lite bug that I found just by observation (Bounty: 500 USD)",
               "Link": "https://theshubh77.medium.com/write-up-irremovable-comments-on-fb-lite-app-a-story-of-a-simple-fb-lite-bug-that-i-found-just-125aaa826dd8"
            }
         ],
         "Authors": ["Shubham Bhamare (@theshubh77)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["Logic flaw"],
         "Bounty": "500",
         "PublicationDate": "2022-12-02",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "Interesting find on the Invite link",
               "Link": "https://medium.com/@sathvika03/interesting-find-on-the-invite-link-17cf5a46d747"
            }
         ],
         "Authors": ["Sathvika"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2022-12-02",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "Command Injection in Asus M25 NAS",
               "Link": "https://onekey.com/blog/security-advisory-asus-m25-nas-vulnerability/"
            }
         ],
         "Authors": ["Quentin Kaiser (@QKaiser)"],
         "Programs": ["Asus"],
         "Bugs": ["OS command injection", "Source code disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-01",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225)",
               "Link": "https://www.rcesecurity.com/2022/12/from-zero-to-hero-part-2-intel-dcm-sql-injection-to-rce-cve-2022-21225/"
            }
         ],
         "Authors": ["Julien Ahrens (@MrTuxracer)"],
         "Programs": ["Intel"],
         "Bugs": ["SQL injection", "Kerberos", "RCE", "Privilege escalation", "Security code review"],
         "Bounty": "10,000",
         "PublicationDate": "2022-12-01",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "Bypassing The Client Side Encryption To Read Internal Windows Server Files",
               "Link": "https://abhishekmorla.medium.com/bypassing-the-client-side-encryption-to-read-internal-windows-server-files-e832da8b4ac8"
            }
         ],
         "Authors": ["Abhishek Morla (@abhishekmorla)"],
         "Programs": ["-"],
         "Bugs": ["Client-side encryption bypass", "LFI", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-12-01",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential for unauthorized database access",
               "Link": "https://www.wiz.io/blog/hells-keychain-supply-chain-attack-in-ibm-cloud-databases-for-postgresql"
            }
         ],
         "Authors": ["Ronen Shustin (@ronenshh)", "Shir Tamari (@shirtamari)"],
         "Programs": ["IBM"],
         "Bugs": ["Cloud", "SQL injection", "Privilege escalation", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-12-01",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "Novel Pipeline Vulnerability Discovered; Rust  Found Vulnerable",
               "Link": "https://www.legitsecurity.com/blog/artifact-poisoning-vulnerability-discovered-in-rust"
            }
         ],
         "Authors": ["Noam Dotan"],
         "Programs": ["GitHub", "Rust"],
         "Bugs": ["Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2022-12-01",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "XSS on account.leagueoflegends.com via easyXDM [2016]",
               "Link": "https://medium.com/bored-engineer/xss-on-account-leagueoflegends-com-via-easyxdm-2016-75bcf9d582b5"
            }
         ],
         "Authors": ["Luke Young (@TheBoredEng)"],
         "Programs": ["Riot Games"],
         "Bugs": ["XSS", "postMessage"],
         "Bounty": "2,000",
         "PublicationDate": "2022-12-01",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "VLC : Integer overflow in vnc module <= 3.0.18 CVE-2022-41325",
               "Link": "https://www.synacktiv.com/sites/default/files/2022-11/vlc_vnc_int_overflow-CVE-2022-41325.pdf"
            }
         ],
         "Authors": ["0xMitsurugi"],
         "Programs": ["VLC"],
         "Bugs": ["Memory corruption", "Integer overflow"],
         "Bounty": "-",
         "PublicationDate": "2022-11-30",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "The space creators can still see the members of the space, even after they have been removed from the space.",
               "Link": "https://hopesamples.blogspot.com/2022/11/the-space-creators-can-still-see.html"
            }
         ],
         "Authors": ["Vivek M"],
         "Programs": ["Google"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2022-11-30",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "Stored XSS at https://www.tiktok.com/ the name of the attacker’s account carrying XSS payload will be triggered when the victim Send Video",
               "Link": "https://aidilarf.medium.com/stored-xss-at-https-www-tiktok-com-11fed6db0590"
            }
         ],
         "Authors": ["Aidil Arief"],
         "Programs": ["TikTok"],
         "Bugs": ["Stored XSS"],
         "Bounty": "500",
         "PublicationDate": "2022-11-30",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Unrestricted file upload in Rocket TRUfusion Enterprise <= 7.9.6.0",
               "Link": "https://www.synacktiv.com/sites/default/files/2022-11/trufusion_enterprise_unauthenticated_arbitrary_file_write.pdf"
            }
         ],
         "Authors": ["Mehdi Elyassa", "Kevin Tellier"],
         "Programs": ["Rocket Software"],
         "Bugs": ["Unrestricted file upload", "Security code review", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-11-30",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Brocade Fabric OS ≤ v8.0.2c rbash escape to read system files",
               "Link": "https://blog.bitcrack.net/fabric-os-8-0-2cs-rbash-escape-to-read-system-files/"
            }
         ],
         "Authors": ["Bitcrack (@bitcrack_cyber)"],
         "Programs": ["Broadcom"],
         "Bugs": ["rbash escape", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-11-29",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "RCE on Apache Struts 2.5.30",
               "Link": "https://mc0wn.blogspot.com/2022/11/rce-on-apache-struts-2530.html"
            }
         ],
         "Authors": ["Chris (@mc_0wn)"],
         "Programs": ["Apache Struts"],
         "Bugs": ["RCE", "Double OGNL evaluation"],
         "Bounty": "-",
         "PublicationDate": "2022-11-29",
         "AddedDate": "2022-12-05"
      },
      {
         "Links": [
            {
               "Title": "VoIP Spoofing (Intigriti) 1,250€",
               "Link": "https://0xjin.medium.com/voip-spoofing-intigriti-1-250-57b99bf8bd2b"
            }
         ],
         "Authors": ["0xJin (@0xJin)"],
         "Programs": ["-"],
         "Bugs": ["VoIP", "Spoofing"],
         "Bounty": "1,296",
         "PublicationDate": "2022-11-29",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Cross-Site Scripting in CodeIgniter version 3.1.13",
               "Link": "https://www.synacktiv.com/sites/default/files/2022-11/CodeIgniter3_XSS_2022.pdf"
            }
         ],
         "Authors": ["Antoine Cervoise", "Maxime Rinaudo"],
         "Programs": ["CodeIgniter"],
         "Bugs": ["Reflected XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-11-29",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "discord.exe – Improper Input Validation",
               "Link": "https://letshack.xyz/offensive/general-research/discord-exe-improper-input-validation"
            }
         ],
         "Authors": ["RiotSecTeam (@RiotSecTeam)", "Isira Adithya (@isira_adithya)"],
         "Programs": ["Discord"],
         "Bugs": ["Security code review", "Local Privilege Escalation", "Phishing"],
         "Bounty": "-",
         "PublicationDate": "2022-11-28",
         "AddedDate": "2022-11-23"
      },
      {
         "Links": [
            {
               "Title": "Broken access control + misconfiguration = Beautiful privilege escalation",
               "Link": "https://medium.com/@Hossam.Mesbah/broken-access-control-misconfiguration-beautiful-privilege-escalation-e4fdfd018efa"
            }
         ],
         "Authors": ["Hossam Mesbah (@m359ah)"],
         "Programs": ["-"],
         "Bugs": ["Broken Access Control", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-11-28",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Improper error handling leads to exposing internal tokens",
               "Link": "https://medium.com/@aa.pietruczuk/improper-error-handling-leads-to-exposing-internal-tokens-3355d6b43a32"
            }
         ],
         "Authors": ["Agnieszka Pietruczuk"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-11-28",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "The Untold SendBird Misconfigurations",
               "Link": "https://ltidi.medium.com/the-untold-sendbird-misconfigurations-1496d252bc69"
            }
         ],
         "Authors": ["LTiDi (@dunglt140150)", "Thái Vũ (@thaivd98)", "LamScun (@LamScun)", "fergus (@fergustr4n)", "thefool45"],
         "Programs": ["SendBird"],
         "Bugs": ["Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2022-11-27",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Multiple Vulnerabilities found in Airtel Android Application",
               "Link": "https://offsec.space/posts/airtel-vulnerabilities/"
            }
         ],
         "Authors": ["Gaurang Bhatnagar (@hax0rgb)"],
         "Programs": ["Airtel", "Google"],
         "Bugs": ["Arbitrary Code Execution", "URL validation bypass", "Symlink attack", "XSS", "Android", "Webview"],
         "Bounty": "4,000",
         "PublicationDate": "2022-11-27",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "2FA Enabled Accounts Can Bypass Authentication & Access Account After Deactivation",
               "Link": "https://medium.com/@sharp488/2fa-enabled-accounts-can-bypass-authentication-access-account-after-deactivation-8276a586be82"
            }
         ],
         "Authors": ["Sharat Kaikolamthuruthil (@sharp488)"],
         "Programs": ["-"],
         "Bugs": ["Authentication bypass", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2022-11-27",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Unique Rate limit bypass worth 1800$",
               "Link": "https://infosecwriteups.com/unique-rate-limit-bypass-worth-1800-6e2947c7d972"
            }
         ],
         "Authors": ["Manav Bankatwala (@ManavBankatwala)"],
         "Programs": ["-"],
         "Bugs": ["Rate limiting bypass", "Captcha bypass"],
         "Bounty": "1,800",
         "PublicationDate": "2022-11-27",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Firebase Exploit bug bounty",
               "Link": "https://medium.com/@damaidec/firebase-exploit-bug-bounty-be63f4dc1e4a"
            }
         ],
         "Authors": ["Damaidec"],
         "Programs": ["-"],
         "Bugs": ["Security misconfiguration", "Firebase"],
         "Bounty": "-",
         "PublicationDate": "2022-11-27",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Access Any Owner Account without Authentication (Auth bypass + 2FA bypass)",
               "Link": "https://medium.com/@sharp488/access-any-owner-account-without-authentication-auth-bypass-2fa-bypass-94d0d3ef0d9c"
            }
         ],
         "Authors": ["Sharat Kaikolamthuruthil (@sharp488)"],
         "Programs": ["-"],
         "Bugs": ["Authentication bypass", "2FA / MFA bypass", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2022-11-27",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Automating Unsolicited Richard Pics; Pwning 60,000 Digital Picture Frames",
               "Link": "https://www.scrawledsecurityblog.com/2022/11/automating-unsolicited-richard-pics.html"
            }
         ],
         "Authors": ["Nick M (@1oopho1e)"],
         "Programs": ["Ourphoto"],
         "Bugs": ["IDOR", "Broken Access Control", "Android", "IoT"],
         "Bounty": "-",
         "PublicationDate": "2022-11-26",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "A Real World Example Of Classic Remote Command Execution (RCE)",
               "Link": "https://bhashit.in/?p=117"
            }
         ],
         "Authors": ["Bhashit Pandya (@x30r_)"],
         "Programs": ["-"],
         "Bugs": ["OS command injection", "XSS", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-11-26",
         "AddedDate": "2022-12-09"
      },
      {
         "Links": [
            {
               "Title": "[Hacking Bank] The Second Story of Finding Critical Vulnerabilities on Banking Application",
               "Link": "https://medium.com/@protostar0/hacking-bank-the-second-story-of-finding-critical-vulnerabilities-on-banking-application-ac20cd8f3dad"
            }
         ],
         "Authors": ["Abdelhak Kharroubi"],
         "Programs": ["-"],
         "Bugs": ["Android", "Hardcoded credentials", "IDOR"],
         "Bounty": "-",
         "PublicationDate": "2022-11-26",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "A great weekend hack(worth $8k)",
               "Link": "https://infosecwriteups.com/a-great-weekend-hack-worth-8k-9bfda8ab65b9"
            }
         ],
         "Authors": ["Manas Harsh (@ManasH4rsh)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "IDOR", "Stored XSS"],
         "Bounty": "8,000",
         "PublicationDate": "2022-11-26",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "WebView XSS, account takeover",
               "Link": "https://shafouz.medium.com/webview-xss-account-takeover-349c1d69606e"
            }
         ],
         "Authors": ["shafou"],
         "Programs": ["-"],
         "Bugs": ["Webview XSS", "Android", "Account takeover", "Improper Export of Android Application Components"],
         "Bounty": "2,500",
         "PublicationDate": "2022-11-26",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Exploiting CORS Misconfigurations",
               "Link": "https://attackshipsonfi.re/p/exploiting-cors-misconfigurations"
            }
         ],
         "Authors": ["scarlet / attack ships on fire"],
         "Programs": ["Apple", "Google", "Mozilla (Firefox)", "WHATWG"],
         "Bugs": ["CORS misconfiguration", "CSRF", "XST"],
         "Bounty": "-",
         "PublicationDate": "2022-11-26",
         "AddedDate": "2022-11-26"
      },
      {
         "Links": [
            {
               "Title": "How I hacked into a government e-learning website",
               "Link": "https://iamgk808.medium.com/how-i-hacked-into-a-government-e-learning-website-ce8da8fb4ccc"
            }
         ],
         "Authors": ["iamgk808 (@iamgk808)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2022-11-26",
         "AddedDate": "2022-11-26"
      },
      {
         "Links": [
            {
               "Title": "Hacking Dutch Government-Broken Authentication To Full Website Takeover (P1)",
               "Link": "https://v1dr4x.medium.com/hacking-dutch-government-broken-authentication-to-full-website-takeover-p1-9af477604d54"
            }
         ],
         "Authors": ["V1dr4X"],
         "Programs": ["Dutch Government"],
         "Bugs": ["Exposed registration page"],
         "Bounty": "-",
         "PublicationDate": "2022-11-26",
         "AddedDate": "2022-11-26"
      },
      {
         "Links": [
            {
               "Title": "Exploiting an N-day vBulletin PHP Object Injection Vulnerability",
               "Link": "https://karmainsecurity.com/exploiting-an-nday-vbulletin-php-object-injection"
            }
         ],
         "Authors": ["Egidio Romano / EgiX"],
         "Programs": ["vBulletin"],
         "Bugs": ["PHP object injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-11-26",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Able to Mass-change profile section leads to my first $BOUNTY$",
               "Link": "https://hacklido.com/d/93-able-to-mass-change-profile-section-leads-to-my-first-bounty"
            }
         ],
         "Authors": ["SYRINE"],
         "Programs": ["-"],
         "Bugs": ["HTML injection", "IDOR", "CSRF"],
         "Bounty": "1,000",
         "PublicationDate": "2022-11-25",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022–43781",
               "Link": "https://petrusviet.medium.com/cve-2022-43781-32bc29de8960"
            }
         ],
         "Authors": ["Petrus Viet (@VietPetrus)"],
         "Programs": ["Atlassian"],
         "Bugs": ["OS command injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-11-25",
         "AddedDate": "2022-11-25"
      },
      {
         "Links": [
            {
               "Title": "Hacker's Guide to Directory/Endpoint Enumeration",
               "Link": "https://rashahacks.com/directory-enumeration-guide/"
            }
         ],
         "Authors": ["Inderjeet Singh (@3nc0d3dGuY)"],
         "Programs": ["-"],
         "Bugs": ["40x bypass"],
         "Bounty": "500",
         "PublicationDate": "2022-11-24",
         "AddedDate": "2023-01-11"
      },
      {
         "Links": [
            {
               "Title": "Legally hacking a Government Satellite?",
               "Link": "https://letshack.xyz/offensive/web-application/legally-hacking-a-government-satellite"
            }
         ],
         "Authors": ["RiotSecTeam (@RiotSecTeam)", "Josh"],
         "Programs": ["-"],
         "Bugs": ["Missing authentication", "OS command injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-11-24",
         "AddedDate": "2022-12-20"
      },
      {
         "Links": [
            {
               "Title": "Contrast discovers zero-day flaw in popular Quarkus Java framework",
               "Link": "https://www.contrastsecurity.com/security-influencers/localhost-attack-against-quarkus-developers-contrast-security"
            }
         ],
         "Authors": ["Joseph Beeton"],
         "Programs": ["Quarkus"],
         "Bugs": ["Drive-by attack", "CSRF", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-11-23",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "Multiple vulnerabilities in H2O ≤ 3.32.1.3",
               "Link": "https://www.synacktiv.com/sites/default/files/2022-11/h2o_multiple_vulnerabilities.pdf"
            }
         ],
         "Authors": ["Clément Amic (@loadlow)", "Lena David"],
         "Programs": ["H2O"],
         "Bugs": ["Insecure deserialization", "RCE", "Arbitrary file read", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-11-23",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "From Zero to Hero Part 1: Bypassing Intel DCM’s Authentication by Spoofing Kerberos and LDAP Responses (CVE-2022-33942)",
               "Link": "https://www.rcesecurity.com/2022/11/from-zero-to-hero-part-1-bypassing-intel-dcms-authentication-cve-2022-33942/"
            }
         ],
         "Authors": ["Julien Ahrens (@MrTuxracer)"],
         "Programs": ["Intel"],
         "Bugs": ["Authentication bypass", "Kerberos", "RCE", "Privilege escalation", "Security code review"],
         "Bounty": "10,000",
         "PublicationDate": "2022-11-23",
         "AddedDate": "2022-11-25"
      },
      {
         "Links": [
            {
               "Title": "Dodging OAuth origin restrictions for Firebase spelunking",
               "Link": "https://saligrama.io/blog/post/dodging-oauth-origin-restrictions/"
            }
         ],
         "Authors": ["Aditya Saligrama (@saligrama_a)", "Glen Husman"],
         "Programs": ["-"],
         "Bugs": ["OAuth", "Security misconfiguration", "Broken authentication"],
         "Bounty": "-",
         "PublicationDate": "2022-11-23",
         "AddedDate": "2022-11-25"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-40300: SQL Injection In Manageengine Privileged Access Management",
               "Link": "https://www.zerodayinitiative.com/blog/2022/11/22/cve-2022-40300-sql-injection-in-manageengine-privileged-access-management"
            }
         ],
         "Authors": ["Justin Hung", "Dusan Stevanovic"],
         "Programs": ["Zoho (ManageEngine)"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2022-11-23",
         "AddedDate": "2022-11-25"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover in KAYAK",
               "Link": "https://fluidattacks.com/blog/account-takeover-kayak/"
            }
         ],
         "Authors": ["Carlos Bello"],
         "Programs": ["KAYAK"],
         "Bugs": ["Account takeover", "Android", "Insecure deeplink"],
         "Bounty": "-",
         "PublicationDate": "2022-11-23",
         "AddedDate": "2022-11-25"
      },
      {
         "Links": [
            {
               "Title": "How I get +10 SQLi and +30 XSS via Automation Tool",
               "Link": "https://medium.com/@0xelkot/how-i-get-10-sqli-and-30-xss-via-automation-tool-cebbd9104479"
            }
         ],
         "Authors": ["Mahmoud Attia (@0xElkot)"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-23",
         "AddedDate": "2022-11-25"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-32898: ANE_ProgramCreate() multiple kernel memory corruption",
               "Link": "https://0x36.github.io/CVE-2022-32898/"
            }
         ],
         "Authors": ["simo (@_simo36)"],
         "Programs": ["Apple"],
         "Bugs": ["Memory corruption", "iOS", "Kernel hacking"],
         "Bounty": "-",
         "PublicationDate": "2022-11-23",
         "AddedDate": "2022-11-25"
      },
      {
         "Links": [
            {
               "Title": "XSS Vulnerability Found in ConnectWise Remote Access Platform With Great Potential For Misuse by Scammers",
               "Link": "https://labs.guard.io/xss-vulnerability-found-in-connectwise-remote-access-platform-with-great-potential-for-misuse-by-scammers-a0773da2aacf"
            }
         ],
         "Authors": ["Nati Tal"],
         "Programs": ["ConnectWise"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-23",
         "AddedDate": "2022-11-26"
      },
      {
         "Links": [
            {
               "Title": "CVE-2021-40662 Chamilo LMS 1.11.14 RCE",
               "Link": "https://hacklido.com/d/90-cve-2021-40662-chamilo-lms-11114-rce"
            }
         ],
         "Authors": ["Febin"],
         "Programs": ["Chamilo LMS"],
         "Bugs": ["Stored XSS", "CSRF", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2021-11-23",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-41924 - RCE in Tailscale, DNS Rebinding, and You",
               "Link": "https://emily.id.au/tailscale"
            }
         ],
         "Authors": ["Jamie McClymont (@JJJollyjim)", "Emily Trau (@emilyposting_)"],
         "Programs": ["Tailscale"],
         "Bugs": ["RCE", "DNS rebinding", "Information disclosure"],
         "Bounty": "10,000",
         "PublicationDate": "2022-11-22",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "SSRF via DNS Rebinding (CVE-2022–4096)",
               "Link": "https://basu-banakar.medium.com/ssrf-via-dns-rebinding-cve-2022-4096-b7bf75928bb2"
            }
         ],
         "Authors": ["Basavaraj Banakar (@basu_banakar)"],
         "Programs": ["Appsmith"],
         "Bugs": ["SSRF", "DNS rebinding", "TOCTOU"],
         "Bounty": "-",
         "PublicationDate": "2022-11-22",
         "AddedDate": "2022-11-23"
      },
      {
         "Links": [
            {
               "Title": "Interesting Stored XSS via meta data",
               "Link": "https://medium.com/pentesternepal/interesting-stored-xss-via-meta-data-eb8fe1de8b33"
            }
         ],
         "Authors": ["Veshraj Ghimire (@GhimireVeshraj)", "Bibek Neupane (@nb1b3k)"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-22",
         "AddedDate": "2022-11-23"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – NETGEAR R7800 AFPD PreAuth",
               "Link": "https://ssd-disclosure.com/ssd-advisory-netgear-r7800-afpd-preauth/"
            }
         ],
         "Authors": ["-"],
         "Programs": ["Netgear"],
         "Bugs": ["Memory corruption", "Buffer Overflow"],
         "Bounty": "-",
         "PublicationDate": "2022-11-22",
         "AddedDate": "2022-11-23"
      },
      {
         "Links": [
            {
               "Title": "Till REcollapse - Fuzzing the web for mysterious bugs",
               "Link": "https://github.com/0xacb/recollapse/blob/main/till_recollapse_fuzzing_the_web_for_mysterious_bugs.pdf"
            },
            {
               "Title": "Blog post",
               "Link": "https://0xacb.com/2022/11/21/recollapse/"
            }
         ],
         "Authors": ["André Baptista (@0xacb)"],
         "Programs": ["-"],
         "Bugs": ["Regex", "Account takeover", "Open redirect", "Web cache deception", "Buffer Overflow", "OAuth", "Normalization"],
         "Bounty": "-",
         "PublicationDate": "2022-11-21",
         "AddedDate": "2022-11-23"
      },
      {
         "Links": [
            {
               "Title": "A Confused Deputy Vulnerability in AWS AppSync",
               "Link": "https://securitylabs.datadoghq.com/articles/appsync-vulnerability-disclosure/"
            }
         ],
         "Authors": ["Nick Frichette (@frichette_n)"],
         "Programs": ["AWS"],
         "Bugs": ["Confused deputy", "Cloud", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-11-21",
         "AddedDate": "2022-11-22"
      },
      {
         "Links": [
            {
               "Title": "Header spoofing via a hidden parameter in Facebook Batch GraphQL APIs",
               "Link": "https://feed.bugs.xdavidhu.me/bugs/0017"
            }
         ],
         "Authors": ["David Schütz (@xdavidhu)"],
         "Programs": ["Meta / Facebook"],
         "Bugs": ["GraphQL", "Security misconfiguration"],
         "Bounty": "3,000",
         "PublicationDate": "2022-11-21",
         "AddedDate": "2022-11-22"
      },
      {
         "Links": [
            {
               "Title": "Fastly Subdomain Takeover $2000",
               "Link": "https://medium.com/@valluvarsploit/fastly-subdomain-takeover-2000-217bb180730f"
            }
         ],
         "Authors": ["ValluvarSploit (@ValluvarSploit)"],
         "Programs": ["-"],
         "Bugs": ["Subdomain takeover"],
         "Bounty": "2,000",
         "PublicationDate": "2022-11-21",
         "AddedDate": "2022-11-22"
      },
      {
         "Links": [
            {
               "Title": "My Account Takeover Writeup: $5000",
               "Link": "https://medium.com/@mrd17x/my-account-takeover-writeup-5000-6895492aa549"
            }
         ],
         "Authors": ["MRD7 (@_mrd7_)"],
         "Programs": ["-"],
         "Bugs": ["Lack of rate limiting", "Bruteforce"],
         "Bounty": "5,000",
         "PublicationDate": "2022-11-21",
         "AddedDate": "2022-11-25"
      },
      {
         "Links": [
            {
               "Title": "Hacking Smartwatches for Spear Phishing",
               "Link": "https://cybervelia.com/?p=1380"
            }
         ],
         "Authors": ["Cybervelia (@cybervelia)"],
         "Programs": ["-"],
         "Bugs": ["IoT", "Phishing", "Android"],
         "Bounty": "-",
         "PublicationDate": "2022-11-20",
         "AddedDate": "2022-11-30"
      },
      {
         "Links": [
            {
               "Title": "Email Graffiti: hacking old email",
               "Link": "https://trufflesecurity.com/blog/email-graffiti/index.html"
            }
         ],
         "Authors": ["Dylan Ayrey (@insecurenature)"],
         "Programs": ["Google (Youtube)"],
         "Bugs": ["Broken link hijacking"],
         "Bounty": "-",
         "PublicationDate": "2022-11-20",
         "AddedDate": "2022-11-23"
      },
      {
         "Links": [
            {
               "Title": "How i found 29 stored XSS in modern framework",
               "Link": "https://dewcode.medium.com/how-i-found-29-stored-xss-in-modern-framework-1cfe60a107a0"
            }
         ],
         "Authors": ["Dewanand Vishal (@dewcode91)"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-20",
         "AddedDate": "2022-11-22"
      },
      {
         "Links": [
            {
               "Title": "System misconfiguration is the number one vulnerability, at least for Mastodon",
               "Link": "https://www.alevsk.com/2022/11/system-misconfiguration-is-the-number-one-vulnerability-at-least-for-mastodon/"
            }
         ],
         "Authors": ["Lenin Alevski (@Alevsk)"],
         "Programs": ["infosec.exchange"],
         "Bugs": ["Security misconfiguration", "MinIO misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2022-11-19",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "Russian roulette XSS",
               "Link": "https://splint3rsec.medium.com/russian-roulette-xss-bbba6afd2570"
            }
         ],
         "Authors": ["Splintersec (@splint3rsec)"],
         "Programs": ["-"],
         "Bugs": ["Blind XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-19",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "Remediation Archeology — Finding and Decoding an Ancient XSS",
               "Link": "https://bendtheory.medium.com/remediation-archeology-finding-and-decoding-an-ancient-xss-ea541c1106d1"
            }
         ],
         "Authors": ["Bend Theory (@bendtheory)"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-18",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "From Static domain to Account Takeover",
               "Link": "https://r29k.com/articles/bb/account-takeover"
            }
         ],
         "Authors": ["Demon (@R29k_)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2022-11-18",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "Remote Command Execution in a Bank Server",
               "Link": "https://medium.com/@win3zz/remote-command-execution-in-a-bank-server-b213f9f42afe"
            }
         ],
         "Authors": ["Bipin Jitiya (@win3zz)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Arbitrary file read", "Unrestricted file upload"],
         "Bounty": "-",
         "PublicationDate": "2022-11-18",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "SyncJacking: Hard Matching Vulnerability Enables Azure AD Account Takeover",
               "Link": "https://www.semperis.com/blog/syncjacking-azure-ad-account-takeover/"
            }
         ],
         "Authors": ["Tomer Nahum (@TomerNahum1)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Account takeover", "Azure AD", "Cloud"],
         "Bounty": "-",
         "PublicationDate": "2022-11-18",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "macOS Sandbox Escape vulnerability via Terminal",
               "Link": "https://wojciechregula.blog/post/macos-sandbox-escape-via-terminal/"
            }
         ],
         "Authors": ["Wojciech Reguła (@_r3ggi)"],
         "Programs": ["Apple"],
         "Bugs": ["MacOS", "Sandbox escape", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-11-18",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "$250 for Email account enumeration using “NameToMail” tool",
               "Link": "https://medium.com/@snoopy101/250-for-email-account-enumeration-using-nametomail-tool-cce02a17ade8"
            }
         ],
         "Authors": ["snoopy (@snoopy101101)"],
         "Programs": ["-"],
         "Bugs": ["Username enumeration"],
         "Bounty": "250",
         "PublicationDate": "2022-11-18",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "How i found 8 vulnerabilities in 24h?",
               "Link": "https://0xm5awy.medium.com/how-i-found-8-vulnerabilities-in-24h-aad3bd5fd487"
            }
         ],
         "Authors": ["Mohamed Anani (@0xM5awy)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2022-11-18",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "Bypassing XSS filters using Double Encoding",
               "Link": "https://hacklido.com/d/87-reflected-xss-using-double-encoding"
            }
         ],
         "Authors": ["ag3n7 (@ag3n7apk)"],
         "Programs": ["-"],
         "Bugs": ["XSS", "WAF bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-11-18",
         "AddedDate": "2022-12-12"
      },
      {
         "Links": [
            {
               "Title": "[RE:SCRUTINY] Delay Then Migrate Your Meterpreter",
               "Link": "https://blog.rehack.xyz/2022/11/rescrutiny-delay-then-migrate-your.html"
            }
         ],
         "Authors": ["RE:HACK (@rehackxyz)"],
         "Programs": ["-"],
         "Bugs": ["Internal pentest", "Lateral movement"],
         "Bounty": "-",
         "PublicationDate": "2022-11-17",
         "AddedDate": "2023-03-10"
      },
      {
         "Links": [
            {
               "Title": "MEGA’s Unlimited Cloud Storage Vulnerability",
               "Link": "https://nirmaldahal.com.np/posts/2022/11/megas-unlimited-cloud-storage-vulnerability/"
            }
         ],
         "Authors": ["Nirmal Dahal (@TheNittam)"],
         "Programs": ["MEGA"],
         "Bugs": ["Logic flaw", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-11-17",
         "AddedDate": "2022-11-23"
      },
      {
         "Links": [
            {
               "Title": "Security concerns with the e-Tugra certificate authority",
               "Link": "https://ian.sh/etugra"
            }
         ],
         "Authors": ["Ian Carroll (@iangcarroll)"],
         "Programs": ["e-Tugra"],
         "Bugs": ["Default credentials", "Exposed registration page"],
         "Bounty": "-",
         "PublicationDate": "2022-11-17",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "Got Another XSS using Double Encoding",
               "Link": "https://ag3n7.medium.com/got-another-xss-using-double-encoding-e6493a9f7368"
            }
         ],
         "Authors": ["ag3n7"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-17",
         "AddedDate": "2022-11-18"
      },
      {
         "Links": [
            {
               "Title": "Information Exposure — My Fourth Finding on Hackerone!",
               "Link": "https://mehedishakeel.medium.com/information-exposure-my-fourth-finding-on-hackerone-4fc4461920c4"
            }
         ],
         "Authors": ["mehedishakeel (@mehedishakeel)"],
         "Programs": ["-"],
         "Bugs": ["Directory listing", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-11-17",
         "AddedDate": "2022-11-18"
      },
      {
         "Links": [
            {
               "Title": "Account Takeover Worth of $2500",
               "Link": "https://gonzxph.medium.com/account-takeover-worth-of-2500-e643661f94e9"
            }
         ],
         "Authors": ["Jefferson Gonzales (@gonzxph)"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "IDOR"],
         "Bounty": "2,500",
         "PublicationDate": "2022-11-16",
         "AddedDate": "2022-11-18"
      },
      {
         "Links": [
            {
               "Title": "The Story Of A Strange / Stored IDOR.",
               "Link": "https://medium.com/@hf6452/a-story-of-a-strange-stored-idor-b6f2769bb6cb"
            }
         ],
         "Authors": ["Hassan Farooq"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2022-11-16",
         "AddedDate": "2022-11-18"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-41622 and CVE-2022-41800 (FIXED): F5 BIG-IP and iControl REST Vulnerabilities and Exposures",
               "Link": "https://www.rapid7.com/blog/post/2022/11/16/cve-2022-41622-and-cve-2022-41800-fixed-f5-big-ip-and-icontrol-rest-vulnerabilities-and-exposures/"
            }
         ],
         "Authors": ["Ron Bowes (@iagox86)"],
         "Programs": ["F5"],
         "Bugs": ["CSRF", "RCE", "RPM Spec Injection"],
         "Bounty": "-",
         "PublicationDate": "2022-11-16",
         "AddedDate": "2022-11-17"
      },
      {
         "Links": [
            {
               "Title": "Chromium: Same Origin Policy bypass within a single site a.k.a. \"Google Roulette\"",
               "Link": "https://www.bentkowski.info/2022/11/google-roulette/"
            }
         ],
         "Authors": ["Michał Bentkowski (@SecurityMB)"],
         "Programs": ["Google (Chromium)"],
         "Bugs": ["SOP bypass", "Browser hacking"],
         "Bounty": "-",
         "PublicationDate": "2022-11-16",
         "AddedDate": "2022-11-17"
      },
      {
         "Links": [
            {
               "Title": "Control Your Types Or Get Pwned: Remote Code Execution In Exchange Powershell Backend",
               "Link": "https://www.zerodayinitiative.com/blog/2022/11/14/control-your-types-or-get-pwned-remote-code-execution-in-exchange-powershell-backend"
            }
         ],
         "Authors": ["Piotr Bazydło (@chudyPB)"],
         "Programs": ["Checkmk"],
         "Bugs": ["RCE", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2022-11-16",
         "AddedDate": "2022-11-17"
      },
      {
         "Links": [
            {
               "Title": "Relaying to AD Certificate Services over RPC",
               "Link": "https://blog.compass-security.com/2022/11/relaying-to-ad-certificate-services-over-rpc/"
            }
         ],
         "Authors": ["Sylvain Heiniger (@sploutchy)"],
         "Programs": ["-"],
         "Bugs": ["Active Directory", "ADCS", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2022-11-16",
         "AddedDate": "2022-11-17"
      },
      {
         "Links": [
            {
               "Title": "Remote Code Execution in Spotify’s Backstage via vm2 Sandbox Escape (CVSS Score of 9.8)",
               "Link": "https://www.oxeye.io/blog/remote-code-execution-in-spotifys-backstage"
            }
         ],
         "Authors": ["Gal Goldsthein (@G4lGo89)", "Yuval Ostrovsky (@yuvalo1212)", "Daniel Abeles (@Daniel_Abeles)"],
         "Programs": ["Spotify"],
         "Bugs": ["RCE", "VM sandbox escape"],
         "Bounty": "-",
         "PublicationDate": "2022-11-15",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "Stealing passwords from infosec Mastodon - without bypassing CSP",
               "Link": "https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp"
            }
         ],
         "Authors": ["Gareth Heyes (@garethheyes)"],
         "Programs": ["Mastodon", "infosec.exchange"],
         "Bugs": ["HTML injection"],
         "Bounty": "-",
         "PublicationDate": "2022-11-15",
         "AddedDate": "2022-11-17"
      },
      {
         "Links": [
            {
               "Title": "Varonis Threat Labs Discovers SQLi and Access Flaws in Zendesk",
               "Link": "https://www.varonis.com/blog/zendesk-sql-injection-and-access-flaws"
            }
         ],
         "Authors": ["Tal Peleg"],
         "Programs": ["Zendesk"],
         "Bugs": ["SQL injection", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2022-11-15",
         "AddedDate": "2022-11-17"
      },
      {
         "Links": [
            {
               "Title": "Checkmk: Remote Code Execution by Chaining Multiple Bugs (1/3)",
               "Link": "https://blog.sonarsource.com/checkmk-rce-chain-1/"
            },
            {
               "Title": "Checkmk: Remote Code Execution by Chaining Multiple Bugs (2/3)",
               "Link": "https://blog.sonarsource.com/checkmk-rce-chain-2/"
            },
            {
               "Title": "Checkmk: Remote Code Execution by Chaining Multiple Bugs (3/3)",
               "Link": "https://blog.sonarsource.com/checkmk-rce-chain-3/"
            }
         ],
         "Authors": ["Stefan Schiller (@scryh_)"],
         "Programs": ["Checkmk"],
         "Bugs": ["RCE", "Code injection", "SSRF", "Line Feed injection", "Arbitrary file read", "Authentication bypass", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-11-15",
         "AddedDate": "2022-11-17"
      },
      {
         "Links": [
            {
               "Title": "Winning QR with DOM-Based XSS | Bug Bounty POC",
               "Link": "https://medium.com/@haroonhameed_76621/winning-qr-with-dom-based-xss-bug-bounty-poc-4b4048cf285d"
            }
         ],
         "Authors": ["Haroon Hameed (@HaroonHameed40)", "Hannan Haseeb (@HannanHaseeb11)"],
         "Programs": ["-"],
         "Bugs": ["DOM XSS"],
         "Bounty": "775",
         "PublicationDate": "2022-11-15",
         "AddedDate": "2022-11-18"
      },
      {
         "Links": [
            {
               "Title": "Firebase: Insecure by Default (feat. that one time our classmates tried to sue us)",
               "Link": "https://saligrama.io/blog/post/firebase-insecure-by-default/"
            }
         ],
         "Authors": ["Aditya Saligrama (@saligrama_a)", "Miles McCain (@MilesMcCain)", "Cooper de Nicola (@CooperDenicola)"],
         "Programs": ["Fizz"],
         "Bugs": ["Hardcoded API keys"],
         "Bounty": "-",
         "PublicationDate": "2022-11-14",
         "AddedDate": "2022-11-17"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – Cisco Secure Manager Appliance jwt_api_impl Hardcoded JWT Secret Elevation of Privilege",
               "Link": "https://ssd-disclosure.com/ssd-advisory-cisco-secure-manager-appliance-jwt_api_impl-hardcoded-jwt-secret-elevation-of-privilege/"
            }
         ],
         "Authors": ["-"],
         "Programs": ["Cisco"],
         "Bugs": ["Hardcoded credentials", "Security code review", "JWT", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-11-14",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – Cisco Secure Manager Appliance remediation_request_utils SQL Injection Remote Code Execution",
               "Link": "https://ssd-disclosure.com/ssd-advisory-cisco-secure-manager-appliance-remediation_request_utils-sql-injection-remote-code-execution/"
            }
         ],
         "Authors": ["-"],
         "Programs": ["Cisco"],
         "Bugs": ["SQL injection", "RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-11-14",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-32929 - Bypass iOS backup's TCC protection",
               "Link": "https://theevilbit.github.io/posts/cve-2022-32929/"
            }
         ],
         "Authors": ["Csaba Fitzl (@theevilbit)"],
         "Programs": ["Apple"],
         "Bugs": ["Local Privilege Escalation", "TCC bypass", "MacOS", "iOS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-14",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "Path Traversal Vulnerability in Payara Platform",
               "Link": "https://sec-consult.com/vulnerability-lab/advisory/path-traversal-vulnerability-in-payara-platform/"
            }
         ],
         "Authors": ["Michael Baer"],
         "Programs": ["Payara"],
         "Bugs": ["Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2022-11-14",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "How i get $100 in just 10 minutes !",
               "Link": "https://medium.com/@jodyritonga/how-i-get-100-in-just-10-minutes-b018b28645ce"
            }
         ],
         "Authors": ["Jody ritonga"],
         "Programs": ["-"],
         "Bugs": ["Race condition"],
         "Bounty": "100",
         "PublicationDate": "2022-11-13",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "Finding Reflected XSS In A Strange Way",
               "Link": "https://medium.com/@raymond-lind/finding-reflected-xss-in-a-strange-way-289a4f3fa630"
            }
         ],
         "Authors": ["Raymond Lind"],
         "Programs": ["-"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-11",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "CVE-2019-8561: A Hard-to-Banish PackageKit Framework Vulnerability in macOS",
               "Link": "https://www.trendmicro.com/en_us/research/22/k/cve-2019-8561-a-hard-to-banish-packagekit-framework-vulnerabilit.html"
            }
         ],
         "Authors": ["Mickey Jin (@patch1t)"],
         "Programs": ["Apple"],
         "Bugs": ["MacOS", "Local Privilege Escalation", "SIP bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-11-11",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js",
               "Link": "https://www.usenix.org/system/files/sec23summer_432-shcherbakov-prepub.pdf"
            }
         ],
         "Authors": ["Mikhail Shcherbakov", "Musard Balliu", "Cristian-Alexandru Staicu"],
         "Programs": ["Rocket.Chat", "NPM CLI", "Parse Server", "Node.js"],
         "Bugs": ["RCE", "Prototype pollution", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-11",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "Every Signature is Broken: On the Insecurity of Microsoft Office’s OOXML Signatures",
               "Link": "https://www.usenix.org/system/files/sec23summer_235-rohlmann-prepub.pdf"
            }
         ],
         "Authors": ["Simon Rohlmann", "Vladislav Mladenov", "Christian Mainka", "Daniel Hirschberger", "Jörg Schwenk"],
         "Programs": ["Microsoft"],
         "Bugs": ["Signature bypass", "Signature forgery", "Cryptographic issues", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2022-11-11",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "Security and Privacy Failures in Popular 2FA Apps",
               "Link": "https://www.usenix.org/system/files/sec23summer_198-gilsenan-prepub.pdf"
            }
         ],
         "Authors": ["Conor Gilsenan", "Fuzail Shakir", "Noura Alomar", "Serge Egelman"],
         "Programs": ["LastPass", "Google", "Twilio", "Microsoft", "Duo", "Salesforce", "Latch", "Zoho"],
         "Bugs": ["Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2022-11-11",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "From Shodan Dork to Grafana 📊Local File Inclusion",
               "Link": "https://varmaanu001.medium.com/from-shodan-dork-to-grafana-local-file-inclusion-e77dc4cfc264"
            }
         ],
         "Authors": ["Anurag__Verma"],
         "Programs": ["-"],
         "Bugs": ["LFI", "Old components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2022-11-11",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "Windows Kernel: Exploit CVE-2022-35803 in Common Log File System",
               "Link": "https://blog.northseapwn.top/2022/11/11/Windows-Kernel-Exploit-CVE-2022-35803-in-Common-Log-File-System/index.html"
            }
         ],
         "Authors": ["luckyu (@uuulucky)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Windows", "Local Privilege Escalation", "Type confusion"],
         "Bounty": "-",
         "PublicationDate": "2022-11-11",
         "AddedDate": "2022-11-18"
      },
      {
         "Links": [
            {
               "Title": "Discovering vendor-specific vulnerabilities in Android",
               "Link": "https://blog.oversecured.com/Discovering-vendor-specific-vulnerabilities-in-Android/"
            }
         ],
         "Authors": ["Oversecured (@OversecuredInc)"],
         "Programs": ["Samsung", "Google"],
         "Bugs": ["Android"],
         "Bounty": "-",
         "PublicationDate": "2022-11-10",
         "AddedDate": "2022-11-21"
      },
      {
         "Links": [
            {
               "Title": "Unit 42 Finds Three Vulnerabilities in OpenLiteSpeed Web Server",
               "Link": "https://unit42.paloaltonetworks.com/openlitespeed-vulnerabilities/"
            }
         ],
         "Authors": ["Artur Avetisyan (@3v1LMonk3y)"],
         "Programs": ["LiteSpeed"],
         "Bugs": ["RCE", "OS command injection", "Path traversal", "Local Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-11-10",
         "AddedDate": "2022-11-17"
      },
      {
         "Links": [
            {
               "Title": "How Sigstore quickly patched an upstream vulnerability",
               "Link": "https://blog.sigstore.dev/how-sigstore-quickly-patched-an-upstream-vulnerability-76ba84ef1122"
            }
         ],
         "Authors": ["Joern Schneeweisz"],
         "Programs": ["Sigstore", "dex"],
         "Bugs": ["OAuth", "Account takeover", "Phishing"],
         "Bounty": "-",
         "PublicationDate": "2022-11-10",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "Accidental $70k Google Pixel Lock Screen Bypass",
               "Link": "https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/"
            }
         ],
         "Authors": ["David Schütz (@xdavidhu)"],
         "Programs": ["Google"],
         "Bugs": ["Lock screen bypass", "Authentication bypass", "Android"],
         "Bounty": "70,000",
         "PublicationDate": "2022-11-10",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "Google VRP (Acquisitions) — [Insecure Direct Object Reference] 2nd",
               "Link": "https://caesarevan23.medium.com/google-vrp-acquisitions-insecure-direct-object-reference-2nd-2ece9b185ade"
            }
         ],
         "Authors": ["Caesar Evan Santoso"],
         "Programs": ["Google"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2022-11-10",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "Sleep SQL injection on Name Parameter While Updating Profile",
               "Link": "https://medium.com/@umeryousuf26/sleep-sql-injection-on-name-parameter-while-updating-profile-2bbac9f47336"
            }
         ],
         "Authors": ["Umer Yousuf"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "500",
         "PublicationDate": "2022-11-10",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "Chaining Path Traversal with SSRF to disclose internal git repo data in a Bank Asset",
               "Link": "https://blog.niksthehacker.com/chaining-path-traversal-with-ssrf-to-disclose-internal-git-repo-data-in-a-bank-asset-8af4de6f12e"
            }
         ],
         "Authors": ["Nikhil (niks) (@niksthehacker)"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2021-11-09",
         "AddedDate": "2022-11-18"
      },
      {
         "Links": [
            {
               "Title": "Jit-Picking: Differential Fuzzing of JavaScript Engines",
               "Link": "https://mu00d8.me/paper/bernhard22jitpicking.pdf"
            }
         ],
         "Authors": ["Lukas Bernhard (@bernhl)", "Tobias Scharnowski (@ScepticCtf)", "Moritz Schloegel (@m_u00d8)"],
         "Programs": ["Mozilla"],
         "Bugs": ["Browser hacking"],
         "Bounty": "10,000",
         "PublicationDate": "2022-11-09",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "My First Account Takeover",
               "Link": "https://medium.com/@nireshpandian19/my-first-account-takeover-fd5570f09c0a"
            }
         ],
         "Authors": ["JAI NIRESH J"],
         "Programs": ["-"],
         "Bugs": ["Account takeover", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2022-11-09",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "Netgear Nighthawk R7000P AWS_JSON Unauthenticated Double Stack Overflow Vulnerability",
               "Link": "https://hdwsec.fr/blog/20221109-netgear/"
            }
         ],
         "Authors": ["Jean-Jamil Khalife"],
         "Programs": ["Netgear"],
         "Bugs": ["Memory corruption"],
         "Bounty": "-",
         "PublicationDate": "2022-11-09",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "Some Tips to Finding IDORs more easily and Fixing them",
               "Link": "https://medium.com/@nxenon/some-tips-to-finding-idors-more-easily-and-fixing-them-2c9d0c58bb4a"
            }
         ],
         "Authors": ["Xenon"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2022-11-08",
         "AddedDate": "2022-11-18"
      },
      {
         "Links": [
            {
               "Title": "Compromising Plesk Via Its REST API",
               "Link": "https://fortbridge.co.uk/research/compromising-plesk-via-its-rest-api/"
            }
         ],
         "Authors": ["Adrian Tiron (@Adrian__T)"],
         "Programs": ["Plesk"],
         "Bugs": ["CORS misconfiguration", "CSRF"],
         "Bounty": "-",
         "PublicationDate": "2022-11-08",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "Comodo: From .Git to Takeover",
               "Link": "https://maordayanofficial.medium.com/comodo-from-git-to-takeover-803ffb8b57e3"
            }
         ],
         "Authors": ["Maor Dayan (@mord1234)"],
         "Programs": ["Comodo"],
         "Bugs": [".git folder disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-11-08",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049)",
               "Link": "https://breakdev.org/zip-motw-bug-analysis/"
            }
         ],
         "Authors": ["Kuba Gretzky (@mrgretzky)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Local Privilege Escalation", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2022-11-08",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "How we ‘hacked’ Telenet’s cybersecurity quiz",
               "Link": "https://mickeydebaets.medium.com/how-we-hacked-telenet-s-cybersecurity-quiz-958c1d3ee2ba"
            }
         ],
         "Authors": ["Mickey De Baets"],
         "Programs": ["Telenet"],
         "Bugs": ["Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2022-11-07",
         "AddedDate": "2022-11-08"
      },
      {
         "Links": [
           {
              "Title": "Stormshield SNS cleartext password leak",
              "Link": "https://medium.com/@mehdi.alouache/stormshield-sns-cleartext-password-leak-b436ef312fe9"
           }
          ],
         "Authors": ["Mehdi Alouache"],
         "Programs": ["Stormshield"],
         "Bugs": ["Use of GET request Method With sensitive query strings"],
         "Bounty": "-",
         "PublicationDate": "2022-11-07",
         "AddedDate": "2022-11-08"
       },
      {
         "Links": [
            {
               "Title": "IDOR on Unsubscribe emails to $200 bounty.",
               "Link": "https://medium.com/@shellyshubh/idor-on-unsubscribe-emails-to-200-bounty-ae16fb783b01"
            }
         ],
         "Authors": ["shbugger1"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "200",
         "PublicationDate": "2022-11-06",
         "AddedDate": "2022-11-08"
      },
      {
         "Links": [
            {
               "Title": "Exploit Feature To Get High Bug impact",
               "Link": "https://0xm5awy.medium.com/exploit-feature-to-get-high-bug-impact-1d3ae6517680"
            }
         ],
         "Authors": ["Mohamed Anani (@0xm5awy)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2022-11-05",
         "AddedDate": "2022-11-14"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-26730 | ColorSync | Hoyt LLC",
               "Link": "https://srd.cx/cve-2022-26730/"
            }
         ],
         "Authors": ["David Hoyt (@h02332)"],
         "Programs": ["Apple"],
         "Bugs": ["MacOS", "Memory corruption", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-11-05",
         "AddedDate": "2022-11-11"
      },
      {
         "Links": [
            {
               "Title": "Story of a $1k bounty — SSRF to leaking access token and other sensitive information",
               "Link": "https://infosecwriteups.com/story-of-a-1k-bounty-ssrf-d5c4868680f5"
            }
         ],
         "Authors": ["Faique (@imfaiqu3)"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "1,000",
         "PublicationDate": "2022-11-05",
         "AddedDate": "2022-11-08"
      },
      {
         "Links": [
            {
               "Title": "Directory traversal in PDF viewing application. Leading to full database takeover",
               "Link": "https://medium.com/@wrinnsec/directory-traversal-in-pdf-viewing-application-leading-to-full-database-takeover-376e68eadd86"
            }
         ],
         "Authors": ["Tom Wrinn"],
         "Programs": ["-"],
         "Bugs": ["Path traversal"],
         "Bounty": "-",
         "PublicationDate": "2022-11-05",
         "AddedDate": "2022-11-08"
      },
      {
         "Links": [
            {
               "Title": "PENTEST TALES: EXIF Data Manipulation",
               "Link": "https://medium.com/@armandjasharaj/pentest-tales-exif-data-manipulation-b36beb291229"
            }
         ],
         "Authors": ["Armand Jasharaj"],
         "Programs": ["-"],
         "Bugs": ["Unrestricted file upload", "Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-05",
         "AddedDate": "2022-11-05"
      },
      {
         "Links": [
            {
               "Title": "Practical Client Side Path Traversal Attacks",
               "Link": "https://mr-medi.github.io/research/2022/11/04/practical-client-side-path-traversal-attacks.html"
            }
         ],
         "Authors": ["Medi (@medi_0ne)"],
         "Programs": ["Acronis"],
         "Bugs": ["Path traversal", "Client-side Path Traversal", "Open redirect", "CSS injection"],
         "Bounty": "$250",
         "PublicationDate": "2022-11-04",
         "AddedDate": "2022-11-08"
      },
      {
         "Links": [
            {
               "Title": "CSRF Leads to Delete User Account",
               "Link": "https://medium.com/@omarbakrey90/csrf-leads-to-delete-user-account-fc362078be2f"
            }
         ],
         "Authors": ["Omarbakrey"],
         "Programs": ["-"],
         "Bugs": ["CSRF"],
         "Bounty": "-",
         "PublicationDate": "2022-11-04",
         "AddedDate": "2022-11-05"
      },
      {
         "Links": [
            {
               "Title": "How I hacked into a Cambridge’s server and got appreciation letter.",
               "Link": "https://medium.com/@prathamrajgor/how-i-hacked-into-a-cambridges-server-and-got-appreciation-letter-d19a830756b2"
            }
         ],
         "Authors": ["Prathamrajgor"],
         "Programs": ["Cambridge"],
         "Bugs": ["Unrestricted file upload", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-11-04",
         "AddedDate": "2022-11-05"
      },
      {
         "Links": [
            {
               "Title": "Case of Admin Bypass for RCE, XSS, and Information Disclosure",
               "Link": "https://caffeinevulns.com/rces-and-acpvs/"
            }
         ],
         "Authors": ["Sam Paredes (@caffeinevulns)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Unrestricted file upload", "Stored XSS", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-11-03",
         "AddedDate": "2022-11-05"
      },
      {
         "Links": [
            {
               "Title": "Invitation Hijacking",
               "Link": "https://medium.com/@vflexo/invitation-hijacking-4d6467f418cc"
            }
         ],
         "Authors": ["vFlexo (@vflexo)"],
         "Programs": ["-"],
         "Bugs": ["Broken authorization", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-11-03",
         "AddedDate": "2022-11-05"
      },
      {
         "Links": [
            {
               "Title": "The power of adaptability through experience.",
               "Link": "https://redsiege.com/blog/2022/11/the-power-of-adaptability-through-experience/"
            }
         ],
         "Authors": ["Mike Saunders (@hardwaterhacker)"],
         "Programs": ["-"],
         "Bugs": ["Lateral movement", "Active Directory Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-11-03",
         "AddedDate": "2022-11-05"
      },
      {
         "Links": [
            {
               "Title": "Get Blind XSS within 5 Minutes — $100",
               "Link": "https://infosecwriteups.com/get-blind-xss-within-5-minutes-100-9718bd056570"
            }
         ],
         "Authors": ["Narayanan M"],
         "Programs": ["-"],
         "Bugs": ["Blind XSS"],
         "Bounty": "100",
         "PublicationDate": "2022-11-03",
         "AddedDate": "2022-11-05"
      },
      {
         "Links": [
            {
               "Title": "How I could have been the administrator for all Dutch companies and create invoices. And still can be…",
               "Link": "https://medium.com/@bobvanderstaak/how-i-could-have-been-the-administrator-for-all-dutch-companies-and-create-invoices-and-still-can-de181160cec5"
            }
         ],
         "Authors": ["bob van der staak"],
         "Programs": ["Dutch Government"],
         "Bugs": ["Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2022-11-03",
         "AddedDate": "2022-11-03"
      },
      {
         "Links": [
            {
               "Title": "Gregor Samsa: Exploiting Java's XML Signature Verification",
               "Link": "https://googleprojectzero.blogspot.com/2022/11/gregor-samsa-exploiting-java-xml.html"
            }
         ],
         "Authors": ["Felix Wilhelm (@_fel1x)"],
         "Programs": ["OpenJDK", "Apache Commons BCEL"],
         "Bugs": ["Integer truncation", "RCE", "SAML"],
         "Bounty": "-",
         "PublicationDate": "2022-11-02",
         "AddedDate": "2022-11-03"
      },
      {
         "Links": [
            {
               "Title": "Chaining Multiple Vulnerabilities Leads to Remote Code Execution (RCE) on One of the Payment Service Companies.",
               "Link": "https://rohit-soni.medium.com/chaining-multiple-vulnerabilities-leads-to-remote-code-execution-rce-on-paytm-e77f2fd2295e"
            }
         ],
         "Authors": ["Rohit Soni (@streetofhacker)"],
         "Programs": ["-"],
         "Bugs": ["Exposed registration page", "Exposed Jenkins instance", "Weak credentials", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-11-02",
         "AddedDate": "2022-11-03"
      },
      {
         "Links": [
            {
               "Title": "Fuzzing For Hidden Params",
               "Link": "https://medium.com/@calfcrusher/fuzzing-for-hidden-params-671724bf3fd7"
            }
         ],
         "Authors": ["calfcrusher"],
         "Programs": ["-"],
         "Bugs": ["SQL injection"],
         "Bounty": "-",
         "PublicationDate": "2022-11-02",
         "AddedDate": "2022-11-03"
      },
      {
         "Links": [
            {
               "Title": "Improper Access Control — My Third Finding on Hackerone!",
               "Link": "https://mehedishakeel.medium.com/improper-access-control-my-third-finding-on-hackerone-1455e95b6c8c"
            }
         ],
         "Authors": ["mehedishakeel (@mehedishakeel)"],
         "Programs": ["-"],
         "Bugs": ["HTML injection", "Broken Access Control"],
         "Bounty": "-",
         "PublicationDate": "2022-11-02",
         "AddedDate": "2022-11-03"
      },
      {
         "Links": [
            {
               "Title": "How 403 Forbidden Bypass got me NOKIA Hall Of Fame (HOF)",
               "Link": "https://infosecwriteups.com/how-403-forbidden-bypass-got-me-nokia-hall-of-fame-hof-8acbd2c1c2c8"
            }
         ],
         "Authors": ["Jaydeepsinh Thakor (@thakor_jd_)"],
         "Programs": ["Nokia"],
         "Bugs": ["403 bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-11-02",
         "AddedDate": "2022-11-03"
      },
      {
         "Links": [
            {
               "Title": "How I Get 5x Swag From Sony",
               "Link": "https://medium.com/@0xnaeem/how-i-get-5x-swag-from-sony-102dbefd0c2c"
            }
         ],
         "Authors": ["Naeem Ahmed Sayed (@0xNaeem)"],
         "Programs": ["Sony"],
         "Bugs": ["DOM XSS", "Directory listing", "Default credentials", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-11-02",
         "AddedDate": "2022-11-03"
      },
      {
         "Links": [
            {
               "Title": "CVE−2022-3602: Punycode buffer overflow in OpenSSL",
               "Link": "https://github.com/colmmacc/CVE-2022-3602"
            }
         ],
         "Authors": ["Colm MacCárthaigh (@colmmacc)"],
         "Programs": ["OpenSSL"],
         "Bugs": ["Memory corruption", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2022-11-01",
         "AddedDate": "2022-11-18"
      },
      {
         "Links": [
            {
               "Title": "urlscan.io's SOAR spot: Chatty security tools leaking private data",
               "Link": "https://positive.security/blog/urlscan-data-leaks"
            }
         ],
         "Authors": ["Fabian Bräunlein"],
         "Programs": ["-"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-11-01",
         "AddedDate": "2022-11-03"
      },
      {
         "Links": [
            {
               "Title": "Safari is hot-linking images to semi-random websites",
               "Link": "https://portswigger.net/research/safari-is-hot-linking-images-to-semi-random-websites"
            }
         ],
         "Authors": ["Gareth Heyes (@garethheyes)"],
         "Programs": ["Apple"],
         "Bugs": ["Browser hacking", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-31",
         "AddedDate": "2022-11-01"
      },
      {
         "Links": [
            {
               "Title": "Blind SQL Injection on Delete Request",
               "Link": "https://medium.com/@jawadmahdi/blind-sql-injection-on-delete-request-486770af75a6"
            }
         ],
         "Authors": ["Jawad Mahdi (@hunter0x1)"],
         "Programs": ["-"],
         "Bugs": ["Blind SQL injection"],
         "Bounty": "1,300",
         "PublicationDate": "2022-10-30",
         "AddedDate": "2022-11-01"
      },
      {
         "Links": [
            {
               "Title": "A tale of a simple Apple kernel bug",
               "Link": "https://pwning.systems/posts/easy-apple-kernel-bug/"
            }
         ],
         "Authors": ["Jordy Zomer (@pwningsystems)"],
         "Programs": ["Apple"],
         "Bugs": ["Out-of-bounds Read", "Memory corruption", "MacOS", "iOS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-31",
         "AddedDate": "2022-11-01"
      },
      {
         "Links": [
            {
               "Title": "Vulnerabilities In Apache Batik Default Security Controls – SSRF And RCE Through Remote Class Loading",
               "Link": "https://www.zerodayinitiative.com/blog/2022/10/28/vulnerabilities-in-apache-batik-default-security-controls-ssrf-and-rce-through-remote-class-loading"
            }
         ],
         "Authors": ["Piotr Bazydło (@chudypb)"],
         "Programs": ["Apache Batik"],
         "Bugs": ["SSRF", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-10-31",
         "AddedDate": "2022-11-01"
      },
      {
         "Links": [
            {
               "Title": "2FA Bypass due to information disclosure & Improper access control.",
               "Link": "https://akashhamal0x01.medium.com/2fa-bypass-due-to-information-disclosure-improper-access-control-f9a5a8a4e0af"
            }
         ],
         "Authors": ["Akash Hamal (@AkashHamal0x01)"],
         "Programs": ["-"],
         "Bugs": ["DoS", "2FA / MFA bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-10-31",
         "AddedDate": "2022-10-31"
      },
      {
         "Links": [
            {
               "Title": "Old RCE worth $3362.",
               "Link": "https://medium.com/@nanwinata/old-rce-worth-3362-1af0cd70c459"
            }
         ],
         "Authors": ["nanwn"],
         "Programs": ["-"],
         "Bugs": ["RCE"],
         "Bounty": "3,362",
         "PublicationDate": "2022-10-30",
         "AddedDate": "2022-10-31"
      },
      {
         "Links": [
            {
               "Title": "Exploiting Static Site Generators: When Static Is Not Actually Static",
               "Link": "https://blog.assetnote.io/2022/10/28/exploiting-static-site-generators/"
            }
         ],
         "Authors": ["Shubham Shah (@infosec_au)", "Sam Curry (@samwcyo)"],
         "Programs": ["Netlify", "Gatsby"],
         "Bugs": ["SSRF", "XSS", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-10-28",
         "AddedDate": "2022-11-01"
      },
      {
         "Links": [
            {
               "Title": "How i was able to get free money via sending negative tokens",
               "Link": "https://0xm5awy.medium.com/how-i-was-able-to-get-free-money-via-sending-negative-tokens-1ed2e0e710e0"
            }
         ],
         "Authors": ["Mohamed Anani (@0xM5awy)"],
         "Programs": ["-"],
         "Bugs": ["Logic flaw", "Payment tampering"],
         "Bounty": "-",
         "PublicationDate": "2022-10-28",
         "AddedDate": "2022-10-29"
      },
      {
         "Links": [
            {
               "Title": "Technical Analysis of Windows CLFS Zero-Day Vulnerability CVE-2022-37969 - Part 1: Root Cause Analysis",
               "Link": "https://www.zscaler.com/blogs/security-research/technical-analysis-windows-clfs-zero-day-vulnerability-cve-2022-37969-part"
            },
            {
               "Title": "Part 2: Exploit Analysis",
               "Link": "https://www.zscaler.com/blogs/security-research/technical-analysis-windows-clfs-zero-day-vulnerability-cve-2022-37969-part2-exploit-analysis"
            }
         ],
         "Authors": ["Zscaler Threatlabz (@Threatlabz)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Local Privilege Escalation", "Windows"],
         "Bounty": "-",
         "PublicationDate": "2022-10-28",
         "AddedDate": "2022-11-01"
      },
      {
         "Links": [
            {
               "Title": "CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities",
               "Link": "https://octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/"
            }
         ],
         "Authors": ["Paulos Yibelo (@PaulosYibelo)"],
         "Programs": ["Juniper"],
         "Bugs": ["RCE", "Phar deserialization", "Reflected XSS", "XPATH injection", "Path traversal", "LFI"],
         "Bounty": "-",
         "PublicationDate": "2022-10-28",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Blind SSRF in Skype (Microsoft)",
               "Link": "https://jayateerthag.medium.com/blind-ssrf-in-skype-microsoft-6639f4961052"
            }
         ],
         "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Blind SSRF"],
         "Bounty": "-",
         "PublicationDate": "2022-10-28",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "RCE docker api, but …",
               "Link": "https://medium.com/@nanwinata/rce-docker-api-but-11ff70825935"
            }
         ],
         "Authors": ["nanwn"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Docker daemon misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2022-10-28",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Abusing Windows’ tokens to compromise Active Directory without touching LSASS",
               "Link": "https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/"
            }
         ],
         "Authors": ["Aurélien Chalot (@Defte_)"],
         "Programs": ["-"],
         "Bugs": ["Local Privilege Escalation", "Windows", "Active Directory Privilege Escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-10-27",
         "AddedDate": "2022-11-01"
      },      {
         "Links": [
            {
               "Title": "AWS SSRF to Root on production instance — A bug worth 1.75Lacs",
               "Link": "https://logicbomb.medium.com/a-bug-worth-1-75lacs-aws-ssrf-to-rce-8d43d5fda899"
            }
         ],
         "Authors": ["Avinash Jain (@logicbomb_1)"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "RCE", "Password reset"],
         "Bounty": "-",
         "PublicationDate": "2022-10-27",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Visual Studio Code Jupyter Notebook RCE",
               "Link": "https://blog.doyensec.com/2022/10/27/jupytervscode.html"
            }
         ],
         "Authors": ["Luca Carettoni (@lucacarettoni)"],
         "Programs": ["Microsoft"],
         "Bugs": ["RCE", "XSS", "Arbitrary file read", "Electron"],
         "Bounty": "-",
         "PublicationDate": "2022-10-27",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "A 250$ CSS Injection — My First Finding on Hackerone!",
               "Link": "https://medium.com/@dsonbacker/a-250-css-injection-my-first-finding-on-hackerone-8863ad253560"
            }
         ],
         "Authors": ["Dsonbacker"],
         "Programs": ["-"],
         "Bugs": ["CSS injection"],
         "Bounty": "250",
         "PublicationDate": "2022-10-27",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Misconfigured AWS S3 Bucket (Information Disclosure & Subdomain Takeover)",
               "Link": "https://medium.com/@gguzelkokar.mdbf15/hatal%C4%B1-yap%C4%B1land%C4%B1r%C4%B1lm%C4%B1%C5%9F-aws-s3-bucket-%C3%BCzerinde-bulunan-g%C3%BCvenlik-a%C3%A7%C4%B1%C4%9F%C4%B1n%C4%B1n-yaratt%C4%B1%C4%9F%C4%B1-etkiler-cb073179360d"
            }
         ],
         "Authors": ["Gokhan Guzelkokar (@gkhck_)"],
         "Programs": ["-"],
         "Bugs": ["AWS misconfiguration"],
         "Bounty": "1,000",
         "PublicationDate": "2022-10-27",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "RC4 Is Still Considered Harmful",
               "Link": "https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html"
            }
         ],
         "Authors": ["James Forshaw (@tiraniddo)"],
         "Programs": ["Microsoft (Windows)"],
         "Bugs": ["Kerberos", "MiTM", "Local Privilege Escalation", "Downgrade attack"],
         "Bounty": "-",
         "PublicationDate": "2022-10-27",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "From Self-Hosted GitHub Runner to Self-Hosted Backdoor",
               "Link": "https://www.praetorian.com/blog/self-hosted-github-runners-are-backdoors/"
            }
         ],
         "Authors": ["Adnan Khan (@adnanthekhan)", "Mason Davis", "Matt Jackoski"],
         "Programs": ["GitHub"],
         "Bugs": ["CI/CD", "Lateral movement", "Post-exploitation"],
         "Bounty": "-",
         "PublicationDate": "2022-10-26",
         "AddedDate": "2024-02-06"
      },
      {
         "Links": [
            {
               "Title": "Hijacking AUR Packages by Searching for Expired Domains",
               "Link": "https://blog.nietaanraken.nl/posts/aur-packages-expired-domains/"
            }
         ],
         "Authors": ["Joren Vrancken"],
         "Programs": ["-"],
         "Bugs": ["Subdomain takeover", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2022-10-26",
         "AddedDate": "2023-04-29"
      },
      {
         "Links": [
            {
               "Title": "Client Side Desync Attack (CL.0 Request Smuggling) — Bounty of $150",
               "Link": "https://bpandasec.medium.com/client-side-desync-attack-cl-0-request-smuggling-bounty-of-150-327d3aeaeea6"
            }
         ],
         "Authors": ["Bodhendu Panda"],
         "Programs": ["-"],
         "Bugs": ["HTTP request smuggling", "Client-Side Desync attack"],
         "Bounty": "150",
         "PublicationDate": "2022-10-26",
         "AddedDate": "2023-05-08"
      },
      {
         "Links": [
            {
               "Title": "SiriSpy - iOS bug allowed apps to eavesdrop on your conversations with Siri",
               "Link": "https://rambo.codes/posts/2022-10-25-sirispy-ios-bug-allowed-apps-to-eavesdrop"
            }
         ],
         "Authors": ["Guilherme Rambo (@_inside)"],
         "Programs": ["Apple"],
         "Bugs": ["iOS", "MacOS", "Bluetooth", "Local Privilege Escalation", "TCC bypass"],
         "Bounty": "7,000",
         "PublicationDate": "2022-10-26",
         "AddedDate": "2022-11-01"
      },
      {
         "Links": [
            {
               "Title": "Attacking The Software Supply Chain With A Simple Rename",
               "Link": "https://checkmarx.com/blog/attacking-the-software-supply-chain-with-a-simple-rename/"
            }
         ],
         "Authors": ["Aviad Gershon (@aviadgershon)", "Elad Rapoport (@eladrapoport)"],
         "Programs": ["GitHub"],
         "Bugs": ["Repojacking", "Supply chain attack"],
         "Bounty": "-",
         "PublicationDate": "2022-10-26",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "SSD Advisory – Galaxy Store Applications Installation/Launching without User Interaction",
               "Link": "https://ssd-disclosure.com/ssd-advisory-galaxy-store-applications-installation-launching-without-user-interaction/"
            }
         ],
         "Authors": ["-"],
         "Programs": ["Samsung"],
         "Bugs": ["XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-26",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "SSRF Bug Leads To AWS Metadata Exposure",
               "Link": "https://medium.com/@raymond-lind/ssrf-bug-leads-to-aws-metadata-exposure-f2ee7d43c6c3"
            }
         ],
         "Authors": ["Raymond Lind"],
         "Programs": ["-"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2022-10-26",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Stored XSS To Cookie Exfiltration",
               "Link": "https://medium.com/@raymond-lind/stored-xss-to-cookie-exfiltration-2cbca6a8c7f0"
            }
         ],
         "Authors": ["Raymond Lind"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-26",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "GL.iNET GL-MT300N-V2 Router Vulnerabilities and Hardware Teardown",
               "Link": "https://boschko.ca/glinet-router/"
            }
         ],
         "Authors": ["Olivier Laflamme (@olivier_boschko)"],
         "Programs": ["GL.iNet"],
         "Bugs": ["OS command injection", "Arbitrary file read", "Information disclosure", "Account takeover", "Stored XSS", "Lack of rate limiting", "Weak credentials", "Password policy bypass"],
         "Bounty": "-",
         "PublicationDate": "2022-10-26",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Microsoft SharePoint Server Post-Authentication Server-Side Request Forgery vulnerability",
               "Link": "https://starlabs.sg/blog/2022/10-sharepoint-post-authenticated-ssrf-vulnerability/"
            }
         ],
         "Authors": ["Li Jiantao (@CurseRed)"],
         "Programs": ["Microsoft"],
         "Bugs": ["SSRF"],
         "Bounty": "-",
         "PublicationDate": "2022-10-25",
         "AddedDate": "2022-11-01"
      },
      {
         "Links": [
            {
               "Title": "Chaining multiple vulnerabilities for credential stealing",
               "Link": "https://web.archive.org/web/20221025185418/https://bergee.it/blog/chaining-multiple-vulnerabilities-for-credential-stealing/"
            }
         ],
         "Authors": ["Bartłomiej Bergier (@_bergee_)"],
         "Programs": ["-"],
         "Bugs": ["CSRF", "Self-XSS", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-25",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Support supports a Hacker",
               "Link": "https://mechboy.medium.com/support-supports-a-hacker-be9931104923"
            }
         ],
         "Authors": ["mechboy (@mechboy_)"],
         "Programs": ["-"],
         "Bugs": ["Social engineering", "Spoofing", "Broken authorization", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2022-10-25",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Eat What You Kill :: Pre-authenticated Remote Code Execution in VMWare NSX Manager",
               "Link": "https://srcincite.io/blog/2022/10/25/eat-what-you-kill-pre-authenticated-rce-in-vmware-nsx-manager.html"
            }
         ],
         "Authors": ["Sina Kheirkhah (@SinSinology)", "Steven Seeley (@steventseeley)"],
         "Programs": ["VMware"],
         "Bugs": ["RCE", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-10-25",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "The Logging Dead: Two Event Log Vulnerabilities Haunting Windows",
               "Link": "https://www.varonis.com/blog/the-logging-dead-two-windows-event-log-vulnerabilities"
            }
         ],
         "Authors": ["Dolev Taler"],
         "Programs": ["Microsoft"],
         "Bugs": ["DoS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-25",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Stranger Strings: An exploitable flaw in SQLite",
               "Link": "https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/"
            }
         ],
         "Authors": ["Andreas Kellas"],
         "Programs": ["SQLite"],
         "Bugs": ["Memory corruption", "Buffer Overflow", "DoS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-25",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Remote Code Execution by Abusing Apache Spark SQL",
               "Link": "https://blog.stratumsecurity.com/2022/10/24/abusing-apache-spark-sql-to-get-code-execution/"
            }
         ],
         "Authors": ["Colin McQueen"],
         "Programs": ["-"],
         "Bugs": ["SQL injection", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-10-24",
         "AddedDate": "2022-11-01"
      },
      {
         "Links": [
            {
               "Title": "5000$ for Apple Stored Xss And Another Blind Xss Still under review",
               "Link": "https://hamzadzworm.medium.com/5000-for-apple-stored-xss-and-another-blind-xss-still-under-review-e9f6f5a76eb1"
            }
         ],
         "Authors": ["Abdelkader Mouaz (@hamzadzworm)"],
         "Programs": ["Apple"],
         "Bugs": ["Blind XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-24",
         "AddedDate": "2022-10-25"
      },
      {
         "Links": [
            {
               "Title": "SSRF & LFI In Uploads Feature",
               "Link": "https://medium.com/@raymond-lind/ssrf-lfi-in-uploads-feature-a134aa467abf"
            }
         ],
         "Authors": ["Raymond Lind"],
         "Programs": ["-"],
         "Bugs": ["SSRF", "LFI"],
         "Bounty": "-",
         "PublicationDate": "2022-10-24",
         "AddedDate": "2022-10-25"
      },
      {
         "Links": [
            {
               "Title": "How I Found A Simple Stored XSS",
               "Link": "https://medium.com/@raymond-lind/how-i-found-a-simple-stored-xss-9a6b1c5e0afa"
            }
         ],
         "Authors": ["Raymond Lind"],
         "Programs": ["-"],
         "Bugs": ["Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-24",
         "AddedDate": "2022-10-25"
      },
      {
         "Links": [
            {
               "Title": "Atlassian Jira Align, Version 10.107.4 Advisory",
               "Link": "https://bishopfox.com/blog/jira-align-advisory"
            }
         ],
         "Authors": ["Jacob Shafer (@fibbot)"],
         "Programs": ["Atlassian"],
         "Bugs": ["SSRF", "Broken Access Control", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-10-24",
         "AddedDate": "2022-10-25"
      },
      {
         "Links": [
           {
              "Title": "Finding Multiple Security Issues on Agorapulse",
              "Link": "https://snapsec.co/blog/Hacking-Agorapulse/"
           }
          ],
         "Authors": ["Snap Sec (@snap_sec)"],
         "Programs": ["Agorapulse"],
         "Bugs": ["Log4shell", "RCE", "Information disclosure", "Broken Access Control", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-10-24",
         "AddedDate": "2022-10-24"
        },
        {
         "Links": [
           {
              "Title": "Missing Authentication in ZKTeco ZEM/ZMM Web Interface",
              "Link": "https://www.redteam-pentesting.de/en/advisories/rt-sa-2021-003/-missing-authentication-in-zkteco-zem-zmm-web-interface"
           }
          ],
         "Authors": ["RedTeam Pentesting (@RedTeamPT)"],
         "Programs": ["ZKTeco"],
         "Bugs": ["Missing authentication"],
         "Bounty": "-",
         "PublicationDate": "2022-10-24",
         "AddedDate": "2022-11-01"
        },
        {
         "Links": [
           {
              "Title": "How I Found Three Credentials Leak on One Google Dork on Bugcrowd program",
              "Link": "https://medium.com/@ittipatjitrada_72022/how-i-found-three-credentials-leak-on-one-google-dork-on-bugcrowd-3dba9a23ace4"
           }
          ],
         "Authors": ["Ittipatjitrada (@IttipatJitrada)"],
         "Programs": ["Cengage"],
         "Bugs": ["Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-10-24",
         "AddedDate": "2022-11-01"
        },
        {
         "Links": [
            {
               "Title": "Broken Link Hijacking — My Second Finding on Hackerone!",
               "Link": "https://mehedishakeel.medium.com/broken-link-hijacking-my-second-finding-on-hackerone-d715b0713fca"
            }
         ],
         "Authors": ["mehedishakeel (@mehedishakeel)"],
         "Programs": ["-"],
         "Bugs": ["Broken link hijacking"],
         "Bounty": "-",
         "PublicationDate": "2022-10-23",
         "AddedDate": "2022-10-24"
      },
        {
         "Links": [
            {
               "Title": "Sail away, sail away, sail away",
               "Link": "https://sensepost.com/blog/2022/sail-away-sail-away-sail-away/"
            }
         ],
         "Authors": ["Reino Mostert"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-10-21",
         "AddedDate": "2022-10-22"
      },
      {
         "Links": [
            {
               "Title": "$1,000+ P1: PII Disclosure W/ IDOR",
               "Link": "https://medium.com/the-gray-area/1-000-p1-pii-disclosure-w-idor-cb344c55d52e"
            }
         ],
         "Authors": ["Graham Zemel (@grahamzemel)"],
         "Programs": ["-"],
         "Bugs": ["IDOR"],
         "Bounty": "-",
         "PublicationDate": "2022-10-21",
         "AddedDate": "2022-10-23"
      },
      {
         "Links": [
           {
              "Title": "Google VRP — [Insecure Direct Object Reference] $3133.70",
              "Link": "https://caesarevan23.medium.com/google-vrp-insecure-direct-object-reference-3133-70-a0e37023a4c7"
           }
          ],
         "Authors": ["Caesar Evan Santoso"],
         "Programs": ["Google"],
         "Bugs": ["IDOR"],
         "Bounty": "3,133.70",
         "PublicationDate": "2022-10-20",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "The Curious Case Of The Password Database",
              "Link": "https://www.trustedsec.com/blog/the-curious-case-of-the-password-database/"
           }
          ],
         "Authors": ["Travis Kaun (@W9HAX)"],
         "Programs": ["Zoho (ManageEngine)"],
         "Bugs": ["Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2022-10-20",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "Reverse Engineering the Apple Multipeer Connectivity Framework",
              "Link": "https://www.evilsocket.net/2022/10/20/Reverse-Engineering-the-Apple-MultiPeer-Connectivity-Framework/"
           }
          ],
         "Authors": ["Simone Margaritelli (@evilsocket)"],
         "Programs": ["Apple"],
         "Bugs": ["Broken authorization", "Reverse engineering", "Networking"],
         "Bounty": "-",
         "PublicationDate": "2022-10-20",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "SHA-3 Buffer Overflow",
              "Link": "https://mouha.be/sha-3-buffer-overflow/"
           }
          ],
         "Authors": ["Nicky Mouha"],
         "Programs": ["XKCP", "Apple", "Python", "PHP", "PyPy", "SHA3 for Ruby"],
         "Bugs": ["Buffer Overflow", "Memory corruption", "Cryptographic issues"],
         "Bounty": "-",
         "PublicationDate": "2022-10-20",
         "AddedDate": "2022-10-24"
      },
      {
         "Links": [
           {
              "Title": "Bypassing Mimecast URL and File Inspection",
              "Link": "https://www.netspi.com/blog/technical/social-engineering/bypassing-mimecast-email-defenses/"
           }
          ],
         "Authors": ["Patrick Sayler (@psaYler)"],
         "Programs": ["Mimecast"],
         "Bugs": ["Secure Email Gateway bypass", "Logic flaw"],
         "Bounty": "-",
         "PublicationDate": "2022-10-20",
         "AddedDate": "2022-10-28"
      },
      {
         "Links": [
            {
               "Title": "Potential Remote Code Execution Vulnerability Discovered In HSQLDB",
               "Link": "https://www.code-intelligence.com/blog/potential-remote-code-execution-in-hsqldb"
            },
            {
               "Title": "Alternative link",
               "Link": "https://medium.com/@CI_Fuzz/potential-remote-code-execution-vulnerability-discovered-in-hsqldb-4a2dfa6275ee"
            }
         ],
         "Authors": ["Code Intelligence (@CI_Fuzz)"],
         "Programs": ["HSQL Development Group (HSQLDB)"],
         "Bugs": ["RCE", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-25"
      },
      {
         "Links": [
            {
               "Title": "23000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite",
               "Link": "https://medium.com/@h4x0r_dz/23000-for-authentication-bypass-file-upload-arbitrary-file-overwrite-2578b730a5f8"
            }
         ],
         "Authors": ["Souhaib Naceri (@h4x0r_dz)"],
         "Programs": ["-"],
         "Bugs": ["JWT", "Authentication bypass", "Arbitrary file write", "Unrestricted file upload"],
         "Bounty": "23,000",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-23"
      },
      {
         "Links": [
           {
              "Title": "A New Attack Surface on MS Exchange Part 4 - ProxyRelay!",
              "Link": "https://devco.re/blog/2022/10/19/a-new-attack-surface-on-MS-exchange-part-4-ProxyRelay/"
           },
           {
            "Title": "Alternative link",
            "Link": "http://blog.orange.tw/2022/10/proxyrelay-a-new-attack-surface-on-ms-exchange-part-4.html"
         }
          ],
         "Authors": ["Orange Tsai (@orange_8361)"],
         "Programs": ["Microsoft"],
         "Bugs": ["RCE", "Privilege escalation"],
         "Bounty": "-",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "HTTP/3 connection contamination: an upcoming threat?",
              "Link": "https://portswigger.net/research/http-3-connection-contamination"
           }
          ],
         "Authors": ["James Kettle (@albinowax)"],
         "Programs": ["-"],
         "Bugs": ["HTTP connection contamination"],
         "Bounty": "-",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "Second Order XXE Exploitation",
              "Link": "https://kuldeep.io/posts/second-order-xxe-exploitation/"
           }
          ],
         "Authors": ["Kuldeep Pandya (@kuldeepdotexe)"],
         "Programs": ["-"],
         "Bugs": ["XXE", "Arbitrary file read"],
         "Bounty": "-",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "FabriXss (CVE-2022-35829): How We Managed to Abuse a Custom Role User Using CSTI and Stored XSS in Azure Fabric Explorer",
              "Link": "https://orca.security/resources/blog/fabrixss-vulnerability-azure-fabric-explorer/"
           }
          ],
         "Authors": ["Lidor Ben Shitrit"],
         "Programs": ["Microsoft"],
         "Bugs": ["CSTI", "Stored XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "Microsoft Office Online Server Remote Code Execution",
              "Link": "https://www.mdsec.co.uk/2022/10/microsoft-office-online-server-remote-code-execution/"
           }
          ],
         "Authors": ["Manish Tanwar (@IndiShell1046)"],
         "Programs": ["Microsoft"],
         "Bugs": ["SSRF", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "CVE-2022-3236: Sophos Firewall User Portal and Web Admin Code Injection",
              "Link": "https://www.zerodayinitiative.com/blog/2022/10/19/cve-2022-3236-sophos-firewall-user-portal-and-web-admin-code-injection"
           }
          ],
         "Authors": ["Guy Lederfein (@glederfein)", "Dusan Stevanovic"],
         "Programs": ["Sophos"],
         "Bugs": ["RCE", "Code injection", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "Scan QR Code and Got Hacked (CVE-2021–43530 : UXSS on Firefox Android Version)",
              "Link": "https://medium.com/@sas.kunz/scan-qr-code-and-got-hacked-cve-2021-43530-uxss-on-firefox-android-version-768b24b326fb"
           }
          ],
         "Authors": ["hafiizh"],
         "Programs": ["Mozilla"],
         "Bugs": ["Universal XSS", "Android"],
         "Bounty": "2,000",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "Found vulnaribility on subdomain of nasa.gov simply using censys",
              "Link": "https://medium.com/@kandar.souvik6/found-vulnaribility-on-subdomain-of-nasa-gov-simply-using-censys-d93f253ff560"
           }
          ],
         "Authors": ["hacker_might"],
         "Programs": ["NASA"],
         "Bugs": ["Exposed registration page"],
         "Bounty": "-",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "Vulnerabilities in Tenda's W15Ev2 AC1200 Router",
              "Link": "https://boschko.ca/tenda_ac1200_router/"
           }
          ],
         "Authors": ["Olivier Laflamme (@olivier_boschko)"],
         "Programs": ["Tenda"],
         "Bugs": ["OS command injection", "Buffer Overflow", "Memory corruption", "Stored XSS", "Broken authorization", "Information disclosure"],
         "Bounty": "-",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "Yet Another Telerik UI Revisit",
              "Link": "https://blog.blacklanternsecurity.com/p/yet-another-telerik-ui-revisit"
           }
          ],
         "Authors": ["Paul Mueller"],
         "Programs": ["Progress (Telerik)"],
         "Bugs": ["Cryptographic issues", "RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-10-19",
         "AddedDate": "2022-10-23"
      },
      {
         "Links": [
            {
               "Title": "Remote Code Execution in Melis Platform",
               "Link": "https://blog.sonarsource.com/remote-code-execution-in-melis-platform/"
            }
         ],
         "Authors": ["Karim El Ouerghemmi", "Thomas Chauchefoin (@swapgs)"],
         "Programs": ["Melis Platform"],
         "Bugs": ["RCE", "Path traversal", "Insecure deserialization", "Security code review"],
         "Bounty": "-",
         "PublicationDate": "2022-10-18",
         "AddedDate": "2022-10-24"
      },
      {
         "Links": [
           {
              "Title": "The Danger of Falling to System Role in AWS SDK Client",
              "Link": "https://blog.doyensec.com/2022/10/18/cloudsectidbit-dataimport.html"
           }
          ],
         "Authors": ["Fracensco Lacerenza (@lacerenza_fra)", "Mohamed Ouad (@ouadmoha)"],
         "Programs": ["-"],
         "Bugs": ["Cloud", "Privilege escalation", "Security misconfiguration"],
         "Bounty": "-",
         "PublicationDate": "2022-10-18",
         "AddedDate": "2022-10-22"
      },
      {
         "Links": [
           {
              "Title": "Basic recon to RCE III",
              "Link": "https://www.jomar.fr/posts/2022/basic_recon_to_rce_iii/"
           }
          ],
         "Authors": ["Joshua Martinelle (@J0_mart)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "OS command injection"],
         "Bounty": "-",
         "PublicationDate": "2022-10-18",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "PHP Filters Chain: What Is It And How To Use It",
              "Link": "https://www.synacktiv.com/en/publications/php-filters-chain-what-is-it-and-how-to-use-it.html"
           }
          ],
         "Authors": ["Rémi Matasse (@_remsio_)"],
         "Programs": ["Laravel"],
         "Bugs": ["Insecure deserialization", "PHP filter chain"],
         "Bounty": "-",
         "PublicationDate": "2022-10-18",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
           {
              "Title": "CVE 2022–24082, RCE in the PEGA Platform — Discovery, Remediation & Technical Details (Long Live JMX!!!)",
              "Link": "https://marcin-wolak.medium.com/cve-2022-24082-rce-in-the-pega-platform-discovery-remediation-technical-details-long-live-69efb5437316"
           }
          ],
         "Authors": ["Marcin Wolak"],
         "Programs": ["PEGA"],
         "Bugs": ["RCE", "JMX"],
         "Bounty": "-",
         "PublicationDate": "2022-10-17",
         "AddedDate": "2023-05-15"
      },
      {
         "Links": [
           {
              "Title": "Guest Blog Post - Memory corruption vulnerabilities in Edge",
              "Link": "https://microsoftedge.github.io/edgevr/posts/memory-corruption-vulnerabilities-in-edge/"
           }
          ],
         "Authors": ["David Erceg (@david_erceg)"],
         "Programs": ["Microsoft"],
         "Bugs": ["Browser hacking", "Memory corruption", "Use-After-Free", "Out-of-bounds Read", "Out-of-bounds Write"],
         "Bounty": "215,000",
         "PublicationDate": "2022-10-17",
         "AddedDate": "2022-11-01"
      },
      {
         "Links": [
           {
              "Title": "Analysis of a Remote Code Execution (RCE) Vulnerability in Cobalt Strike 4.7.1",
              "Link": "https://securityintelligence.com/posts/analysis-rce-vulnerability-cobalt-strike/"
           }
          ],
         "Authors": ["Rio (@0x09AL)", "b33f (@FuzzySec)"],
         "Programs": ["HelpSystems"],
         "Bugs": ["RCE", "XSS"],
         "Bounty": "-",
         "PublicationDate": "2022-10-17",
         "AddedDate": "2022-10-21"
      },
      {
         "Links": [
            {
               "Title": "Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution",
               "Link": "https://sector7.computest.nl/post/2022-10-iconics-genesis64/"
            }
         ],
         "Authors": ["Sector 7 (@sector7_nl)"],
         "Programs": ["ICONICS"],
         "Bugs": ["RCE"],
         "Bounty": "5,000",
         "PublicationDate": "2022-10-17",
         "AddedDate": "2022-10-17"
      },
     {
              "Links": [
                {
                   "Title": "Facebook SMS Captcha Was Vulnerable to CSRF Attack",
                   "Link": "https://lokeshdlk77.medium.com/facebook-sms-captcha-was-vulnerable-to-csrf-attack-8db537b1e980"
                }
               ],
              "Authors": ["Lokesh Kumar (@lokeshdlk77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "18,750",
              "PublicationDate": "2022-10-17",
              "AddedDate": "2022-10-17"
      },
           {
              "Links": [
                {
                   "Title": "Toner Deaf – Printing your next persistence (Hexacon 2022)",
                   "Link": "https://research.nccgroup.com/2022/10/17/toner-deaf-printing-your-next-persistence-hexacon-2022/"
                }
               ],
              "Authors": ["Alex Plaskett (@alexjplaskett)", "Cedric Halbronn (@saidelike)"],
              "Programs": ["Lexmark"],
              "Bugs": ["Path traversal", "Arbitrary file write", "RCE", "Printer hacking"],
              "Bounty": "-",
              "PublicationDate": "2022-10-17",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                 {
                    "Title": "How I Got $10,000 From GitHub For Bypassing Filtration of HTML tags",
                    "Link": "https://saajan.bhujel.cyou/blog/web/2022-10-16-how-i-got-10000-from-github-for-bypassing-filtration-of-html-tags"
                 },
                 {
                   "Title": "Alternative link",
                   "Link": "https://infosecwriteups.com/how-i-got-10-000-from-github-for-bypassing-filtration-of-html-tags-db31173c8b37"
                }
               ],
              "Authors": ["Saajan Bhujel (@saajanbhujel)"],
              "Programs": ["GitHub"],
              "Bugs": ["XSS"],
              "Bounty": "10,000",
              "PublicationDate": "2022-10-16",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "My First Critical Bug In HackerOne Platform",
                   "Link": "https://web.archive.org/web/20221017025828/https://medium.com/@EX_097/my-first-critical-bug-in-hackerone-platform-2ce9adcb39a6"
                }
               ],
              "Authors": ["EX_097"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "-",
              "PublicationDate": "2022-10-16",
              "AddedDate": "2022-10-17"
           },
           {
            "Links": [
              {
                 "Title": "[CVE-2022-1786] A Journey To The Dawn",
                 "Link": "https://blog.kylebot.net/2022/10/16/CVE-2022-1786/"
              }
             ],
            "Authors": ["kylebot (@ky1ebot)"],
            "Programs": ["Google (kCTF)", "Linux Kernel Organization"],
            "Bugs": ["Use-After-Free", "Memory corruption", "Local Privilege Escalation"],
            "Bounty": "91,337",
            "PublicationDate": "2022-10-15",
            "AddedDate": "2022-10-23"
         },
           {
              "Links": [
                {
                   "Title": "Google SSO misconfiguration leading to Account Takeover",
                   "Link": "https://0x4kd.medium.com/google-sso-misconfiguration-leading-to-account-takeover-cf9bcf63e76e"
                }
               ],
              "Authors": ["0x4KD (@0x4kd)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "Account takeover", "SSO"],
              "Bounty": "-",
              "PublicationDate": "2022-10-14",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Story about Escalation of HTML Injection to EC2 Instance credentials leak",
                   "Link": "https://medium.com/@Cybervenom/story-about-escalation-of-html-injection-to-ec2-instance-credentials-leak-e2cbd7343a83"
                }
               ],
              "Authors": ["Harsh Tandel (@H4r5h_T4nd37)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2022-10-14",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "The Castle’s Latrine",
                   "Link": "https://blog.infiltrateops.io/the-castles-latrine-10f9c16548bd"
                }
               ],
              "Authors": ["infiltrateops"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-10-14",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Microsoft Office 365 Message Encryption Insecure Mode of Operation",
                   "Link": "https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation"
                }
               ],
              "Authors": ["Harry Sintonen"],
              "Programs": ["Microsoft"],
              "Bugs": ["Weak crypto"],
              "Bounty": "5,000",
              "PublicationDate": "2022-10-14",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Code Injection and SQLi in WP ALL Export Pro",
                   "Link": "https://payatu.com/blog/p3n7a90n/wp-all-export-pro"
                }
               ],
              "Authors": ["p3n7a90n (@p3n7a90n)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "Security code review"],
              "Bounty": "500",
              "PublicationDate": "2022-10-14",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Weak private key generation in SSH.NET <= 2020.0.1",
                   "Link": "https://www.synacktiv.com/sites/default/files/2022-10/SSH.NET_weak_private_key_generation_0.pdf"
                }
               ],
              "Authors": ["Guillaume André (@yaumn_)"],
              "Programs": ["SSH.NET"],
              "Bugs": ["Weak crypto", "Security code review"],
              "Bounty": "-",
              "PublicationDate": "2022-10-14",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "It’s the Little Things : Breaking an AI",
                   "Link": "https://infosecwriteups.com/its-the-little-things-breaking-an-ai-40c30ae85f37"
                }
               ],
              "Authors": ["Debangshu Kundu (@debangshu_kundu)", "Rajesh (@_rajesh_ranjan_)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-10-13",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Some Vulnerabilities Don’t Have A Name",
                   "Link": "https://checkmarx.com/blog/some-vulnerabilities-dont-have-a-name/"
                }
               ],
              "Authors": ["Mario Teixeira", "Bruno Dias"],
              "Programs": ["Node.js third-party modules (debug)"],
              "Bugs": ["ReDoS", "Memory leak"],
              "Bounty": "-",
              "PublicationDate": "2022-10-13",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Fall account takeover via Amazon Cognito misconfiguration",
                   "Link": "https://medium.com/@iknowhatodo/fall-account-takeover-via-amazon-cognito-misconfiguration-ba5975b06c24"
                }
               ],
              "Authors": ["Hossam Ahmed (@iknowhatodo0x01)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-10-13",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "FortiOS, FortiProxy, and FortiSwitchManager Authentication Bypass Technical Deep Dive (CVE-2022-40684)",
                   "Link": "https://www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684"
                }
               ],
              "Authors": ["James Horseman (@JamesHorseman2)", "Zach Hanley (@hacks_zach)"],
              "Programs": ["Fortinet"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-10-13",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Code flaws leads to Org/Admin Account Takeover",
                   "Link": "https://mr23r0.medium.com/code-flaws-leads-to-org-admin-account-takeover-ad9515a96eab"
                }
               ],
              "Authors": ["Saransh Saraf (@mr23r0)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-10-13",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "SQL Injection in GraphQL",
                   "Link": "https://0xgad.medium.com/sql-injection-in-graphql-2859c96547a8"
                }
               ],
              "Authors": ["Ahmed Gad (@0xGAD)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "GraphQL"],
              "Bounty": "-",
              "PublicationDate": "2022-10-13",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Adobe Reader - XFA - ANSI-Unicode Confusion Information Leak",
                   "Link": "https://hacksys.io/blogs/adobe-reader-xfa-ansi-unicode-confusion-information-leak"
                }
               ],
              "Authors": ["Ashfaq Ansari (@HackSysTeam)", "Krishnakant Patil (@shsirk)"],
              "Programs": ["Adobe"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-10-13",
              "AddedDate": "2022-10-17"
           },
           {
            "Links": [
               {
                  "Title": "Compromising a Backup System by iSCSI Interface During a Routine Penetration Test",
                  "Link": "https://www.directdefense.com/compromising-a-backup-system-by-iscsi-interface-during-a-routine-penetration-test/"
               }
            ],
            "Authors": ["Bruno Oliveira"],
            "Programs": ["-"],
            "Bugs": ["Missing authentication"],
            "Bounty": "-",
            "PublicationDate": "2022-10-13",
            "AddedDate": "2022-10-24"
         },
         {
            "Links": [
               {
                  "Title": "The story of a [P5] that lead me to a [P3] find",
                  "Link": "https://medium.com/@nireshpandian19/the-story-of-a-p5-that-lead-me-to-a-p3-find-3f8a5ea2c6e1"
               }
            ],
            "Authors": ["JAI NIRESH J"],
            "Programs": ["-"],
            "Bugs": ["Pre-account takeover"],
            "Bounty": "-",
            "PublicationDate": "2022-10-13",
            "AddedDate": "2022-11-03"
         },
         {
              "Links": [
                {
                   "Title": "$6000 with Microsoft Hall of Fame | Microsoft Firewall Bypass | CRLF to XSS | Microsoft Bug Bounty",
                   "Link": "https://infosecwriteups.com/6000-with-microsoft-hall-of-fame-microsoft-firewall-bypass-crlf-to-xss-microsoft-bug-bounty-8f6615c47922"
                }
               ],
              "Authors": ["Neh Patel (@thecyberneh)"],
              "Programs": ["Microsoft"],
              "Bugs": ["CRLF injection", "XSS"],
              "Bounty": "6,000",
              "PublicationDate": "2022-10-12",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Threat Alert: Private npm Packages Disclosed via Timing Attacks",
                   "Link": "https://blog.aquasec.com/private-packages-disclosed-via-timing-attack-on-npm"
                }
               ],
              "Authors": ["Yakir Kadkoda"],
              "Programs": ["GitHub"],
              "Bugs": ["Timing attack", "Supply chain attack"],
              "Bounty": "-",
              "PublicationDate": "2022-10-12",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Broken Access Control leads to full team takeover and privilege escalation",
                   "Link": "https://abdelhameedghazy.medium.com/broken-access-control-leads-to-full-team-takeover-and-privilege-escalation-6f50174f29ce"
                }
               ],
              "Authors": ["Abdelhameed Ghazy (@El3Etraa1)"],
              "Programs": ["-"],
              "Bugs": ["Broken Access Control", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-10-12",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Pwning ManageEngine — From Endpoint to Exploit: A deep dive into CVE-2021–42847",
                   "Link": "https://medium.com/@erik.wynter/pwning-manageengine-from-endpoint-to-exploit-bc5793836fd"
                }
               ],
              "Authors": ["Erik Wynter (@WynterErik)"],
              "Programs": ["Zoho"],
              "Bugs": ["Arbitrary file write", "XXE", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-10-12",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Critical IDOR Vulnerability on Medium?",
                   "Link": "https://infosecwriteups.com/critical-idor-vulnerability-on-medium-f78346edbcb1"
                }
               ],
              "Authors": ["zer0d"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-10-12",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                {
                   "Title": "Breaking Parser Logic: Gain Access To NGINX Plus API — Read/Write Upstreams.",
                   "Link": "https://cyberlix.io/breaking-parser-logic-gain-access-to-nginx-plus-api-read-write-upstreams/"
                }
               ],
              "Authors": ["Cyberlix (@cyberlixio)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-10-12",
              "AddedDate": "2022-10-12"
      },
      {
         "Links": [
           {
              "Title": "In GUID We Trust",
              "Link": "https://www.intruder.io/research/in-guid-we-trust"
           }
          ],
         "Authors": ["Daniel Thatcher (@_danielthatcher)"],
         "Programs": ["-"],
         "Bugs": ["IDOR", "Password reset", "Race condition", "Account takeover"],
         "Bounty": "-",
         "PublicationDate": "2022-10-11",
         "AddedDate": "2022-10-17"
 },
      {
              "Links": [
                {
                   "Title": "Cold Hard Cache — Bypassing RPC Interface Security with Cache Abuse",
                   "Link": "https://www.akamai.com/blog/security-research/cold-hard-cache-bypassing-rpc-with-cache-abuse"
                }
               ],
              "Authors": ["-"],
              "Programs": ["Microsoft"],
              "Bugs": ["Privilege escalation", "Windows"],
              "Bounty": "-",
              "PublicationDate": "2022-10-11",
              "AddedDate": "2022-10-17"
      },
      {
              "Links": [
                {
                   "Title": "Web application firewall bypass",
                   "Link": "https://blog.yeswehack.com/yeswerhackers/web-application-firewall-bypass/"
                }
               ],
              "Authors": ["-"],
              "Programs": ["-"],
              "Bugs": ["WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-10-11",
              "AddedDate": "2022-10-12"
      },
      {
               "Links": [
                  {
                     "Title": "Taking over the Medium subdomain using Medium",
                     "Link": "https://smaranchand.com.np/2022/10/taking-over-the-medium-subdomain-using-medium/"
                  }
               ],
               "Authors": ["Smaran Chand (@smaranchand)"],
               "Programs": ["Medium"],
               "Bugs": ["Subdomain takeover"],
               "Bounty": "-",
               "PublicationDate": "2022-10-10",
               "AddedDate": "2022-10-24"
            },
            {
              "Links": [
                {
                   "Title": "Enter \"Sandbreak\" - Vulnerability In vm2 Sandbox Module Enables Remote Code Execution (CVE-2022-36067)",
                   "Link": "https://www.oxeye.io/blog/vm2-sandbreak-vulnerability-cve-2022-36067"
                }
              ],
              "Authors": ["Oxeye (@OxeyeSecurity)"],
              "Programs": ["vm2"],
              "Bugs": ["RCE", "Sandbox bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-10-10",
              "AddedDate": "2022-10-17"
            },
            {
              "Links": [
                {
                   "Title": "[Hacking Banks] Broken Access Control Vulnerability in Banking application [PART I]",
                   "Link": "https://medium.com/@protostar0/hacking-banks-broken-access-control-vulnerability-in-banking-application-part-i-c442ed5ae170"
                },
                {
                 "Title": "[PART II]",
                 "Link": "https://medium.com/@protostar0/hacking-bank-broken-access-control-vulnerability-in-banking-application-part-ii-89c8edc1baef"
              }
              ],
              "Authors": ["Abdelhak Kharroubi"],
              "Programs": ["-"],
              "Bugs": ["Broken Access Control", "Android"],
              "Bounty": "-",
              "PublicationDate": "2022-10-10",
              "AddedDate": "2022-10-12"
            },
            {
              "Links": [
                {
                   "Title": "VMware vCenter Server Platform Services Controller Unsafe Deserialization vulnerability",
                   "Link": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1587"
                }
               ],
              "Authors": ["Marcin 'Icewall' Noga (@_Icewall)"],
              "Programs": ["VMware"],
              "Bugs": ["Insecure deserialization", "Security code review"],
              "Bounty": "-",
              "PublicationDate": "2022-10-10",
              "AddedDate": "2022-10-12"
            },
            {
              "Links": [
                {
                   "Title": "Reflected cross-site scripting vulnerability in Crealogix EBICS implementation",
                   "Link": "https://www.pentagrid.ch/de/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/"
                }
               ],
              "Authors": ["Tobias Ospelt (@floyd_ch)"],
              "Programs": ["CREALOGIX AG"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-10-10",
              "AddedDate": "2022-10-12"
            },
            {
              "Links": [
                {
                   "Title": "Gcash Vulnerability Walkthrough",
                   "Link": "https://nmochea.medium.com/gcash-vulnerability-walkthrough-c7c938163dfb"
                }
               ],
              "Authors": ["Neil Mark Ochea (@nmochea)"],
              "Programs": ["Globe Telecom (Gcash)"],
              "Bugs": ["Android", "Insecure deeplink", "Insecure intent"],
              "Bounty": "-",
              "PublicationDate": "2022-10-10",
              "AddedDate": "2022-10-10"
            },
            {
              "Links": [
                {
                   "Title": "Persistent PHP Payloads In PNGs: How To Inject PHP Code In An Image – And Keep It There !",
                   "Link": "https://www.synacktiv.com/publications/persistent-php-payloads-in-pngs-how-to-inject-php-code-in-an-image-and-keep-it-there.html"
                }
               ],
              "Authors": ["Quentin Roland (@croco_byte)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "Code injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-10-10",
              "AddedDate": "2022-10-10"
            },
            {
              "Links": [
                {
                   "Title": "The easiest bug to get a Hall of fame from a Billion dollar company.",
                   "Link": "https://debprasadbanerjee502.medium.com/the-easiest-bug-to-get-a-hall-of-fame-from-a-billion-dollar-company-8278fd7b3035"
                }
               ],
              "Authors": ["Ravaan"],
              "Programs": ["GeHealthcare"],
              "Bugs": ["GraphQL", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-10-10",
              "AddedDate": "2022-10-10"
            },
            {
              "Links": [
                {
                   "Title": "Vulnerabilities in Online Payment Systems",
                   "Link": "https://medium.com/@claudio_moranb/vulnerabilities-in-online-payment-systems-edd2d3c06905"
                }
               ],
              "Authors": ["Claudio Moran"],
              "Programs": ["-"],
              "Bugs": ["Payment bypass", "Payment tampering", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-10-08",
              "AddedDate": "2022-10-08"
            },
            {
               "Links": [
                  {
                     "Title": "Auth Bypass Via Exposed Credentials",
                     "Link": "https://crypt0g30rgy.github.io/post/AuthBypass"
                  }
               ],
               "Authors": ["g30rgy th3 d4rk (@Crypt0g30rgy)"],
               "Programs": ["-"],
               "Bugs": ["Hardcoded API keys"],
               "Bounty": "700",
               "PublicationDate": "2022-10-07",
               "AddedDate": "2023-02-26"
            },
            {
              "Links": [
                {
                   "Title": "Insecure Comments",
                   "Link": "https://mearegtu.medium.com/insecure-comments-73399193f804"
                }
               ],
              "Authors": ["Meareg"],
              "Programs": ["Microsoft"],
              "Bugs": ["IDOR", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-10-07",
              "AddedDate": "2022-10-08"
            },
            {
              "Links": [
                {
                   "Title": "CVE-2022–36635 — A SQL Injection in ZKSecurityBio to RCE",
                   "Link": "https://medium.com/stolabs/cve-2022-36635-a-sql-injection-in-zksecuritybio-to-rce-c5bde2962d47"
                }
               ],
              "Authors": ["Caio Burgardt (@CaioBurgardt)", "Silton Santos"],
              "Programs": ["ZKTeco"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-10-06",
              "AddedDate": "2022-10-08"
            },
            {
              "Links": [
                {
                   "Title": "Full Company Building Takeover",
                   "Link": "https://omar0x01.medium.com/company-building-takeover-10a422385390"
                }
               ],
              "Authors": ["Omar Hashem (@OmarHashem666)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-10-06",
              "AddedDate": "2022-10-08"
            },
            {
              "Links": [
                {
                   "Title": "Technical Advisory – OpenJDK – Weak Parsing Logic in java.net.InetAddress and Related Classes",
                   "Link": "https://research.nccgroup.com/2022/10/06/technical-advisory-openjdk-weak-parsing-logic-in-java-net-inetaddress-and-related-classes/"
                }
               ],
              "Authors": ["Jeff Dileo (@ChaosDatumz)"],
              "Programs": ["OpenJDK"],
              "Bugs": ["IP address validation bypass", "Hostname validation bypass", "URL parsing issue"],
              "Bounty": "-",
              "PublicationDate": "2022-10-06",
              "AddedDate": "2022-10-08"
            },
            {
              "Links": [
                {
                   "Title": "SSD Advisory – pfSense Post Auth RCE",
                   "Link": "https://ssd-disclosure.com/ssd-advisory-pfsense-post-auth-rce/"
                }
               ],
              "Authors": ["이예랑 (@yelang123x)"],
              "Programs": ["pfSense"],
              "Bugs": ["RCE", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-10-06",
              "AddedDate": "2022-10-08"
            },
            {
              "Links": [
                {
                   "Title": "Mr. Robot: Self Xss from Informative to high 1200$ ,csrf, open redirect,self xss to stored",
                   "Link": "https://ahmadaabdulla.medium.com/mr-robot-self-xss-from-informative-to-high-1200-csrf-open-redirect-self-xss-to-stored-92f371ba3da1"
                }
               ],
              "Authors": ["Ahmad A Abdulla (@lu3ky13)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "CSRF"],
              "Bounty": "1,200",
              "PublicationDate": "2022-10-06",
              "AddedDate": "2022-10-08"
            },
            {
              "Links": [
                {
                   "Title": "CVE-2022-41343",
                   "Link": "https://tantosec.com/blog/cve-2022-41343/"
                }
               ],
              "Authors": ["Tanto Security team (@TantoSecurity)"],
              "Programs": ["dompdf"],
              "Bugs": ["RCE", "Insecure deserialization", "Phar deserialization"],
              "Bounty": "-",
              "PublicationDate": "2022-10-06",
              "AddedDate": "2022-10-06"
            },
            {
              "Links": [
                {
                   "Title": "Melting the DNS Iceberg: Taking over your infrastructure Kaminsky style",
                   "Link": "https://sec-consult.com/blog/detail/melting-the-dns-iceberg-taking-over-your-infrastructure-kaminsky-style/"
                }
               ],
              "Authors": ["Timo Longin (@timolongin)", "Clemens Stockenreitne"],
              "Programs": ["-"],
              "Bugs": ["DNS cache poisoning", "Kaminsky attack", "DNS"],
              "Bounty": "-",
              "PublicationDate": "2022-10-06",
              "AddedDate": "2022-10-06"
            },
            {
              "Links": [
                {
                   "Title": "Error based SQL Injection with WAF bypass manual Exploit 100%",
                   "Link": "https://c0nqr0r.medium.com/error-based-sql-injection-with-waf-bypass-manual-exploit-100-bab36b769005"
                }
               ],
              "Authors": ["Ahmed Qaramany (@c0nqr0r)", "Mahmoud samaha (@0x__4m)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-10-06",
              "AddedDate": "2022-10-06"
            },
            {
              "Links": [
                {
                   "Title": "A Deep Dive of CVE-2022–33987 (Got allows a redirect to a UNIX socket)",
                   "Link": "https://itnext.io/a-deep-dive-of-cve-2022-33987-got-allows-a-redirect-to-a-unix-socket-cdeed53944f7"
                }
               ],
              "Authors": ["Chaim Sanders"],
              "Programs": ["MediaWiki"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-10-06",
              "AddedDate": "2022-10-06"
            },
            {
              "Links": [
                {
                   "Title": "Exploit Disclosure: Turning Thunderbird into a Decryption Oracle",
                   "Link": "https://pseudorandom.resistant.tech/disclosing-security-and-privacy-issues-in-thunderbird.html"
                }
               ],
              "Authors": ["Sarah Jamie Lewis (@SarahJamieLewis)"],
              "Programs": ["Mozilla (Thunderbird)"],
              "Bugs": ["Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2022-10-05",
              "AddedDate": "2022-10-08"
            },
            {
              "Links": [
                {
                   "Title": "Appsmith Patches Full-Read SSRF Vulnerabilities Reported by CloudSEK",
                   "Link": "https://cloudsek.com/appsmith-patches-full-read-ssrf-vulnerabilities-reported-by-cloudsek/"
                }
               ],
              "Authors": ["Sparsh Kulshrestha (@d0tdotslash)", "Shashank Bharthwal (@xscorp7)"],
              "Programs": ["Appsmith"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-10-05",
              "AddedDate": "2022-10-06"
            },
            {
              "Links": [
                {
                   "Title": "How I Found A P1 Bug",
                   "Link": "https://medium.com/@amithc38/how-i-found-a-p1-bug-a9873819a2d0"
                }
               ],
              "Authors": ["Amith"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-10-05",
              "AddedDate": "2022-10-06"
            },
           {
              "Links": [
                {
                   "Title": "Hacking TMNF: Part 1 - Fuzzing the game server",
                   "Link": "https://blog.bricked.tech/posts/tmnf/part1/"
                },
                {
                 "Title": "Part 2 - Exploiting a blind format string",
                 "Link": "https://blog.bricked.tech/posts/tmnf/part2/"
              }
              ],
              "Authors": ["-"],
              "Programs": ["Ubisoft"],
              "Bugs": ["RCE", "Memory corruption", "Format string vulnerability"],
              "Bounty": "-",
              "PublicationDate": "2022-10-05",
              "AddedDate": "2022-10-06"
            },
           {
              "Links": [
                {
                   "Title": "Securing Developer Tools: A New Supply Chain Attack on PHP",
                   "Link": "https://blog.sonarsource.com/securing-developer-tools-a-new-supply-chain-attack-on-php/"
                }
               ],
              "Authors": ["Thomas Chauchefoin (@swapgs)"],
              "Programs": ["Packagist"],
              "Bugs": ["Argument injection", "RCE", "Supply chain attack", "Security code review"],
              "Bounty": "-",
              "PublicationDate": "2022-10-04",
              "AddedDate": "2022-10-06"
            },
           {
              "Links": [
                {
                   "Title": "Bugcrowd — Tale of multiple misconfigurations!! ❌",
                   "Link": "https://medium.com/@302Found/bugcrowd-tale-of-multiple-misconfigurations-cb5b98f09302"
                }
               ],
              "Authors": ["Vaibhav Lakhani", "Dhir Parmar"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "OAuth", "OTP bypass", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2022-10-04",
              "AddedDate": "2022-10-04"
            },
            {
              "Links": [
                {
                   "Title": "My First And Second Bugs Are — 2FA Bypass",
                   "Link": "https://medium.com/@nireshpandian19/my-first-and-second-bugs-are-2fa-bypass-1f6fd823b467"
                }
               ],
              "Authors": ["Jai Niresh J"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass", "HTTP response manipulation", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-10-03",
              "AddedDate": "2022-10-04"
            },
            {
              "Links": [
                {
                   "Title": "CSRF Attack — 0 click account delete - 1st write-up",
                   "Link": "https://medium.com/@bug_vs_me/csrf-attack-0-click-account-delete-1st-write-up-3d67b267b931"
                }
               ],
              "Authors": ["Deepak (@bug_vs_me)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2022-10-03",
              "AddedDate": "2022-10-04"
            },
            {
              "Links": [
                {
                   "Title": "Using Default Credential to Admin Account Takeover",
                   "Link": "https://rohit443.medium.com/using-default-credential-to-admin-account-takeover-677e782ff2f2"
                }
               ],
              "Authors": ["Rohit Kumar (Rohit_443)"],
              "Programs": ["-"],
              "Bugs": ["Weak credentials"],
              "Bounty": "-",
              "PublicationDate": "2022-10-02",
              "AddedDate": "2022-10-10"
            },
            {
              "Links": [
                {
                   "Title": "How I found an IDOR Worth $1500",
                   "Link": "https://adilnbabras.medium.com/how-i-found-an-idor-worth-1500-d5f78bc22a7e"
                }
               ],
              "Authors": ["Adil Nadeem Babras"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "1,500",
              "PublicationDate": "2022-10-02",
              "AddedDate": "2022-10-02"
      },
      {
              "Links": [
                {
                   "Title": "Breaking Business Logic - Part: 2^7 = 1",
                   "Link": "https://thehemdeep.medium.com/breaking-business-logic-part-2-7-1-f19924b18783"
                }
               ],
              "Authors": ["Hemdeep Gamit"],
              "Programs": ["-"],
              "Bugs": ["Race condition"],
              "Bounty": "-",
              "PublicationDate": "2022-10-02",
              "AddedDate": "2022-10-04"
      },
      {
              "Links": [
                {
                   "Title": "Tale of Easy P1 Bugs in Wild",
                   "Link": "https://medium.com/@Cybervenom/tale-of-easy-p1-bugs-in-wild-1b7f5bf80eef"
                }
               ],
              "Authors": ["Harsh Tandel"],
              "Programs": ["-"],
              "Bugs": ["Forced browsing", "403 bypass", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-10-01",
              "AddedDate": "2022-10-02"
      },
      {
              "Links": [
                {
                   "Title": "Zoneminder – Web App Testing – Oct 2022",
                   "Link": "https://www.trenchesofit.com/2022/09/30/zoneminder-web-app-testing/"
                }
               ],
              "Authors": ["Trenches of IT (@TrenchesofIT)"],
              "Programs": ["ZoneMinder"],
              "Bugs": ["DoS", "Log injection", "CSRF", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-09-30",
              "AddedDate": "2022-10-07"
      },
      {
              "Links": [
                {
                   "Title": "Two Lines Of JScript For $20,000 – Pwn2Own Miami 2022",
                   "Link": "https://trenchant.io/two-lines-of-jscript-for-20000-pwn2own-miami-2022/"
                }
               ],
              "Authors": ["Ben McBride (@bdmcbri)"],
              "Programs": ["ICONICS"],
              "Bugs": ["RCE"],
              "Bounty": "20,000",
              "PublicationDate": "2022-09-29",
              "AddedDate": "2022-10-04"
      },
      {
              "Links": [
                {
                   "Title": "How Scanning Your Projects for Security Issues Can Lead to Remote Code Execution",
                   "Link": "https://www.imperva.com/blog/how-scanning-your-projects-for-security-issues-can-lead-to-remote-code-execution/"
                }
               ],
              "Authors": ["Ron Masas (@RonMasas)"],
              "Programs": ["Snyk"],
              "Bugs": ["RCE", "OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2022-09-29",
              "AddedDate": "2022-10-04"
      },
      {
              "Links": [
                {
                   "Title": "Security vs Compliance-Cloudflare Password Policy Restriction Bypass",
                   "Link": "https://infosecwriteups.com/security-vs-compliance-cloudflare-password-policy-restriction-bypass-da07ca7df4f2"
                }
               ],
              "Authors": ["Lohith Gowda M (@lohigowda_in)"],
              "Programs": ["Cloudflare"],
              "Bugs": ["Client-side enforcement of server-side security"],
              "Bounty": "300",
              "PublicationDate": "2022-09-29",
              "AddedDate": "2022-10-02"
      },
      {
              "Links": [
                {
                   "Title": "Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned)",
                   "Link": "https://medium.com/@jacopotediosi/worldwide-server-side-cache-poisoning-on-all-akamai-edge-nodes-50k-bounty-earned-f97d80f3922b"
                }
               ],
              "Authors": ["Francesco Mariani (@_medusa_1_)", "Jacopo Tediosi (@jacopotediosi)"],
              "Programs": ["Akamai", "Paypal", "Airbnb", "Tesla", "Valve", "Zomato", "Whitejar", "Starbucks", "PlayStation", "Marriott", "Hyatt Hotels", "Goldman Sachs", "Microsoft", "Apple", "LastPass", "Brussels Airlines", "Mastercard", "eToro BBP", "BMW Group", "Rockstar Games"],
              "Bugs": ["Web cache poisoning"],
              "Bounty": "50,000",
              "PublicationDate": "2022-09-29",
              "AddedDate": "2022-10-02"
      },
      {
              "Links": [
                {
                   "Title": "Orange Arbitrary Command Execution",
                   "Link": "https://omar0x01.medium.com/orange-arbitrary-command-execution-75ba7f283d53"
                }
               ],
              "Authors": ["Omar Hashem (@OmarHashem666)"],
              "Programs": ["Orange"],
              "Bugs": ["RCE", "Docker daemon misconfiguration", "Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2022-09-29",
              "AddedDate": "2022-10-02"
      },
      {
              "Links": [
                {
                   "Title": "ECDSA Nonce Reuse",
                   "Link": "https://labs.ingredous.com/2022/09/29/ecdsa-nonce-reuse/"
                }
               ],
              "Authors": ["Ingredous Labs"],
              "Programs": ["-"],
              "Bugs": ["Cryptographic issues"],
              "Bounty": "-",
              "PublicationDate": "2022-09-29",
              "AddedDate": "2022-10-02"
      },
      {
              "Links": [
                {
                   "Title": "XSS through DHCP: How Attackers Use Standards",
                   "Link": "https://carvesystems.com/news/xss-through-dhcp-how-attackers-use-standards/"
                }
               ],
              "Authors": ["Dylan Ross"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-09-29",
              "AddedDate": "2022-10-02"
      },
      {
              "Links": [
                {
                   "Title": "A vulnerability on Patreon, and their elusive bounty program.",
                   "Link": "https://daturamater.medium.com/a-breach-on-patreon-and-their-elusive-bounty-program-5e7ea62dc738"
                }
               ],
              "Authors": ["Datura Mater (@DaturaMater)"],
              "Programs": ["Patreon"],
              "Bugs": ["Payment bypass", "Weak crypto"],
              "Bounty": "-",
              "PublicationDate": "2022-09-29",
              "AddedDate": "2022-10-02"
      },
      {
              "Links": [
                {
                   "Title": "CVE-2022-37461: Two Reflected XSS Vulnerabilities in Canon Medical’s Vitrea View",
                   "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2022-37461-two-reflected-xss-vulnerabilities-in-canon-medicals-vitrea-view/"
                }
               ],
              "Authors": ["Jordan Hedges", "Avery Warddhana"],
              "Programs": ["Canon"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-09-29",
              "AddedDate": "2022-10-02"
      },
      {
              "Links": [
                {
                   "Title": "Apple CoreText - An Unexpected Journey to Learn about Failure",
                   "Link": "https://starlabs.sg/blog/2022/09-apple-coretext-an-unexpected-journey-to-learn-about-failure/"
                }
               ],
              "Authors": ["Daniel Lim Wee Soong (@daniellimws)"],
              "Programs": ["Apple"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-09-29",
              "AddedDate": "2022-09-30"
      },
            {
              "Links": [
                {
                   "Title": "The forgotten IPFS vulnerabilities",
                   "Link": "https://consensys.net/diligence/blog/2022/09/the-forgotten-ipfs-vulnerabilities/"
                }
               ],
              "Authors": ["tintinweb", "Joran Honig (@joranhonig)"],
              "Programs": ["Filecoin Security"],
              "Bugs": ["Web3 hacking", "Path traversal", "CORS misconfiguration", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2022-09-28",
              "AddedDate": "2022-10-10"
            },
            {
              "Links": [
                {
                   "Title": "Practically-exploitable Cryptographic Vulnerabilities in Matrix",
                   "Link": "https://nebuchadnezzar-megolm.github.io"
                },
                {
                  "Title": "Whitepaper & Slides",
                  "Link": "https://www.blackhat.com/eu-22/briefings/schedule/#practically-exploitable-cryptographic--vulnerabilities-in-matrix-29883"
               }
               ],
              "Authors": ["Martin Albrecht (@martinralbrecht)", "Sofía Celi (@claucece)", "Benjamin Dowling (@DowlingBJ)", "Daniel Jones (@djwj_)"],
              "Programs": ["Matrix"],
              "Bugs": ["Cryptographic issues"],
              "Bounty": "-",
              "PublicationDate": "2022-09-28",
              "AddedDate": "2022-10-04"
            },
            {
              "Links": [
                {
                   "Title": "Exploits Explained: 5 Unusual Authentication Bypass Techniques",
                   "Link": "https://www.synack.com/blog/exploits-explained-5-unusual-authentication-bypass-techniques/"
                }
               ],
              "Authors": ["Ozgur Alp (@ozgur_bbh)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "JWT", "CMS", "SSO"],
              "Bounty": "-",
              "PublicationDate": "2022-09-28",
              "AddedDate": "2022-09-29"
            },
            {
              "Links": [
                {
                   "Title": "Two RCEs are better than one: write-up of an interesting lateral movement",
                   "Link": "https://medium.com/@seeu-inspace/two-rces-are-better-than-one-write-up-of-an-interesting-lateral-movement-66a52d42e075"
                }
               ],
              "Authors": ["Riccardo Malatesta (@seeu_inspace)"],
              "Programs": ["-"],
              "Bugs": ["Local Privilege Escalation", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-09-28",
              "AddedDate": "2022-09-29"
            },
            {
              "Links": [
                {
                   "Title": "Another Tale Of IBM I (AS/400) Hacking",
                   "Link": "https://blog.silentsignal.eu/2022/09/28/another-tale-of-ibm-i-as-400-hacking/"
                }
               ],
              "Authors": ["pz"],
              "Programs": ["-"],
              "Bugs": ["Local Privilege Escalation", "Midrange system", "Menu security"],
              "Bounty": "-",
              "PublicationDate": "2022-09-28",
              "AddedDate": "2022-09-29"
            },
            {
              "Links": [
                {
                   "Title": "From nothing to AWS credentials",
                   "Link": "https://webs3c.com/t/from-nothing-to-aws-credentials/220"
                }
               ],
              "Authors": ["(@darkandroider)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-09-27",
              "AddedDate": "2022-10-10"
            },
            {
              "Links": [
                {
                   "Title": "Layer 2 network security bypass using VLAN 0, LLC/SNAP headers and invalid length",
                   "Link": "https://blog.champtar.fr/VLAN0_LLC_SNAP/"
                }
               ],
              "Authors": ["Etienne Champetier / champtar"],
              "Programs": ["Microsoft", "Cisco"],
              "Bugs": ["Layer 2 networking vulnerability", "Ethernet", "MiTM", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-09-27",
              "AddedDate": "2022-10-02"
            },
            {
               "Links": [
                 {
                    "Title": "Discovering The Less-known Vulnerability In Oracle Peoplesoft",
                    "Link": "https://blog.rehack.xyz/2022/09/tips-tricks-discovering-less-known.html"
                 }
                ],
               "Authors": ["RE:HACK (@rehackxyz)"],
               "Programs": ["-"],
               "Bugs": ["TockenChpoken", "Privilege escalation", "Bruteforce", "Cookie manipulation"],
               "Bounty": "-",
               "PublicationDate": "2022-09-26",
               "AddedDate": "2023-03-10"
             },
            {
              "Links": [
                {
                   "Title": "“Hey Siri, follow that car!” - How traffic cameras expose your location through parking apps.",
                   "Link": "https://notmyplate.com/whitepaper/"
                }
               ],
              "Authors": ["Inti De Ceukelaire (@securinti)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Session hijacking"],
              "Bounty": "-",
              "PublicationDate": "2022-09-26",
              "AddedDate": "2022-10-02"
            },
            {
              "Links": [
                {
                   "Title": "Skype for Business Audit Part 2 - SKYPErimeterleak",
                   "Link": "https://frycos.github.io/vulns4free/2022/09/26/skype-audit-part2.html"
                }
               ],
              "Authors": ["Florian Hauser (@frycos)"],
              "Programs": ["Microsoft"],
              "Bugs": ["SSRF", "Security code review"],
              "Bounty": "-",
              "PublicationDate": "2022-09-26",
              "AddedDate": "2022-10-02"
            },
            {
              "Links": [
                {
                   "Title": "New Attack Paths? AS Requested Service Tickets",
                   "Link": "https://www.semperis.com/blog/new-attack-paths-as-requested-sts/"
                }
               ],
              "Authors": ["Charlie Clark (@exploitph)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation", "Windows", "Kerberos", "Active Directory"],
              "Bounty": "-",
              "PublicationDate": "2022-09-25",
              "AddedDate": "2022-09-29"
            },
           {
              "Links": [
                {
                   "Title": "Blind account takeover",
                   "Link": "https://bergee.it/blog/blind-account-takeover/"
                }
               ],
              "Authors": ["Bartłomiej Bergier (@_bergee_)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "250",
              "PublicationDate": "2022-09-25",
              "AddedDate": "2022-09-26"
            },
           {
              "Links": [
                {
                   "Title": "Tesla paid me $10,000 because of Directory Indexing",
                   "Link": "https://blog.infiltrateops.io/tesla-paid-me-10-000-because-of-directory-indexing-c1be06c77a3e"
                }
               ],
              "Authors": ["infiltrateops"],
              "Programs": ["Tesla"],
              "Bugs": ["Directory listing"],
              "Bounty": "10,000",
              "PublicationDate": "2022-09-25",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                {
                   "Title": "Shopping App Deeplink Arbitrary URLs",
                   "Link": "https://nmochea.medium.com/shopping-app-deeplink-arbitrary-urls-91a143a45c11"
                }
               ],
              "Authors": ["Neil Mark Ochea (@nmochea)"],
              "Programs": ["-"],
              "Bugs": ["Insecure deeplink", "Android"],
              "Bounty": "-",
              "PublicationDate": "2022-09-25",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                {
                   "Title": "Stored XSS in Nvidia via Angular JS template injection",
                   "Link": "https://xthemo.medium.com/stored-xss-at-nvidia-via-angular-js-template-injection-3c9793218860"
                }
               ],
              "Authors": ["Mohamed Abdelhady"],
              "Programs": ["Nvidia"],
              "Bugs": ["CSTI", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-09-25",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                 {
                    "Title": "Escalating SSTI to Reflected XSS using curly braces {}",
                    "Link": "https://sagarsajeev.medium.com/escalating-ssti-to-reflected-xss-using-curly-braces-825685bd93ec"
                 }
               ],
              "Authors": ["Sagar Sajeev (@Sagar__Sajeev)"],
              "Programs": ["-"],
              "Bugs": ["SSTI", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-09-24",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                 {
                    "Title": "Blind XSS on Admin Portal Leads to Information Disclosure",
                    "Link": "https://rohit443.medium.com/blind-xss-on-admin-portal-leads-to-information-disclosure-121d26b2a35a"
                 }
               ],
              "Authors": ["Rohit Kumar (Rohit_443)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-09-24",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                 {
                    "Title": "Microsoft Windows Shift F10 Bypass and Autopilot privilge escalation",
                    "Link": "https://k4m1ll0.com/ShiftF10Bypass-and-privesc.html"
                 }
               ],
              "Authors": ["Matek Kamilló (@k4m1ll0)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-09-24",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                 {
                    "Title": "Complete take-over of Cisco Unified Communications Manager due consecutively misconfigurations",
                    "Link": "https://infosecwriteups.com/complete-take-over-of-cisco-unified-communications-manager-due-consecutively-misconfigurations-2a1b5ce8bd9a"
                 }
               ],
              "Authors": ["hackthebox"],
              "Programs": ["-"],
              "Bugs": ["Security misconfiguration", "VoIP hacking"],
              "Bounty": "-",
              "PublicationDate": "2022-09-24",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                 {
                    "Title": "CVE-2022-35256 - HTTP Request Smuggling in NodeJS",
                   "Link": "https://www.preludesecurity.com/blog/cve-2022-35256-http-request-smuggling-in-nodejs"
                }
               ],
              "Authors": ["VVX7 (@VV_X_7)"],
              "Programs": ["Node.js"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "-",
              "PublicationDate": "2022-09-23",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                {
                   "Title": "Pre-Auth Remote Code Execution - Web Page Test",
                   "Link": "https://thinkloveshare.com/hacking/preauth_remote_code_execution_web_page_test/"
                },
                {
                 "Title": "Alternative link",
                 "Link": "https://medium.com/manomano-tech/pre-auth-remote-code-execution-web-page-test-9937d78d2f41"
              }
              ],
              "Authors": ["Laluka (@TheLaluka)"],
              "Programs": ["CatchPoint"],
              "Bugs": ["RCE", "SSRF"],
              "Bounty": "300",
              "PublicationDate": "2022-09-23",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                {
                   "Title": "WAF bypasses via 0days",
                   "Link": "https://terjanq.medium.com/waf-bypasses-via-0days-d4ef1f212ec"
                }
               ],
              "Authors": ["Terjanq (@terjanq)"],
              "Programs": ["ModSecurity"],
              "Bugs": ["WAF bypass", "Content-type confusion", "Charset confusion"],
              "Bounty": "-",
              "PublicationDate": "2022-09-23",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                {
                   "Title": "Arbitrary File Corruption: End - to - End Encrypted Messaging Application",
                   "Link": "https://nmochea.medium.com/arbitrary-file-corruption-end-to-end-encrypted-messaging-application-674963dceef8"
                }
               ],
              "Authors": ["Neil Mark Ochea (@nmochea)"],
              "Programs": ["-"],
              "Bugs": ["Insecure intent", "Android"],
              "Bounty": "-",
              "PublicationDate": "2022-09-23",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                {
                   "Title": "My First Valid Bug “Bypass the Admin Panel”",
                   "Link": "https://medium.com/@digant_15/my-first-valid-bug-bypass-the-admin-panel-e859e72a1b7d"
                }
               ],
              "Authors": ["Digant Prajapati"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-09-23",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                {
                   "Title": "My First XSS",
                   "Link": "https://medium.com/@AvyuktSyrine/my-first-xss-d88ee864df82"
                }
               ],
              "Authors": ["Avyukt Syrine (@AvyuktSyrine)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-09-23",
              "AddedDate": "2022-09-26"
            },
            {
               "Links": [
                 {
                    "Title": "Opera Browser VPN Bypass",
                    "Link": "https://medium.com/@renwa/opera-browser-vpn-bypass-20877aaf08c0"
                 }
                ],
               "Authors": ["Renwa (@RenwaX23)"],
               "Programs": ["Opera"],
               "Bugs": ["Privacy issue", "Logic flaw"],
               "Bounty": "1,000",
               "PublicationDate": "2022-09-22",
               "AddedDate": "2024-02-06"
             },
            {
               "Links": [
                 {
                    "Title": "Exploiting Distroless Images",
                    "Link": "https://www.form3.tech/engineering/content/exploiting-distroless-images"
                 }
                ],
               "Authors": ["Daniel Teixeira (@TheRedOperator)"],
               "Programs": ["Google"],
               "Bugs": ["Command injection", "Arbitrary file read", "Arbitrary file write", "Container escape"],
               "Bounty": "-",
               "PublicationDate": "2022-09-22",
               "AddedDate": "2023-01-18"
             },
            {
              "Links": [
                {
                   "Title": "Skype for Business Audit Part 1 - SKYPErsistence",
                   "Link": "https://frycos.github.io/vulns4free/2022/09/22/skype-audit-part1.html"
                }
               ],
              "Authors": ["Florian Hauser (@frycos)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation", "Windows", "Security code review"],
              "Bounty": "-",
              "PublicationDate": "2022-09-22",
              "AddedDate": "2022-10-02"
            },
            {
              "Links": [
                {
                   "Title": "Making HTTP header injection critical via response queue poisoning",
                   "Link": "https://portswigger.net/research/making-http-header-injection-critical-via-response-queue-poisoning"
                }
               ],
              "Authors": ["James Kettle (@albinowax)"],
              "Programs": ["-"],
              "Bugs": ["HTTP header injection", "HTTP request smuggling"],
              "Bounty": "12,500",
              "PublicationDate": "2022-09-22",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "How I Found Multiple SQL Injections in 5 Minutes in Bug Bounty",
                   "Link": "https://infosecwriteups.com/how-i-found-multiple-sql-injections-in-5-minutes-in-bug-bounty-40155964c498"
                }
               ],
              "Authors": ["Omar Hashem (@OmarHashem666)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-09-22",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                {
                   "Title": "Tarfile: Exploiting the World With a 15-Year-Old Vulnerability",
                   "Link": "https://www.trellix.com/en-us/about/newsroom/stories/research/tarfile-exploiting-the-world.html"
                }
               ],
              "Authors": ["Kasimir Schulz (@Abraxus7331)"],
              "Programs": ["Python"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-09-21",
              "AddedDate": "2023-01-31"
            },
            {
              "Links": [
                {
                   "Title": "One takeover to rule them all",
                   "Link": "https://10degres.net/one-takeover-to-rule-them-all/"
                }
               ],
              "Authors": ["Gwendal Le Coguic (@gwendallecoguic)"],
              "Programs": ["EDF"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-09-21",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                {
                   "Title": "Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library",
                   "Link": "https://samcurry.net/universal-xss-on-netlifys-next-js-library/"
                }
               ],
              "Authors": ["Sam Curry (@samwcyo)"],
              "Programs": ["Netlify", "Gemini", "PancakeSwap", "Docusign", "Moonpay", "Celo"],
              "Bugs": ["Universal XSS", "SSRF", "Open redirect", "Web cache poisoning"],
              "Bounty": "-",
              "PublicationDate": "2022-09-21",
              "AddedDate": "2022-09-22"
            },
           {
              "Links": [
                {
                   "Title": "Tarfile: Exploiting the World With a 15-Year-Old Vulnerability",
                   "Link": "https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/tarfile-exploiting-the-world.html"
                }
               ],
              "Authors": ["Kasimir Schulz (@Abraxus7331)"],
              "Programs": ["Python"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-09-21",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "TypeORM Prototype Pollution Leading To SQL Injection (CVE-2022-36531)",
                   "Link": "https://doyensec.com/resources/Doyensec_Advisory_TypeORM_Q32022.pdf"
                }
               ],
              "Authors": ["Norbert Szetei (@73696e65)", "Viktor Chuchurski (@viktorot)"],
              "Programs": ["TypeORM"],
              "Bugs": ["DoS", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-09-21",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "Mass Assignment Leading to Pre Account Takeover",
                   "Link": "https://medium.com/@cyberali/mass-assignment-leading-to-pre-account-takeover-13041280a0d9"
                }
               ],
              "Authors": ["Cyberali"],
              "Programs": ["-"],
              "Bugs": ["Mass assignment"],
              "Bounty": "1,300",
              "PublicationDate": "2022-09-21",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "Parameters in Lambda Functions that lead to XSS and Injection",
                   "Link": "https://medium.com/cloud-security/parameters-in-lambda-functions-that-lead-to-xss-and-injection-1bc8e14fca6f"
                }
               ],
              "Authors": ["Teri Radichel (@TeriRadichel)"],
              "Programs": ["AWS"],
              "Bugs": ["XSS", "Serverless"],
              "Bounty": "-",
              "PublicationDate": "2022-09-20",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "How we Abused Repository Webhooks to Access Internal CI Systems at Scale",
                   "Link": "https://www.cidersecurity.io/blog/research/how-we-abused-repository-webhooks-to-access-internal-ci-systems-at-scale/"
                }
               ],
              "Authors": ["Omer Gil (@omer_gil)", "Asi Greenholts (@TupleType)"],
              "Programs": ["-"],
              "Bugs": ["CI/CD"],
              "Bounty": "-",
              "PublicationDate": "2022-09-20",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "Securing Developer Tools: OneDev Remote Code Execution",
                   "Link": "https://blog.sonarsource.com/onedev-remote-code-execution/"
                }
               ],
              "Authors": ["Paul Gerste"],
              "Programs": ["OneDev"],
              "Bugs": ["RCE", "SSRF", "Broken Access Control", "Container escape"],
              "Bounty": "-",
              "PublicationDate": "2022-09-20",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "Apollo Router Security Audit Report (Q2 2022)",
                   "Link": "https://doyensec.com/resources/Doyensec_Apollo_Report_Q22022_v4_AfterRetest.pdf"
                }
               ],
              "Authors": ["Norbert Szetei (@73696e65)", "Mykhailo Baraniak"],
              "Programs": ["Apollo GraphQL"],
              "Bugs": ["DoS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-09-20",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes",
                   "Link": "https://www.wiz.io/blog/attachme-oracle-cloud-vulnerability-allows-unauthorized-cross-tenant-volume-access"
                }
               ],
              "Authors": ["Elad Gabay (@eladgabay_)"],
              "Programs": ["Oracle"],
              "Bugs": ["Cloud", "Cross-tenant vulnerability", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-09-20",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "7,500$ – IDOR on Apple [consultants.apple.com]",
                   "Link": "https://apapedulimu.click/idor-on-apple/"
                }
               ],
              "Authors": ["apapedulimu / Nosa Shandy (@LocalHost31337)"],
              "Programs": ["Apple"],
              "Bugs": ["IDOR"],
              "Bounty": "7,500",
              "PublicationDate": "2022-09-20",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "Tag Myself in Your Favorite TikTok Artist Video [IDOR]",
                   "Link": "https://apapedulimu.click/tag-myself-in-your-favorite-tiktok-artist-video-idor/"
                }
               ],
              "Authors": ["apapedulimu / Nosa Shandy (@LocalHost31337)"],
              "Programs": ["TikTok"],
              "Bugs": ["IDOR"],
              "Bounty": "3,000",
              "PublicationDate": "2022-09-20",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "Privilege Escalation Leads to making authenticated actions (payment processing, creating invoices.. etc)",
                   "Link": "https://x-vector.medium.com/privilege-escalation-leads-to-making-authenticated-actions-payment-processing-creating-invoices-2cf808d517ed"
                }
               ],
              "Authors": ["X-Vector (@XVector11)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-09-20",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "Exploiting a Seagate service to create a SYSTEM shell (CVE-2022-40286)",
                   "Link": "https://www.x86matthew.com/view_post?id=windows_seagate_lpe"
                }
               ],
              "Authors": ["x86matthew (@x86matthew)"],
              "Programs": ["Seagate"],
              "Bugs": ["Local Privilege Escalation", "Windows", "Driver hacking"],
              "Bounty": "-",
              "PublicationDate": "2022-09-20",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "SSD Advisory – Linux CLOCK_THREAD_CPUTIME_ID LPE",
                   "Link": "https://ssd-disclosure.com/ssd-advisory-linux-clock_thread_cputime_id-lpe/"
                }
               ],
              "Authors": ["-"],
              "Programs": ["Linux Kernel Organization"],
              "Bugs": ["Memory corruption", "Race condition", "Kernel hacking"],
              "Bounty": "-",
              "PublicationDate": "2022-09-20",
              "AddedDate": "2022-09-22"
            },
            {
              "Links": [
                {
                   "Title": "How to hack Github Actions",
                   "Link": "https://github.com/StackOverflowExcept1on/how-to-hack-github-actions"
                }
               ],
              "Authors": ["StackOverflowExcept1on"],
              "Programs": ["GitHub"],
              "Bugs": ["CI/CD"],
              "Bounty": "500",
              "PublicationDate": "2022-09-19",
              "AddedDate": "2022-09-26"
            },
            {
              "Links": [
                {
                   "Title": "Android Application Forgot Password Token Leakage Leading to Account Takeover",
                   "Link": "https://medium.com/@cyberali/android-application-forgot-password-token-leakage-leading-to-account-takeover-8a0b28296531"
                }
               ],
              "Authors": ["Cyberali"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Password reset", "Account takeover", "Android"],
              "Bounty": "-",
              "PublicationDate": "2022-09-19",
              "AddedDate": "2022-09-15"
            },
            {
              "Links": [
                {
                   "Title": "Turning Your Computer Into a GPS Tracker With Apple Maps",
                   "Link": "https://breakpoint.sh/posts/turning-your-computer-into-a-gps-tracker-with-apple-maps"
                }
               ],
              "Authors": ["Ron Masas (@RonMasas)"],
              "Programs": ["Apple"],
              "Bugs": ["Privacy issue", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-09-18",
              "AddedDate": "2022-09-19"
            },
           {
              "Links": [
                {
                   "Title": "Bug Bounty { How I found an Sensitive Information Disclosure( Reconnaissance ) }",
                   "Link": "https://srahulceh.medium.com/bug-bounty-how-i-found-an-sensitive-information-disclosure-reconnaissance-542daf10dd19"
                }
               ],
              "Authors": ["S Rahul (@7srambo)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-09-18",
              "AddedDate": "2022-09-19"
            },
           {
              "Links": [
                {
                   "Title": "SSRF Attack Leading To AWS Metadata",
                   "Link": "https://medium.com/@Parag_Bagul/ssrf-attack-leading-to-aws-metadata-e95155fa6c6f"
                }
               ],
              "Authors": ["ParagBagul"],
              "Programs": ["CERT-EU"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-09-18",
              "AddedDate": "2022-09-19"
            },
            {
              "Links": [
                {
                   "Title": "How i Found Unauthorized Bypass RCE",
                   "Link": "https://medium.com/@yashshirke7806/how-i-found-unauthorized-bypass-rce-3591a86425a9"
                }
               ],
              "Authors": ["Yashshirke"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Old components with known vulnerabilities"],
              "Bounty": "-",
              "PublicationDate": "2022-09-18",
              "AddedDate": "2022-09-20"
            },
            {
              "Links": [
                {
                   "Title": "How an Akamai misconfiguration earned us USD 46.000",
                   "Link": "https://blog.hacktivesecurity.com/index.php/2022/09/17/http/"
                }
               ],
              "Authors": ["Francesco Mariani (@_medusa_1_)", "Jacopo Tediosi (@jacopotediosi)"],
              "Programs": ["Akamai", "Microsoft", "Apple"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "46,000",
              "PublicationDate": "2022-09-17",
              "AddedDate": "2022-09-20"
            },
            {
            "Links": [
              {
                 "Title": "How i made the multiple hall of fame in Nokia within 2 minutes",
                 "Link": "https://systemweakness.com/how-i-made-the-multiple-hall-of-fame-in-nokia-within-2-minutes-535056fcb66d"
              }
             ],
            "Authors": ["Vedavyasan"],
            "Programs": ["Nokia"],
            "Bugs": ["Clickjacking"],
            "Bounty": "-",
            "PublicationDate": "2022-09-17",
            "AddedDate": "2022-09-17"
          },
          {
           "Links": [
             {
                "Title": "Cloning internal Google repos for fun and… info?",
                "Link": "https://medium.com/@lukeberner/cloning-internal-google-repos-for-fun-and-info-bf2c83d0ae00"
             }
            ],
           "Authors": ["Luke Berner"],
           "Programs": ["Google"],
           "Bugs": ["Broken authorization"],
           "Bounty": "-",
           "PublicationDate": "2022-09-16",
           "AddedDate": "2022-09-19"
         },
          {
            "Links": [
              {
                 "Title": "Getting Paid With Just Picking Color — Bug Bounty",
                 "Link": "https://medium.com/@rdzsp/getting-paid-with-just-picking-color-bug-bounty-d3dbbac277fa"
              }
             ],
            "Authors": ["Redza"],
            "Programs": ["-"],
            "Bugs": ["CSS injection"],
            "Bounty": "-",
            "PublicationDate": "2022-09-16",
            "AddedDate": "2022-09-17"
          },
          {
            "Links": [
              {
                 "Title": "Abusing Broken Link In Fitbit (Google Acquisition)To Collect BugBounty Reports On Behalf Of Google !",
                 "Link": "https://infosecwriteups.com/abusing-broken-link-in-fitbit-google-acquisition-to-collect-bugbounty-reports-on-behalf-of-google-5885a556eb7c"
              }
             ],
            "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
            "Programs": ["Google"],
            "Bugs": ["Broken link hijacking"],
            "Bounty": "-",
            "PublicationDate": "2022-09-16",
            "AddedDate": "2022-09-17"
          },
          {
            "Links": [
              {
                 "Title": "The Tale Of SSRF To RCE on .GOV Domain",
                 "Link": "https://medium.com/@tobydavenn/the-tale-of-ssrf-to-rce-on-gov-domain-191185b32b37"
              }
             ],
            "Authors": ["Tobydavenn"],
            "Programs": ["-"],
            "Bugs": ["SSRF", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2022-09-16",
            "AddedDate": "2022-09-17"
          },
          {
            "Links": [
              {
                 "Title": "HTTP Desync Attack (Request Smuggling) - Mass Account Takeover at a Cryptocurrency based asset and 121 other websites",
                 "Link": "https://github.com/AnkitCuriosity/Write-Ups/blob/main/HTTP%20Desync%20Attack%20(Request%20Smuggling).md"
              }
             ],
            "Authors": ["Ankit Singh (@AnkitCuriosity)"],
            "Programs": ["-"],
            "Bugs": ["HTTP request smuggling", "Desync attack"],
            "Bounty": "4,300",
            "PublicationDate": "2022-09-14",
            "AddedDate": "2022-12-12"
          },
          {
           "Links": [
             {
                "Title": "Breaking Bitbucket: Pre Auth Remote Command Execution (CVE-2022-36804)",
                "Link": "https://blog.assetnote.io/2022/09/14/rce-in-bitbucket-server/"
             }
            ],
           "Authors": ["Maxwell Garrett (@TheGrandPew)"],
           "Programs": ["Atlassian"],
           "Bugs": ["RCE", "OS command injection"],
           "Bounty": "-",
           "PublicationDate": "2022-09-14",
           "AddedDate": "2022-09-15"
         },
          {
            "Links": [
              {
                 "Title": "Security Advisory: NETGEAR Routers FunJSQ Vulnerabilities",
                 "Link": "https://onekey.com/blog/security-advisory-netgear-routers-funjsq-vulnerabilities/"
              }
             ],
            "Authors": ["Quentin Kaiser (@QKaiser)", "Mücahid Kır (@muc0ze)"],
            "Programs": ["Netgear"],
            "Bugs": ["OS command injection", "RCE", "MiTM"],
            "Bounty": "-",
            "PublicationDate": "2022-09-14",
            "AddedDate": "2022-09-15"
          },
          {
            "Links": [
              {
                 "Title": "How I abused the file upload function to get a high severity vulnerability in Bug Bounty",
                 "Link": "https://infosecwriteups.com/how-i-abused-the-file-upload-function-to-get-a-high-severity-vulnerability-in-bug-bounty-7cdcf349080b"
              }
             ],
            "Authors": ["Omar Hashem (@OmarHashem666)"],
            "Programs": ["-"],
            "Bugs": ["Unrestricted file upload", "Information disclosure"],
            "Bounty": "-",
            "PublicationDate": "2022-09-14",
            "AddedDate": "2022-09-15"
          },
          {
            "Links": [
              {
                 "Title": "Pwn2Own Miami 2022: Unified Automation C++ Demo Server DoS",
                 "Link": "https://sector7.computest.nl/post/2022-09-unified-automation-opcua-cpp/"
              }
             ],
            "Authors": ["Sector 7 (@sector7_nl)"],
            "Programs": ["Unified Automation"],
            "Bugs": ["DoS"],
            "Bounty": "5,000",
            "PublicationDate": "2022-09-14",
            "AddedDate": "2022-09-15"
          },
          {
            "Links": [
              {
                 "Title": "Attacking the Android kernel using the Qualcomm TrustZone",
                 "Link": "https://tamirzb.com/attacking-android-kernel-using-qualcomm-trustzone"
              }
             ],
            "Authors": ["Tamir Zahavi-Brunner (@tamir_zb)"],
            "Programs": ["Qalcomm", "Google"],
            "Bugs": ["Memory corruption"],
            "Bounty": "-",
            "PublicationDate": "2022-09-14",
            "AddedDate": "2022-09-15"
          },
          {
           "Links": [
             {
                "Title": "mast1c0re: Hacking the PS4 / PS5 through the PS2 Emulator - Part 1 - Escape",
                "Link": "https://cturt.github.io/mast1c0re.html"
             }
            ],
           "Authors": ["CTurt (@CTurtE)"],
           "Programs": ["PlayStation"],
           "Bugs": ["Memory corruption"],
           "Bounty": "-",
           "PublicationDate": "2022-09-26",
           "AddedDate": "2022-09-15"
         },
         {
           "Links": [
             {
                "Title": "Colorful Vulnerabilities",
                "Link": "https://www.cyberark.com/resources/threat-research-blog/colorful-vulnerabilities"
             }
            ],
           "Authors": ["Tal Lossos (@TalLossos)"],
           "Programs": ["OpenRazer"],
           "Bugs": ["Memory corruption", "Buffer Overflow"],
           "Bounty": "-",
           "PublicationDate": "2022-09-14",
           "AddedDate": "2022-09-26"
         },
         {
           "Links": [
             {
                "Title": "Data Exfiltration through Blind XXE on PDF Generator",
                "Link": "https://arben.sh/bugbounty/Blind-XXE-CVE-2019-12154/"
             }
            ],
           "Authors": ["Arben Shala (@arbennsh)"],
           "Programs": ["-"],
           "Bugs": ["Blind XXE", "WAF bypass"],
           "Bounty": "-",
           "PublicationDate": "2022-09-13",
           "AddedDate": "2022-09-26"
         },
          {
           "Links": [
             {
                "Title": "Blind XSS and Time-Based SQL Injection to Admin Panel Control and Database Takeover",
                "Link": "https://medium.com/@cyberali/blind-xss-and-time-based-sql-injection-to-admin-panel-control-and-database-takeover-9b7645a53748"
             }
            ],
           "Authors": ["Cyberali"],
           "Programs": ["-"],
           "Bugs": ["Blind XSS", "SQL injection"],
           "Bounty": "-",
           "PublicationDate": "2022-09-13",
           "AddedDate": "2022-09-15"
         },
          {
            "Links": [
              {
                 "Title": "Hacking Unity Games with Malicious GameObjects",
                 "Link": "https://blog.includesecurity.com/2021/06/hacking-unity-games-malicious-unity-game-objects/"
              },
              {
                "Title": "Hacking Unity Games with Malicious GameObjects, Part 2",
                "Link": "https://blog.includesecurity.com/2022/09/hacking-unity-games-with-malicious-gameobjects-part-2/"
             }
             ],
            "Authors": ["Jason Kielpinski (@f2jason)"],
            "Programs": ["Unity"],
            "Bugs": ["Arbitrary code execution", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2022-09-13",
            "AddedDate": "2022-09-15"
          },
          {
           "Links": [
             {
                "Title": "Undermining Microsoft Teams Security by Mining Tokens",
                "Link": "https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens"
             }
            ],
           "Authors": ["Vectra Protect team (@Vectra_AI)"],
           "Programs": ["Microsoft"],
           "Bugs": ["Insecure storage of sensitive information"],
           "Bounty": "-",
           "PublicationDate": "2022-09-13",
           "AddedDate": "2022-09-20"
         },
        {
         "Links": [
           {
              "Title": "LiveHelperChat - Remote Code Execution via Vulnerable Theme Upload Function",
              "Link": "https://arben.sh/research/LiveHelperChat-RCE/"
           }
          ],
         "Authors": ["Arben Shala (@arbennsh)"],
         "Programs": ["Live Helper Chat"],
         "Bugs": ["RCE"],
         "Bounty": "-",
         "PublicationDate": "2022-09-13",
         "AddedDate": "2022-09-26"
        },
        {
         "Links": [
           {
              "Title": "How I DIDN’T get an RCE in a $200 Billion company — Bug Bounty",
              "Link": "https://medium.com/@nynan/how-i-didnt-get-an-rce-in-a-200-billion-company-bug-bounty-377afb2fb4ec"
           }
          ],
         "Authors": ["nynan (@_nynan)"],
         "Programs": ["-"],
         "Bugs": ["RCE", "Components with known vulnerabilities"],
         "Bounty": "-",
         "PublicationDate": "2022-09-12",
         "AddedDate": "2022-11-30"
       },
       {
         "Links": [
           {
              "Title": "Bug Bounty - Cross-site request forgery is a thing",
              "Link": "https://hesec.de/posts/bbh-csrf/"
           }
          ],
         "Authors": ["Patrick Hener (@C1sc01)"],
         "Programs": ["-"],
         "Bugs": ["CSRF", "XSS"],
         "Bounty": "2,400",
         "PublicationDate": "2022-09-12",
         "AddedDate": "2022-11-30"
       },
       {
           "Links": [
             {
                "Title": "Contentful Access Token Disclosure in Android APK",
                "Link": "https://medium.com/@cyberali/contentful-access-token-disclosure-in-android-apk-ace5f7bdf98"
             }
            ],
           "Authors": ["Cyberali"],
           "Programs": ["-"],
           "Bugs": ["Information disclosure", "Android"],
           "Bounty": "-",
           "PublicationDate": "2022-09-12",
           "AddedDate": "2022-09-15"
         },
          {
            "Links": [
              {
                 "Title": "SSRF(g/vrp) for 5000$",
                 "Link": "https://0x01alka.medium.com/ssrf-g-vrp-for-5000-d08c8f515c95"
              }
             ],
            "Authors": ["lalka (@0x01alka)"],
            "Programs": ["-"],
            "Bugs": ["SSRF"],
            "Bounty": "5,000",
            "PublicationDate": "2022-09-12",
            "AddedDate": "2022-09-15"
          },
          {
            "Links": [
              {
                 "Title": "Privacy Violation In Chat System",
                 "Link": "https://rashahacks.com/privacy-violation-in-chat-system/"
              }
             ],
            "Authors": ["Inderjeet Singh - rashahacks"],
            "Programs": ["-"],
            "Bugs": ["Privacy issue"],
            "Bounty": "-",
            "PublicationDate": "2022-09-12",
            "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "How I found 3 rare security bug in a day",
               "Link": "https://medium.com/@zer0d/how-i-found-3-bug-bounties-in-a-day-c82fe023716e"
            }
           ],
          "Authors": ["zer0d"],
          "Programs": ["-"],
          "Bugs": ["Session expiration issue", "Payment bypass", "Lack of rate limiting"],
          "Bounty": "-",
          "PublicationDate": "2022-09-10",
          "AddedDate": "2022-09-15"
         },
         {
           "Links": [
             {
                "Title": "How I was able to Bypass Philips Authentication",
                "Link": "https://medium.com/@Parag_Bagul/how-i-was-able-to-bypass-philips-authentication-c3bd3e1df9ff"
             }
            ],
           "Authors": ["ParagBagul"],
           "Programs": ["Philips"],
           "Bugs": ["Outdated component with a known vulnerability", "Authentication bypass"],
           "Bounty": "-",
           "PublicationDate": "2022-09-10",
           "AddedDate": "2022-09-19"
         },
         {
          "Links": [
            {
               "Title": "Attackers Can Bypass GitHub Required Reviewers to Submit Malicious Code",
               "Link": "https://www.legitsecurity.com/blog/bypassing-github-required-reviewers-to-submit-malicious-code"
            }
           ],
          "Authors": ["Noam Dotan"],
          "Programs": ["GitHub"],
          "Bugs": ["Broken authorization", "Logic flaw"],
          "Bounty": "-",
          "PublicationDate": "2022-09-08",
          "AddedDate": "2022-09-15"
         },
         {
           "Links": [
             {
                "Title": "Attacking Firecracker: AWS' microVM Monitor Written in Rust",
                "Link": "https://www.graplsecurity.com/post/attacking-firecracker"
             }
            ],
           "Authors": ["Valentina Palmiotti (@chompie1337)"],
           "Programs": ["Firecracker"],
           "Bugs": ["Memory corruption"],
           "Bounty": "-",
           "PublicationDate": "2020-09-08",
           "AddedDate": "2022-09-15"
          },
         {
          "Links": [
            {
               "Title": "Riding The Inforail To Exploit Ivanti Avalanche  Part 2",
               "Link": "https://www.zerodayinitiative.com/blog/2022/9/7/riding-the-inforail-to-exploit-ivanti-avalanche-part-2"
            }
           ],
           "Authors": ["Piotr Bazydło (@chudyPB)"],
           "Programs": ["Ivanti"],
           "Bugs": ["RCE", "Insecure deserialization", "Path traversal", "Authentication bypass", "Unrestricted file upload", "Arbitrary file write", "Arbitrary file read"],
           "Bounty": "-",
           "PublicationDate": "2021-09-08",
           "AddedDate": "2022-09-15"
          },
         {
          "Links": [
            {
               "Title": "Avalanche remote network crash",
               "Link": "https://gist.github.com/karalabe/4d10a879e361bb5b85302d57c193f532"
            }
           ],
           "Authors": ["Pter Szilgyi (@peter_szilagyi)"],
           "Programs": ["Ava Labs"],
           "Bugs": ["DoS"],
           "Bounty": "-",
           "PublicationDate": "2022-09-08",
           "AddedDate": "2022-09-15"
          },
         {
          "Links": [
            {
               "Title": "New technique 403 bypass lyncdiscover.microsoft.com",
               "Link": "https://medium.com/@abbasheybati1/403-bypass-lyncdiscover-microsoft-com-db2778458c33"
            }
           ],
           "Authors": ["Abbas Heybati (@abbas_heybati)"],
           "Programs": ["Microsoft"],
           "Bugs": ["403 bypass"],
           "Bounty": "-",
           "PublicationDate": "2022-09-08",
           "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "How I was able to see likes count even though is hidden by victim | YouTube",
               "Link": "https://bloggerrando.blogspot.com/2022/09/09-1.html"
            }
           ],
           "Authors": ["R ando (@Rando02355205)"],
           "Programs": ["Google"],
           "Bugs": ["Information disclosure", "Logic flaw"],
           "Bounty": "-",
           "PublicationDate": "2022-09-08",
           "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "Fun With CORS",
               "Link": "https://www.whiteoaksecurity.com/blog/fun-with-cors/"
            }
           ],
           "Authors": ["Talis Ozols"],
           "Programs": ["-"],
           "Bugs": ["CORS misconfiguration", "Token leak"],
           "Bounty": "-",
           "PublicationDate": "2022-09-08",
           "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "QUEST KACE Desktop Authority Pre-Auth Remote Code Execution (CVE-2021-44031)",
               "Link": "https://labs.jumpsec.com/quest-kace-desktop-authority-pre-auth-remote-code-execution-cve-2021-44031/"
            }
           ],
           "Authors": ["Tom Ellson (@tde_sec)"],
           "Programs": ["Quest"],
           "Bugs": ["RCE", "Path traversal"],
           "Bounty": "-",
           "PublicationDate": "2022-09-08",
           "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution",
               "Link": "https://sector7.computest.nl/post/2022-09-aveva-edge/"
            }
           ],
          "Authors": ["Daan Keuper (@daankeuper)", "Thijs Alkemade (@xnyhps)"],
          "Programs": ["AVEVA"],
          "Bugs": ["Arbitrary Code Execution", "Local Privilege Escalation"],
          "Bounty": "20,000",
          "PublicationDate": "2022-09-08",
          "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "Baxter SIGMA Spectrum Infusion Pumps: Multiple Vulnerabilities (FIXED)",
               "Link": "https://www.rapid7.com/blog/post/2022/09/08/baxter-sigma-spectrum-infusion-pumps-multiple-vulnerabilities-fixed/"
            }
           ],
          "Authors": ["Deral Heiland (@Percent_X)"],
          "Programs": ["Baxter Healthcare"],
          "Bugs": ["Hardcoded credentials", "Memory corruption", "MiTM", "Information disclosure"],
          "Bounty": "-",
          "PublicationDate": "2022-09-08",
          "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "Binarly Finds Six High Severity Firmware Vulnerabilities In HP Enterprise Devices",
               "Link": "https://www.binarly.io/posts/Binarly_Finds_Six_High_Severity_Firmware_Vulnerabilities_in_HP_Enterprise_Devices/index.html"
            }
           ],
          "Authors": ["Binarly efiXplorer Team"],
          "Programs": ["HP"],
          "Bugs": ["Memory corruption"],
          "Bounty": "-",
          "PublicationDate": "2022-09-08",
          "AddedDate": "2022-09-15"
      },
      {
           "Links": [
             {
                "Title": "Step-by-Step Walkthrough of CVE-2022-32792 - WebKit B3ReduceStrength Out-of-Bounds Write",
                "Link": "https://starlabs.sg/blog/2022/09-step-by-step-walkthrough-of-cve-2022-32792/"
             }
            ],
           "Authors": ["Daniel Lim (@daniellimws)", "Đỗ Minh Tuấn (@tuanit96)"],
           "Programs": ["Apple"],
           "Bugs": ["Memory corruption", "Browser hacking", "Out-of-bounds Write"],
           "Bounty": "-",
           "PublicationDate": "2022-09-08",
           "AddedDate": "2022-10-02"
      },
      {
           "Links": [
             {
                "Title": "Groovy Template Engine Exploitation – Notes from a real case scenario",
                "Link": "https://security.humanativaspa.it/groovy-template-engine-exploitation-notes-from-a-real-case-scenario/"
             }
            ],
           "Authors": ["Gianluca Baldi (@0x_nope)"],
           "Programs": ["-"],
           "Bugs": ["RCE", "Code injection"],
           "Bounty": "-",
           "PublicationDate": "2022-09-07",
           "AddedDate": "2022-09-20"
      },
      {
          "Links": [
            {
               "Title": "$900 Blind XSS",
               "Link": "https://shinchina.in/blog/2022-09-07/$900-blind-xss.html"
            }
           ],
          "Authors": ["ѕнín (@shinchina_)"],
          "Programs": ["-"],
          "Bugs": ["Blind XSS"],
          "Bounty": "900",
          "PublicationDate": "2022-09-07",
          "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "Exploiting Laravel based applications with leaked APP_KEYs and Queues",
               "Link": "https://mogwailabs.de/en/blog/2022/08/exploiting-laravel-based-applications-with-leaked-app_keys-and-queues/"
            }
           ],
          "Authors": ["Timo Müller (@mtimo44)"],
          "Programs": ["-"],
          "Bugs": ["RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-09-07",
          "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "How I found 3 RXSS on the Lululemon bug bounty program",
               "Link": "https://omar0x01.medium.com/how-i-found-3-rxss-on-the-lululemon-bug-bounty-program-fa357a0154c2"
            }
           ],
          "Authors": ["Omar Hashem (@OmarHashem666)"],
          "Programs": ["lululemon"],
          "Bugs": ["XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-09-07",
          "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "Groovy Template Engine Exploitation – Notes from a real case scenario",
               "Link": "https://security.humanativaspa.it/groovy-template-engine-exploitation-notes-from-a-real-case-scenario/"
            }
           ],
          "Authors": ["Gianluca Baldi (@0x_nope)"],
          "Programs": ["-"],
          "Bugs": ["RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-09-07",
          "AddedDate": "2022-09-15"
      },
      {
           "Links": [
             {
                "Title": "How I found Moodle Cross site scripting",
                "Link": "https://medium.com/@Parag_Bagul/how-i-found-moodle-cross-site-scripting-459a1c9ad4d5"
             }
            ],
           "Authors": ["ParagBagul"],
           "Programs": ["Moodle"],
           "Bugs": ["XSS"],
           "Bounty": "-",
           "PublicationDate": "2022-09-07",
           "AddedDate": "2022-09-19"
      },
      {
          "Links": [
            {
               "Title": "Zuckerpunch - Abusing Self Hosted Github Runners at Facebook",
               "Link": "https://marcyoung.us/post/zuckerpunch/"
            }
           ],
          "Authors": ["Marcus Young"],
          "Programs": ["Meta / Facebook"],
          "Bugs": ["CI/CD"],
          "Bounty": "10,000",
          "PublicationDate": "2022-09-06",
          "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "IDOR leads to removing members from any Google Chat Space.",
               "Link": "https://hopesamples.blogspot.com/2022/09/idor-leads-to-removing-members-from-any.html"
            }
           ],
          "Authors": ["Vivek M"],
          "Programs": ["Google"],
          "Bugs": ["IDOR"],
          "Bounty": "3,133.70",
          "PublicationDate": "2022-09-06",
          "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "Group expert's pending expertise request leaking on Facebook",
               "Link": "https://hopesamples.blogspot.com/2022/09/group-experts-pending-expertise-request.html"
            }
           ],
          "Authors": ["Vivek M"],
          "Programs": ["Meta / Facebook"],
          "Bugs": ["IDOR"],
          "Bounty": "-",
          "PublicationDate": "2022-09-06",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Details about future collaboration profiles and pages have been revealed",
               "Link": "https://hopesamples.blogspot.com/2022/09/details-about-future-collaboration.html"
            }
           ],
          "Authors": ["Vivek M"],
          "Programs": ["Meta / Facebook"],
          "Bugs": ["IDOR"],
          "Bounty": "-",
          "PublicationDate": "2022-09-06",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Quasar: Compromising Electron Apps",
               "Link": "https://taggart-tech.com/quasar-electron/"
            }
           ],
          "Authors": ["Taggart (@mttaggart)"],
          "Programs": ["Microsoft"],
          "Bugs": ["Local Privilege Escalation"],
          "Bounty": "-",
          "PublicationDate": "2022-09-06",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "How to turn security research into profit: a CL.0 case study",
               "Link": "https://portswigger.net/research/how-to-turn-security-research-into-profit"
            }
           ],
          "Authors": ["James Kettle (@albinowax)"],
          "Programs": ["-"],
          "Bugs": ["HTTP request smuggling", "Desync attack"],
          "Bounty": "-",
          "PublicationDate": "2022-09-08",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Exploiting Out-of-Band XXE in the Wild",
               "Link": "https://0xmahmoudjo0.medium.com/exploiting-out-of-band-xxe-in-the-wild-16fc6dad9ee2"
            }
           ],
          "Authors": ["Mahmoud Youssef (@0xmahmoudjo0)"],
          "Programs": ["-"],
          "Bugs": ["XXE", "SSRF"],
          "Bounty": "-",
          "PublicationDate": "2022-09-06",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "WordPress Core - Unauthenticated Blind SSRF",
               "Link": "https://blog.sonarsource.com/wordpress-core-unauthenticated-blind-ssrf/"
            }
           ],
          "Authors": ["Simon Scannell (@scannell_simon)", "Thomas Chauchefoin (@swapgs)"],
          "Programs": ["WordPress"],
          "Bugs": ["SSRF"],
          "Bounty": "-",
          "PublicationDate": "2022-09-06",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
              "Title": "Turning cookie based XSS into account takeover",
              "Link": "https://bergee.it/blog/turning-cookie-based-xss-into-account-takeover/"
           }
           ],
          "Authors": ["Bartłomiej Bergier (@_bergee_)"],
          "Programs": ["Terrahost"],
          "Bugs": ["XSS", "Account takeover"],
          "Bounty": "500",
          "PublicationDate": "2022-09-06",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "CVE-2022-35405 Manage engines RCE (Password Manager Pro, PAM360 and Access Manager Plus)",
               "Link": "https://www.bigous.me/2022/09/06/CVE-2022-35405.html"
            }
           ],
          "Authors": ["Vinicius Pereira (@big0x75)"],
          "Programs": ["Zoho"],
          "Bugs": ["RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-09-08",
          "AddedDate": "2022-09-15"
         },
         {
           "Links": [
             {
                "Title": "Bug Bounty { How I found an SSRF ( Reconnaissance ) }",
                "Link": "https://srahulceh.medium.com/bug-bounty-how-i-found-an-ssrf-reconnaissance-7b1821a1b1fd"
             }
            ],
           "Authors": ["S Rahul (@7srambo)"],
           "Programs": ["-"],
           "Bugs": ["SSRF"],
           "Bounty": "-",
           "PublicationDate": "2022-09-06",
           "AddedDate": "2022-09-15"
          },
          {
           "Links": [
             {
                "Title": "CVE-2022-34715: More Microsoft Windows NFS V4 Remote Code Execution",
                "Link": "https://www.zerodayinitiative.com/blog/2022/8/31/cve-2022-34715-more-microsoft-windows-nfs-v4-remote-code-execution"
             }
            ],
           "Authors": ["Quintin Crist", "Dusan Stevanovic", "Arimura"],
           "Programs": ["Microsoft"],
           "Bugs": ["RCE", "Memory corruption"],
           "Bounty": "-",
           "PublicationDate": "2022-09-06",
           "AddedDate": "2022-09-15"
          },
          {
            "Links": [
              {
                 "Title": "How to Decrypt Manage Engine PMP Passwords for Fun and Domain Admin - a Red Teaming Tale",
                 "Link": "https://www.shielder.com/blog/2022/09/how-to-decrypt-manage-engine-pmp-passwords-for-fun-and-domain-admin-a-red-teaming-tale/"
              }
             ],
            "Authors": ["smaury (@smaury92)", "TheZero (@Th3Zer0)"],
            "Programs": ["Zoho (ManageEngine)"],
            "Bugs": ["Cryptographic issues"],
            "Bounty": "-",
            "PublicationDate": "2022-09-05",
            "AddedDate": "2022-10-21"
         },
          {
           "Links": [
             {
                "Title": "IDOR “Insecure direct object references”, my first P1 in Bugbounty",
                "Link": "https://medium.com/@jedus0r/idor-insecure-direct-object-references-my-first-p1-in-bugbounty-fb01f50e25df"
             }
            ],
           "Authors": ["jedus0r"],
           "Programs": ["-"],
           "Bugs": ["IDOR"],
           "Bounty": "-",
           "PublicationDate": "2022-09-05",
           "AddedDate": "2022-09-15"
          },
          {
           "Links": [
             {
                "Title": "A Bug That Was 23 Years Old Or Not",
                "Link": "https://daniel.haxx.se/blog/2022/09/05/a-bug-that-was-23-years-old-or-not/"
             }
            ],
           "Authors": ["Daniel Stenberg (@bagder)"],
           "Programs": ["Internet Bug Bounty (curl)"],
           "Bugs": ["DoS"],
           "Bounty": "-",
           "PublicationDate": "2022-09-05",
           "AddedDate": "2022-09-15"
          },
         {
          "Links": [
            {
               "Title": "Hacking My Helium Crypto Miner",
               "Link": "https://zolder.io/hacking-my-helium-crypto-miner/"
            }
           ],
          "Authors": ["Md. Asif Hossain (@0x0asif)"],
          "Programs": ["Pycom"],
          "Bugs": ["Hardcoded credentials", "Missing authentication", "RCE", "Local Privilege Escalation"],
          "Bounty": "-",
          "PublicationDate": "2022-09-05",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "SSD Advisory – Linux CONFIG_WATCH_QUEUE LPE",
               "Link": "https://ssd-disclosure.com/ssd-advisory-linux-config_watch_queue-lpe/"
            }
           ],
          "Authors": ["-"],
          "Programs": ["Ubuntu", "Linux Kernel Organization"],
          "Bugs": ["Memory corruption", "Race condition", "Local Privilege Escalation"],
          "Bounty": "-",
          "PublicationDate": "2022-09-05",
          "AddedDate": "2022-09-15"
         },
         {
           "Links": [
             {
                "Title": "Simple IBM I (AS/400) Hacking",
                "Link": "https://blog.silentsignal.eu/2022/09/05/simple-ibm-i-as-400-hacking/"
             }
            ],
           "Authors": ["pz"],
           "Programs": ["-"],
           "Bugs": ["Local Privilege Escalation", "Midrange system", "Menu security"],
           "Bounty": "-",
           "PublicationDate": "2022-09-05",
           "AddedDate": "2022-09-29"
         },
         {
           "Links": [
             {
                "Title": "Your Amiibo’s Haunted",
                "Link": "https://vvx7.io/posts/2022/09/your-amiibos-haunted/"
             }
            ],
            "Authors": ["VVX7 (@VV_X_7)"],
           "Programs": ["Flipper Zero"],
           "Bugs": ["Memory corruption", "Buffer Overflow", "DoS"],
           "Bounty": "-",
           "PublicationDate": "2022-09-05",
           "AddedDate": "2022-11-21"
         },
         {
          "Links": [
            {
               "Title": "How I found my first SSRF to RCE!",
               "Link": "https://medium.com/@0x0Asif/how-i-found-my-first-rce-8f8033883dc4"
            }
           ],
          "Authors": ["Md. Asif Hossain (@0x0asif)"],
          "Programs": ["-"],
          "Bugs": ["IDOR", "SSRF", "RCE"],
          "Bounty": "3,200",
          "PublicationDate": "2022-09-04",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Discovery of CVE-2022-35406",
               "Link": "https://medium.com/@mr.vrushabh/discovery-of-cve-2022-35406-303f4bca2742"
            }
           ],
          "Authors": ["Mr. Vrushabh (@doshi_vrushabh)"],
          "Programs": ["PortSwigger"],
          "Bugs": ["Logic flaw", "Referer leakage"],
          "Bounty": "150",
          "PublicationDate": "2022-09-03",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)",
               "Link": "https://nokline.github.io/bugbounty/2022/09/02/Glassdoor-Cache-Poisoning.html"
            },
            {
              "Title": "HackerOne report",
              "Link": "https://hackerone.com/reports/1621540"
            }
           ],
          "Authors": ["Harel (@h4r3l)"],
          "Programs": ["Glassdoor"],
          "Bugs": ["Web cache poisoning", "XSS", "DoS"],
          "Bounty": "1,700",
          "PublicationDate": "2022-09-02",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Viewing Instagram live streams anonymously without notifying the host",
               "Link": "https://feed.bugs.xdavidhu.me/bugs/0015"
            }
           ],
          "Authors": ["David Schütz (@xdavidhu)"],
          "Programs": ["Meta / Facebook"],
          "Bugs": ["IDOR", "Logic flaw", "Privacy issue"],
          "Bounty": "-",
          "PublicationDate": "2022-09-02",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "The Database Handover | A Dumb Mistake | Critical BUG",
               "Link": "https://mr23r0.medium.com/the-database-handover-a-dumb-mistake-critical-bug-f73c99e72e40"
            }
           ],
          "Authors": ["Saransh Saraf (@mr23r0)"],
          "Programs": ["-"],
          "Bugs": ["Information disclosure"],
          "Bounty": "1,000",
          "PublicationDate": "2022-09-02",
          "AddedDate": "2022-09-15"
         },
         {
           "Links": [
             {
                "Title": "How can i get SQL Injection",
                "Link": "https://xthemo.medium.com/how-can-i-get-sql-injection-b8337c2c2bef"
             }
            ],
           "Authors": ["Mohamed Abdelhady"],
           "Programs": ["-"],
           "Bugs": ["SQL injection"],
           "Bounty": "-",
           "PublicationDate": "2022-09-02",
           "AddedDate": "2022-09-26"
          },
         {
          "Links": [
            {
               "Title": "Google & Apache Found Vulnerable to GitHub Environment Injection",
               "Link": "https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability-0"
            }
           ],
          "Authors": ["Noam Dotan"],
          "Programs": ["Google", "Apache"],
          "Bugs": ["Privilege escalation", "CI/CD"],
          "Bounty": "-",
          "PublicationDate": "2022-09-01",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "AngularJS Client-Side Template Injection: The orderBy Filter.",
               "Link": "https://medium.com/@xJay/angularjs-client-side-template-injection-the-orderby-filter-20002ca2a0e8"
            }
           ],
          "Authors": ["Jay"],
          "Programs": ["-"],
          "Bugs": ["CSTI"],
          "Bounty": "-",
          "PublicationDate": "2022-09-01",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Azure Synapse: Local Privilege Escalation Vulnerability in Spark",
               "Link": "https://orca.security/resources/blog/synapse-local-privilege-escalation-vulnerability-spark/"
            }
           ],
          "Authors": ["Tzah Pahima (@TzahPahima)"],
          "Programs": ["Microsoft"],
          "Bugs": ["Race condition", "Local Privilege Escalation","Cloud"],
          "Bounty": "-",
          "PublicationDate": "2022-09-01",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Using Hackability to uncover a Chrome infoleak",
               "Link": "https://portswigger.net/research/using-hackability-to-uncover-a-chrome-infoleak"
            }
           ],
          "Authors": ["Gareth Heyes (@garethheyes)"],
          "Programs": ["Google"],
          "Bugs": ["SOP bypass"],
          "Bounty": "2,000",
          "PublicationDate": "2022-09-01",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "How did we Found Log4shell on Agorapulse",
               "Link": "https://snapsec.co/blog/Log4shell-on-agorapulse/"
            }
           ],
          "Authors": ["Snap Sec (@snap_sec)"],
          "Programs": ["Agorapulse"],
          "Bugs": ["Log4shell", "RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-09-01",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250)",
               "Link": "https://research.nccgroup.com/2022/09/01/settlers-of-netlink-exploiting-a-limited-uaf-in-nf_tables-cve-2022-32250/"
            }
           ],
          "Authors": ["Cedric Halbronn (@saidelike)", "Alex Plaskett (@alexjplaskett)", "fidgeting bits (@FidgetingBits)"],
          "Programs": ["Ubuntu", "Linux Kernel Organization"],
          "Bugs": ["Memory corruption", "Local Privilege Escalation"],
          "Bounty": "-",
          "PublicationDate": "2022-09-01",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Abusing Microsoft Teams Direct Routing",
               "Link": "https://blog.syss.com/posts/abusing-ms-teams-direct-routing/"
            }
           ],
          "Authors": ["Moritz Abrell (@moritz_abrell)"],
          "Programs": ["AudioCodes Ltd."],
          "Bugs": ["Spoofing", "Fraud attack"],
          "Bounty": "-",
          "PublicationDate": "2022-09-01",
          "AddedDate": "2022-09-15"
         },
         {
           "Links": [
             {
                "Title": "How reading robots.txt file got me 4 XSS reports ?",
                "Link": "https://c0nqr0r.medium.com/reading-robots-txt-got-me-4-xss-reports-9fd2234c635f"
             }
            ],
           "Authors": ["Ahmed Qaramany (@c0nqr0r)"],
           "Programs": ["-"],
           "Bugs": ["XSS"],
           "Bounty": "-",
           "PublicationDate": "2022-08-31",
           "AddedDate": "2022-10-06"
         },
         {
          "Links": [
            {
               "Title": "Vulnerability in TikTok Android app could lead to one-click account hijacking",
               "Link": "https://www.microsoft.com/security/blog/2022/08/31/vulnerability-in-tiktok-android-app-could-lead-to-one-click-account-hijacking/"
            }
           ],
          "Authors": ["Microsoft 365 Defender Research Team"],
          "Programs": ["TikTok"],
          "Bugs": ["Insecure deeplink", "Android"],
          "Bounty": "-",
          "PublicationDate": "2022-08-31",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Saving more than 100,000 website from a Watering Hole attack",
               "Link": "https://med-mahmoudi26.medium.com/saving-more-than-100-000-website-from-a-watering-hole-attack-a22f63a37f94"
            }
           ],
          "Authors": ["mohamad mahmoudi (@Lotus_619)"],
          "Programs": ["HubSpot"],
          "Bugs": ["Web cache poisoning", "Watering hole attack"],
          "Bounty": "5,000",
          "PublicationDate": "2022-08-31",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "HTMLI/XSS - Crafting a better PoC",
               "Link": "https://blog.riotsecurityteam.com/xsshtmli-crafting-better-pocs"
            }
           ],
          "Authors": ["RiotSecurityTeam (@RiotSecTeam)"],
          "Programs": ["-"],
          "Bugs": ["XSS", "HTML injection"],
          "Bounty": "-",
          "PublicationDate": "2022-08-30",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "CVE-2022-26113: FortiClient Arbitrary File Write As SYSTEM",
               "Link": "https://rhinosecuritylabs.com/research/cve-2022-26113-forticlient-arbitrary-file-write-as-system/"
            }
           ],
          "Authors": ["David Yesland (@daveysec)"],
          "Programs": ["Fortinet"],
          "Bugs": ["Arbitrary file write", "Local Privilege Escalation"],
          "Bounty": "-",
          "PublicationDate": "2022-08-30",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "mfa bypass in private program, the abdulsec way",
               "Link": "https://abdulsec.medium.com/mfa-bypass-in-private-program-the-abdulsec-way-f677fea209f7"
            }
           ],
          "Authors": ["abdulsec (@moodiAbdoul)"],
          "Programs": ["-"],
          "Bugs": ["2FA / MFA bypass"],
          "Bounty": "600",
          "PublicationDate": "2022-08-30",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "IDOR at Login function leads to leak user’s PII data",
               "Link": "https://eslam3kl.medium.com/idor-at-login-function-leads-to-leak-users-pii-data-d77e6613e9e0"
            }
           ],
          "Authors": ["Eslam Akl (@eslam3kll)"],
          "Programs": ["-"],
          "Bugs": ["IDOR", "Information disclosure"],
          "Bounty": "-",
          "PublicationDate": "2022-08-30",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "My findings on Hack U.S Program",
               "Link": "https://falcon319.medium.com/my-findings-on-hack-u-s-program-43b692a5c057"
            }
           ],
          "Authors": ["Charansai"],
          "Programs": ["U.S. Dept Of Defense"],
          "Bugs": ["Missing authentication", ".git folder disclosure", "Information disclosure"],
          "Bounty": "500",
          "PublicationDate": "2022-08-30",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
              "Title": "Found SQL Injection Vulnerability on Government Organization Website!",
               "Link": "https://mehedishakeel.medium.com/found-sql-injection-vulnerability-on-government-organization-website-3eb33c0c49a4"
            }
           ],
          "Authors": ["mehedishakeel (@mehedishakeel)"],
          "Programs": ["-"],
          "Bugs": ["SQL injection"],
          "Bounty": "-",
          "PublicationDate": "2022-08-30",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
              "Title": "CVE-2021-38297 – Analysis of a Go Web Assembly vulnerability",
              "Link": "https://jfrog.com/blog/cve-2021-38297-analysis-of-a-go-web-assembly-vulnerability/"
           }
           ],
          "Authors": ["Uriya Yavnieli (@uriya_yavniely)"],
          "Programs": ["-"],
          "Bugs": ["Memory corruption"],
          "Bounty": "-",
          "PublicationDate": "2022-08-30",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Exploiting Improper Validation of Amazon Simple Notification Service SigningCertUrl",
               "Link": "https://spaceraccoon.dev/exploiting-improper-validation-amazon-simple-notification-service/"
            }
           ],
          "Authors": ["Eugene Lim (@spaceraccoonsec)"],
          "Programs": ["Amazon"],
          "Bugs": ["Broken authorization", "Signature validation bypass"],
          "Bounty": "-",
          "PublicationDate": "2022-08-30",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Bypassing ModSecurity for RCEs",
               "Link": "https://s0md3v.github.io/blog/modsecurity-rce-bypass"
            }
           ],
          "Authors": ["Somdev Sangwan (s0md3v)"],
          "Programs": ["ModSecurity"],
          "Bugs": ["WAF bypass", "Code injection", "RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-29",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Blind Exploits To Rule Watchguard Firewalls",
               "Link": "https://www.ambionics.io/blog/hacking-watchguard-firewalls"
            }
           ],
          "Authors": ["Charles Fol (@cfreal_)"],
          "Programs": ["WatchGuard"],
          "Bugs": ["XPath injection", "Memory corruption", "Local Privilege Escalation", "RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-29",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
              "Title": "Bypassing Amazon WAF to pop an alert()",
               "Link": "https://infosecwriteups.com/bypassing-amazon-waf-to-pop-an-alert-4646ce35554e"
            }
           ],
          "Authors": ["Manash (@manash036)"],
          "Programs": ["-"],
          "Bugs": ["WAF bypass", "XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-29",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "How I bypassed Reflected XSS in well-known platform",
               "Link": "https://moustadif.medium.com/how-i-bypassed-reflected-xss-in-well-known-platform-274c07f97674"
            }
           ],
          "Authors": ["Iori Yagami"],
          "Programs": ["-"],
          "Bugs": ["XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-29",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Out-Of-Bond Remote code Execution(RCE) on De Nederlandsche Bank N.V. with burp-suite collaborator",
               "Link": "https://infosecwriteups.com/out-of-bond-remote-code-execution-rce-on-de-nederlandsche-bank-n-v-with-burp-suite-collaborator-2ce50260e2e4"
            }
           ],
          "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
          "Programs": ["De Nederlandsche Bank"],
          "Bugs": ["OS command injection", "RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-28",
          "AddedDate": "2022-09-15"
      },
      {
          "Links": [
            {
               "Title": "How I found reflected XSS on IDFC Bank with burp-suite Intruder",
               "Link": "https://notifybugme.medium.com/how-i-found-reflected-xss-on-idfc-bank-with-burp-suite-intruder-7c53275daf02"
            }
           ],
          "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
          "Programs": ["IDFC Bank"],
          "Bugs": ["Reflected XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-28",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Unsubscribe any user’s e-mail notifications via IDOR",
               "Link": "https://sagarsajeev.medium.com/unsubscribe-any-users-e-mail-notifications-via-idor-2c2e05b79dac"
            }
           ],
          "Authors": ["Sagar Sajeev (@Sagar__Sajeev)"],
          "Programs": ["-"],
          "Bugs": ["IDOR"],
          "Bounty": "200",
          "PublicationDate": "2022-08-28",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "CSRF Vulnerability In The NodeJS Ecosystem",
               "Link": "https://fortbridge.co.uk/research/csrf-vulnerability-in-nodejs-ecosystem/"
            }
           ],
          "Authors": ["Adrian Tiron (@adrian__t)"],
          "Programs": ["Node.js third-party modules (csurf)"],
          "Bugs": ["CSRF"],
          "Bounty": "-",
          "PublicationDate": "2022-08-28",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "The Million Dollar IDOR",
               "Link": "https://monish-basaniwal.medium.com/the-million-dollar-hack-8163892bfe2f"
            }
           ],
          "Authors": ["Monish Basaniwal"],
          "Programs": ["-"],
          "Bugs": ["IDOR", "Race condition", "GraphQL"],
          "Bounty": "-",
          "PublicationDate": "2022-08-27",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "SSRF leads to access AWS metadata.",
               "Link": "https://infosecwriteups.com/ssrf-leads-to-access-aws-metadata-21952c220aeb"
            }
           ],
          "Authors": ["Akash Patil (@skypatil98)"],
          "Programs": ["-"],
          "Bugs": ["SSRF"],
          "Bounty": "50",
          "PublicationDate": "2022-08-27",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Improper Input Validation Leads To Email Spamming",
               "Link": "https://akshayravic09yc47.medium.com/improper-input-validation-leads-to-email-spamming-5d1a53b2a579"
            }
           ],
          "Authors": ["Akshay Ravi (@AKSHAYC09YC47)"],
          "Programs": ["-"],
          "Bugs": ["Email content injection"],
          "Bounty": "-",
          "PublicationDate": "2022-08-27",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "My Hall of Fame at United Nations Success Story",
               "Link": "https://joshuaarulsamy.medium.com/my-hall-of-fame-at-united-nations-success-story-97675232aed7"
            }
           ],
          "Authors": ["Joshua Arulsamy (@Joshua_Arulsamy)"],
          "Programs": ["United Nations"],
          "Bugs": ["XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-27",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later",
               "Link": "https://xcellerator.github.io/posts/tetsuji/"
            }
           ],
          "Authors": ["xcellerator (@TheXcellerator)"],
          "Programs": ["Nintendo"],
          "Bugs": ["RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-27",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Zimbra Open Bucket Data Leak – Responsible Disclosure",
               "Link": "https://members.backbox.org/zimbra-open-bucket-data-leak-responsible-disclosure/"
            }
           ],
          "Authors": ["Raffaele Forte (@raffaele_forte)"],
          "Programs": ["Zimbra"],
          "Bugs": ["AWS misconfiguration"],
          "Bounty": "-",
          "PublicationDate": "2022-08-26",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Break the Logic: 5 Different Perspectives in Single Page (€1500)",
               "Link": "https://infosecwriteups.com/break-the-logic-5-different-perspectives-in-single-page-1500-5aa09da0fe7a"
            }
           ],
          "Authors": ["can1337 (@canmustdie)"],
          "Programs": ["-"],
          "Bugs": ["Client-side enforcement of server-side security", "IDOR", "Broken authorization"],
          "Bounty": "1,500",
          "PublicationDate": "2022-08-26",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "ASP.NET Boilerplate Multiple Vulnerabilities",
               "Link": "https://pulsesecurity.co.nz/advisories/aspnetboilerplate-jwt"
            }
           ],
          "Authors": ["Sana Oshika (@bigshika)"],
          "Programs": ["Volosoft (ASP.NET Boilerplate)"],
          "Bugs": ["Broken authentication", "Hardcoded credentials", "JWT", "Padding oracle attack", "Cryptographic issues"],
          "Bounty": "-",
          "PublicationDate": "2022-08-26",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "SSD Advisory – VhdmpiValidateVirtualDiskSurface LPE",
               "Link": "https://ssd-disclosure.com/ssd-advisory-vhdmpivalidatevirtualdisksurface-lpe/"
            }
           ],
          "Authors": ["Sana Oshika (@bigshika)"],
          "Programs": ["Microsoft (Windows)"],
          "Bugs": ["Local Privilege Escalation"],
          "Bounty": "-",
          "PublicationDate": "2022-08-26",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Command Injection in the GitHub Pages Build Pipeline",
               "Link": "https://blog.nietaanraken.nl/posts/github-pages-command-injection/"
            }
           ],
          "Authors": ["Joren Vrancken"],
          "Programs": ["GitHub"],
          "Bugs": ["RCE", "OS command injection"],
          "Bounty": "4,000",
          "PublicationDate": "2022-08-25",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Chaining Telegram bugs to steal session-related files.",
               "Link": "https://dphoeniixx.medium.com/chaining-telegram-bugs-to-steal-session-related-files-c90eac4749bd"
            }
           ],
          "Authors": ["Sayed Abdelhafiz (@dPhoeniixx)"],
          "Programs": ["Telegram"],
          "Bugs": ["Arbitrary file read", "Android"],
          "Bounty": "-",
          "PublicationDate": "2022-08-25",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "SATisfying our way into remote code execution in the OPC UA industrial stack",
               "Link": "https://jfrog.com/blog/satisfying-our-way-into-remote-code-execution-in-the-opc-ua-industrial-stack/"
            }
           ],
          "Authors": ["JFrog Security Research Team (@JFrogSecurity)"],
          "Programs": ["Unified Automation"],
          "Bugs": ["Memory corruption", "RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-25",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Crashing Industrial Control Systems at Pwn2Own Miami 2022",
               "Link": "https://jfrog.com/blog/crashing-industrial-control-systems-at-pwn2own-miami-2022/"
            }
           ],
          "Authors": ["JFrog Security Research Team (@JFrogSecurity)"],
          "Programs": ["Unified Automation"],
          "Bugs": ["DoS", "Memory corruption", "RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-25",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "“GIFShell” — Covert Attack Chain and C2 Utilizing Microsoft Teams GIFs",
               "Link": "https://medium.com/@bobbyrsec/gifshell-covert-attack-chain-and-c2-utilizing-microsoft-teams-gifs-1618c4e64ed7"
            }
           ],
          "Authors": ["Bobby Rauch"],
          "Programs": ["Microsoft"],
          "Bugs": ["Phishing"],
          "Bounty": "-",
          "PublicationDate": "2022-08-24",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "2-byte DoS in freebsd-telnetd / netbsd-telnetd / netkit-telnetd / inetutils-telnetd / telnetd in Kerberos Version 5 Applications - Binary Golf Grand Prix 3",
               "Link": "https://pierrekim.github.io/blog/2022-08-24-2-byte-dos-freebsd-netbsd-telnetd-netkit-telnetd-inetutils-telnetd-kerberos-telnetd.html"
            }
           ],
          "Authors": ["Pierre Kim (@PierreKimSec)", "Alexandre Torres (@AlexTorSec)"],
          "Programs": ["FreeBSD Security Team"],
          "Bugs": ["DoS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-24",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Break the Logic: Insecure Parameters (€300)",
               "Link": "https://canmustdie.medium.com/break-the-logic-insecure-parameters-300-e655cc4fcc42"
            }
           ],
          "Authors": ["can1337 (@canmustdie)"],
          "Programs": ["-"],
          "Bugs": ["Parameter manipulation", "Logic flaw", "Mass assignment"],
          "Bounty": "300",
          "PublicationDate": "2022-08-24",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Oracle SBC: Multiple Security Vulnerabilities Leading to Unauthorized Access and Denial of Service",
               "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/oracle-sbc-multiple-security-vulnerabilities-leading-to-unauthorized-access-and-denial-of-service/"
            }
           ],
          "Authors": ["Harold Zang"],
          "Programs": ["Oracle"],
          "Bugs": ["IDOR", "Path traversal", "DoS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-23",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Securing Developer Tools: Argument Injection in Visual Studio Code",
               "Link": "https://blog.sonarsource.com/securing-developer-tools-argument-injection-in-vscode/"
            }
           ],
          "Authors": ["Thomas Chauchefoin (@swapgs)"],
          "Programs": ["Microsoft"],
          "Bugs": ["Argument injection", "RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-23",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "[CVE-2020-2733] JD Edwards EnterpriseOne Tools admin password not adequately protected",
               "Link": "https://redrays.io/cve-2020-2733-jd-edwards/"
            }
           ],
          "Authors": ["Vahagn Vardanyan (@vah_13)"],
          "Programs": ["Oracle"],
          "Bugs": ["Information disclosure"],
          "Bounty": "-",
          "PublicationDate": "2022-08-23",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "But You Told Me You Were Safe: Attacking The Mozilla Firefox Renderer (Part 1)",
               "Link": "https://www.zerodayinitiative.com/blog/2022/8/17/but-you-told-me-you-were-safe-attacking-the-mozilla-firefox-renderer-part-1"
            },
            {
              "Title": "But You Told Me You Were Safe: Attacking The Mozilla Firefox Sandbox (Part 2)",
              "Link": "https://www.zerodayinitiative.com/blog/2022/8/23/but-you-told-me-you-were-safe-attacking-the-mozilla-firefox-renderer-part-2"
           }
           ],
          "Authors": ["Hossein Lotfi (@hosselot)", "Manfred Paul (@_manfp)"],
          "Programs": ["Mozilla"],
          "Bugs": ["Browser hacking", "RCE", "Prototype pollution"],
          "Bounty": "100,000",
          "PublicationDate": "2022-08-23",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Break Me Out Of Sandbox In Old Pipe - CVE-2022-22715 Windows Dirty Pipe",
               "Link": "https://whereisk0shl.top/post/break-me-out-of-sandbox-in-old-pipe-cve-2022-22715-windows-dirty-pipe"
            }
           ],
          "Authors": ["k0shl (@KeyZ3r0)"],
          "Programs": ["Microsoft"],
          "Bugs": ["Local Privilege Escalation"],
          "Bounty": "-",
          "PublicationDate": "2022-08-23",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Paracosme - CVE-2022-33318 - Remote Code Execution in ICONICS Genesis64",
               "Link": "https://github.com/0vercl0k/paracosme"
            }
           ],
          "Authors": ["Axel Souchet (@0vercl0k)"],
          "Programs": ["ICONICS"],
          "Bugs": ["Memory corruption", "RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-22",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Patch bypass for [CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager",
               "Link": "https://redrays.io/cve-2020-6369-patch-bypass/"
            }
           ],
          "Authors": ["Arpine Maghakyan"],
          "Programs": ["SAP"],
          "Bugs": ["Hardcoded credentials", "Information disclosure"],
          "Bounty": "-",
          "PublicationDate": "2022-08-22",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Vulnerability in Linux containers – investigation and mitigation",
               "Link": "https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/"
            }
           ],
          "Authors": ["Steven Murdoch (@sjmurdoch)"],
          "Programs": ["Moby Project"],
          "Bugs": ["Local Privilege Escalation"],
          "Bounty": "-",
          "PublicationDate": "2022-08-22",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Useless path traversals in Zyxel admin interface (CVE-2022-2030)",
               "Link": "https://security.humanativaspa.it/useless-path-traversals-in-zyxel-admin-interface-cve-2022-2030/"
            }
           ],
          "Authors": ["Maurizio Agazzini (@0x696e6f6465)"],
          "Programs": ["Zyxel"],
          "Bugs": ["Path traversal"],
          "Bounty": "-",
          "PublicationDate": "2022-08-22",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "SSRF & Google HOF(Hall of Fame)",
               "Link": "https://apth3hack3r.medium.com/ssrf-google-hof-hall-of-fame-2c159dda04e3"
            }
           ],
          "Authors": ["Aman Pareek (@aman_notsogreat)"],
          "Programs": ["Google"],
          "Bugs": ["SSRF"],
          "Bounty": "-",
          "PublicationDate": "2022-08-22",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "How a Port scan got me Nokia Hall of Fame",
               "Link": "https://medium.com/@mullangisashank/how-a-port-scan-got-me-nokia-hall-of-fame-6f9b65e920e3"
            }
           ],
          "Authors": ["Mani Sashank"],
          "Programs": ["Nokia"],
          "Bugs": ["Missing authentication", "Information disclosure"],
          "Bounty": "-",
          "PublicationDate": "2022-08-22",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Blockchain Network is Secured! But not the apps and their Integrations",
               "Link": "https://wesecureapp.com/blog/blockchain-network-is-secured-but-not-the-apps-and-their-integrations/"
            }
           ],
          "Authors": ["Keyur Talati"],
          "Programs": ["-"],
          "Bugs": ["Payment tampering", "Logic flaw"],
          "Bounty": "-",
          "PublicationDate": "2022-08-22",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Blind command injection",
               "Link": "https://bergee.it/blog/blind-command-injection/"
            }
           ],
          "Authors": ["Bartłomiej Bergier (@_bergee_)"],
          "Programs": ["-"],
          "Bugs": ["RCE", "OS command injection"],
          "Bounty": "-",
          "PublicationDate": "2022-08-21",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Failed Coding Assessment to Remote Code Execution - Part 1",
               "Link": "https://hackingguy.medium.com/failed-coding-assessment-to-remote-code-execution-a-case-study-part-1-1778934b3b34"
            }
           ],
          "Authors": ["Akash Chhabra (@_hackingguy)"],
          "Programs": ["HackerEarth"],
          "Bugs": ["RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-20",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "VPNs on iOS are a scam",
               "Link": "https://www.michaelhorowitz.com/VPNs.on.iOS.are.scam.php"
            }
           ],
          "Authors": ["Michael Horowitz (@defensivecomput)"],
          "Programs": ["Apple"],
          "Bugs": ["Privacy issue"],
          "Bounty": "-",
          "PublicationDate": "2022-08-20",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Never underestimate the power of open redirect, a story of a full account takeover",
               "Link": "https://www.bugbounty.info/2022/08/never-underestimate-power-of-open.html"
            }
           ],
          "Authors": ["Ibrahim Auwal (@ibrahimatix0x01)"],
          "Programs": ["-"],
          "Bugs": ["Open redirect", "Account takeover", "Token leak"],
          "Bounty": "-",
          "PublicationDate": "2022-08-20",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Account takeover worth $1000",
               "Link": "https://medium.com/@faique/account-takeover-worth-1000-611452063cf"
            }
           ],
          "Authors": ["Faique (@imfaiqu3)"],
          "Programs": ["-"],
          "Bugs": ["Account takeover", "Authentication bypass", "Information disclosure", "Password reset"],
          "Bounty": "1,000",
          "PublicationDate": "2022-08-19",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Uncovering a ChromeOS remote memory corruption vulnerability",
               "Link": "https://www.microsoft.com/security/blog/2022/08/19/uncovering-a-chromeos-remote-memory-corruption-vulnerability/"
            }
           ],
          "Authors": ["Microsoft 365 Defender Research Team"],
          "Programs": ["Google"],
          "Bugs": ["Memory corruption"],
          "Bounty": "25,000",
          "PublicationDate": "2022-08-19",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Amazon Quickly Fixed A Vulnerability In Ring Android App That Could Expose Users’ Camera Recordings",
               "Link": "https://checkmarx.com/blog/amazon-quickly-fixed-a-vulnerability-in-ring-android-app-that-could-expose-users-camera-recordings/"
            }
           ],
          "Authors": ["David Sopas (@dsopas)", "João Morais (@jmoraissec)", "Pedro Umbelino (@kripthor)"],
          "Programs": ["Amazon"],
          "Bugs": ["XSS", "iOS", "Android"],
          "Bounty": "-",
          "PublicationDate": "2022-08-18",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "XSS by Javascript Overriding",
               "Link": "https://monke.ie/xss-by-javascript-overriding/"
            }
           ],
          "Authors": ["Monke (@pmofcats)"],
          "Programs": ["-"],
          "Bugs": ["XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-18",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Outlook CVE-2022-35742",
               "Link": "https://blog.78researchlab.com/b9c80d00-d935-43b1-8805-969000df301d"
            },
            {
              "Title": "Alternative link",
              "Link": "https://github.com/78ResearchLab/PoC/tree/main/CVE-2022-35742"
           }
           ],
          "Authors": ["insu (@hpy_insu)"],
          "Programs": ["Microsoft"],
          "Bugs": ["DoS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-18",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Trust Me, I’m a Robot: Can We Trust RPA With Our Most Guarded Secrets?",
               "Link": "https://www.cyberark.com/resources/threat-research-blog/trust-me-i-m-a-robot-can-we-trust-rpa-with-our-most-guarded-secrets"
            }
           ],
          "Authors": ["Nimrod Stoler (@n1mr0d5)", "Nethanel Coppenhagen"],
          "Programs": ["Blue Prism"],
          "Bugs": ["Robotic Process Automation", "Insecure deserialization", "SQL injection", "MiTM"],
          "Bounty": "-",
          "PublicationDate": "2022-08-18",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Fishbowl Disclosure: CVE-2022-29805",
               "Link": "https://www.whiteoaksecurity.com/blog/fishbowl-disclosure-cve-2022-29805/"
            }
           ],
          "Authors": ["Michael Rand"],
          "Programs": ["Fishbowl"],
          "Bugs": ["Insecure deserialization"],
          "Bounty": "-",
          "PublicationDate": "2022-08-18",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Let's Dance in the Cache - Destabilizing Hash Table on Microsoft IIS!",
               "Link": "https://blog.orange.tw/2022/08/lets-dance-in-the-cache-destabilizing-hash-table-on-microsoft-iis.html"
            }
           ],
          "Authors": ["Orange Tsai (@orange_8361)"],
          "Programs": ["Microsoft"],
          "Bugs": ["DoS", "Web cache poisoning", "Authentication bypass"],
          "Bounty": "30,000",
          "PublicationDate": "2022-08-18",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "You Have One New Appwntment: Exploiting iCalendar Properties in Enterprise Applications",
               "Link": "https://spaceraccoon.dev/exploiting-icalendar-properties-enterprise-applications/"
            }
           ],
          "Authors": ["Eugene Lim (@spaceraccoonsec)"],
          "Programs": ["VMware", "Synology", "Apple", "Microsoft", "Google", "NextCloud"],
          "Bugs": ["XSS", "SMTP injection"],
          "Bounty": "-",
          "PublicationDate": "2022-08-18",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "N/a to $750 bounty for a Blind XSS.",
               "Link": "https://medium.com/@dirtycoder0124/n-a-to-750-bounty-for-a-blind-xss-dc218c84a340"
            }
           ],
          "Authors": ["Dirtycoder (@dirtycoder0124)"],
          "Programs": ["-"],
          "Bugs": ["Blind XSS"],
          "Bounty": "750",
          "PublicationDate": "2022-08-18",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Critical Local File Read in Electron Desktop App",
               "Link": "https://bugcrowd.com/disclosures/f7ce8504-0152-483b-bbf3-fb9b759f9f89/critical-local-file-read-in-electron-desktop-app"
            }
           ],
          "Authors": ["Renwa (@RenwaX23)"],
          "Programs": ["Asana"],
          "Bugs": ["LFI"],
          "Bounty": "6,200",
          "PublicationDate": "2022-08-17",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "RCE on Spip and Root-Me, v2!",
               "Link": "https://thinkloveshare.com/hacking/rce_on_spip_and_root_me_v2/"
            }
           ],
          "Authors": ["Laluka (@TheLaluka)", "t0 (@___t0___)"],
          "Programs": ["SPIP"],
          "Bugs": ["RCE", "SSTI", "DNS rebinding", "XSS", "Code injection", "Unrestricted file upload"],
          "Bounty": "-",
          "PublicationDate": "2022-08-16",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Monitoring Linux host metrics with the Node Exporter information disclosure $350",
               "Link": "https://medium.com/@Dhamuharker/monitoring-linux-host-metrics-with-the-node-exporter-information-disclosure-350-bab3baa75bdc"
            }
           ],
          "Authors": ["Dhamotharan (@Dhamu_offi)"],
          "Programs": ["Slack"],
          "Bugs": ["Information disclosure", "Missing authentication"],
          "Bounty": "350",
          "PublicationDate": "2022-08-16",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "DOM XSS On A Gov Domain Bypassing WAF",
               "Link": "https://medium.com/@tobydavenn/dom-xss-on-a-gov-domain-bypassing-waf-93daec67fda9"
            }
           ],
          "Authors": ["Tobydavenn"],
          "Programs": ["-"],
          "Bugs": ["DOM XSS", "WAF bypass"],
          "Bounty": "-",
          "PublicationDate": "2022-08-16",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "CSRF leads to Account Takeover | Samsung",
               "Link": "https://bloggerrando.blogspot.com/2022/08/17-1.html"
            }
           ],
          "Authors": ["R ando (@Rando02355205)"],
          "Programs": ["Samsung"],
          "Bugs": ["CSRF", "Account takeover"],
          "Bounty": "-",
          "PublicationDate": "2022-08-16",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "2FA Bypass Do Re Mi",
               "Link": "https://medium.com/@ashlyn.lau_17206/2fa-bypass-do-re-mi-cfcfc3775d2e"
            }
           ],
          "Authors": ["Ashlyn Lau (@ashlyn_lau)"],
          "Programs": ["-"],
          "Bugs": ["2FA / MFA bypass"],
          "Bounty": "-",
          "PublicationDate": "2022-08-16",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Multiple Denial of Service (DoS) Vulnerabilities in GoProxy, Smokescreen libraries",
               "Link": "https://doyensec.com/resources/Doyensec_Advisory_SmokescreenGoProxy_Q12022.pdf"
            }
           ],
          "Authors": ["Lorenzo Stella (@lorenzostella)"],
          "Programs": ["Stripe"],
          "Bugs": ["DoS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-16",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "FreeBSD 11.0-13.0 LPE via aio_aqueue Kernel Refcount Bug",
               "Link": "https://accessvector.net/2022/freebsd-aio-lpe"
            }
           ],
          "Authors": ["Chris (@accessvector)"],
          "Programs": ["FreeBSD Security Team"],
          "Bugs": ["Memory corruption", "Local Privilege Escalation"],
          "Bounty": "-",
          "PublicationDate": "2022-08-16",
          "AddedDate": "2022-09-15"
         },
         {
           "Links": [
             {
                "Title": "Open Redirect at Nvidia",
                "Link": "https://xthemo.medium.com/open-redirect-at-nvidia-62343b45f85b"
             }
            ],
           "Authors": ["Mohamed Abdelhady"],
           "Programs": ["Nvidia"],
           "Bugs": ["Open redirect"],
           "Bounty": "-",
           "PublicationDate": "2022-08-16",
           "AddedDate": "2022-09-26"
          },
         {
          "Links": [
            {
               "Title": "CVE-2022-30211: Windows L2TP VPN Memory Leak and Use after Free Vulnerability",
               "Link": "https://labs.nettitude.com/blog/cve-2022-30211-windows-l2tp-vpn-memory-leak-and-use-after-free-vulnerability/"
            }
           ],
          "Authors": ["Alex Nichols (@i4mchr00t)"],
          "Programs": ["Microsoft"],
          "Bugs": ["Memory corruption", "RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-15",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "We discovered major vulnerabilities in Control Web Panel. Here’s how we found them.",
               "Link": "https://www.immersivelabs.com/blog/we-discovered-major-vulnerabilities-in-control-web-panel-heres-how-we-found-them/"
            }
           ],
          "Authors": ["Immersive Labs (@immersivelabs)"],
          "Programs": ["Centos Web Panel (CWP)"],
          "Bugs": ["Path traversal", "RCE", "Weak crypto", "Password reset", "Account takeover"],
          "Bounty": "-",
          "PublicationDate": "2022-08-15",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Salesforce bug hunting to Critical bug",
               "Link": "https://infosecwriteups.com/salesforce-bug-hunting-to-critical-bug-b5da44789d3"
            }
           ],
          "Authors": ["Vuk Ivanovic"],
          "Programs": ["-"],
          "Bugs": ["Information disclosure", "Salesforce"],
          "Bounty": "-",
          "PublicationDate": "2022-08-15",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Business Logic Vulnerability via IDOR",
               "Link": "https://sagarsajeev.medium.com/business-logic-vulnerability-via-idor-6d510f1caea9"
            }
           ],
          "Authors": ["Sagar Sajeev (@Sagar__Sajeev)"],
          "Programs": ["-"],
          "Bugs": ["IDOR", "Payment tampering"],
          "Bounty": "2,000",
          "PublicationDate": "2022-08-15",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "1day to 0day(CVE-2022-30024) on TP-Link TL-WR841N",
               "Link": "https://blog.viettelcybersecurity.com/1day-to-0day-on-tl-link-tl-wr841n/"
            }
           ],
          "Authors": ["Trần Minh Cường"],
          "Programs": ["TP-Link"],
          "Bugs": ["Memory corruption"],
          "Bounty": "-",
          "PublicationDate": "2022-08-15",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Five-minute hunting for hidden XSS",
               "Link": "https://bergee.it/blog/five-minute-hunting-for-hidden-xss/"
            }
           ],
          "Authors": ["Bartłomiej Bergier (@_bergee_)"],
          "Programs": ["-"],
          "Bugs": ["Reflected XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-15",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "The forgotten API and XSS filter bypass",
               "Link": "https://bergee.it/blog/the-forgotten-api-and-xss-filter-bypass/"
            }
           ],
          "Authors": ["Bartłomiej Bergier (@_bergee_)"],
          "Programs": ["-"],
          "Bugs": ["XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-14",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "URL filter bypass, RFI and XSS",
               "Link": "https://bergee.it/blog/url-filter-bypass-rfi-and-xss/"
            }
           ],
          "Authors": ["Bartłomiej Bergier (@_bergee_)"],
          "Programs": ["-"],
          "Bugs": ["Stored XSS", "RFI"],
          "Bounty": "-",
          "PublicationDate": "2022-08-14",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Hacking Zyxel IP cameras to gain a root shell",
               "Link": "http://www.hydrogen18.com/blog/hacking-zyxel-ip-cameras-pt-1.html"
            }
           ],
          "Authors": ["Eric Urban"],
          "Programs": ["Zyxel"],
          "Bugs": ["Missing authentication", "DoS", "Information disclosure", "Local Privilege Escalation"],
          "Bounty": "-",
          "PublicationDate": "2022-08-14",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "How I got into the United Nations’ Hall of Fame",
               "Link": "https://blog.bugzero.io/how-i-get-into-united-nations-hall-of-fame-6975e3d3cc45"
            }
           ],
          "Authors": ["Ameya Andhare (@cryptoknight028)"],
          "Programs": ["United Nations"],
          "Bugs": ["Missing authentication"],
          "Bounty": "-",
          "PublicationDate": "2022-08-14",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "XSS via Angular Template Injection",
               "Link": "https://bergee.it/blog/xss-via-angular-template-injection/"
            }
           ],
          "Authors": ["Bartłomiej Bergier (@_bergee_)"],
          "Programs": ["-"],
          "Bugs": ["CSTI", "XSS", "WAF bypass"],
          "Bounty": "-",
          "PublicationDate": "2022-08-13",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Remote Code Execution on Element Desktop Application using Node Integration in Sub Frames Bypass - CVE-2022-23597",
               "Link": "https://blog.electrovolt.io/posts/element-rce/"
            },
            {
              "Title": "Video PoC",
              "Link": "https://twitter.com/S1r1u5_/status/1559561002349633536"
           }
           ],
          "Authors": ["s1r1us (@s1r1u5_)", "Maxwell Garrett (@TheGrandPew)"],
          "Programs": ["Matrix (Element)"],
          "Bugs": ["RCE", "XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-13",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Story of 5000$ bounty for Grafana Panel Access in Apple",
               "Link": "https://medium.com/@lovely.goyal1998/story-of-5000-bounty-for-grafana-panel-access-in-apple-89c93ab4486f"
            }
           ],
          "Authors": ["hckerl00 (@lokeshg62498939)"],
          "Programs": ["Apple"],
          "Bugs": ["Missing authentication", "Information disclosure"],
          "Bounty": "5,000",
          "PublicationDate": "2022-08-13",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "CVE-2022-30216 - Authentication coercion of the Windows “Server” service",
               "Link": "https://www.akamai.com/blog/security/authentication-coercion-windows-server-service"
            }
           ],
          "Authors": ["Ben Barnea (@nachoskrnl)"],
          "Programs": ["Microsoft"],
          "Bugs": ["Off-by-one Error", "Authentication coercion"],
          "Bounty": "-",
          "PublicationDate": "2022-08-13",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "How I earned a $7000 bug bounty from Grab (RCE Unique Bugs)",
               "Link": "https://web.archive.org/web/20220815093448/https://deb0con.medium.com/how-i-earned-a-7000-bug-bounty-from-grab-rce-unique-bugs-5e5037c5a58d"
            }
           ],
          "Authors": ["ANDRI"],
          "Programs": ["Grab"],
          "Bugs": ["RCE", "Android"],
          "Bounty": "7,000",
          "PublicationDate": "2022-08-13",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Escalating Open Redirect to XSS",
               "Link": "https://sagarsajeev.medium.com/escalating-open-redirect-to-xss-d2b9355e5f05"
            }
           ],
          "Authors": ["Sagar Sajeev (@Sagar__Sajeev)"],
          "Programs": ["-"],
          "Bugs": ["Open redirect", "XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-13",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "An Unusual Tale of Email Verification Bypass",
               "Link": "https://sagarsajeev.medium.com/an-unusual-tale-of-email-verification-bypass-dcf884d544eb"
            }
           ],
          "Authors": ["Sagar Sajeev (@Sagar__Sajeev)"],
          "Programs": ["-"],
          "Bugs": ["Email verification bypass", "Bruteforce", "Rate limiting bypass"],
          "Bounty": "-",
          "PublicationDate": "2022-08-13",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Bypassing unexpected IDOR",
               "Link": "https://medium.com/@bharatsingh070601/bypassing-unexpected-idor-e6a9da2e0498"
            }
           ],
          "Authors": ["Bharatsingh"],
          "Programs": ["-"],
          "Bugs": ["IDOR", "40x bypass"],
          "Bounty": "-",
          "PublicationDate": "2022-08-13",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "UN United Nations Host Header Injection leads to any Full Account Takeover (ATO)",
               "Link": "https://medium.com/@Bishoo97x/un-united-nations-host-header-injection-leads-to-any-full-account-takeover-ato-795bc9ebc670"
            }
           ],
          "Authors": ["Ahmed Hassan"],
          "Programs": ["United Nations"],
          "Bugs": ["Host header injection", "Password reset", "Account takeover"],
          "Bounty": "-",
          "PublicationDate": "2022-08-13",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "DOM Cross-Site Scripting Via postMessage in AnnounceKit",
               "Link": "https://doyensec.com/resources/Doyensec_Advisory_AnnounceKit_Q12022.pdf"
            }
           ],
          "Authors": ["Lorenzo Stella (@lorenzostella)"],
          "Programs": ["Announcekit"],
          "Bugs": ["DOM XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-12",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Exploiting CVE-2022-24816: A Code Injection In The Jt-jiffle Extension Of Geoserver",
               "Link": "https://www.synacktiv.com/en/publications/exploiting-cve-2022-24816-a-code-injection-in-the-jt-jiffle-extension-of-geoserver.html"
            }
           ],
          "Authors": ["Remsio (@_remsio_)", "Us3r777 (@us3r777)"],
          "Programs": ["-"],
          "Bugs": ["RCE", "Code injection"],
          "Bounty": "-",
          "PublicationDate": "2022-08-12",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "How I found an XSS vulnerability via using emojis",
               "Link": "https://medium.com/@fpatrik/how-i-found-an-xss-vulnerability-via-using-emojis-7ad72de49209"
            }
           ],
          "Authors": ["Patrik Fabian"],
          "Programs": ["Swisscom"],
          "Bugs": ["XSS"],
          "Bounty": "-",
          "PublicationDate": "2022-08-12",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Researching Xiaomi’s TEE to get to Chinese money",
               "Link": "https://research.checkpoint.com/2022/researching-xiaomis-tee/"
            }
           ],
          "Authors": ["Slava Makkaveev"],
          "Programs": ["Xiaomi"],
          "Bugs": ["Payment bypass", "Android", "Memory corruption"],
          "Bounty": "-",
          "PublicationDate": "2022-08-12",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Process injection: breaking all macOS security layers with a single vulnerability",
               "Link": "https://sector7.computest.nl/post/2022-08-process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability/"
            }
           ],
          "Authors": ["Thijs Alkemade (@xnyhps)"],
          "Programs": ["Apple"],
          "Bugs": ["Local Privilege Escalation", "Process injection"],
          "Bounty": "-",
          "PublicationDate": "2022-08-12",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "File Upload Bypass to RCE == $$$$",
               "Link": "https://sagarsajeev.medium.com/file-upload-bypass-to-rce-76991b47ad8f"
            }
           ],
          "Authors": ["Sagar Sajeev (@Sagar__Sajeev)"],
          "Programs": ["-"],
          "Bugs": ["Unrestricted file upload", "RCE"],
          "Bounty": "-",
          "PublicationDate": "2022-08-12",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Amazon Cognito misconfiguration lead to account takeover",
               "Link": "https://medium.com/@iknowhatodo/amazon-cognito-misconfiguration-lead-to-account-takeover-20694243ca40"
            }
           ],
          "Authors": ["Hossam Ahmed (@iknowhatodo0x01)"],
          "Programs": ["-"],
          "Bugs": ["Account takeover"],
          "Bounty": "-",
          "PublicationDate": "2022-08-12",
          "AddedDate": "2022-09-15"
         },
         {
           "Links": [
             {
                "Title": "FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies",
                "Link": "https://bahruz.me/publications/11844"
             },
             {
                 "Title": "Biological Inspiration",
                 "Link": "https://bahruz.me/posts/biological-inspiration"
              }
            ],
           "Authors": ["Bahruz Jabiyev (@BahruzJabiyev)", "Steven Sprecher (@StevenSprecher)", "Anthony Gavazzi", "Tommaso Innocenti (@innotommy)", "Kaan Onarlioglu", "Engin Kirda"],
           "Programs": ["-"],
           "Bugs": ["HTTP request smuggling", "DoS"],
           "Bounty": "-",
           "PublicationDate": "2022-08-11",
           "AddedDate": "2022-09-15"
        },
         {
           "Links": [
              {
                "Title": "IAM Whoever I Say IAM :: Infiltrating VMWare Workspace ONE Access Using a 0-Click Exploit",
                "Link": "https://srcincite.io/blog/2022/08/11/i-am-whoever-i-say-i-am-infiltrating-vmware-workspace-one-access-using-a-0-click-exploit.html"
              },
              {
                 "Title": "Hekate exploits",
                 "Link": "https://github.com/sourceincite/hekate/"
              },
              {
                  "Title": "Slides",
                  "Link": "https://srcincite.io/assets/iam-who-i-say-iam.pdf"
              }
           ],
           "Authors": ["Steven Seeley (@steventseeley)"],
           "Programs": ["VMware"],
           "Bugs": ["Authentication bypass", "Information disclosure", "CSRF", "RCE", "Local Privilege Escalation"],
           "Bounty": "-",
           "PublicationDate": "2022-08-11",
           "AddedDate": "2022-09-15"
        },
         {
           "Links": [
            {
                   "Title": "The cloud has an isolation problem: PostgreSQL vulnerabilities affect multiple cloud vendors",
                   "Link": "https://www.wiz.io/blog/the-cloud-has-an-isolation-problem-postgresql-vulnerabilities"
                }
               ],
              "Authors": ["Shir Tamari (@shirtamari)", "Nir Ohfeld (@nirohfeld)" , "Sagi Tzadik (@sagitz_)"],
              "Programs": ["Google", "Microsoft", "Aiven"],
              "Bugs": ["Privilege escalation", "Cross-tenant vulnerability", "OS command injection", "Local Privilege Escalation", "Cloud"],
              "Bounty": "-",
              "PublicationDate": "2022-08-11",
              "AddedDate": "2022-09-15"
           },
         {
              "Links": [
                {
                   "Title": "Attacking Titan M with Only One Byte",
                   "Link": "https://blog.quarkslab.com/attacking-titan-m-with-only-one-byte.html"
                }
               ],
              "Authors": ["Damiano Melotti (@DamianoMelotti)" , "Maxime Rossi Bellom (@max_r_b)"],
              "Programs": ["Google"],
              "Bugs": ["Memory corruption", "Local Privilege Escalation"],
              "Bounty": "75,000",
              "PublicationDate": "2022-08-11",
              "AddedDate": "2022-09-15"
           },
         {
           "Links": [
              {
                 "Title": "My Experience on Hacking the Dutch Government",
                 "Link": "https://gonzx.medium.com/my-experience-on-hacking-the-dutch-government-a2c5a5f43d83"
              }
           ],
              "Authors": ["Jefferson Gonzales (@gonzxph)"],
              "Programs": ["Dutch Government"],
              "Bugs": ["XSS", "Open redirect", "CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-08-11",
              "AddedDate": "2022-09-15"
           },
         {
                "Links": [
                  {
                     "Title": "Rapid7 Discovered Vulnerabilities in Cisco ASA, ASDM, and FirePOWER Services Software",
                     "Link": "https://www.rapid7.com/blog/post/2022/08/11/rapid7-discovered-vulnerabilities-in-cisco-asa-asdm-and-firepower-services-software/"
                  }
                 ],
                "Authors": ["Jake Baines (@Junior_Baines)"],
                "Programs": ["Cisco"],
                "Bugs": ["RCE", "OS command injection", "Local Privilege Escalation", "MiTM"],
                "Bounty": "-",
                "PublicationDate": "2022-08-11",
                "AddedDate": "2022-09-15"
              },
              {
                 "Links": [
                   {
                      "Title": "Identity Confusion in WebView-based Mobile App-in-app Ecosystems",
                      "Link": "https://www.usenix.org/conference/usenixsecurity22/presentation/zhang-lei"
                   }
                  ],
                 "Authors": ["Lei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao, Xiaohan Zhang, Yanjun Chen, Yuan Zhang, Guangliang Yang & Min Yang"],
                 "Programs": ["Alipay"],
                 "Bugs": ["Android", "iOS"],
                 "Bounty": "2,500",
                 "PublicationDate": "2022-08-11",
                 "AddedDate": "2022-10-02"
               },
              {
                  "Links": [
                    {
                       "Title": "Mining Node.js Vulnerabilities via Object Dependence Graph and Query",
                       "Link": "https://www.usenix.org/conference/usenixsecurity22/presentation/li-song"
                    }
                   ],
                  "Authors": ["Song Li", "Mingqing Kang", "Jianwei Hou", "Yinzhi Cao"],
                  "Programs": ["-"],
                  "Bugs": ["RCE", "OS command injection", "Prototype pollution", "Path traversal"],
                  "Bounty": "-",
                  "PublicationDate": "2022-08-10",
                  "AddedDate": "2022-09-15"
                 },
         {
                  "Links": [
                    {
                       "Title": "Web Cache Deception Escalates!",
                       "Link": "https://www.usenix.org/conference/usenixsecurity22/presentation/mirheidari"
                    }
                   ],
                  "Authors": ["Ali Mirheidari", "Matteo Golinelli", "Kaan Onarlioglu", "Engin Kirda", "Bruno Crispo"],
                  "Programs": ["-"],
                  "Bugs": ["Web cache deception"],
                  "Bounty": "-",
                  "PublicationDate": "2022-08-10",
                  "AddedDate": "2022-09-15"
                 },
           {
              "Links": [
                 {
                    "Title": "Advanced Inter-Process Desynchronization in SAP’s HTTP Server",
                    "Link": "https://i.blackhat.com/USA-22/Wednesday/US-22-Doyhenard-Internal-Server-Error-wp.pdf"
                 },
                 {
                    "Title": "Slides",
                    "Link": "https://i.blackhat.com/USA-22/Wednesday/US-22-Doyhenard-Internal-Server-Error.pdf"
                 }
              ],
              "Authors": ["Martin Doyhenard (@tincho_508)"],
              "Programs": ["SAP"],
              "Bugs": ["Memory corruption", "RCE", "HTTP request smuggling", "Web cache poisoning", "Desync attack"],
              "Bounty": "-",
              "PublicationDate": "2022-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling",
                    "Link": "https://portswigger.net/research/browser-powered-desync-attacks"
                 }
              ],
              "Authors": ["James Kettle (@albinowax)"],
              "Programs": ["AWS", "Amazon", "Akamai", "Cisco", "Verisign", "Pulse Secure", "Varnish"],
              "Bugs": ["HTTP request smuggling", "Desync attack"],
              "Bounty": "-",
              "PublicationDate": "2022-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Email Confirmation bypass at Instagram",
                    "Link": "https://medium.com/@avinash_/email-confirmation-bypass-at-instagram-cc968f9a126"
                 }
              ],
              "Authors": ["Avinash Kumar (@itsavinash_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Email verification bypass", "Logic flaw"],
              "Bounty": "3,000",
              "PublicationDate": "2022-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned a $6000 bug bounty from Cloudflare",
                    "Link": "https://web.archive.org/web/20220812183449/https://deb0con.medium.com/how-i-earned-a-6000-bug-bounty-from-cloudflare-db6949e39cf7"
                 }
              ],
              "Authors": ["ANDRI"],
              "Programs": ["Cloudflare"],
              "Bugs": ["Path traversal"],
              "Bounty": "6,000",
              "PublicationDate": "2022-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Cloud Shell - Command Injection",
                    "Link": "https://bugra.ninja/posts/cloudshell-command-injection/"
                 }
              ],
              "Authors": ["Bugra Eskici (@bugraeskici)"],
              "Programs": ["Google"],
              "Bugs": ["OS command injection", "RCE", "Cloud"],
              "Bounty": "-",
              "PublicationDate": "2022-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "403 Forbidden Bypass Leading to Admin Endpoint Access.",
                    "Link": "https://medium.com/@engrdrayc/403-forbidden-bypass-leading-to-admin-endpoint-access-b696a36665ed"
                 }
              ],
              "Authors": ["Christian Dray (@G0ds0nXY)"],
              "Programs": ["-"],
              "Bugs": ["403 bypass", "Information disclosure"],
              "Bounty": "1,800",
              "PublicationDate": "2022-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Defeat the HttpOnly flag to achieve Account Takeover | RXSS",
                    "Link": "https://mohamedtarekq.medium.com/defeat-the-httponly-flag-to-achieve-account-takeover-rxss-c16849d3d192"
                 }
              ],
              "Authors": ["Mohamed Tarek (@timooon107)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "iOS Privacy: Instagram and Facebook can track anything you do on any website in their in-app browser",
                    "Link": "https://krausefx.com/blog/ios-privacy-instagram-and-facebook-can-track-anything-you-do-on-any-website-in-their-in-app-browser"
                 }
              ],
              "Authors": ["Felix Krause (@KrauseFx)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2022-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The quantum state of Linux kernel garbage collection CVE-2021-0920 (Part I)",
                    "Link": "https://googleprojectzero.blogspot.com/2022/08/the-quantum-state-of-linux-kernel.html"
                 }
              ],
              "Authors": ["Xingyu Jin"],
              "Programs": ["Linux Kernel Organization", "Google", "Samsung"],
              "Bugs": ["Memory corruption", "Race condition", "Local Privilege Escalation", "Android"],
              "Bounty": "-",
              "PublicationDate": "2022-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Security Implications of URL Parsing Differentials",
                    "Link": "https://blog.sonarsource.com/security-implications-of-url-parsing-differentials"
                 }
              ],
              "Authors": ["Security Implications of URL Parsing Differentials"],
              "Programs": ["Thomas Chauchefoin (@swapgs)"],
              "Bugs": ["Open redirect", "Parsing differentials", "URL parsing issue"],
              "Bounty": "-",
              "PublicationDate": "2022-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Advisory: Cisco Small Business RV Series Routers Web Filter Database Update Command Injection Vulnerability",
                    "Link": "https://onekey.com/blog/advisory-cisco-small-business-rv-series-routers-web-filter-database-update-command-injection-vulnerability/"
                 }
              ],
              "Authors": ["Quentin Kaiser (@QKaiser)"],
              "Programs": ["Cisco"],
              "Bugs": ["OS command injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Shared Dash to Root Bash :: Pre-Authenticated RCE in VMWare vRealize Operations Manager",
                    "Link": "https://srcincite.io/blog/2022/08/09/from-shared-dash-to-root-bash-pre-authenticated-rce-in-vmware-vrealize-operations-manager.html"
                 }
              ],
              "Authors": ["Steven Seeley (@steventseeley)"],
              "Programs": ["VMware"],
              "Bugs": ["Authentication bypass", "Information disclosure", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dancing on the architecture of VMware Workspace ONE Access (ENG)",
                    "Link": "https://petrusviet.medium.com/dancing-on-the-architecture-of-vmware-workspace-one-access-eng-ad592ae1b6dd"
                 }
              ],
              "Authors": ["Petrus Viet (@VietPetrus)"],
              "Programs": ["VMware"],
              "Bugs": ["Authentication bypass", "SQL injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassed Cloudflare’s Web Application Firewall (WAF)",
                    "Link": "https://medium.com/@the_harvester/bypassed-cloudflares-web-application-firewall-waf-44da57f3a1d3"
                 }
              ],
              "Authors": ["Ansh Vaid (@anshvaid4)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "HTML injection", "WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Simple Open Redirect Bypass.",
                    "Link": "http://blog.h4rsh4d.com/2022/08/open-redirect-bypass.html"
                 }
              ],
              "Authors": ["Harshad Gaikwad (@h4rsh4d)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2022-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Shodan to RCE: That one time I hacked a Fortune 500 company.",
                    "Link": "https://systemweakness.com/rooting-jenkins-remote-code-execution-on-a-live-bug-bounty-target-fc2c12d89a2e"
                 }
              ],
              "Authors": ["vimanari_ (@vimanari_)"],
              "Programs": ["-"],
              "Bugs": ["Missing authentication", "Arbitrary file read", "RCE", "Exposed Jenkins instance"],
              "Bounty": "-",
              "PublicationDate": "2022-08-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in app.gitbook.com",
                    "Link": "https://alpinnnnnn13.medium.com/stored-xss-in-app-gitbook-com-6349f42661f7"
                 }
              ],
              "Authors": ["Mohammad Alfin Hidayatullah (@Alpinbrainsec)"],
              "Programs": ["GitBook"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-08-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSD Advisory – Apple Safari ICU Out-Of-Bounds Write",
                    "Link": "https://ssd-disclosure.com/ssd-advisory-apple-safari-icu-out-of-bounds-write/"
                 }
              ],
              "Authors": ["Dohyun Lee (@l33d0hyun)"],
              "Programs": ["Apple"],
              "Bugs": ["Memory corruption", "Out-of-bounds Write"],
              "Bounty": "-",
              "PublicationDate": "2022-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2FA Bypass via Google Identity & OAuth Login",
                    "Link": "https://medium.com/@sharp488/2fa-bypass-via-google-identity-oauth-login-6c991ac837af"
                 }
              ],
              "Authors": ["Sharat Kaikolamthuruthil (@sharp488)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Liferay revisited: A tale of 20k$",
                    "Link": "https://vsrc.vng.com.vn/blog/liferay-revisited-a-tale-of-20k/"
                 }
              ],
              "Authors": ["VNG Security Response Center (@vngsecresponse)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "20,000",
              "PublicationDate": "2022-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Irremovable guest in facebook event — Facebook bug bounty",
                    "Link": "https://medium.com/@rajeevgyawali92/irremovable-guest-in-facebook-event-facebook-bug-bounty-e10e03c98cd5"
                 }
              ],
              "Authors": ["Rajiv Gyawali (@rajiv_gyawali)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-29582 - An io_uring vulnerability",
                    "Link": "https://ruia-ruia.github.io/2022/08/05/CVE-2022-29582-io-uring/"
                 }
              ],
              "Authors": ["Jayden (@Awarau1)", "David Bouman (@pqlqpql)"],
              "Programs": ["Google"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to get 29 free products. | Bug Bounty",
                    "Link": "https://infosecwriteups.com/how-i-was-able-to-get-29-free-products-bug-bounty-845667ab4ad4"
                 }
              ],
              "Authors": ["Fırat"],
              "Programs": ["-"],
              "Bugs": ["Race condition"],
              "Bounty": "-",
              "PublicationDate": "2022-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Revisiting OMI: Analysis of CVE-2022-29149, a privilege escalation vulnerability in Azure OMI",
                    "Link": "https://www.wiz.io/blog/omi-returns-lpe-technical-analysis"
                 }
              ],
              "Authors": ["Nir Ohfeld (@nirohfeld)", "Rotem Lipowitch (@rotemlipowitch)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation","Cloud"],
              "Bounty": "-",
              "PublicationDate": "2022-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-31660 and CVE-2022-31661 (FIXED): VMware Workspace ONE Access, Identity Manager, and vRealize Automation LPE",
                    "Link": "https://www.rapid7.com/blog/post/2022/08/05/cve-2022-31660-and-cve-2022-31661-fixed-vmware-workspace-one-access-identity-manager-and-vrealize-automation-lpe/"
                 }
              ],
              "Authors": ["Spencer McIntyre (@zeroSteiner)"],
              "Programs": ["VMware"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Symlinks as mount portals: Abusing container mount points on MikroTik's RouterOS to gain code execution",
                    "Link": "https://nns.ee/blog/2022/08/05/routeros-container-rce.html"
                 }
              ],
              "Authors": ["nns"],
              "Programs": ["MikroTik"],
              "Bugs": ["Container escape", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "QNAP Poisoned XML Command Injection (Silently Patched)",
                    "Link": "https://www.rapid7.com/blog/post/2022/08/04/qnap-poisoned-xml-command-injection-silently-patched/"
                 }
              ],
              "Authors": ["Jake Baines (@Junior_Baines)"],
              "Programs": ["QNAP"],
              "Bugs": ["OS command injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-08-04",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Came looking for SSRF and found XSS",
                  "Link": "https://ibraradi.gitbook.io/write-up/came-looking-for-ssrf-and-found-xss"
               }
            ],
            "Authors": ["Ibrahim Radi (@ibraradi9)"],
            "Programs": ["-"],
            "Bugs": ["XSS", "WAF bypass"],
            "Bounty": "-",
            "PublicationDate": "2022-08-04",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Hijacking email with Cloudflare Email Routing",
                    "Link": "https://albertpedersen.com/blog/hijacking-email-with-cloudflare-email-routing/"
                 }
              ],
              "Authors": ["Albert Pedersen (@AlbertSPedersen)"],
              "Programs": ["-"],
              "Bugs": ["HTTP response manipulation", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Elasticsearch A Easy Win For Bug Bounty Hunters || How To Find and Report",
                    "Link": "https://tamimhasan404.medium.com/elasticsearch-a-easy-win-for-bug-bounty-hunters-how-to-find-and-report-ddd900395bcb"
                 }
              ],
              "Authors": ["Tamim Hasan (@tamimhasan404)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Gmail's Amp4Email",
                    "Link": "https://www.adico.me/post/xss-in-gmail-s-amp4email"
                 }
              ],
              "Authors": ["Adi \"Adico\" Cohen (@wir3less2)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2022-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "(ZOHO) Manage Engine Desktop Central – SQL Injection / Arbitrary File Write",
                    "Link": "https://labs.jumpsec.com/zoho-manage-engine-desktop-central-sql-injection-arbitrary-file-write/"
                 },
                 {
                    "Title": "Path Traversal / Arbitrary File Write",
                    "Link": "https://labs.jumpsec.com/zoho-manageengine-desktop-central-path-traversal-arbitrary-file-write/"
                 }
              ],
              "Authors": ["Tom Ellson (@tde_sec)"],
              "Programs": ["Zoho"],
              "Bugs": ["SQL injection", "Arbitrary file write", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple bugs in one program leads to 1500€",
                    "Link": "https://canmustdie.medium.com/multiple-bugs-in-one-program-leads-to-1500-c35fcde06bc7"
                 }
              ],
              "Authors": ["can1337 (@canmustdie)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "IDOR", "Broken authorization"],
              "Bounty": "1,500",
              "PublicationDate": "2022-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned 500$ by uploading a file: write-up of one of my first bug bounty",
                    "Link": "https://medium.com/@seeu-inspace/how-i-earned-500-by-uploading-a-file-write-up-of-one-of-my-first-bug-bounty-c174cf8ea553"
                 }
              ],
              "Authors": ["Riccardo Malatesta (@seeu_inspace)"],
              "Programs": ["Semrush"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "500",
              "PublicationDate": "2022-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Instagram photo was present in data backup nearly after two years being deleted.",
                    "Link": "https://medium.com/@the_null_kid/instagram-photo-was-present-in-data-backup-nearly-after-two-years-being-deleted-f0e4d6e108"
                 }
              ],
              "Authors": ["Jeewan Bhatta (@thenullkid)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Privacy issue"],
              "Bounty": "550",
              "PublicationDate": "2022-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS to Account Takeover : Going beyond document.cookie | Stealing Session Data from IndexedDB",
                    "Link": "https://infosecwriteups.com/stored-xss-to-account-takeover-going-beyond-document-cookie-970e42362f43"
                 }
              ],
              "Authors": ["Syed Mushfik Hasan Tahsin (@SMHTahsin33)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned $10,000 within the last 7 months — a 17y/o Edition",
                    "Link": "https://gowtham-naidu.medium.com/how-i-earned-10-000-within-the-last-7-months-17y-o-edition-f566651cef82"
                 }
              ],
              "Authors": ["Gowtham Naidu Ponnana (@gowtham_ponnana)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "10,000",
              "PublicationDate": "2022-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Analysis of Adobe Acrobat Reader Javascript Doc.print() Use-After-Free Vulnerability (CVE-2022-34233)",
                    "Link": "https://www.zscaler.com/blogs/security-research/analysis-adobe-acrobat-reader-javascript-docprint-use-after-free"
                 }
              ],
              "Authors": ["ThreatLabz (@Threatlabz)"],
              "Programs": ["Adobe"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I get Full Account Takeover via stealing action’s login form | XSS",
                    "Link": "https://medium.com/@mohamedtarekq/how-i-get-full-account-takeover-via-stealing-actions-login-form-xss-9e50068c2b2d"
                 }
              ],
              "Authors": ["Mohamed Tarek (@timooon107)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Earned €150 in 2 Minutes | HTML injection in email",
                    "Link": "https://medium.com/@whitehatcyber404/how-i-earned-150-in-2-minutes-html-injection-in-email-3f26f27d3822"
                 }
              ],
              "Authors": ["Thillai Raj"],
              "Programs": ["-"],
              "Bugs": ["HTML injection"],
              "Bounty": "150",
              "PublicationDate": "2022-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Second CVE (CVE-2022-31855)",
                    "Link": "https://y0ungdst.medium.com/my-second-cve-cve-2022-31855-6c071c4fb9d9"
                 }
              ],
              "Authors": ["y0ung_dst (@Y0ung_MA)"],
              "Programs": ["RStudio"],
              "Bugs": ["OS command injection", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zero-day XSS",
                    "Link": "https://infosecwriteups.com/zero-day-xss-309916922ea6"
                 }
              ],
              "Authors": ["th3.d1p4k (@DipakPanchal05)"],
              "Programs": ["IRCTC"],
              "Bugs": ["HTML injection", "Open redirect", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Discord Desktop - Remote Code Execution",
                    "Link": "https://blog.electrovolt.io/posts/discord-rce/"
                 },
                 {
                    "Title": "Video PoC",
                    "Link": "https://twitter.com/S1r1u5_/status/1558689435985752065"
                 }
              ],
              "Authors": ["s1r1us (@s1r1u5_)", "ptr-yudai (@ptrYudai)"],
              "Programs": ["Discord"],
              "Bugs": ["RCE", "XSS", "Sandbox bypass", "CSP bypass"],
              "Bounty": "5,000",
              "PublicationDate": "2022-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business logic vulnerabilities",
                    "Link": "https://sagarsajeev.medium.com/business-logic-vulnerabilities-b4db2af08aaf"
                 }
              ],
              "Authors": ["Sagar Sajeev (@Sagar__Sajeev)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Payment tampering"],
              "Bounty": "400",
              "PublicationDate": "2022-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Arris / Arris-variant DSL/Fiber router critical vulnerability exposure",
                    "Link": "https://derekabdine.com/blog/2022-arris-advisory"
                 }
              ],
              "Authors": ["Derek Abdine (@dabdine)"],
              "Programs": ["ARRIS"],
              "Bugs": ["Path traversal", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reading Message from Microsoft’s Private Yammer Group",
                    "Link": "https://mearegtu.medium.com/reading-message-from-microsofts-private-yammer-group-6be844639bca"
                 }
              ],
              "Authors": ["Meareg"],
              "Programs": ["Microsoft"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "“ParseThru” – Exploiting HTTP Parameter Smuggling in Golang",
                    "Link": "https://www.oxeye.io/blog/golang-parameter-smuggling-attack"
                 }
              ],
              "Authors": ["Daniel Abeles (@Daniel_Abeles)", "Gal Goldsthein (@G4lGo89)"],
              "Programs": ["Harbor", "Traefik", "Skipper"],
              "Bugs": ["HTTP Parameter Smuggling"],
              "Bounty": "-",
              "PublicationDate": "2022-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Researching Open Source apps for XSS to RCE flaws",
                    "Link": "https://swarm.ptsecurity.com/researching-open-source-apps-for-xss-to-rce-flaws/"
                 }
              ],
              "Authors": ["Aleksey Solovev"],
              "Programs": ["-"],
              "Bugs": ["XSS", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerability in Dahua’s ONVIF Implementation Threatens IP Camera Security",
                    "Link": "https://www.nozominetworks.com/blog/vulnerability-in-dahua-s-onvif-implementation-threatens-ip-camera-security/"
                 }
              ],
              "Authors": ["Nozomi Networks Labs (@nozominetworks)"],
              "Programs": ["Dahua"],
              "Bugs": ["MiTM"],
              "Bounty": "-",
              "PublicationDate": "2022-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Corrupting memory without memory corruption",
                    "Link": "https://github.blog/2022-07-27-corrupting-memory-without-memory-corruption/"
                 }
              ],
              "Authors": ["Man Yue Mo (@mmolgtm)"],
              "Programs": ["Google"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSD Advisory – Apple Safari IDN URL Spoofing",
                    "Link": "https://ssd-disclosure.com/ssd-advisory-apple-safari-idn-url-spoofing/"
                 }
              ],
              "Authors": ["Dohyun Lee (@l33d0hyun)"],
              "Programs": ["Apple"],
              "Bugs": ["URL spoofing"],
              "Bounty": "-",
              "PublicationDate": "2022-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected Cross Site Scripting on User Agent-Dependent Response",
                    "Link": "https://medium.com/@xpertwhitehat/reflected-cross-site-scripting-on-user-agent-dependent-response-b44258a3d978"
                 }
              ],
              "Authors": ["Ali Hassan Ghori (@alihasanghauri)"],
              "Programs": ["proto.io"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "100",
              "PublicationDate": "2022-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting GitHub Actions on open source projects",
                    "Link": "https://medium.com/tinder/exploiting-github-actions-on-open-source-projects-5d93936d189f"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)", "Johnny Nipper (@ratherbeonline)", "Tanner Emek (@itscachemoney)"],
              "Programs": ["Elastic"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google XSS",
                    "Link": "https://ndevtk.github.io/writeups/2022/07/26/google-xss/"
                 }
              ],
              "Authors": ["NDevTK (@ndevtk)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "8,133.70",
              "PublicationDate": "2022-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HTTP Parameter Pollution - It’s Contaminated Again",
                    "Link": "https://shahjerry33.medium.com/http-parameter-pollution-its-contaminated-again-95c75b0295e1"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)", "ethicalbughunter (@ethicalbughuntr)", "droppyy33"],
              "Programs": ["-"],
              "Bugs": ["HTTP parameter pollution", "Rate limiting bypass"],
              "Bounty": "50",
              "PublicationDate": "2022-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-31813: Forwarding Addresses Is Hard",
                    "Link": "https://www.synacktiv.com/publications/cve-2022-31813-forwarding-addresses-is-hard.html"
                 }
              ],
              "Authors": ["Gaetan Ferry (@_mabote_)"],
              "Programs": ["Internet Bug Bounty (Apache HTTPD)"],
              "Bugs": ["Host header injection", "DoS", "IP address spoofing"],
              "Bounty": "-",
              "PublicationDate": "2022-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclosing information with a side-channel in Django",
                    "Link": "https://www.sonarsource.com/blog/disclosing-information-with-a-side-channel-in-django/"
                 }
              ],
              "Authors": ["Dennis Brinkrolf (@DBrinkrolf)"],
              "Programs": ["Django"],
              "Bugs": ["Side channel attack"],
              "Bounty": "-",
              "PublicationDate": "2022-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting For Mass Assignment Vulnerabilities Using GitHub CodeSearch and grep.app",
                    "Link": "https://blog.includesecurity.com/2022/07/hunting-for-mass-assignment-vulnerabilities-using-github-codesearch-and-grep-app/"
                 }
              ],
              "Authors": ["Laurence Tennant"],
              "Programs": ["freeCodeCamp"],
              "Bugs": ["Mass assignment"],
              "Bounty": "-",
              "PublicationDate": "2022-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Advisory | Roxy-WI Unauthenticated Remote Code Executions CVE-2022-31137",
                    "Link": "https://pentest.blog/advisory-roxy-wi-unauthenticated-remote-code-executions-cve-2022-31137/"
                 }
              ],
              "Authors": ["Nuri Çilengir (@ncilengir)"],
              "Programs": ["Roxy-WI"],
              "Bugs": ["RCE", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Publicly Accessible Android Crash Reports Containing Sensitive Information",
                    "Link": "https://medium.com/@xpertwhitehat/publicly-accessible-android-crash-reports-containing-sensitive-information-ec1220079f31"
                 }
              ],
              "Authors": ["Ali Hassan Ghori (@alihasanghauri)"],
              "Programs": ["proto.io"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "100",
              "PublicationDate": "2022-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-26712: The POC for SIP-Bypass Is Even Tweetable",
                    "Link": "https://jhftss.github.io/CVE-2022-26712-The-POC-For-SIP-Bypass-Is-Even-Tweetable/"
                 }
              ],
              "Authors": ["Mickey Jin (@patch1t)"],
              "Programs": ["Apple"],
              "Bugs": ["MacOS", "SIP bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022–36446 — Webmin 1.996 — Remote Code Execution (RCE — Authenticated) During Install New Packages",
                    "Link": "https://medium.com/@emirpolat/cve-2022-36446-webmin-1-997-7a9225af3165"
                 }
              ],
              "Authors": ["Emir Polat (@devilsgrins)"],
              "Programs": ["Webmin"],
              "Bugs": ["RCE", "OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2022-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Digging JS files to find BUGs",
                    "Link": "https://adnanmalik.info/blog/digging-js-files-to-find-bugs/"
                 }
              ],
              "Authors": ["Adnan Malik (@adnanmalikinfo)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "2,114",
              "PublicationDate": "2022-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Outdated PHP Version leads to RCE",
                    "Link": "https://medium.com/@iamdevansharya/outdated-php-version-leads-to-rce-380fb4db32f4"
                 }
              ],
              "Authors": ["iamdevansharya (@iamdevansharya)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Old components with known vulnerabilities"],
              "Bounty": "-",
              "PublicationDate": "2022-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DoS worth $650 ? Interesting right!",
                    "Link": "https://sagarsajeev.medium.com/dos-worth-650-interesting-right-144ff45ccf3b"
                 }
              ],
              "Authors": ["Sagar Sajeev (@Sagar__Sajeev)"],
              "Programs": ["-"],
              "Bugs": ["DoS", "Pixel flood attack"],
              "Bounty": "650",
              "PublicationDate": "2022-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Mail Server Misconfiguration leads to sending a fax from anyone’s account on HelloFax (Dropbox BBP) for a bounty of $4,913",
                    "Link": "https://infosecwriteups.com/mail-server-misconfiguration-leads-to-sending-a-fax-from-anyones-account-on-hellofax-dropbox-bbp-aab3d97ab4e7"
                 }
              ],
              "Authors": ["Sayaan Alam (@ehsayaan)"],
              "Programs": ["Dropbox"],
              "Bugs": ["Email spoofing"],
              "Bounty": "4,913",
              "PublicationDate": "2022-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "With Management Comes Risk: Finding Flaws in FileWave MDM",
                    "Link": "https://claroty.com/team82/blog/with-management-comes-risk-finding-flaws-in-filewave-mdm"
                 }
              ],
              "Authors": ["Claroty's Team82 (@Claroty)"],
              "Programs": ["Filewave"],
              "Bugs": ["Authentication bypass", "Hardcoded credentials", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Deep understand ASPX file handling and some related attack vectors",
                    "Link": "https://blog.viettelcybersecurity.com/deep-understand-aspx-file-handling-and-some-related-attack-vector/"
                 }
              ],
              "Authors": ["Rskvp93 (@rskvp93)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation", "WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Technical Advisory – Multiple vulnerabilities in Nuki smart locks (CVE-2022-32509, CVE-2022-32504, CVE-2022-32502, CVE-2022-32507, CVE-2022-32503, CVE-2022-32510, CVE-2022-32506, CVE-2022-32508, CVE-2022-32505)",
                    "Link": "https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/"
                 }
              ],
              "Authors": ["Daniel Romero (@daniel_rome)", "Pablo Lorenzo & Guillermo del Valle Gil"],
              "Programs": ["Nuki"],
              "Bugs": ["Memory corruption", "DoS", "Broken Access Control", "Sensitive Information Sent Over an Unencrypted Channel"],
              "Bounty": "-",
              "PublicationDate": "2022-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Gained Access To A Finance Company’s Accounts (Session Hijacking)",
                    "Link": "https://medium.com/@talhakarakumru/how-i-gained-access-to-a-finance-companys-accounts-session-hijacking-2c6c5d9d84bd"
                 }
              ],
              "Authors": ["Talha Karakumru"],
              "Programs": ["-"],
              "Bugs": ["Session fixation", "Weak crypto"],
              "Bounty": "-",
              "PublicationDate": "2022-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Developer’s Nightmare: Story of a simple IDOR and some poor fixes worth $1125",
                    "Link": "https://medium.com/@720922/a-developers-nightmare-story-of-a-simple-idor-and-some-poor-fixes-worth-1125-5ead70b0a1de"
                 }
              ],
              "Authors": ["Marcos IAF (@marcos_iaf)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "1,125",
              "PublicationDate": "2022-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made 300 GitHub repos point to my blog using Azure subdomains takeover",
                    "Link": "https://0xpwn.wordpress.com/2022/07/23/how-i-made-300-github-repos-point-to-my-blog-using-azure-subdomains-takeover/"
                 }
              ],
              "Authors": ["0xPwN (@msd0s7)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$$$ bounty in less 3 minutes from a google dork",
                    "Link": "https://medium.com/@Steiner254/bounty-in-less-3-minutes-from-a-google-dork-54bd9bf3a650"
                 }
              ],
              "Authors": ["Steiner254 (@steiner254)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Un3xpected DoS Attack on Profile Pictur3",
                    "Link": "https://infosecwriteups.com/un3xpected-dos-attack-on-profile-pictur3-b957979dcc7"
                 }
              ],
              "Authors": ["Roxst4r (@mveswar98)"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "100",
              "PublicationDate": "2022-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SecStory: How I Found Multiple P1 Vulnerabilities without Recon",
                    "Link": "https://medium.com/@rival.rvdt/secstory-how-i-found-multiple-p1-vulnerabilities-without-recon-c9f3a19cad45"
                 }
              ],
              "Authors": ["rvdt (@rival_rvdt)"],
              "Programs": ["-"],
              "Bugs": ["Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2022-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WordPress Transposh: Exploiting a Blind SQL Injection via XSS - RCE Security",
                    "Link": "https://www.rcesecurity.com/2022/07/WordPress-Transposh-Exploiting-a-Blind-SQL-Injection-via-XSS/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["WordPress"],
              "Bugs": ["SQL injection", "XSS", "Account takeover"],
              "Bounty": "30,000",
              "PublicationDate": "2022-07-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Permanent Crash Instagram Followers.",
                    "Link": "https://www.yesnaveen.com/2022/07/permanently-crash-instagram-followers.html"
                 }
              ],
              "Authors": ["Naveen (@NaveenHax)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS"],
              "Bounty": "1,000",
              "PublicationDate": "2022-07-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to Take over a support chat using leaked Keys",
                    "Link": "https://medium.com/@IroquoisPliskin/how-i-was-able-to-take-over-a-support-chat-using-leaked-keys-d5c4922bb3d4"
                 }
              ],
              "Authors": ["Pliskin"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,000",
              "PublicationDate": "2022-07-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwn2Own Miami 2022: Inductive Automation Remote Code Execution",
                    "Link": "https://sector7.computest.nl/post/2022-07-inductive-automation-ignition-rce/"
                 }
              ],
              "Authors": ["Sector 7 (@sector7_nl)"],
              "Programs": ["Inductive Automation Ignition"],
              "Bugs": ["RCE", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-07-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I mean, IDOR is NOT only about others ID",
                    "Link": "https://infosecwriteups.com/i-mean-idor-is-not-only-about-others-id-2d26115072ba"
                 }
              ],
              "Authors": ["can1337 (@canmustdie)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-07-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Test For Web Cache Vulnerabilities + Tips And Tricks",
                    "Link": "https://bxmbn.medium.com/how-i-test-for-web-cache-vulnerabilities-tips-and-tricks-9b138da08ff9"
                 }
              ],
              "Authors": ["Kevin (@bxmbn)"],
              "Programs": ["-"],
              "Bugs": ["Web cache poisoning", "Web cache deception"],
              "Bounty": "3,500",
              "PublicationDate": "2022-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Gitlab Project Import RCE Analysis (CVE-2022-2185)",
                    "Link": "https://starlabs.sg/blog/2022/07-gitlab-project-import-rce-analysis-cve-2022-2185/"
                 }
              ],
              "Authors": ["Nguyễn Tiến Giang (@testanull)"],
              "Programs": ["GitLab"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing the Replicator: Silently Exfiltrating Data with the AWS S3 Replication Service",
                    "Link": "https://www.vectra.ai/blogpost/abusing-the-replicator-silently-exfiltrating-data-with-the-aws-s3-replication-service"
                 }
              ],
              "Authors": ["Kat Traxler (@NightmareJS)"],
              "Programs": ["AWS"],
              "Bugs": ["Security Logging and Monitoring Failure"],
              "Bounty": "-",
              "PublicationDate": "2022-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[CVE-2022-34918] A crack in the Linux firewall",
                    "Link": "https://www.randorisec.fr/crack-linux-firewall/"
                 }
              ],
              "Authors": ["Arthur Mongodin"],
              "Programs": ["Linux Kernel Organization"],
              "Bugs": ["Memory corruption", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "React debug.keystore key was trusted by Meta(Facebook) which caused to Instagram account takeover by malicious apps.",
                    "Link": "https://www.vulnano.com/2022/07/react-debugkeystore-key-was-trusted-by.html"
                 }
              ],
              "Authors": ["Dzmitry Lukyanenka (@vulnano)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Account takeover", "Android"],
              "Bounty": "12,000",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Riding The Inforail To Exploit Ivanti Avalanche",
                    "Link": "https://www.zerodayinitiative.com/blog/2022/7/19/riding-the-inforail-to-exploit-ivanti-avalanche"
                 }
              ],
              "Authors": ["Piotr Bazydło (@chudyPB)"],
              "Programs": ["Ivanti"],
              "Bugs": ["RCE", "Insecure deserialization", "Race condition", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write-up: BlogEngine .NET - 0day Discovery",
                    "Link": "https://www.0xlanks.me/blog/blogengine-writeup"
                 }
              ],
              "Authors": ["Jake McCallum (@0xLanks)", "Ethan (@complex201)"],
              "Programs": ["BlogEngine .NET"],
              "Bugs": ["Path traversal", "XXE"],
              "Bounty": "-",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Local File Inclusion (interesting method)",
                    "Link": "https://captainhoook.medium.com/local-file-inclusion-interesting-method-8263c2cb7cd2"
                 }
              ],
              "Authors": ["Captain hook"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-30526 (Fixed): Zyxel Firewall Local Privilege Escalation",
                    "Link": "https://www.rapid7.com/blog/post/2022/07/19/cve-2022-30526-fixed-zyxel-firewall-local-privilege-escalation/"
                 }
              ],
              "Authors": ["Jake Baines (@Junior_Baines)"],
              "Programs": ["Zyxel"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSD Advisory – Microsoft SharePoint Server WizardConnectToDataStep4 Deserialization Of Untrusted Data RCE",
                    "Link": "https://ssd-disclosure.com/ssd-advisory-microsoft-sharepoint-server-wizardconnecttodatastep4-deserialization-of-untrusted-data-rce/"
                 }
              ],
              "Authors": ["Alex Birnberg (@alexbirnberg)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Insecure deserialization", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Logging Passwords in Plaintext in Azure Arc",
                    "Link": "https://medium.com/tenable-techblog/logging-passwords-in-plaintext-in-azure-arc-2f94cb046a"
                 }
              ],
              "Authors": ["Jimi Sebree (@DinoBytes)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure", "Local Privilege Escalation", "Cloud"],
              "Bounty": "-",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to bypass Open Redirect 3 times on same program.",
                    "Link": "https://hunter-55.medium.com/how-i-was-able-to-bypass-open-redirect-3-times-on-same-program-d78f9d2443f6"
                 }
              ],
              "Authors": ["himanshu pdy (@himanshu_pdy)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "300",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass",
                    "Link": "https://sector7.computest.nl/post/2022-07-opc-ua-net-standard-trusted-application-check-bypass/"
                 }
              ],
              "Authors": ["Sector 7 (@sector7_nl)"],
              "Programs": ["OPC Foundation"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "40,000",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authomize Discovers PassBleed Password Stealing and Impersonation Risks in Okta",
                    "Link": "https://www.authomize.com/blog/authomize-discovers-password-stealing-and-impersonation-risks-to-in-okta/"
                 },
                 {
                    "Title": "Okta Response to Security Report",
                    "Link": "https://www.okta.com/blog/2022/07/okta-response-to-security-report/"
                 }
              ],
              "Authors": ["Authomize (@Authomize)"],
              "Programs": ["Okta"],
              "Bugs": ["Sensitive data sent over an unencrypted channel", "Broken authorization", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "MyBB 0day Authenticated Remote code execution",
                    "Link": "https://0x1337.ninja/2022/07/19/mybb-0day-authenticated-remote-code-execution/"
                 }
              ],
              "Authors": ["Anna / 416e6e61 (@AnnaViolet20)"],
              "Programs": ["MyBB"],
              "Bugs": ["RCE", "Argument injection"],
              "Bounty": "-",
              "PublicationDate": "2022-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Facebook Invoice: How I could’ve bought anything for Free from Facebook Business Pages",
                    "Link": "https://infosecwriteups.com/hacking-facebook-invoice-how-i-couldve-bought-anything-for-free-from-facebook-business-pages-42bcfaa73ec4"
                 }
              ],
              "Authors": ["Samip Aryal (@samiparyal_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Payment bypass"],
              "Bounty": "250",
              "PublicationDate": "2022-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hey Google Lets submit bug from Victim Account !",
                    "Link": "https://virtuvil.medium.com/hey-google-lets-submit-bug-from-victim-account-af6a25d390e1"
                 }
              ],
              "Authors": ["Prasanth Elangovan"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Good things takes time | Story of my first “valid” critical bug!",
                    "Link": "https://infosecwriteups.com/story-of-my-first-valid-critical-bug-22029115f8d7"
                 }
              ],
              "Authors": ["Kr1shna 4garwal (@Kr1shna4garwal)"],
              "Programs": ["-"],
              "Bugs": ["Missing authentication", "Exposed administrative interface"],
              "Bounty": "-",
              "PublicationDate": "2022-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022–35909 / CVE-2022–35910, Incorrect Access Control and XSS Stored to Jellyfin",
                    "Link": "https://medium.com/stolabs/cve-2022-35909-cve-2022-35910-incorrect-access-control-and-xss-stored-to-jellyfin-967359c91058"
                 }
              ],
              "Authors": ["Dan Barros", "Eduardo Cardoso"],
              "Programs": ["jellyfin"],
              "Bugs": ["Broken Access Control", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "FFUF-ing RECON, or how to get to P1–P3 from a slightly different recon",
                    "Link": "https://infosecwriteups.com/ffuf-ing-recon-1ee4e79b3256"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["vHost misconfiguration", "403 bypass", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Story Of My First Bug Bounty",
                    "Link": "https://medium.com/@rajqureshi07/a-story-of-my-first-bug-bounty-dda320db78d9"
                 }
              ],
              "Authors": ["Raj Qureshi (@RajQureshi9)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Going beyond Alert with XSS",
                    "Link": "https://securityflow.io/going-beyond-alert-with-xss/"
                 }
              ],
              "Authors": ["pipsh"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CRLF to Account takeover (chaining bugs)",
                    "Link": "https://medium.com/@moSec/crlf-to-account-takeover-chaining-bugs-21a25dfa1cdf"
                 }
              ],
              "Authors": ["MoSec (@moe1n1)"],
              "Programs": ["-"],
              "Bugs": ["CRLF injection", "XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain takeover and Text injection on a 404 error page-$100 bounty",
                    "Link": "https://medium.com/@the_null_kid/subdomain-takeover-and-text-injection-on-a-404-error-page-100-bounty-e47ccf359e6b"
                 }
              ],
              "Authors": ["Jeewan Bhatta (@thenullkid)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "100",
              "PublicationDate": "2022-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business logic error",
                    "Link": "https://medium.com/@anjaneyulukanakatla1996/business-logic-error-6922ba75cad8"
                 }
              ],
              "Authors": ["anjaneyulu kanakatla"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "First Bug Bounty from DOS: Taking the service down",
                    "Link": "https://medium.com/@faique/first-bug-bounty-from-dos-taking-the-service-down-30f9ad4e0246"
                 }
              ],
              "Authors": ["Faique (@imfaiqu3)"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "200",
              "PublicationDate": "2022-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authorization token leak from verify email endpoint",
                    "Link": "https://vengeance.medium.com/authorization-token-leak-from-verifying-email-endpoint-f28803476680"
                 }
              ],
              "Authors": ["Vengeance"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Ability to login as google staff in Google Cloud Community",
                    "Link": "https://medium.com/@bhatiagaurav1211/ability-to-login-as-google-staff-in-google-cloud-community-57c45809de05"
                 }
              ],
              "Authors": ["Gaurav Bhatia"],
              "Programs": ["Google"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "100",
              "PublicationDate": "2022-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Good Recon Leads To Senssitive Accounts",
                    "Link": "https://medium.com/@milanjain7906/good-recon-leads-to-senssitive-accounts-a8abb6c21333"
                 }
              ],
              "Authors": ["Milanjain"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Username enumeration"],
              "Bounty": "-",
              "PublicationDate": "2022-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Arbitrary Object Instantiations in PHP without Custom Classes",
                    "Link": "https://medium.com/@evilmango/this-is-what-i-call-mass-idor-20e6ec146c0e"
                 }
              ],
              "Authors": ["Muhammad Talha / evilmango"],
              "Programs": ["-"],
              "Bugs": ["Lack of rate limiting", "Privilege escalation", "IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Got My First CVE",
                    "Link": "https://medium.com/@tobydavenn/how-i-got-my-first-cve-a157606cc86e"
                 }
              ],
              "Authors": ["Tobydavenn"],
              "Programs": ["U.S. Dept Of Defense"],
              "Bugs": ["Application-level DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I spammed a Google meet (But for good)",
                    "Link": "https://medium.com/@shaunak007/how-i-spammed-a-google-meet-but-for-good-8bc5b328f1bb"
                 }
              ],
              "Authors": ["Shaunak (SHA25)"],
              "Programs": ["Google"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Arbitrary Object Instantiations in PHP without Custom Classes",
                    "Link": "https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations/"
                 }
              ],
              "Authors": ["Arseniy Sharoglazov (@_mohemiv)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Arbitrary Object Instantiation", "Bruteforce", "LDAP injection"],
              "Bounty": "-",
              "PublicationDate": "2022-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tableau Server Leaks Sensitive Information From Reflected XSS",
                    "Link": "https://www.gosecure.net/blog/2022/07/13/tableau-server-leaks-sensitive-information-from-reflected-xss/"
                 }
              ],
              "Authors": ["Simon Bouchard (@SimTwisted)"],
              "Programs": ["Salesforce"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing URL Shortners for fun and profit",
                    "Link": "https://infosecwriteups.com/abusing-url-shortners-for-fun-and-profit-c83c67713916"
                 }
              ],
              "Authors": ["Sicksec (@OriginalSicksec)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Account takeover", "IDOR"],
              "Bounty": "3,000",
              "PublicationDate": "2022-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-30136: Microsoft Windows Network File System V4 Remote Code Execution Vulnerability",
                    "Link": "https://www.zerodayinitiative.com/blog/2022/7/13/cve-2022-30136-microsoft-windows-network-file-system-v4-remote-code-execution-vulnerability"
                 }
              ],
              "Authors": ["Yuki Chen (@guhe120)", "Guy Lederfein (@glederfein)", "Quintin Crist"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE", "DoS", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Open Redirect to Reflected XSS manually",
                    "Link": "https://medium.com/@rodricbr/from-open-redirect-to-reflected-xss-manually-64e633a3d23f"
                 }
              ],
              "Authors": ["Rodric"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-07-14",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "How I found my first RCE!",
                  "Link": "https://infosecwriteups.com/how-i-found-my-first-rce-c063546114ef"
               }
            ],
            "Authors": ["TheBountyBox (@thebountybox)"],
            "Programs": ["-"],
            "Bugs": ["RCE", "Components with known vulnerabilities", "WSO2", "SSRF"],
            "Bounty": "-",
            "PublicationDate": "2022-07-13",
            "AddedDate": "2022-12-12"
         },
           {
              "Links": [
                 {
                    "Title": "Microsoft Teams — Cross Site Scripting (XSS) Bypass CSP",
                    "Link": "https://medium.com/@numanturle/microsoft-teams-stored-xss-bypass-csp-8b4a7f5fccbf"
                 }
              ],
              "Authors": ["Numan Turle (@numanturle)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS", "CSP bypass", "HTML injection"],
              "Bounty": "6,000",
              "PublicationDate": "2022-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-26706",
                    "Link": "https://www.microsoft.com/security/blog/2022/07/13/uncovering-a-macos-app-sandbox-escape-vulnerability-a-deep-dive-into-cve-2022-26706/"
                 }
              ],
              "Authors": ["Microsoft 365 Defender Research Team"],
              "Programs": ["Apple"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking on a Private Program (Salseforce crm)",
                    "Link": "https://thinkermaruf.medium.com/hacking-on-a-private-program-salseforce-crm-12bfef43fcc7"
                 }
              ],
              "Authors": ["Maruf Hosan (@thinkermaruff)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "OS command injection"],
              "Bounty": "300",
              "PublicationDate": "2022-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-29885 - Don't Open That Port - A Denial Of Service vulnerability on Apache Tomcat Cluster Service Listener",
                    "Link": "https://voidzone.me/cve-2022-29885-apache-tomcat-cluster-service-dos/"
                 }
              ],
              "Authors": ["void (@voidz0r)"],
              "Programs": ["Internet Bug Bounty"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Netwrix Auditor Advisory",
                    "Link": "https://bishopfox.com/blog/netwrix-auditor-advisory"
                 }
              ],
              "Authors": ["Jordan Parkin"],
              "Programs": ["Netwrix"],
              "Bugs": ["Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2022-07-13",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Leveraging the SQL Injection to Execute the XSS by Evading CSP",
                  "Link": "https://nirmaldahal.com.np/posts/2022/07/leveraging-the-sql-injection-to-execute-the-xss-by-evading-csp/"
               }
            ],
            "Authors": ["Nirmal Dahal (@TheNittam)"],
            "Programs": ["-"],
            "Bugs": ["CSP bypass", "SQL injection", "XSS"],
            "Bounty": "-",
            "PublicationDate": "2022-07-12",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-32223 Discovery: DLL Hijacking via npm CLI",
                    "Link": "https://blog.aquasec.com/cve-2022-32223-dll-hijacking"
                 }
              ],
              "Authors": ["Yakir Kadkoda"],
              "Programs": ["Node.js"],
              "Bugs": ["DLL Hijacking", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Azure Site Recovery DLL Hijacking",
                    "Link": "https://medium.com/tenable-techblog/microsoft-azure-site-recovery-dll-hijacking-cd8cc34ef80c"
                 }
              ],
              "Authors": ["Jimi Sebree (@DinoBytes)"],
              "Programs": ["Microsoft"],
              "Bugs": ["DLL Hijacking", "Privilege escalation"],
              "Bounty": "10,000",
              "PublicationDate": "2022-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up 1: Hellosign Integration [Full Read SSRF]",
                    "Link": "https://medium.com/@soufianehabti/write-up-1-hellosign-integration-full-read-ssrf-df5e1a5bc627"
                 }
              ],
              "Authors": ["Soufiane Habti (@wld_basha)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "2,000",
              "PublicationDate": "2022-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How a Simple IDOR Led Me to Delete Any Account",
                    "Link": "https://payatu.com/blog/rajesh.r/idor-to-account-deletion"
                 }
              ],
              "Authors": ["rajesh.r (@_rajesh_ranjan_)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Code Execution via Prototype Pollution in Blitz.js",
                    "Link": "https://blog.sonarsource.com/blitzjs-prototype-pollution/"
                 }
              ],
              "Authors": ["Paul Gerste"],
              "Programs": ["Blitz.js"],
              "Bugs": ["Prototype pollution", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How we have pwned Root-Me in 2022",
                    "Link": "https://spawnzii.github.io/posts/2022/07/how-we-have-pwned-root-me-in-2022/"
                 }
              ],
              "Authors": ["Romain Brun (@SpawnZii)", "Abyss Watcher"],
              "Programs": ["SPIP"],
              "Bugs": ["XSS", "CSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty Collaboration and Manual Exploitation of an Interesting Boolean SQL Injection",
                    "Link": "https://h3k.ro/2022/07/11/bsqli/"
                 }
              ],
              "Authors": ["Tavi (@0xtavi)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "1,000",
              "PublicationDate": "2022-07-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Authentication in AWS IAM Authenticator for Kubernetes",
                    "Link": "https://blog.lightspin.io/exploiting-eks-authentication-vulnerability-in-aws-iam-authenticator"
                 }
              ],
              "Authors": ["Gafnit Amiga (@gafnitav)"],
              "Programs": ["AWS"],
              "Bugs": ["Broken authentication", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-07-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned 200$ in Bug Bounty Program",
                    "Link": "https://medium.com/@idan_malihi/how-i-earned-200-in-bug-bounty-program-6d7225a7ff1a"
                 }
              ],
              "Authors": ["Idan Malihi"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "200",
              "PublicationDate": "2022-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting SQL Injection at Authorization token",
                    "Link": "https://www.techncyber.com/2022/07/sql-injection-at-authorization-token.html"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://medium.com/@basudev_18233/exploiting-sql-injection-at-authorization-token-8764a0dcac1a"
                 }
              ],
              "Authors": ["Basudev"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An interesting idor that allowed me to See all projects ($$$$ Bounty)",
                    "Link": "https://hamzadzworm.medium.com/an-interesting-idor-that-allowed-me-to-see-all-projects-bounty-8cd74b5edf72"
                 }
              ],
              "Authors": ["Abdelkader Mouaz (@hamzadzworm)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Flash XSS in ajax.googleapis.com",
                    "Link": "https://bloggerrando.blogspot.com/2022/07/09-1.html"
                 }
              ],
              "Authors": ["R ando (@Rando02355205)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-07-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Advisory | GLPI Service Management Software Multiple Vulnerabilities and Remote Code Execution",
                    "Link": "https://pentest.blog/advisory-glpi-service-management-software-sql-injection-remote-code-execution-and-local-file-inclusion/"
                 }
              ],
              "Authors": ["Nuri Çilengir (@ncilengir)"],
              "Programs": ["GLPI"],
              "Bugs": ["SQL injection", "RCE", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2022-07-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "stored XSS and stored HTML Injection in United Nations Website",
                    "Link": "https://medium.com/@Bishoo97x/stored-xss-and-stored-html-injection-in-united-nations-website-db87d445e41"
                 }
              ],
              "Authors": ["Ahmed Hassan"],
              "Programs": ["United Nations"],
              "Bugs": ["XSS", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2022-07-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover via Response Manipulation",
                    "Link": "https://medium.com/@bughunt789/account-takeover-via-response-manipulation-96be568feb7e"
                 }
              ],
              "Authors": ["BUG HUNTER"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "Account takeover", "2FA / MFA bypass", "HTTP response manipulation"],
              "Bounty": "2,500",
              "PublicationDate": "2022-07-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PII Disclosure of Apple Users ($10k)",
                    "Link": "https://ahmdhalabi.medium.com/pii-disclosure-of-apple-users-10k-d1e3d29bae36"
                 }
              ],
              "Authors": ["Ahmad Halabi (@Ahmad_Halabi_)"],
              "Programs": ["Apple"],
              "Bugs": ["IDOR", "Lack of rate limiting", "Bruteforce", "Information disclosure"],
              "Bounty": "10,000",
              "PublicationDate": "2022-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Case Study of API Vulnerabilities - Part 2, and Empty Heads",
                    "Link": "https://monke.ie/case-study-part-2/"
                 }
              ],
              "Authors": ["Monke (@pmofcats)", "Bend Theory (@bendtheory)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I find open redirect in Facebook",
                    "Link": "https://medium.com/@abhinavsecondary/how-i-find-open-redirect-in-facebook-7e7aeb89535d"
                 }
              ],
              "Authors": ["Abhinav Kumar (@abhinavsecond)"],
              "Programs": ["Brave Software"],
              "Bugs": ["Open redirect"],
              "Bounty": "500",
              "PublicationDate": "2022-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Interesting Privilege Escalation In an Old Private Program",
                    "Link": "https://ivreznap.medium.com/interesting-privilege-escalation-in-an-old-private-program-225d27253e13"
                 }
              ],
              "Authors": ["Zunaid Mahmud (@SZ_Mahmud_7)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "900",
              "PublicationDate": "2022-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account hijacking using \"dirty dancing\" in sign-in OAuth-flows",
                    "Link": "https://labs.detectify.com/2022/07/06/account-hijacking-using-dirty-dancing-in-sign-in-oauth-flows/"
                 },
                 {
                    "Title": "PoC video",
                    "Link": "https://twitter.com/fransrosen/status/1554498536909201408"
                 }
              ],
              "Authors": ["Frans Rosén (@fransrosen)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "Account takeover", "OAuth Dirty Dancing"],
              "Bounty": "-",
              "PublicationDate": "2022-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-34265",
                    "Link": "https://github.com/aeyesec/CVE-2022-34265"
                 }
              ],
              "Authors": ["Takuto Yoshikai (@TakutoYoshikai)"],
              "Programs": ["Django"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found Open redirect on Bug crowd public program in 2 day",
                    "Link": "https://medium.com/@ittipatjitrada_72022/how-i-found-open-redirect-on-bug-crowd-public-program-in-2-day-a217cfb70f3"
                 }
              ],
              "Authors": ["Ittipatjitrada (@IttipatJitrada)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2022-07-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exposing Millions of Voter ID card users’ details.",
                    "Link": "https://infosecwriteups.com/exposing-millions-of-voter-id-card-users-details-8a993c9a5d35"
                 }
              ],
              "Authors": ["Aziz Al Aman (@nxtexploit)"],
              "Programs": ["CERT-In"],
              "Bugs": ["IDOR", "OTP bypass", "Account takeover", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-07-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Rediscovering Epic Games 0-Days (Forever Unpatched?)",
                    "Link": "https://www.signal-labs.com/blog/rediscovering-epic-games-0-days"
                 }
              ],
              "Authors": ["Christopher Vella (@Kharosx0)"],
              "Programs": ["Epic Games"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-07-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "We Hacked Larksuite For 1 month and Here is what we found",
                    "Link": "https://web.archive.org/web/20220716152713/https://snapsec.co/blog/hacking-larksuite/"
                 }
              ],
              "Authors": ["Snap Sec (@snap_sec)"],
              "Programs": ["Lark Technologies"],
              "Bugs": ["XSS", "IDOR", "Privilege escalation", "Broken Access Control", "CSRF", "40x bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-07-04",
              "AddedDate": "2022-09-15"
           },
         {
            "Links": [
               {
                  "Title": "Penetration Testing Firebase Web Applications",
                  "Link": "https://bhashit.in/?p=71"
               }
            ],
            "Authors": ["Bhashit Pandya (@x30r_)"],
            "Programs": ["-"],
            "Bugs": ["Firebase", "Information disclosure"],
            "Bounty": "-",
            "PublicationDate": "2022-07-03",
            "AddedDate": "2022-12-09"
         },
           {
            "Links": [
               {
                  "Title": "($$$) Origin ip to account takeover",
                  "Link": "https://medium.com/@kashyapherry147/origin-ip-to-account-takeover-62d7a54abebf"
               }
            ],
            "Authors": ["Hemant Kumar"],
            "Programs": ["-"],
            "Bugs": ["WAF bypass", "Password reset", "Host header injection", "Account takeover"],
            "Bounty": "-",
            "PublicationDate": "2022-07-02",
            "AddedDate": "2022-12-09"
         },
         {
            "Links": [
               {
                  "Title": "Vertical Privilege Escalation: The user can takeover an admin account via response manipulation",
                  "Link": "https://janmuhammadzaidi.medium.com/vertical-privilege-escalation-the-user-can-takeover-an-admin-account-via-response-manipulation-9237c8b2fefa"
               }
            ],
            "Authors": ["Jan Muhammad Zaidi (@hasanakajan)"],
            "Programs": ["-"],
            "Bugs": ["Privilege escalation", "HTTP response manipulation"],
            "Bounty": "-",
            "PublicationDate": "2022-07-02",
            "AddedDate": "2022-12-09"
         },
         {
              "Links": [
                 {
                    "Title": "A swag for a Open Redirect — Google Dork — Bug Bounty",
                    "Link": "https://infosecwriteups.com/a-swag-for-a-open-redirect-google-dork-bug-bounty-2143b943f34e"
                 }
              ],
              "Authors": ["Proviesec (@proviesec)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2022-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Admin account takeover via weird Password Reset Functionality",
                    "Link": "https://0xmahmoudjo0.medium.com/admin-account-takeover-via-weird-password-reset-functionality-166ce90b1e58"
                 }
              ],
              "Authors": ["Mahmoud Youssef (@0xmahmoudjo0)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Authentication bypass", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2022-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Get root on macOS 12.3.1: proof-of-concepts for Linus Henze's CoreTrust and DriverKit bugs (CVE-2022-26766, CVE-2022-26763)",
                    "Link": "https://worthdoingbadly.com/coretrust/"
                 }
              ],
              "Authors": ["Zhuowei Zhang (@zhuowei)"],
              "Programs": ["Apple"],
              "Bugs": ["Signature validation bypass", "Memory corruption", "Local Privilege Escalation", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2022-07-02",
              "AddedDate": "2022-10-10"
           },
           {
              "Links": [
                 {
                    "Title": "Two faces of a same PDF document",
                    "Link": "https://blog.fraktal.fi/two-faces-of-the-same-pdf-document-17e7a15522a0"
                 }
              ],
              "Authors": ["Toni Huttunen"],
              "Programs": ["Mozilla", "Google", "Adobe"],
              "Bugs": ["PDF parser differential attack"],
              "Bounty": "-",
              "PublicationDate": "2022-07-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Portal’s business logic error lead to 500$",
                    "Link": "https://medium.com/@unurbayar1998/facebook-portals-business-logic-error-lead-to-500-708e91b4055f"
                 }
              ],
              "Authors": ["unurbayar amarsaikhan (@0xunuruu)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2022-06-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Visual Studio Code - Remote Code Execution in Restricted Mode (CVE-2021-43908)",
                    "Link": "https://blog.electrovolt.io/posts/vscode-rce/"
                 }
              ],
              "Authors": ["s1r1us (@s1r1u5_)", "Maxwell Garrett (@TheGrandPew)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE", "XSS"],
              "Bounty": "3,000",
              "PublicationDate": "2022-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Firefox's HTML Sanitizer API",
                    "Link": "https://portswigger.net/research/bypassing-firefoxs-html-sanitizer-api"
                 }
              ],
              "Authors": ["Gareth Heyes (@garethheyes)"],
              "Programs": ["Mozilla"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus",
                    "Link": "https://www.horizon3.ai/red-team-blog-cve-2022-28219/"
                 }
              ],
              "Authors": ["Naveen Sunkavally"],
              "Programs": ["Zoho"],
              "Bugs": ["XXE", "SSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Blind Stored at 2 Assets TikTok",
                    "Link": "https://aidilarf.medium.com/xss-blind-stored-at-2-assets-tiktok-f32829f11e58"
                 }
              ],
              "Authors": ["Aidil Arief"],
              "Programs": ["TikTok"],
              "Bugs": ["XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2022-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Apple Bug And My First Writeup",
                    "Link": "https://medium.com/@aravindb26/my-first-apple-bug-and-my-first-writeup-8a833e8e953c"
                 }
              ],
              "Authors": ["Banavath Aravind (@nanicyb)"],
              "Programs": ["Apple"],
              "Bugs": ["IDOR", "Email verification bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[BugBounty] how do I get a premium tier account without paying a penny",
                    "Link": "https://iamnoob.medium.com/bugbounty-how-do-i-get-a-premium-tier-account-without-paying-a-penny-767921a6c4e4"
                 }
              ],
              "Authors": ["Marzuki (@aizack_ma)"],
              "Programs": ["-"],
              "Bugs": ["Mass assignment", "Payment bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Army Of The Headless Browsers",
                    "Link": "https://medium.com/@TheKomodoconsulting/the-army-of-the-headless-browsers-11aad3f7ee81"
                 }
              ],
              "Authors": ["Komodo Cyber Consulting (@Komodosec)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DDoS", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                {
                   "Title": "Pwning ManageEngine — From PoC to Exploit: A deep dive into CVE-2020–11531 and CVE-2020–11532",
                   "Link": "https://medium.com/@erik.wynter/pwning-manageengine-from-poc-to-exploit-cfe5adb8c175"
                }
               ],
              "Authors": ["Erik Wynter (@WynterErik)"],
              "Programs": ["Zoho"],
              "Bugs": ["Path traversal", "RCE", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-06-28",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                 {
                    "Title": "Unrar Path Traversal Vulnerability affects Zimbra Mail",
                    "Link": "https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/"
                 }
              ],
              "Authors": ["Sonar (@SonarSource)"],
              "Programs": ["Zimbra"],
              "Bugs": ["Path traversal", "Arbitrary file write", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing .NET Serialization Binders",
                    "Link": "https://codewhitesec.blogspot.com/2022/06/bypassing-dotnet-serialization-binders.html"
                 }
              ],
              "Authors": ["Markus Wulftange (@mwulftange)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Insecure deserialization", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "FabricScape: Escaping Service Fabric and Taking Over the Cluster",
                    "Link": "https://unit42.paloaltonetworks.com/fabricscape-cve-2022-30137/"
                 }
              ],
              "Authors": ["Unit 42 (@Unit42_Intel)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Container escape", "Local Privilege Escalation", "Cross-tenant vulnerability"],
              "Bounty": "-",
              "PublicationDate": "2022-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Access control worth $2000 (everyone missed this IDOR+Access control between two admins.)",
                    "Link": "https://medium.com/pentesternepal/access-control-worth-2000-everyone-missed-this-idor-access-control-between-two-admins-9745eaf15d21"
                 }
              ],
              "Authors": ["dhakal_bibek (@dhakal__bibek)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Broken Access Control"],
              "Bounty": "2,000",
              "PublicationDate": "2022-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-3779: Ruby-MySQL Gem Client File Read (FIXED)",
                    "Link": "https://www.rapid7.com/blog/post/2022/06/28/cve-2021-3779-ruby-mysql-gem-client-file-read-fixed/"
                 }
              ],
              "Authors": ["Hans-Martin Münch (@h0ng10)"],
              "Programs": ["Rapid7"],
              "Bugs": ["Client File Read"],
              "Bounty": "-",
              "PublicationDate": "2022-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-30522 – Denial of Service (DoS) Vulnerability in Apache httpd “mod_sed” filter",
                    "Link": "https://jfrog.com/blog/cve-2022-30522-denial-of-service-dos-vulnerability-in-apache-httpd-mod_sed-filter/"
                 }
              ],
              "Authors": ["JFrog Security Research Team (@JFrogSecurity)"],
              "Programs": ["Internet Bug Bounty"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HTML and Hyperlink Injection via Share Option In Microsoft Onenote Application",
                    "Link": "https://infosecwriteups.com/html-and-hyperlink-injection-via-share-option-in-microsoft-onenote-application-47e94d0e6478"
                 }
              ],
              "Authors": ["Divyanshu Shukla (@justm0rph3u5)"],
              "Programs": ["Microsoft"],
              "Bugs": ["HTML injection", "Phishing"],
              "Bounty": "-",
              "PublicationDate": "2022-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-32208: FTP-KRB bad message verification",
                    "Link": "https://curl.se/docs/CVE-2022-32208.html"
                 }
              ],
              "Authors": ["Harry Sintonen"],
              "Programs": ["Internet Bug Bounty (curl)"],
              "Bugs": ["MiTM"],
              "Bounty": "480",
              "PublicationDate": "2022-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-32207: Unpreserved file permissions",
                    "Link": "https://curl.se/docs/CVE-2022-32207.html"
                 }
              ],
              "Authors": ["Harry Sintonen"],
              "Programs": ["Internet Bug Bounty (curl)"],
              "Bugs": ["Improper Preservation of Permissions"],
              "Bounty": "2,400",
              "PublicationDate": "2022-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-32206: HTTP compression denial of service",
                    "Link": "https://curl.se/docs/CVE-2022-32206.html"
                 }
              ],
              "Authors": ["Harry Sintonen"],
              "Programs": ["Internet Bug Bounty (curl)"],
              "Bugs": ["DoS"],
              "Bounty": "2,400",
              "PublicationDate": "2022-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-32205: Set-Cookie denial of service",
                    "Link": "https://curl.se/docs/CVE-2022-32205.html"
                 }
              ],
              "Authors": ["Harry Sintonen"],
              "Programs": ["Internet Bug Bounty (curl)"],
              "Bugs": ["DoS"],
              "Bounty": "480",
              "PublicationDate": "2022-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing functionality to exploit a super SSRF in Jira Server (CVE-2022-26135)",
                    "Link": "https://blog.assetnote.io/2022/06/26/exploiting-ssrf-in-jira/"
                 }
              ],
              "Authors": ["Shubham Shah (@infosec_au)", "Dylan Pindur"],
              "Programs": ["Atlassian"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-06-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hyperlink Injection On IRC Cloud",
                    "Link": "https://medium.com/@deepmarketer/hyperlink-injection-on-irc-cloud-809e5243406f"
                 }
              ],
              "Authors": ["Aswin K V (@deep_marketer_)"],
              "Programs": ["IRCCloud"],
              "Bugs": ["Hyperlink injection"],
              "Bounty": "-",
              "PublicationDate": "2022-06-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug: Cisco IOS SNMPv3 ACL Issues",
                    "Link": "https://medium.com/@gerrygosselin/cisco-ios-snmpv3-acl-issues-66dbab0bd138"
                 }
              ],
              "Authors": ["Gerry Gosselin (@ggPixelHealth)"],
              "Programs": ["Cisco"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-06-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "mysqlnd/pdo password buffer overflow leading to RCE (CVE 2022-31626)",
                    "Link": "https://bugs.php.net/bug.php?id=81719"
                 },
                 {
                    "Title": "@cyberguru007's analysis and PoC",
                    "Link": "https://github.com/CFandR-github/PHP-binary-bugs/blob/main/cve_2022_31626_remote_exploit/cve_writeup.md"
                 }
              ],
              "Authors": ["Charles Fol (@cfreal_)"],
              "Programs": ["PHP"],
              "Bugs": ["Buffer Overflow", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-06-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Moderation Filter Bypass in support.mozilla.org",
                    "Link": "https://tomorrowisnew.com/posts/moderation-filter-bypass/"
                 }
              ],
              "Authors": ["tomorrowisnew (@tomorrowisnew_)"],
              "Programs": ["Mozilla"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-06-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An Out Of Scope domain Leads To a Critical Bug[$1500]",
                    "Link": "https://medium.com/@shakti.gtp/an-out-of-scope-domain-leads-to-a-critical-bug-1500-f228d2c7db4b"
                 }
              ],
              "Authors": ["Shakti Mohanty (@3ncryptSaan)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization", "Broken Access Control"],
              "Bounty": "1,500",
              "PublicationDate": "2022-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Miracle - One Vulnerability To Rule Them All",
                    "Link": "https://peterjson.medium.com/miracle-one-vulnerability-to-rule-them-all-c3aed9edeea2"
                 }
              ],
              "Authors": ["Nguyễn Tiến Giang (@testanull)", "peterjson (@peterjson)"],
              "Programs": ["Oracle"],
              "Bugs": ["Insecure deserialization", "SSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-06-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwn2Own 2021 Microsoft Exchange Exploit Chain",
                    "Link": "https://blog.viettelcybersecurity.com/pwn2own-2021-microsoft-exchange-exploit-chain/"
                 }
              ],
              "Authors": ["Rskvp93 (@rskvp93)"],
              "Programs": ["Microsoft"],
              "Bugs": ["SSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-06-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-31749: WatchGuard Authenticated Arbitrary File Read/Write (Fixed)",
                    "Link": "https://www.rapid7.com/blog/post/2022/06/23/cve-2022-31749-watchguard-authenticated-arbitrary-file-read-write-fixed/"
                 }
              ],
              "Authors": ["Jake Baines (@Junior_Baines)"],
              "Programs": ["WatchGuard"],
              "Bugs": ["Argument injection"],
              "Bounty": "-",
              "PublicationDate": "2022-06-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Lock Screen Bypass Exploit of Android Devices (CVE-2022–20006)",
                    "Link": "https://medium.com/maverislabs/lock-screen-bypass-exploit-of-android-devices-cve-2022-20006-604958fcee3a"
                 }
              ],
              "Authors": ["Joshua Nearchos"],
              "Programs": ["Google"],
              "Bugs": ["Authentication bypass", "Lock screen bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-06-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Filesatck Upload Advisory Summary",
                    "Link": "https://bishopfox.com/blog/filestack-upload-advisory"
                 }
              ],
              "Authors": ["Carlos Yanez"],
              "Programs": ["Filestack"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-06-23",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Exploiting Bitdefender Antivirus: RCE from any website",
                  "Link": "https://palant.info/2020/06/22/exploiting-bitdefender-antivirus-rce-from-any-website/"
               }
            ],
            "Authors": ["Wladimir Palant (@WPalant)"],
            "Programs": ["Bitdefender"],
            "Bugs": ["RCE", "Command injection"],
            "Bounty": "-",
            "PublicationDate": "2022-06-22",
            "AddedDate": "2022-12-09"
         },
           {
              "Links": [
                 {
                    "Title": "We were vulnerable - how a security company could have vulns",
                    "Link": "https://www.volkis.com.au/blog/we-were-vulnerable/"
                 }
              ],
              "Authors": ["Soman Verma", "Alexei Doudkine (@skorov8)"],
              "Programs": ["Volkis"],
              "Bugs": ["Broken Access Control", "Broken authorization", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$1500 Of Broken Access Controls",
                    "Link": "https://medium.com/@tobydavenn/1500-of-broken-access-controls-503d8a5f56f5"
                 }
              ],
              "Authors": ["Tobydavenn"],
              "Programs": ["-"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "1,500",
              "PublicationDate": "2022-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting vulnerabilities in iOS Application",
                    "Link": "https://lonewolf-raj.medium.com/exploiting-vulnerabilities-in-ios-application-cf5718910c47"
                 }
              ],
              "Authors": ["Raj Singh Chauhan (@raj_singh_ch)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Bruteforce", "Lack of rate limiting", "Account takeover", "iOS"],
              "Bounty": "-",
              "PublicationDate": "2022-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Widespread prototype pollution gadgets",
                    "Link": "https://portswigger.net/research/widespread-prototype-pollution-gadgets"
                 }
              ],
              "Authors": ["Gareth Heyes (@garethheyes)"],
              "Programs": ["-"],
              "Bugs": ["Prototype pollution"],
              "Bounty": "-",
              "PublicationDate": "2022-06-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Vulnerability in IBM Content Navigator (CVE-2020-4757)",
                    "Link": "https://www.gosecure.net/blog/2022/06/21/xss-vulnerability-in-ibm-content-navigator-cve-2020-4757/"
                 }
              ],
              "Authors": ["Olivier Laflamme (@olivier_boschko)"],
              "Programs": ["IBM"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-06-21",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Hacking into the worldwide Jacuzzi SmartTub network",
                  "Link": "https://eaton-works.com/2022/06/20/hacking-into-the-worldwide-jacuzzi-smarttub-network/"
               }
            ],
            "Authors": ["Eaton Z. (@XeEaton)"],
            "Programs": ["Jacuzzi Group", "SmartTub"],
            "Bugs": ["SPA", "Android", "JWT", "Privilege escalation", "Mass assignment"],
            "Bounty": "-",
            "PublicationDate": "2022-06-20",
            "AddedDate": "2023-02-16"
         },
           {
              "Links": [
                 {
                    "Title": "Response Manipulation in the Admin panel lead to PII leakage",
                    "Link": "https://7odamo.medium.com/response-manipulation-in-the-admin-panel-lead-to-pii-leakage-2926b89ea2d0"
                 }
              ],
              "Authors": ["Mahmoud Hamed (@7odamo_)"],
              "Programs": ["UPS VDP"],
              "Bugs": ["Account takeover", "HTTP response manipulation"],
              "Bounty": "-",
              "PublicationDate": "2022-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Every XSS is different",
                    "Link": "https://medium.com/@leomsec/every-xss-is-different-c98528fee5e0"
                 }
              ],
              "Authors": ["Leonardo"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover by OTP bypass",
                    "Link": "https://codewithvamp.medium.com/account-takeover-by-otp-bypass-ec0cff67f516"
                 }
              ],
              "Authors": ["Vaibhav Kumar Srivastava"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Client-side enforcement of server-side security", "OTP bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Personal Access Token Disclosure in Asana Desktop Application",
                    "Link": "https://security.lauritz-holtmann.de/advisories/asana-desktop-credential-disclosure/"
                 },
                 {
                    "Title": "Bugcrowd report",
                    "Link": "https://bugcrowd.com/disclosures/caf10f76-f1fb-4dea-8434-9ed2c56a40bb/asana-desktop-application-includes-personal-access-token"
                 }
              ],
              "Authors": ["Lauritz Holtmann (@_lauritz_)"],
              "Programs": ["Asana"],
              "Bugs": ["Information disclosure", "Hardcoded credentials"],
              "Bounty": "6,100",
              "PublicationDate": "2022-06-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked one of the biggest Airline in the world",
                    "Link": "https://medium.com/@sazouki/how-i-hacked-one-of-the-biggest-airline-in-the-world-e7810dc43791"
                 }
              ],
              "Authors": ["Dali Jandro (@Sazouki_)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-06-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking a NFT Platform",
                    "Link": "https://medium.com/@mahitman1/hacking-a-nft-platform-56fc59479d3b"
                 }
              ],
              "Authors": ["Muhammad Abdullah"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to see likes and dislikes count which is hidden by victim | YouTube #2",
                    "Link": "https://medium.com/@janijay007/how-i-was-able-to-see-likes-and-dislikes-count-which-is-hidden-by-victim-youtube-2-721d8e4686a5"
                 }
              ],
              "Authors": ["Jay Jani (@JayJani007)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "That Pipe is Still Leaking: Revisiting the RDP Named Pipe Vulnerability",
                    "Link": "https://www.cyberark.com/resources/threat-research-blog/that-pipe-is-still-leaking-revisiting-the-rdp-named-pipe-vulnerability"
                 }
              ],
              "Authors": ["Gabriel Sztejnworcel (@sztejnworcel)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF leads to account takeover in Yahoo!",
                    "Link": "https://webs3c.com/t/csrf-leads-to-account-takeover-in-yahoo/93"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://retr02332.medium.com/csrf-leads-to-account-takeover-in-yahoo-aa96c678d2aa"
                 }
              ],
              "Authors": ["Retr02332 (@Retr02332)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "3,000",
              "PublicationDate": "2022-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining MFA-Enabled IAM Users with IAM Roles for Potential Privilege Escalation in AWS",
                    "Link": "https://www.praetorian.com/blog/stsgetsessiontoken-role-chaining-in-aws/"
                 }
              ],
              "Authors": ["Jason Kao"],
              "Programs": ["AWS"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Android kernel mitigations obstacle race",
                    "Link": "https://github.blog/2022-06-16-the-android-kernel-mitigations-obstacle-race/"
                 }
              ],
              "Authors": ["Man Yue Mo (@mmolgtm)"],
              "Programs": ["Qualcomm"],
              "Bugs": ["Memory corruption", "Android"],
              "Bounty": "-",
              "PublicationDate": "2022-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Blind Stored at Asset Domain Android Apps TikTok",
                    "Link": "https://aidilarf.medium.com/xss-blind-stored-at-asset-domain-android-apps-tiktok-ae2f4c2dbc07"
                 }
              ],
              "Authors": ["Aidil Arief"],
              "Programs": ["TikTok"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,500",
              "PublicationDate": "2022-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Proofpoint Discovers Potentially Dangerous Microsoft Office 365 Functionality that can Ransom Files Stored on SharePoint and OneDrive",
                    "Link": "https://www.proofpoint.com/us/blog/cloud-security/proofpoint-discovers-potentially-dangerous-microsoft-office-365-functionality"
                 }
              ],
              "Authors": ["Proofpoint (@proofpoint)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-23088: Exploiting A Heap Overflow In The Freebsd Wi-fi Stack",
                    "Link": "https://www.zerodayinitiative.com/blog/2022/6/15/cve-2022-23088-exploiting-a-heap-overflow-in-the-freebsd-wi-fi-stack"
                 }
              ],
              "Authors": ["m00nbsd (@m00nbsd)"],
              "Programs": ["FreeBSD Security Team"],
              "Bugs": ["Memory corruption", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Amazon Linux \"log4j hotpatch\" <1.3-5 local privilege escalation to root (race condition)",
                    "Link": "https://github.com/justinsteven/advisories/blob/main/2022_amazon_log4j-cve-2021-44228-hotpatch_local_privesc.md"
                 }
              ],
              "Authors": ["Justin Steven (@justinsteven)"],
              "Programs": ["Amazon"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu",
                    "Link": "https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html"
                 }
              ],
              "Authors": ["Frédéric Basse (@FredoBasse)"],
              "Programs": ["Google"],
              "Bugs": ["Hardware hacking", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation in AKS Clusters",
                    "Link": "https://www.securesystems.de/blog/privilege-escalation-in-aks-clusters/"
                 }
              ],
              "Authors": ["Anneke Breust", "Aymen Segni (@aops_solutions)", "Philipp Belitz"],
              "Programs": ["Microsoft"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[BugTales] UnZiploc: From 0-click To Platform Compromise",
                    "Link": "https://labs.taszk.io/articles/post/unziploc/"
                 }
              ],
              "Authors": ["Daniel Komaromy (@kutyacica)", "Lorant Szabo (@szabolor)", "Gyorgy Miru (@gymiru)"],
              "Programs": ["Huawei"],
              "Bugs": ["Memory corruption", "Logic flaw", "RCE", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hertzbleed Attack",
                    "Link": "https://www.hertzbleed.com"
                 }
              ],
              "Authors": ["Yingchen Wang (@YingchenWang96)", "Riccardo Paccagnella (@ricpacca)", "Elizabeth Tang He", "Hovav Shacham (@hovav)", "Christopher Fletcher", "David Kohlbrenner (@dkohlbre)"],
              "Programs": ["Intel", "Cloudflare", "Microsoft"],
              "Bugs": ["Side-channel attack", "Hardware hacking", "Cryptographic issues"],
              "Bounty": "-",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Automating reflected XSS with burp-suite Intruder",
                    "Link": "https://notifybugme.medium.com/automating-reflected-xss-with-burp-suite-intruder-a39b2f060db7"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "750",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2FA Bypass via Basic Authentication on private bug bounty program",
                    "Link": "https://medium.com/@sharp488/2fa-bypass-via-basic-authentication-on-private-bug-bounty-program-93bb457cd065"
                 }
              ],
              "Authors": ["Sharat Kaikolamthuruthil (@sharp488)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zimbra Email - Stealing Clear-Text Credentials via Memcache injection",
                    "Link": "https://www.sonarsource.com/blog/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/"
                 }
              ],
              "Authors": ["Sonar (@SonarSource)"],
              "Programs": ["Zimbra"],
              "Bugs": ["Memcache injection", "CRLF injection"],
              "Bounty": "-",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "403 bypass on a fortune 100 financial institution (P3)",
                    "Link": "https://medium.com/@damaidec/403-bypass-on-a-fortune-100-financial-institution-p3-156d33bc6ed"
                 }
              ],
              "Authors": ["Damaidec"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Broken authorization", "Forced browsing"],
              "Bounty": "-",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cryptographic Side-Channels (Timing Leaks) in JSBN",
                    "Link": "https://github.com/andyperlitch/jsbn/issues/43"
                 }
              ],
              "Authors": ["Soatok (@SoatokDhole)"],
              "Programs": ["Xfinity Opensource"],
              "Bugs": ["Cryptographic issues", "Side-channel attack", "Timing attack"],
              "Bounty": "-",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SynLapse – Technical Details for Critical Azure Synapse Vulnerability",
                    "Link": "https://orca.security/resources/blog/synlapse-critical-azure-synapse-analytics-service-vulnerability/"
                 },
                 {
                    "Title": "TL;DR",
                    "Link": "https://twitter.com/TzahPahima/status/1536704823722184704"
                 }
              ],
              "Authors": ["Tzah Pahima (@TzahPahima)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Cross-tenant vulnerability", "RCE", "Cloud"],
              "Bounty": "60,000",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing CSP with dangling iframes",
                    "Link": "https://portswigger.net/research/bypassing-csp-with-dangling-iframes"
                 }
              ],
              "Authors": ["Gareth Heyes (@garethheyes)"],
              "Programs": ["Google", "Mozilla"],
              "Bugs": ["CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "500$ Account Takeover",
                    "Link": "https://medium.com/@kashyapherry147/500-account-takeover-b008f1ccb4a2"
                 }
              ],
              "Authors": ["Hemant Kumar"],
              "Programs": ["Xsolla"],
              "Bugs": ["Account takeover", "Information disclosure", "HTTP response manipulation"],
              "Bounty": "500",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to see likes and dislikes count which is hidden by victim | YouTube #1",
                    "Link": "https://medium.com/@janijay007/how-i-was-able-to-see-likes-and-dislikes-count-which-is-hidden-by-victim-youtube-1-fa9cfe7cce7d"
                 }
              ],
              "Authors": ["Jay Jani (@JayJani007)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Azure Synapse Pwnalytics",
                    "Link": "https://medium.com/tenable-techblog/microsoft-azure-synapse-pwnalytics-87c99c036291"
                 }
              ],
              "Authors": ["Jimi Sebree (@DinoBytes)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Privilege escalation","Cloud"],
              "Bounty": "-",
              "PublicationDate": "2022-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Yet another bug into Netfilter",
                    "Link": "https://www.randorisec.fr/yet-another-bug-netfilter/"
                 }
              ],
              "Authors": ["Arthur Mongodin"],
              "Programs": ["Linux Kernel Organization"],
              "Bugs": ["Memory corruption", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding vulnerabilities in curl 7.83.0 without reading a single-line of C code",
                    "Link": "https://haxatron.gitbook.io/vulnerability-research/vr2"
                 }
              ],
              "Authors": ["Haxatron (@Haxatron1)"],
              "Programs": ["Internet Bug Bounty (curl)"],
              "Bugs": ["SSRF", "Information disclosure", "HSTS bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking 6.5+ million websites => CVE-2022-29455 (Elementor)",
                    "Link": "https://rotem-bar.com/hacking-65-million-websites-greater-cve-2022-29455-elementor"
                 }
              ],
              "Authors": ["Rotem Bar (@rotembar)", "Gal Nagli (@naglinagli)", "Tomer Zait (@realgam3)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found a Critical Bug in Instagram and Got 49500$ Bounty From Facebook",
                    "Link": "https://infosecwriteups.com/how-i-found-a-critical-bug-in-instagram-and-got-49500-bounty-from-facebook-626ff2c6a853"
                 }
              ],
              "Authors": ["Neeraj Sharma (@root_n33r4j)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "49,500",
              "PublicationDate": "2022-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Same bug different platform",
                    "Link": "https://prajwoldhungana487.medium.com/same-bug-different-platform-4c648e91af6b"
                 }
              ],
              "Authors": ["Prajwol Dhungana (@PrajwolDhunga14)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From blind SSRF to localhost dirbusting and asset enumeration",
                    "Link": "https://medium.com/@joshibeast/from-blind-ssrf-to-localhost-dirbusting-and-asset-enumeration-dc0179310038"
                 }
              ],
              "Authors": ["Jovan Šikanja (@joshibeast)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Story of a Bug Found Fuzzing",
                    "Link": "https://microsoftedge.github.io/edgevr/posts/a-story-of-a-bug-found-fuzzing/"
                 }
              ],
              "Authors": ["Abdulrhman Alqabandi (@qab)"],
              "Programs": ["Google", "Microsoft"],
              "Bugs": ["Browser hacking", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ed25519-unsafe-libs",
                    "Link": "https://github.com/MystenLabs/ed25519-unsafe-libs"
                 }
              ],
              "Authors": ["Konstantinos Chalkias"],
              "Programs": ["-"],
              "Bugs": ["Cryptographic issues"],
              "Bounty": "-",
              "PublicationDate": "2022-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first CVE-2022–31289",
                    "Link": "https://web.archive.org/web/20220611144030/https://medium.com/@pmmali/my-first-cve-2022-31289-4081c57e90fb"
                 }
              ],
              "Authors": ["Praveen Mali (@pmmali_)"],
              "Programs": ["Sonatype"],
              "Bugs": ["Authentication bypass", "403 bypass", "HTTP response manipulation"],
              "Bounty": "-",
              "PublicationDate": "2022-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to download eBooks from Google Play Store without paying for them",
                    "Link": "https://webs3c.com/t/how-to-download-ebooks-from-google-play-store-without-paying-for-them/79"
                 }
              ],
              "Authors": ["Yess (@Yess_2021xD)"],
              "Programs": ["Google"],
              "Bugs": ["Payment bypass", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-06-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-1040 Sophos XG Firewall Authentication bypass",
                    "Link": "https://blog.viettelcybersecurity.com/cve-2022-1040-sophos-xg-firewall-authentication-bypass/"
                 }
              ],
              "Authors": ["Nguyễn Đình Biển (@biennd279)"],
              "Programs": ["Sophos"],
              "Bugs": ["Authentication bypass", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-06-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining vulnerabilities to criticality in Progress WhatsUp Gold",
                    "Link": "https://blog.assetnote.io/2022/06/09/whatsup-gold-exploit/"
                 }
              ],
              "Authors": ["Shubham Shah (@infosec_au)"],
              "Programs": ["Progress (WhatsUp Gold)"],
              "Bugs": ["SSRF", "Local File Disclosure", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-06-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Autodesk Fusion 360 <= 2.0.12887 “Insert SVG” Blind XXE",
                    "Link": "https://www.shielder.com/advisories/autodesk-fusion-import-svg-blind-xxe/"
                 }
              ],
              "Authors": ["Giulio 'linset' Casciaro (@Lins3t)"],
              "Programs": ["Autodesk"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2022-06-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Denial of Service Vulnerability in Envoy Proxy – CVE-2022-29225",
                    "Link": "https://jfrog.com/blog/denial-of-service-vulnerability-in-envoy-proxy-cve-2022-29225/"
                 }
              ],
              "Authors": ["JFrog Security Research Team (@JFrogSecurity)"],
              "Programs": ["Envoy"],
              "Bugs": ["Zip bomb", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-06-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "De-Anonymization attacks against Proton services",
                    "Link": "https://www.reversemode.com/2022/06/de-anonymization-attacks-against-proton.html"
                 }
              ],
              "Authors": ["Ruben Santamarta (@reversemode)"],
              "Programs": ["Proton AG"],
              "Bugs": ["Privacy issue", "Information disclosure", "HTML injection", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-06-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Extracting Clear-Text Credentials Directly From Chromium’s Memory",
                    "Link": "https://www.cyberark.com/resources/threat-research-blog/extracting-clear-text-credentials-directly-from-chromium-s-memory"
                 },
                 {
                    "Title": "Go BLUE! A Protection Plan for Credentials in Chromium-based Browsers",
                    "Link": "https://www.cyberark.com/resources/threat-research-blog/go-blue-a-protection-plan-for-credentials-in-chromium-based-browsers"
                 }
              ],
              "Authors": ["Zeev Ben Porat"],
              "Programs": ["Google (Chromium)"],
              "Bugs": ["Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2022-06-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover by Chaining Two IDORs",
                    "Link": "https://www.r29k.com/articles/bb/account-takeover-via-idors"
                 }
              ],
              "Authors": ["Demon (@R29k_)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-06-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Amazon active vulnerability",
                    "Link": "https://gatolouco.medium.com/exploiting-amazon-active-vulnerability-d2554c8c7ffd"
                 }
              ],
              "Authors": ["Benjamin Walter"],
              "Programs": ["Amazon"],
              "Bugs": ["Payment bypass", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-06-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-26937: Microsoft Windows Network File System NLM Portmap Stack Buffer Overflow",
                    "Link": "https://www.zerodayinitiative.com/blog/2022/6/7/cve-2022-26937-microsoft-windows-network-file-system-nlm-portmap-stack-buffer-overflow"
                 }
              ],
              "Authors": ["Yuki Chen (@guhe120)", "Guy Lederfein (@glederfein)", "Jason McFadyen"],
              "Programs": ["Microsoft"],
              "Bugs": ["Buffer Overflow", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-06-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Security Vulnerability in GitLab: Sending Arbitrary Requests through Jupyter Notebooks",
                    "Link": "https://liman.io/blog/gitlab-security-vulnerability-jupyter-notebooks"
                 }
              ],
              "Authors": ["Daniel Fürst (@DnlFrst)"],
              "Programs": ["GitLab"],
              "Bugs": ["HTML injection"],
              "Bounty": "1,500",
              "PublicationDate": "2022-06-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An unusual way to find XSS injection in one minute",
                    "Link": "https://medium.com/@ao64400225/an-unusual-way-to-find-xss-injection-in-one-minute-9ed2c7e2a848"
                 }
              ],
              "Authors": ["Andrey Onishchenko"],
              "Programs": ["TimeWeb"],
              "Bugs": ["CSTI", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-06-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple vulnerabilities in Zyxel zysh",
                    "Link": "https://security.humanativaspa.it/multiple-vulnerabilities-in-zyxel-zysh/"
                 }
              ],
              "Authors": ["Marco Ivaldi / Raptor (@0xdea)"],
              "Programs": ["Zyxel"],
              "Bugs": ["OS command injection", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-06-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Another vision for SSRF",
                    "Link": "https://gccybermonks.com/posts/ssrfvision/"
                 }
              ],
              "Authors": ["phor3nsic (@phor3nsic_br)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-06-06",
              "AddedDate": "2022-09-15"
            },
            {
             "Links": [
                {
                   "Title": "Ivanti EPM Remote Code Execution",
                   "Link": "https://machevalia.blog/blog/ivanti-epm-remote-code-execution"
                }
             ],
             "Authors": ["Nick Berrie (@machevalia)"],
             "Programs": ["-"],
             "Bugs": ["RCE", "Components with known vulnerabilities"],
             "Bounty": "6,500",
             "PublicationDate": "2022-06-05",
             "AddedDate": "2023-01-11"
          },
           {
              "Links": [
                 {
                    "Title": "If It’s a Feature!!! Let’s Abuse It for $750",
                    "Link": "https://medium.com/@shakti.gtp/if-its-a-feature-let-s-abuse-it-for-750-19cfb9848d4b"
                 }
              ],
              "Authors": ["Shakti Mohanty (@3ncryptSaan)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "750",
              "PublicationDate": "2022-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Attacker could have suffocated the company staff",
                    "Link": "https://medium.com/@mahitman1/how-attacker-could-have-suffocated-the-company-staff-37a6b7192f12"
                 }
              ],
              "Authors": ["Muhammad Abdullah"],
              "Programs": ["-"],
              "Bugs": ["Default credentials"],
              "Bounty": "1,400",
              "PublicationDate": "2022-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Is Exploiting A Null Pointer Deref For LPE Just A Pipe Dream?",
                    "Link": "https://www.zerodayinitiative.com/blog/2022/6/1/is-exploiting-a-null-pointer-deref-for-lpe-just-a-pipe-dream"
                 }
              ],
              "Authors": ["Michael DePlante (@izobashi)"],
              "Programs": ["Microsoft (Bitdefender)"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-06-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Mass hunt for Admin Panel Access…🤩",
                    "Link": "https://medium.com/@ratnadip1998/how-i-mass-hunt-for-admin-panel-access-8c2ad145054"
                 }
              ],
              "Authors": ["Ratnadip Gajbhiye (@scspcommunity)"],
              "Programs": ["Gemeente Delft (The City of Delft)"],
              "Bugs": ["Default credentials"],
              "Bounty": "-",
              "PublicationDate": "2022-06-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Dynamics Container Sandbox RCE via Unauthenticated Docker Remote API 20,000$ Bounty",
                    "Link": "https://hencohen10.medium.com/microsoft-dynamics-container-sandbox-rce-via-unauthenticated-docker-remote-api-20-000-bounty-7f726340a93b"
                 }
              ],
              "Authors": ["Chen Cohen (@chencococococo)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "20,000",
              "PublicationDate": "2022-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found a GoldMine but got No Gold",
                    "Link": "https://medium.com/@mahitman1/how-i-found-a-goldmine-but-got-no-gold-e912a89fa522"
                 }
              ],
              "Authors": ["Muhammad Abdullah"],
              "Programs": ["-"],
              "Bugs": ["Old components with known vulnerabilities"],
              "Bounty": "-",
              "PublicationDate": "2022-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL injection to Remote Command Execution (RCE)",
                    "Link": "https://systemweakness.com/sql-injection-to-remote-command-execution-rce-dd9a75292d1d"
                 }
              ],
              "Authors": ["Kwadwo Amoako"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From open redirect to RCE in one week",
                    "Link": "https://medium.com/@byq/from-open-redirect-to-rce-in-one-week-66a7f73fd082"
                 }
              ],
              "Authors": ["byq (@ByQwert)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["Open redirect", "SSRF", "Insecure deserialization", "LFI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing Facebook’s feature for a permanent account confusion(logic vulnerability)",
                    "Link": "https://medium.com/@terminatorLM/abusing-facebooks-feature-for-a-permanent-account-confusion-logic-vulnerability-d7f5160f373a"
                 }
              ],
              "Authors": ["Liv"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["2FA / MFA bypass", "DoS", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to find & access Admin Panel by digging into JS files…🥰",
                    "Link": "https://medium.com/@ratnadip1998/how-to-find-access-admin-panel-by-digging-into-js-files-282d89391a2d"
                 }
              ],
              "Authors": ["Ratnadip Gajbhiye (@scspcommunity)"],
              "Programs": ["-"],
              "Bugs": ["Weak credentials", "WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-05-30",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Bypass CSP Using WordPress By Abusing Same Origin Method Execution",
                  "Link": "https://octagon.net/blog/2022/05/29/bypass-csp-using-wordpress-by-abusing-same-origin-method-execution/"
               }
            ],
            "Authors": ["Paulos Yibelo (@PaulosYibelo)"],
            "Programs": ["WordPress"],
            "Bugs": ["CSP bypass", "Same Origin Method Execution"],
            "Bounty": "-",
            "PublicationDate": "2022-05-29",
            "AddedDate": "2023-03-08"
         },
           {
            "Links": [
               {
                  "Title": "DOMAIN ADMIN Compromise in 3 HOURS",
                  "Link": "https://infosecwriteups.com/domain-admin-compromise-in-3-hours-5778902604c9"
               }
            ],
            "Authors": ["popalltheshells"],
            "Programs": ["-"],
            "Bugs": ["Default credentials"],
            "Bounty": "-",
            "PublicationDate": "2022-05-29",
            "AddedDate": "2023-02-09"
         },
           {
              "Links": [
                 {
                    "Title": "External Authentication bypass in ingress-nginx",
                    "Link": "https://xvnpw.github.io/posts/external_authentication_bypass_in_ingress_nginx/"
                 }
              ],
              "Authors": ["Niemiec Marcin (@xvnpw)"],
              "Programs": ["Kubernetes"],
              "Bugs": ["Path traversal", "Authentication bypass"],
              "Bounty": "500",
              "PublicationDate": "2022-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting iOS app for fun and profit",
                    "Link": "https://web.archive.org/web/20220529130635/https://pwnsec.ninja/2022/05/29/exploiting-ios-app-for-fun-and-profit/"
                 }
              ],
              "Authors": ["Bijan Murmu (@0xbijan)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hall of Fame Vice Media ? hacking while sleepy…",
                    "Link": "https://medium.com/@b0x_in/hall-of-fame-vice-media-hacking-while-sleepy-3eb931f124e1"
                 }
              ],
              "Authors": ["Muhammad Syahrul Haniawan"],
              "Programs": ["Vice Media"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weird Email Verification Bypass",
                    "Link": "https://medium.com/@vaibhavatkale/weird-email-verification-bypass-96c793c36d7e"
                 }
              ],
              "Authors": ["Vaibhav Atkale"],
              "Programs": ["-"],
              "Bugs": ["Email verification bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Simple SQL Injection in an Air Force Website",
                    "Link": "https://corben.io/blog/a-simple-sql-injection-in-an-air-force-website"
                 }
              ],
              "Authors": ["Corben Leo (@hacker_)"],
              "Programs": ["U.S. Dept Of Defense"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-05-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bygone Vulnerabilities - Remote Code Execution in IBM Lotus SameTime Clients (CVE-2013-0553)",
                    "Link": "https://hoyahaxa.blogspot.com/2022/05/bygone-vulnerabilities-remote-code.html"
                 }
              ],
              "Authors": ["Brian (@hoyahaxa)"],
              "Programs": ["IBM"],
              "Bugs": ["XSS", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-05-27",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "DNN CMS Server-Side Request Forgery (CVE-2021-40186)",
                  "Link": "https://appcheck-ng.com/dnn-cms-server-side-request-forgery-cve-2021-40186"
               }
            ],
            "Authors": ["Appcheck NG"],
            "Programs": ["DNN (DotNetNuke)"],
            "Bugs": ["SSRF", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2022-05-26",
            "AddedDate": "2023-01-11"
         },
           {
              "Links": [
                 {
                    "Title": "Social Media Take Over = Easy Money",
                    "Link": "https://hogarth45.medium.com/social-media-take-over-easy-money-aa6274b4b70d"
                 }
              ],
              "Authors": ["Jesse Clark (@Hogarth45_)"],
              "Programs": ["-"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2022-05-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How an Open Redirection Leads to an Account Takeover?",
                    "Link": "https://infosecwriteups.com/how-an-open-redirection-leads-to-an-account-takeover-73ea883055d1"
                 }
              ],
              "Authors": ["Mahendra Purbia (@Mah3Sec_)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-05-26",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "2nd RCE and XSS in Apache Struts before 2.5.30",
                  "Link": "https://mc0wn.blogspot.com/2022/05/2nd-rce-and-xss-in-apache-struts-before-2530.html"
               }
            ],
            "Authors": ["Chris (@mc_0wn)"],
            "Programs": ["Apache Struts"],
            "Bugs": ["RCE", "Double OGNL evaluation", "XSS"],
            "Bounty": "-",
            "PublicationDate": "2022-05-25",
            "AddedDate": "2022-12-05"
         },
           {
              "Links": [
                 {
                    "Title": "Hijacking Over 100k GoDaddy Websites",
                    "Link": "https://labs.ingredous.com/2022/05/25/hijacking-over-100k-godaddy-websites/"
                 }
              ],
              "Authors": ["Jonathan Cran (@jcran)", "Shpend Kurtishaj (@shpendk)", "Maxim Gofnung"],
              "Programs": ["GoDaddy"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-05-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Printer Goes BRRRRR!!!",
                    "Link": "https://www.synacktiv.com/en/publications/the-printer-goes-brrrrr.html"
                 },
                 {
                    "Title": "Slides",
                    "Link": "https://twitter.com/Synacktiv/status/1529399465618153473"
                 }
              ],
              "Authors": ["Mehdi Talbi (@abu_y0ussef)", "Rémi Jullian (@netsecurity1)", "Thomas Jeunet  (@cleptho)"],
              "Programs": ["HP", "Lexmark", "Canon"],
              "Bugs": ["Memory corruption"],
              "Bounty": "60,000",
              "PublicationDate": "2022-05-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made it into the United Nations hall of fame as I slept",
                    "Link": "https://vikaran101.medium.com/how-i-made-it-into-the-united-nations-hall-of-fame-as-i-slept-f567c90be227"
                 }
              ],
              "Authors": ["Vikaran (@vikaran101)"],
              "Programs": ["United Nations"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-05-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found a company’s internal S3 Bucket with 41k Files",
                    "Link": "https://infosecwriteups.com/how-i-found-a-companys-internal-s3-bucket-with-41k-files-94b453e588b5"
                 }
              ],
              "Authors": ["Tarun Koyalwar (@KoyalwarTarun)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "250",
              "PublicationDate": "2022-05-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spoofing Microsoft 365 Like It’s 1995",
                    "Link": "https://www.blackhillsinfosec.com/spoofing-microsoft-365-like-its-1995/"
                 }
              ],
              "Authors": ["Steve Borosh (@424f424f)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Spoofing", "Phishing"],
              "Bounty": "-",
              "PublicationDate": "2022-05-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-22977: VMware Guest Authentication Service LPE (FIXED)",
                    "Link": "https://www.rapid7.com/blog/post/2022/05/24/cve-2022-22977-vmware-guest-authentication-service-lpe-fixed/"
                 }
              ],
              "Authors": ["Jacob Baines (@Junior_Baines)"],
              "Programs": ["VMware"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-05-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Get Bounty From Takeover Account",
                    "Link": "https://medium.com/@ryuukhagetsu/how-i-get-bounty-from-takeover-account-ed17cd838b2a"
                 }
              ],
              "Authors": ["RyuuKhagetsu"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Information disclosure", "Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-05-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Breaking Reverse Proxy Parser Logic",
                    "Link": "https://www.secjuice.cz0idsecom/breaking-parser-logic-gain-access-to-nginx-plus-api-read-write-upstreams/"
                 }
              ],
              "Authors": ["Blake Jacobs (@z0idsec)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding vulnerabilities in Swiss Post's future e-voting system - Part 2",
                    "Link": "https://www.reversemode.com/2022/05/finding-vulnerabilities-in-swiss-posts.html"
                 }
              ],
              "Authors": ["Ruben Santamarta (@reversemode)"],
              "Programs": ["-"],
              "Bugs": ["Insecure deserialization", "Cryptographic issues"],
              "Bounty": "-",
              "PublicationDate": "2022-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2FA Bypass on private bug bounty program due to improper caching mechanism",
                    "Link": "https://medium.com/@sharp488/2fa-bypass-on-private-bug-bounty-program-due-to-improper-caching-mechanism-212c5912bd00"
                 }
              ],
              "Authors": ["Sharat Kaikolamthuruthil (@sharp488)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2FA Bypass on private bug bounty program due to CSRF token misconfiguration",
                    "Link": "https://medium.com/@sharp488/2fa-bypass-on-private-bug-bounty-program-due-to-csrf-token-misconfiguration-5a9c82151a1"
                 }
              ],
              "Authors": ["Sharat Kaikolamthuruthil (@sharp488)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerability In PayPal worth 200000$ bounty, Attacker can Steal Your Balance by One-Click",
                    "Link": "https://medium.com/@h4x0r_dz/vulnerability-in-paypal-worth-200000-bounty-attacker-can-steal-your-balance-by-one-click-2b358c1607cc"
                 }
              ],
              "Authors": ["Souhaib Naceri (@h4x0r_dz)"],
              "Programs": ["Paypal"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2022-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A business Logic issue worth $1500",
                    "Link": "https://mokhansec.medium.com/a-business-logic-issue-worth-1500-a0f1a0b76570"
                 }
              ],
              "Authors": ["Mohsin Khan (@tabaahi_)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,500",
              "PublicationDate": "2022-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to down a service of Microsoft ? Denial of Service (DOS) Attack on Microsoft.",
                    "Link": "https://medium.com/@harshbanshpal/how-i-was-able-to-down-a-service-of-microsoft-denial-of-service-dos-attack-on-microsoft-ec9d599ab3f8"
                 }
              ],
              "Authors": ["Harsh Banshpal (@harshbanshpal)"],
              "Programs": ["Microsoft"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PayPal IDOR via billing Agreement Token (closed Informative, payment fraud)",
                    "Link": "https://medium.com/@h4x0r_dz/paypal-idor-via-billing-agreement-token-closed-informative-payment-fraud-3245202fab38"
                 }
              ],
              "Authors": ["Souhaib Naceri (@h4x0r_dz)"],
              "Programs": ["Paypal"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-05-21",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "I Obtained ADMIN access via the Account Activation link [In 30 seconds]",
                  "Link": "https://systemweakness.com/i-obtained-admin-access-via-account-activation-link-in-30-seconds-dd7f115ae1d2"
               }
            ],
            "Authors": ["popalltheshells"],
            "Programs": ["-"],
            "Bugs": ["Privilege escalation", "Amazon cognito misconfiguration"],
            "Bounty": "-",
            "PublicationDate": "2022-05-20",
            "AddedDate": "2023-02-09"
         },
           {
              "Links": [
                 {
                    "Title": "Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web",
                    "Link": "https://arxiv.org/pdf/2205.10174.pdf"
                 }
              ],
              "Authors": ["Avinash Sudhodanan (@sudoavi)", "Andrew Paverd (@ajpaverd)"],
              "Programs": ["Dropbox", "Meta / Facebook", "LinkedIn", "WordPress", "Zoom"],
              "Bugs": ["Account takeover", "Pre-hijacking attack"],
              "Bounty": "-",
              "PublicationDate": "2022-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaking Your GitHub Repositories With Snyk Code",
                    "Link": "https://breakpoint.sh/posts/snyk-code-broken-access-control"
                 }
              ],
              "Authors": ["Ron Masas (@RonMasas)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Research: Auditing WordPress Plugins",
                    "Link": "https://cyllective.com/blog/posts/wordpress-audit-plugins"
                 }
              ],
              "Authors": ["cyllective (@cyllective)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "LFI", "XSS", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-05-20",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Gaining access through error-based SQLi using WebSockets",
                  "Link": "https://blog.bitcrack.net/pwning-portals-error-based-sqli-using-websockets/"
               }
            ],
            "Authors": ["Bitcrack (@bitcrack_cyber)"],
            "Programs": ["-"],
            "Bugs": ["SQL injection", "Websockets", "Password reset"],
            "Bounty": "-",
            "PublicationDate": "2022-01-12",
            "AddedDate": "2023-03-10"
         },
           {
              "Links": [
                 {
                    "Title": "How I was able to access IBM internal documents",
                    "Link": "https://medium.com/@mohamedtaha_42562/how-i-was-able-to-access-ibm-internal-documents-a33858387d30"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://motaha22.github.io/bugbounty/ibm-bounty/"
                 }
              ],
              "Authors": ["Mohamed Taha (@Mohamed12742780)"],
              "Programs": ["IBM"],
              "Bugs": ["Information disclosure", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Wayback to Account Takeover",
                    "Link": "https://medium.com/@mohamedtaha_42562/from-wayback-to-account-takeover-ea7e80600188"
                 }
              ],
              "Authors": ["Mohamed Taha (@Mohamed12742780)"],
              "Programs": ["Plex"],
              "Bugs": ["Information disclosure", "Account takeover"],
              "Bounty": "120",
              "PublicationDate": "2022-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-21404: Another Story Of Developers Fixing Vulnerabilities Unknowingly Because Of CodeQL",
                    "Link": "https://www.websec.ca/publication/Blog/CVE-2022-21404-Another-story-of-developers-fixing-vulnerabilities-unknowingly-because-of-CodeQL"
                 }
              ],
              "Authors": ["Paulino Calderon (@calderpwn)"],
              "Programs": ["Oracle"],
              "Bugs": ["Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2022-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting an Unbounded memcpy in Parallels Desktop: A Pwn2Own 2021 Guest-to-Host Virtualization Escape",
                    "Link": "https://blog.ret2.io/2022/05/19/pwn2own-2021-parallels-desktop-exploit/"
                 }
              ],
              "Authors": ["RET2 Systems (@ret2systems)"],
              "Programs": ["Parallels"],
              "Bugs": ["Memory corruption"],
              "Bounty": "40,000",
              "PublicationDate": "2022-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Tale of Confusing IDOR",
                    "Link": "https://quip.com/Uks4AzL33oAu"
                 }
              ],
              "Authors": ["Avi (@_naaash_)"],
              "Programs": ["TikTok"],
              "Bugs": ["IDOR"],
              "Bounty": "2,500",
              "PublicationDate": "2022-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Variant Cloud Analysis",
                    "Link": "https://jspin.re/variant-cloud-analysis/"
                 }
              ],
              "Authors": ["jspin (@jespinhara)"],
              "Programs": ["-"],
              "Bugs": ["Default credentials"],
              "Bounty": "-",
              "PublicationDate": "2022-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerability in Huawei's AppGallery can download paid apps for free",
                    "Link": "https://evowizz.dev/blog/huawei-appgallery-vulnerability"
                 }
              ],
              "Authors": ["Dylan Roussel (@evowizz)"],
              "Programs": ["Huawei"],
              "Bugs": ["Payment bypass", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-05-18",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Kubernetes Privilege Escalation: Excessive Permissions in Popular Platforms",
                  "Link": "https://www.paloaltonetworks.com/resources/whitepapers/kubernetes-privilege-escalation-excessive-permissions-in-popular-platforms"
               },
               {
                  "Title": "Mitigating RBAC-Based Privilege Escalation in Popular Kubernetes Platforms",
                  "Link": "https://unit42.paloaltonetworks.com/kubernetes-privilege-escalation/#post-126770-_5e5x5pdas37n"
               }
            ],
            "Authors": ["Yuval Avrahami (@yuval_avrahami)", "Shaul Ben Hai"],
            "Programs": ["Google", "AWS", "Microsoft", "Red Hat"],
            "Bugs": ["Privilege escalation", "Broken Access Control", "Kubernetes"],
            "Bounty": "13,022",
            "PublicationDate": "2022-05-17",
            "AddedDate": "2023-01-27"
         },
           {
              "Links": [
                 {
                    "Title": "Stealing Google Drive OAuth tokens from Dropbox",
                    "Link": "https://blog.stazot.com/stealing-google-drive-oauth-tokens-from-dropbox/"
                 }
              ],
              "Authors": ["Sivanesh Ashok (@sivaneshashok)", "Sreeram KL (@kl_sree)"],
              "Programs": ["Dropbox"],
              "Bugs": ["CSRF", "SSRF", "Account takeover"],
              "Bounty": "1,728",
              "PublicationDate": "2022-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing WAF to Weaponize a Stored XSS",
                    "Link": "https://infosecwriteups.com/bypassing-waf-to-weaponize-a-stored-xss-ff9963c421ee"
                 }
              ],
              "Authors": ["ne555"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Swagger-UI - from XSS to account takeovers",
                    "Link": "https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/"
                 }
              ],
              "Authors": ["Dawid Moczadło (@kannthu1)"],
              "Programs": ["Shopify", "Paypal", "GitLab", "Atlassian", "Yahoo! / Verizon Media", "Microsoft", "Jamf"],
              "Bugs": ["DOM XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Impact of an Insecure DeepLink",
                    "Link": "https://securityflow.io/impact-of-an-insecure-deep-link/"
                 }
              ],
              "Authors": ["Yashar Shahinzadeh (@YShahinzadeh)", "Аli Dinifаr (@binb4sh)"],
              "Programs": ["CafeBazaar"],
              "Bugs": ["Insecure deeplink", "Android"],
              "Bounty": "-",
              "PublicationDate": "2022-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple bugs chained to takeover Facebook Accounts which uses Gmail.",
                    "Link": "https://ysamm.com/?p=763"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS", "CSRF", "Account takeover"],
              "Bounty": "44,625",
              "PublicationDate": "2022-05-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My New Discovery In Oracle E-Business Login Panel That Allowed To Access For All Employees Information's & In Some cases Passwords At More Than 1000 Companies",
                    "Link": "https://orwaatyat.medium.com/my-new-discovery-in-oracle-e-business-login-panel-that-allowed-to-access-for-all-employees-ed0ec4cad7ac"
                 }
              ],
              "Authors": ["Orwa Atyat (@GodfatherOrwa)", "Abdullah Nawaf (@XHackerx007)"],
              "Programs": ["-"],
              "Bugs": ["Exposed registration page"],
              "Bounty": "-",
              "PublicationDate": "2022-05-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From android app to access admin dashboard",
                    "Link": "https://medium.com/@odayalhalbe1/from-android-app-to-access-admin-dashboard-a8f825e8e806"
                 }
              ],
              "Authors": ["Oday Alhalabi (@OdayAlhalabi)"],
              "Programs": ["-"],
              "Bugs": ["Exposed registration page", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-05-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Forging OAuth tokens using discovered client id and client secret",
                    "Link": "https://basyounii.medium.com/forging-oauth-tokens-using-discovered-client-id-and-client-secret-d224e4e7892a"
                 }
              ],
              "Authors": ["Basyouni (@AshrafBasyoni4)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-05-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "New Wine in Old Bottle - Microsoft Sharepoint Post-Auth Deserialization RCE (CVE-2022-29108)",
                    "Link": "https://www.starlabs.sg/blog/2022/05-new-wine-in-old-bottle-microsoft-sharepoint-post-auth-deserialization-rce-cve-2022-29108/"
                 }
              ],
              "Authors": ["Nguyễn Tiến Giang (@testanull)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Insecure deserialization", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-05-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Takeover seller accounts worth billions & millions",
                    "Link": "https://web.archive.org/web/20220513145411/https://pwnsec.ninja/2022/05/12/takeover-seller-accounts-worth-billions-millions/"
                 }
              ],
              "Authors": ["Bijan Murmu (@0xBijan)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-05-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spoofing SaaS Vanity URLs for Social Engineering Attacks",
                    "Link": "https://www.varonis.com/blog/url-spoofing"
                 }
              ],
              "Authors": ["Tal Peleg"],
              "Programs": ["Box", "Zoom", "Google"],
              "Bugs": ["URL spoofing"],
              "Bounty": "-",
              "PublicationDate": "2022-05-11",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Diving Into Pre-created Computer Accounts",
                  "Link": "https://www.trustedsec.com/blog/diving-into-pre-created-computer-accounts/"
               }
            ],
            "Authors": ["Oddvar Moe (@Oddvarmoe)"],
            "Programs": ["-"],
            "Bugs": ["Active Directory", "Local Privilege Escalation", "Windows"],
            "Bounty": "-",
            "PublicationDate": "2022-05-10",
            "AddedDate": "2023-03-10"
         },
           {
              "Links": [
                 {
                    "Title": "Certifried: Active Directory Domain Privilege Escalation (CVE-2022–26923)",
                    "Link": "https://research.ifcr.dk/certifried-active-directory-domain-privilege-escalation-cve-2022-26923-9e098fe298f4"
                 }
              ],
              "Authors": ["Oliver Lyak (@ly4k_)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Active Directory Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-05-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF…",
                    "Link": "https://medium.com/@renwa/the-underrated-bugs-clickjacking-css-injection-drag-drop-xss-cookie-bomb-login-logout-csrf-84307a98fffa"
                 }
              ],
              "Authors": ["Renwa (@RenwaX23)"],
              "Programs": ["-"],
              "Bugs": ["CSS injection", "Clickjacking", "Account takeover", "XSS", "Cookie bomb", "Self-XSS", "CSRF"],
              "Bounty": "3,850",
              "PublicationDate": "2022-05-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ResolveURI RXSS Imperva Waf Bypass",
                    "Link": "https://systemweakness.com/resolveuri-rxss-imperva-waf-bypass-c834ca573bd4"
                 }
              ],
              "Authors": ["Ahsan Shahid (@hunter0x8)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-05-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE via Dependency Confusion",
                    "Link": "https://systemweakness.com/rce-via-dependency-confusion-e0ed2a127013"
                 }
              ],
              "Authors": ["Samrat Gupta (@Sm4rty_)"],
              "Programs": ["-"],
              "Bugs": ["Dependency confusion"],
              "Bounty": "-",
              "PublicationDate": "2022-05-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account verification code bypass lead to a $4000 bounty",
                    "Link": "https://mokhansec.medium.com/account-verification-code-bypass-lead-to-a-4000-bounty-b31dda6f3011"
                 }
              ],
              "Authors": ["Mohsin Khan (@tabaahi_)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass"],
              "Bounty": "4,000",
              "PublicationDate": "2022-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Can analyzing javascript files lead to remote code execution?",
                    "Link": "https://melotover.medium.com/can-analyzing-javascript-files-lead-to-remote-code-execution-f24112f1aa1f"
                 }
              ],
              "Authors": ["Asem Eleraky (@melotover)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Paid For My Holiday With Bug Bounty",
                    "Link": "https://web.archive.org/web/20220516024454/https://medium.com/@tobydavenn/how-i-paid-for-my-holiday-with-bug-bounty-668f1f59e6e5"
                 }
              ],
              "Authors": ["Tobydavenn"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Broken Access Control", "IDOR", "Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2022-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "P1 Bug — PII information disclosure",
                    "Link": "https://medium.com/@huntersherlock11/p1-bug-pii-information-disclosure-7669ebbb91a8"
                 }
              ],
              "Authors": ["Huntersherlock"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Its all about 2fa bypass, or Account Takeover",
                    "Link": "https://medium.com/@anjaneyulukanakatla1996/its-all-about-2fa-bypass-or-account-takeover-f9521f0a03b5"
                 }
              ],
              "Authors": ["anjaneyulu kanakatla"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover", "OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The $16,000 Dev Mistake",
                    "Link": "https://medium.com/@masonhck357/the-16-000-dev-mistake-13e516e86be6"
                 }
              ],
              "Authors": ["Daniel Marte (@Masonhck3571)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "16,000",
              "PublicationDate": "2022-05-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cloudflare Pages, part 1: The fellowship of the secret",
                    "Link": "https://www.assetnote.io/resources/research/cloudflare-pages-part-1-the-fellowship-of-the-secret"
                 },
                 {
                    "Title": "Part 2: The two privescs",
                    "Link": "https://www.assetnote.io/resources/research/cloudflare-pages-part-2-the-two-privescs"
                 },
                 {
                    "Title": "Part 3: The return of the secrets",
                    "Link": "https://www.assetnote.io/resources/research/cloudflare-pages-part-3-the-return-of-the-secrets"
                 },
                 {
                    "Title": "Cloudflare writeup",
                    "Link": "https://blog.cloudflare.com/pages-bug-bounty/"
                 }
              ],
              "Authors": ["Sean Yeoh (@seanyeoh)", "James Hebden (@devec0)"],
              "Programs": ["Cloudflare"],
              "Bugs": ["Command injection", "Container escape", "Bash Path injection", "RCE", "Local Privilege Escalation", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-05-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Advanced sqlmap Case Study",
                    "Link": "https://www.pmnh.site/post/advanced-sqlmap-case-study-1/"
                 }
              ],
              "Authors": ["Peter M (@pmnh_)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-05-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How We hacked (bypassed) Admin Panel just by JS file",
                    "Link": "https://medium.com/@z.x/how-we-hacked-bypassed-admin-panel-just-by-js-file-eaa773b5cdb4"
                 }
              ],
              "Authors": ["Zhenwar Hawlery (@zhenwarx)", "moSec (@moe1n1)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-05-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-0540 - Authentication bypass in Seraph",
                    "Link": "https://blog.viettelcybersecurity.com/cve-2022-0540-authentication-bypass-in-seraph/"
                 }
              ],
              "Authors": ["Khoa Dinh (@_l0gg)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-05-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chained Bug: XML File Upload to XSS to CSRF to Full Account Take Over (ATO)",
                    "Link": "https://systemweakness.com/chained-bug-xml-file-upload-to-xss-to-csrf-to-full-account-take-over-ato-156409c41b57"
                 }
              ],
              "Authors": ["Zulfi Al-Farizi"],
              "Programs": ["-"],
              "Bugs": ["XSS", "CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-05-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Samsung Galaxy - Any App Can Install Any App In The Galaxy App Store",
                    "Link": "https://labs.f-secure.com/advisories/samsung-galaxy-any-app-can-install-any-app/"
                 }
              ],
              "Authors": ["Ken Gannon (@Yogehi)"],
              "Programs": ["Samsung"],
              "Bugs": ["Android", "Insecure intent"],
              "Bounty": "-",
              "PublicationDate": "2022-05-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Samsung Flow - Any App Can Read The External Storage",
                    "Link": "https://labs.f-secure.com/advisories/samsung-flow-any-app-can-read-the-external-storage/"
                 }
              ],
              "Authors": ["Ken Gannon (@Yogehi)"],
              "Programs": ["Samsung"],
              "Bugs": ["Android", "Insecure intent"],
              "Bounty": "-",
              "PublicationDate": "2022-05-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remotely permanent crash any Instagram user via permanent DoS in user DM's.",
                    "Link": "https://www.yesnaveen.com/remotely-permanent-crash-any-instagram"
                 }
              ],
              "Authors": ["Naveen (@NaveenHax)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS"],
              "Bounty": "1,575",
              "PublicationDate": "2022-05-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business Logic Errors - Art of Testing Cards",
                    "Link": "https://shahjerry33.medium.com/business-logic-errors-art-of-testing-cards-4907cfb46a57"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Payment bypass", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-05-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i found a vulnerability that leads to access any users’ sensitive data and got $500",
                    "Link": "https://medium.com/@robert0/how-did-i-find-a-vulnerability-that-leads-to-access-any-users-sensitive-data-and-got-500-5cce1c21d86a"
                 }
              ],
              "Authors": ["Mr Robert | Ahmed M Hassan (@Mr_Robert20)"],
              "Programs": ["Flickr"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2022-05-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[UNPATCHED] Cli: gh run download implementation allows overwriting git repository configuration upon artifacts downloading",
                    "Link": "https://github.com/Metnew/write-ups/tree/main/rce-gh-cli-run-download"
                 }
              ],
              "Authors": ["Vladimir Metnew (@vladimir_metnew)"],
              "Programs": ["GitHub"],
              "Bugs": ["RCE"],
              "Bounty": "500",
              "PublicationDate": "2022-05-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking a Bank by Finding a 0day in DotCMS",
                    "Link": "https://blog.assetnote.io/2022/05/03/hacking-a-bank-using-dotcms-rce/"
                 }
              ],
              "Authors": ["Shubham Shah (@infosec_au)", "Hussein Daher (@HusseiN98D)"],
              "Programs": ["-"],
              "Bugs": ["Directory traversal", "Unrestricted file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-05-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-25262 | JetBrains Hub single-click SAML response takeover",
                    "Link": "https://github.com/yuriisanin/CVE-2022-25262"
                 }
              ],
              "Authors": ["Yurii Sanin (@SaninYurii)"],
              "Programs": ["JetBrains"],
              "Bugs": ["Broken authorization", "SAML", "OAuth"],
              "Bounty": "-",
              "PublicationDate": "2022-05-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got a lousyT-Shirt from the Dutch Government.",
                    "Link": "https://maxva.medium.com/how-i-got-a-lousyt-shirt-from-the-dutch-goverment-2a0d13fe7675"
                 }
              ],
              "Authors": ["Mava (@mava656)"],
              "Programs": ["Dutch Government"],
              "Bugs": ["Old components with known vulnerabilities"],
              "Bounty": "-",
              "PublicationDate": "2022-05-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerable GitHub Actions Workflows Part 2: Actions That Open the Door to CI/CD Pipeline Attacks",
                    "Link": "https://www.legitsecurity.com/blog/github-actions-that-open-the-door-to-cicd-pipeline-attacks"
                 }
              ],
              "Authors": ["Noam Dotan"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "CI/CD"],
              "Bounty": "-",
              "PublicationDate": "2022-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ATO without any interaction [aws cognito misconfiguration]",
                    "Link": "https://shreyaskoli.medium.com/ato-without-any-interaction-aws-cognito-misconfiguration-d690f4b3da11"
                 }
              ],
              "Authors": ["Shreyaskoli (@SPY8OY)"],
              "Programs": ["GitHub"],
              "Bugs": ["Account takeover", "Lack of rate limiting"],
              "Bounty": "550",
              "PublicationDate": "2022-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Page Admin Disclosure when Posting a Reel",
                    "Link": "https://zerocode-ph.medium.com/page-admin-disclosure-when-posting-a-reel-1bfac9bd7f71"
                 }
              ],
              "Authors": ["Syd Ricafort (@devsyd11)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Spoofing"],
              "Bounty": "1,000",
              "PublicationDate": "2022-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sensitive Data Exfiltration through XSS ($450)",
                    "Link": "https://medium.com/system-weakness/sensitive-data-exfiltration-through-xss-450-409162eced3a"
                 }
              ],
              "Authors": ["Zulfi Al-Farizi"],
              "Programs": ["-"],
              "Bugs": ["Token leak"],
              "Bounty": "450",
              "PublicationDate": "2022-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploitation of an SSRF vulnerability against EC2 IMDSv2",
                    "Link": "https://www.yassineaboukir.com//blog/exploitation-of-an-SSRF-vulnerability-against-EC2-IMDSv2/"
                 }
              ],
              "Authors": ["Yassine Aboukir (@Yassineaboukir)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-04-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Contact Point Deanonymization Vulnerability in Meta",
                    "Link": "https://lokeshdlk77.medium.com/contact-point-deanonymization-vulnerability-in-meta-90d575c4d8ef"
                 }
              ],
              "Authors": ["Lokesh Kumar (@lokeshdlk77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "12,000",
              "PublicationDate": "2022-04-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Wiz Research discovers \"ExtraReplica\"— a cross-account database vulnerability in Azure PostgreSQL",
                    "Link": "https://www.wiz.io/blog/wiz-research-discovers-extrareplica-cross-account-database-vulnerability-in-azure-postgresql/"
                 }
              ],
              "Authors": ["Shir Tamari (@shirtamari)", "Ronen Shustin (@ronenshh)", "Nir Ohfeld (@nirohfeld)", "Sagi Tzadik (@sagitz_)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Cross-tenant vulnerability", "Privilege escalation", "Authentication bypass", "Cloud"],
              "Bounty": "-",
              "PublicationDate": "2022-04-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2FA Secret value disclosure leads to 2FA Bypass - Bug Bounty Writeup",
                    "Link": "https://www.cyberick.com/post/2fa-secret-value-disclosure-leads-to-2fa-bypass-bug-bounty-writeup"
                 }
              ],
              "Authors": ["Aditya Singh / rook1337 (@imrook1337)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-04-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Encrypting our way to SSRF in VMWare Workspace One UEM (CVE-2021-22054)",
                    "Link": "https://blog.assetnote.io/2022/04/27/vmware-workspace-one-uem-ssrf/"
                 }
              ],
              "Authors": ["Keiran Sampson (@hpy_downunder)", "James Hebden (@devec0)", "Shubham Shah (@infosec_au)"],
              "Programs": ["VMware"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing WAF for $2222",
                    "Link": "https://divyanshsharma2401.medium.com/bypassing-waf-for-2222-f99b80cfdb9b"
                 }
              ],
              "Authors": ["Divyansh Sharma"],
              "Programs": ["-"],
              "Bugs": ["WAF bypass", "Path traversal"],
              "Bounty": "2,222",
              "PublicationDate": "2022-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Azure Monitor – Malicious KQL Query",
                    "Link": "https://securecloud.blog/2022/04/27/azure-monitor-malicious-kql-query/"
                 }
              ],
              "Authors": ["Joosua Santasalo (@SantasaloJoosua)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Privilege escalation", "Cloud"],
              "Bounty": "-",
              "PublicationDate": "2022-04-27",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Privileged account creation via Mass Assignment towards a full compromise using a Stored XSS",
                  "Link": "https://www.aeth.cc/public/Article-Pass-Culture/mass-assignment-article-en.html"
               }
            ],
            "Authors": ["Aethlios (@AethliosIK)"],
            "Programs": ["pass Culture"],
            "Bugs": ["Stored XSS", "Mass assignment", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2022-04-26",
            "AddedDate": "2023-01-09"
         },
           {
              "Links": [
                 {
                    "Title": "Package Planting: Are You [Unknowingly] Maintaining Poisoned Packages?",
                    "Link": "https://blog.aquasec.com/npm-package-planting"
                 }
              ],
              "Authors": ["Yakir Kadkoda"],
              "Programs": ["GitHub"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-04-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fuzzing and credentials leakage..awesome bug hunting writeup",
                    "Link": "https://medium.com/@abdalrahman.alshammas/fuzzing-and-credentials-leakage-nice-bug-hunting-writeup-38b2e774b300"
                 }
              ],
              "Authors": ["Abdalrahman Alshammas"],
              "Programs": ["-"],
              "Bugs": ["Hardcoded credentials", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unlock any blur text/picture without membership/subscription on Scribd.com |By Neuchi",
                    "Link": "https://systemweakness.com/unlock-any-blur-text-picture-without-membership-subscription-on-scribd-com-by-neuchi-69237776e24"
                 }
              ],
              "Authors": ["Neil Neuchi"],
              "Programs": ["Scribd.com"],
              "Bugs": ["Payment bypass", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "EJS, Server side template injection RCE (CVE-2022-29078) - writeup",
                    "Link": "https://eslam.io/posts/ejs-server-side-template-injection-rce/"
                 }
              ],
              "Authors": ["Eslam Salem (@net_code)"],
              "Programs": ["ejs", "NetApp"],
              "Bugs": ["SSTI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got Apple Hall Of Fame !",
                    "Link": "https://shubhdeepp.medium.com/how-i-got-apple-hall-of-fame-3d86f858c05f"
                 }
              ],
              "Authors": ["shubhdeep (@Shubhdeeppp)"],
              "Programs": ["Apple"],
              "Bugs": ["Content injection"],
              "Bounty": "-",
              "PublicationDate": "2022-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Bypassed 2FA while Resetting Password",
                    "Link": "https://infosecwriteups.com/how-i-bypass-2fa-while-resetting-password-3f73bf665728"
                 }
              ],
              "Authors": ["Sufiyan Gouri (@gouri_sufyan)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2022-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Adventures Into The MeowCorp Bug Bounty Program",
                    "Link": "https://www.tnirmal.com.np/2022/04/adventures-into-meowcorp-bug-bounty.html"
                 }
              ],
              "Authors": ["Nirmal Thapa (@tnirmalz)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Weak credentials", "SSRF", ".git folder disclosure", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Security issues with cloudflare/odoh-server-go and the ODoH RFC draft",
                    "Link": "https://github.com/cloudflare/odoh-server-go/issues/30"
                 }
              ],
              "Authors": ["Frans Rosén (@fransrosen)"],
              "Programs": ["Cloudflare"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Smashing the Modern Web Tech Stack — Part 1: The Evolving Threat Landscape in 2022 and DOM-based XSS in Cloud-Native React Apps.",
                    "Link": "https://medium.com/@malwarejoe/smashing-the-modern-web-tech-stack-part-1-the-evolving-threat-landscape-in-2022-and-dom-based-324696684239"
                 }
              ],
              "Authors": ["MalwareJoe"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open Redirection into Bentley System",
                    "Link": "https://amit-lt.medium.com/open-redirection-into-bentley-system-d1ee188bfb25"
                 }
              ],
              "Authors": ["Amit Kumar (@Amitlt2)"],
              "Programs": ["Bentley Systems"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Gaining Unlimited access to graph AuditLogs endpoint using complex filters with non-privileged user account",
                    "Link": "https://securecloud.blog/2022/04/21/microsoft-cloud-security-research-public-disclosure-gaining-unlimited-access-to-graph-auditlogs-endpoint-using-complex-filters-with-non-privileged-user-account/"
                 }
              ],
              "Authors": ["Joosua Santasalo (@SantasaloJoosua)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting a File Upload Vulnerability — A Directory Traversal Attack",
                    "Link": "https://systemweakness.com/exploiting-a-file-upload-vulnerability-a-directory-traversal-attack-419308cdb059"
                 }
              ],
              "Authors": ["Kwadwo Amoako"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-04-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-21449: Psychic Signatures in Java",
                    "Link": "https://neilmadden.blog/2022/04/19/psychic-signatures-in-java/"
                 },
                 {
                    "Title": "A few clarifications about CVE-2022-21449",
                    "Link": "https://neilmadden.blog/2022/04/25/a-few-clarifications-about-cve-2022-21449/"
                 },
                 {
                    "Title": "Lab by @datadoghq",
                    "Link": "https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/jwt-null-signature-vulnerable-app"
                 },
                 {
                    "Title": "Lab by @SecCodeWarrior",
                    "Link": "https://www.securecodewarrior.com/blog/psychic-signatures"
                 }
              ],
              "Authors": ["Neil Madden (@neilmaddog)"],
              "Programs": ["Oracle"],
              "Bugs": ["Signature bypass", "Cryptographic issues"],
              "Bounty": "-",
              "PublicationDate": "2022-04-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation",
                    "Link": "https://unit42.paloaltonetworks.com/aws-log4shell-hot-patch-vulnerabilities/"
                 }
              ],
              "Authors": ["Unit 42 (@Unit42_Intel)"],
              "Programs": ["AWS"],
              "Bugs": ["Privilege escalation", "Container escape"],
              "Bounty": "-",
              "PublicationDate": "2022-04-19",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Adobe Acrobat hollowing out same-origin policy",
                  "Link": "https://palant.info/2022/04/19/adobe-acrobat-hollowing-out-same-origin-policy/"
               }
            ],
            "Authors": ["Wladimir Palant (@WPalant)"],
            "Programs": ["Adobe"],
            "Bugs": ["XSS", "SOP bypass", "Open redirect", "postMessage"],
            "Bounty": "-",
            "PublicationDate": "2022-04-19",
            "AddedDate": "2022-12-09"
         },
           {
              "Links": [
                 {
                    "Title": "Palisade identifies Wormable Cross-Site Scripting Vulnerability affecting Rarible’s NFT Marketplace",
                    "Link": "https://palisade.consulting/blog/rarible-vulnerability"
                 }
              ],
              "Authors": ["Palissade (@PalisadeLLC)"],
              "Programs": ["Rarible"],
              "Bugs": ["XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2022-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS To Other Users Via Messages",
                    "Link": "https://systemweakness.com/stored-xss-to-other-users-via-messages-e033239821b5"
                 }
              ],
              "Authors": ["Tobydavenn"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection in Harvard’s Subdomain",
                    "Link": "https://medium.com/pentesternepal/sql-injection-in-harvards-subdomain-c3148f8be156"
                 }
              ],
              "Authors": ["Bibek Neupane (@nb1b3k)"],
              "Programs": ["Harvard"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full Account Takeover via Open Redirection",
                    "Link": "https://medium.com/@vflexo/full-account-takeover-via-open-redirection-41c167db46"
                 }
              ],
              "Authors": ["vFlexo (@vflexo)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Token leak", "Account takeover", "OAuth"],
              "Bounty": "-",
              "PublicationDate": "2022-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSLeaking with my best bud SOP",
                    "Link": "https://blog.viettelcybersecurity.com/searching-against-the-flow/"
                 }
              ],
              "Authors": ["Ha Anh Hoang"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How we spoofed ENS domains for $15k",
                    "Link": "https://medium.com/@hacxyk/how-we-spoofed-ens-domains-52acea2079f6"
                 }
              ],
              "Authors": ["Hacxyk. (@Hacxyk)"],
              "Programs": ["ENS"],
              "Bugs": ["Homograph attack"],
              "Bounty": "15,000",
              "PublicationDate": "2022-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to see likes and dislikes count even though is hidden by victim | YouTube #4",
                    "Link": "https://bloggerrando.blogspot.com/2022/04/15-1.html"
                 }
              ],
              "Authors": ["R ando (@Rando02355205)"],
              "Programs": ["Google"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[3/3] Cache Poisoning & Lateral Movement @ GitLab",
                    "Link": "https://medium.com/@_ip_/3-3-cache-poisoning-lateral-movement-gitlab-9c6288708576"
                 }
              ],
              "Authors": ["IP"],
              "Programs": ["GitLab"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Crazy Simple Insecure Design & 300$ Bounty!",
                    "Link": "https://mr23r0.medium.com/crazy-smiple-insecure-design-300-bounty-16a2b8e80522"
                 }
              ],
              "Authors": ["Saransh Saraf (@mr23r0)"],
              "Programs": ["-"],
              "Bugs": ["IP grabbing"],
              "Bounty": "300",
              "PublicationDate": "2022-04-15",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Prototype Pollution in fast-xml-parser",
                  "Link": "https://github.com/Sudistark/advisories/blob/main/2023/npm-package/fast-xml-parser.md"
               }
            ],
            "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
            "Programs": ["-"],
            "Bugs": ["Prototype pollution"],
            "Bounty": "-",
            "PublicationDate": "2022-04-14",
            "AddedDate": "2022-06-05"
         },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-26133 - Bitbucket Data Center - Java Deserialization Vulnerability",
                    "Link": "https://github.com/snowyyowl/writeups/tree/main/CVE-2022-26133"
                 }
              ],
              "Authors": ["Benny Jacob (@bennyyjacob)"],
              "Programs": ["Atlassian"],
              "Bugs": ["Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2022-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Vulnerabilities in Cisco Expressway",
                    "Link": "https://firefart.at/post/multiple_vulnerabilities_cisco_expressway/"
                 }
              ],
              "Authors": ["Christian Mehlmauer (@firefart)"],
              "Programs": ["Cisco"],
              "Bugs": ["Memory leak", "Exposed administrative interface", "STUN", "TURN"],
              "Bounty": "-",
              "PublicationDate": "2022-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "United Nations bug bounty[writeup]",
                    "Link": "https://debprasadbanerjee502.medium.com/united-nations-bug-bounty-writeup-4bcfdefbb8d3"
                 }
              ],
              "Authors": ["Debprasad Banerjee"],
              "Programs": ["United Nations"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing Azure Hybrid Workers for Privilege Escalation – Part 2: An Azure PrivSec Story",
                    "Link": "https://www.netspi.com/blog/technical/cloud-penetration-testing/abusing-azure-hybrid-workers-part-2/"
                 }
              ],
              "Authors": ["Josh Magri (@passthehashbrwn)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "10,000",
              "PublicationDate": "2022-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blinding Snort: Breaking The Modbus OT Preprocessor",
                    "Link": "https://claroty.com/2022/04/14/blog-research-blinding-snort-breaking-the-modbus-ot-preprocessor/"
                 }
              ],
              "Authors": ["Claroty's Team82 (@Claroty)"],
              "Programs": ["Cisco"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass Rate Limit — A blank space leads to this random encounter!",
                    "Link": "https://infosecwriteups.com/bypass-rate-limit-a-blank-space-leads-to-this-random-encounter-e18e72fbf228"
                 }
              ],
              "Authors": ["Roxst4r (@mveswar98)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Rate limiting bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "MY First Bug In Hackerone",
                    "Link": "https://medium.com/@anjaneyulukanakatla1996/my-first-bug-in-hackerone-a68cf7b05510"
                 }
              ],
              "Authors": ["anjaneyulu kanakatla"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[2/3] XSS Through The Front-Door @ GitLab",
                    "Link": "https://medium.com/@_ip_/2-3-xss-through-the-front-door-gitlab-fc4b6799e743"
                 }
              ],
              "Authors": ["IP"],
              "Programs": ["GitLab"],
              "Bugs": ["XSS", "CSP bypass", "DOM-based JavaScript injection"],
              "Bounty": "-",
              "PublicationDate": "2022-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Threat Evasion for aws:multifactorAuthPresent condition using Cloudshell",
                    "Link": "https://falcnix.medium.com/threat-evasion-for-aws-multifactorauthpresent-condition-using-cloudshell-8296b34ecad4"
                 }
              ],
              "Authors": ["Falcnix (@falcnix)"],
              "Programs": ["AWS"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Inside the Black Box | How We Fuzzed Microsoft Defender for IoT and Found Multiple Vulnerabilities",
                    "Link": "https://www.sentinelone.com/labs/inside-the-black-box-how-we-fuzzed-microsoft-defender-for-iot-and-found-multiple-vulnerabilities/"
                 }
              ],
              "Authors": ["Kasif Dekel (@kasifdekel)", "Ronen Shustin (@ronenshh)"],
              "Programs": ["Microsoft"],
              "Bugs": ["DoS", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass Apple Corp SSO on Apple Admin Panel",
                    "Link": "https://medium.com/@StealthyBugs/bypass-apple-corp-sso-on-apple-admin-panel-dbfb72c7e634"
                 }
              ],
              "Authors": ["Stealthy (@stealthybugs)"],
              "Programs": ["Apple"],
              "Bugs": ["Path traversal"],
              "Bounty": "6,000",
              "PublicationDate": "2022-04-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-25165: Privilege Escalation to SYSTEM in AWS VPN Client",
                    "Link": "https://rhinosecuritylabs.com/aws/cve-2022-25165-aws-vpn-client/"
                 }
              ],
              "Authors": ["Rhino Security Labs (@RhinoSecurity)"],
              "Programs": ["AWS"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-04-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR (Insecure Direct Object Reference) leads to listing all valid Users and edit their Profiles",
                    "Link": "https://medium.com/@Bishoo97x/idor-insecure-direct-object-reference-leads-to-listing-all-valid-users-and-edit-their-profiles-2d7bcba78890"
                 }
              ],
              "Authors": ["Ahmed Hassan"],
              "Programs": ["Drexel University"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-04-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-24527: Microsoft Connected Cache Local Privilege Escalation (Fixed)",
                    "Link": "https://www.rapid7.com/blog/post/2022/04/12/cve-2022-24527-microsoft-connected-cache-local-privilege-escalation-fixed/"
                 }
              ],
              "Authors": ["Jacob Baines (@Junior_Baines)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-04-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS - The LocalStorage Robbery",
                    "Link": "https://shahjerry33.medium.com/xss-the-localstorage-robbery-d5fbf353c6b0"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)", "ethicalbughunter (@ethicalbughuntr)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-04-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken session control leads to access the admin panel even after revoking the access!! — #ZOHO",
                    "Link": "https://naveenroy008.medium.com/broken-session-control-leads-to-access-the-admin-panel-even-after-revoking-the-access-zoho-db219b19d2dd"
                 }
              ],
              "Authors": ["Naveenroy"],
              "Programs": ["Zoho"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-04-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "NotGitBleed",
                    "Link": "https://www.notgitbleed.com"
                 }
              ],
              "Authors": ["Aaron Devaney"],
              "Programs": ["GitHub"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-04-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AWS RDS Vulnerability Leads to AWS Internal Service Credentials",
                    "Link": "https://blog.lightspin.io/aws-rds-critical-security-vulnerability"
                 }
              ],
              "Authors": ["Gafnit Amiga (@gafnitav)"],
              "Programs": ["AWS"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2022-04-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SVG SSRFs and saga of bypasses",
                    "Link": "https://infosecwriteups.com/svg-ssrfs-and-saga-of-bypasses-777e035a17a7"
                 }
              ],
              "Authors": ["Preetham Bomma (@cyber01_)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2022-04-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[1/3] Brute-Force Protection Bypass @ GitLab",
                    "Link": "https://medium.com/@_ip_/1-3-brute-force-protection-bypass-gitlab-15a17909bb"
                 }
              ],
              "Authors": ["IP"],
              "Programs": ["GitLab"],
              "Bugs": ["Bruteforce", "Rate limiting bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-04-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The #100DaysOfHacking Challenge : A Game Changer for Me",
                    "Link": "https://njmulsqb.engineer/2022/04/10/the-100daysofhacking-challenge.html"
                 }
              ],
              "Authors": ["Najam Ul Saqib (@NjmUlSqb)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-04-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privacy Disclosure on Facebook Lite after Creating a Post",
                    "Link": "https://medium.com/@RheyJuls/privacy-disclosure-on-facebook-lite-after-creating-a-post-b12a1cad8d8a"
                 }
              ],
              "Authors": ["Rhey"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Privacy issue"],
              "Bounty": "400",
              "PublicationDate": "2022-04-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS | HTML Injection and File Upload Bypass in HUAWEI Subdomain",
                    "Link": "https://medium.com/@Bishoo97x/xss-html-injection-and-file-upload-bypass-in-huawei-subdomain-64966ba4f4ac"
                 }
              ],
              "Authors": ["Ahmed Hassan"],
              "Programs": ["Huawei"],
              "Bugs": ["XSS", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2022-04-10",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Securing Easy Appointments and earning CVE-2022-0482",
                  "Link": "https://opencirt.com/hacking/securing-easy-appointments-cve-2022-0482/"
               }
            ],
            "Authors": ["Francesco Carlucci (@francecarlucci)"],
            "Programs": ["Easy!Appointments"],
            "Bugs": ["Broken Access Control"],
            "Bounty": "-",
            "PublicationDate": "2022-04-09",
            "AddedDate": "2022-10-24"
         },
           {
              "Links": [
                 {
                    "Title": "MSRC – Joint security research write up – Azure AD Consent bypass disclosure with Kim Jamia – Q1/2022",
                    "Link": "https://securecloud.blog/2022/04/09/msrc-join-security-research-write-up-azure-ad-consent-bypass-disclosure-with-kim-jamia-q1-2022/"
                 }
              ],
              "Authors": ["Joosua Santasalo (@SantasaloJoosua)", "Kim Jämiä (@KimJamia)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-04-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How a YouTube Video lead to pwning a web application via SQL Injection worth $4324 bounty",
                    "Link": "https://infosecwriteups.com/how-a-youtube-video-lead-to-pwning-a-web-application-via-sql-injection-worth-4324-bounty-285f0a9b9f6c"
                 }
              ],
              "Authors": ["Vishal Saini (@k4k4r07)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "4,324",
              "PublicationDate": "2022-04-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Meta's SparkAR RCE Via ZIP Path Traversal",
                    "Link": "https://blog.fadyothman.com/metas-sparkar/"
                 }
              ],
              "Authors": ["Fady Othman (@Fady_Othman)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["RCE", "Path traversal"],
              "Bounty": "2,500",
              "PublicationDate": "2022-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple vulnerability leading to account takeover in TikTok SMB subdomain.",
                    "Link": "https://ahmadaabdulla.medium.com/vulnerabilitymultiple-vulnerability-leading-to-account-takeover-in-tiktok-smb-subdomain-c99e4a50b377"
                 }
              ],
              "Authors": ["Ahmad A Abdulla (@lu3ky13)"],
              "Programs": ["TikTok"],
              "Bugs": ["IDOR"],
              "Bounty": "1,000",
              "PublicationDate": "2022-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i got access to 1600k Users PII Data $$$$",
                    "Link": "https://gokulap.medium.com/how-i-got-access-to-1600k-users-pii-data-64a27a540963"
                 }
              ],
              "Authors": ["Gokul AP (@CodingGokul)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,500",
              "PublicationDate": "2022-04-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF and Account Takeover via XSS in ERPNext (0-day)",
                    "Link": "https://tech-blog.cymetrics.io/en/posts/huli/erpnext-ssrf-and-xss-to-account-takeover/"
                 }
              ],
              "Authors": ["huli (@aszx87410)"],
              "Programs": ["ERPNext"],
              "Bugs": ["SSRF", "XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-04-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Watch out the links : Account takeover!",
                    "Link": "https://akashhamal0x01.medium.com/watch-out-the-links-account-takeover-32b9315390a7"
                 }
              ],
              "Authors": ["Akash Hamal (@AkashHamal0x01)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-04-06",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Azure Active Directory Exposes Internal Information",
                  "Link": "https://www.secureworks.com/research/azure-active-directory-exposes-internal-information"
               }
            ],
            "Authors": ["Counter Threat Unit Research Team"],
            "Programs": ["Microsoft (Azure)"],
            "Bugs": ["Cloud", "Information disclosure", "Azure AD"],
            "Bounty": "-",
            "PublicationDate": "2022-04-05",
            "AddedDate": "2023-02-26"
         },
           {
            "Links": [
               {
                  "Title": "The Bug That Kept On Giving :: PaymentBypass :: Eposed Return Url",
                  "Link": "https://crypt0g30rgy.github.io/post/PaymentBypassThree"
               }
            ],
            "Authors": ["g30rgy th3 d4rk (@Crypt0g30rgy)"],
            "Programs": ["-"],
            "Bugs": ["Payment bypass", "Logic flaw"],
            "Bounty": "500",
            "PublicationDate": "2022-04-05",
            "AddedDate": "2023-02-26"
         },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-4119: [Bookstack] Email harvesting via SQL \"LIKE\" clause exploitation",
                    "Link": "https://haxatron.gitbook.io/vulnerability-research/vr1"
                 }
              ],
              "Authors": ["Haxatron (@Haxatron1)"],
              "Programs": ["Bookstack"],
              "Bugs": ["Broken Access Control", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "New npm Flaws Let Attackers Better Target Packages for Account Takeover",
                    "Link": "https://blog.aquasec.com/npm-supply-chain-attack"
                 }
              ],
              "Authors": ["Yakir Kadkoda"],
              "Programs": ["GitHub"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HTTP Request Smuggling on business.apple.com and Others.",
                    "Link": "https://medium.com/@StealthyBugs/http-request-smuggling-on-business-apple-com-and-others-2c43e81bcc52"
                 }
              ],
              "Authors": ["Stealthy (@stealthybugs)"],
              "Programs": ["Apple"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "36,000",
              "PublicationDate": "2022-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Azure Active Directory Exposes Internal Information",
                    "Link": "https://www.secureworks.com/research/azure-active-directory-exposes-internal-information"
                 }
              ],
              "Authors": ["Secureworks Counter Threat Unit (@Secureworks)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked one of the biggest airlines group of the world",
                    "Link": "https://tarekbouali.com/posts/how-i-hacked-one-of-the-biggest-airlines-group-of-the-world/"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://webs3c.com/t/how-i-hacked-one-of-the-biggest-airlines-group-in-the-world/32"
                 }
              ],
              "Authors": ["Tarek Bouali (@iambouali)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CloudKit Share Records leak the title of private iCloud files",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0014"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Apple"],
              "Bugs": ["IDOR", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-38159: MOVEit Transfer SQL Injection Analysis",
                    "Link": "https://blog.viettelcybersecurity.com/moveit-transfer-cve/"
                 }
              ],
              "Authors": ["Tuan Anh Nguyen (@haxor31337)"],
              "Programs": ["Palantir Public"],
              "Bugs": ["SQL injection"],
              "Bounty": "5,000",
              "PublicationDate": "2022-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spoof as another Facebook user to report an impostor account",
                    "Link": "https://zerocode-ph.medium.com/spoof-as-another-facebook-user-to-report-an-impostor-account-f2dd6683744d"
                 }
              ],
              "Authors": ["Syd Ricafort (@devsyd11)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Spoofing"],
              "Bounty": "-",
              "PublicationDate": "2022-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "NoSQL Injection in Plain Sight",
                    "Link": "https://kuldeep.io/posts/nosql-injection-in-plain-sight/"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://www.synack.com/blog/exploits-explained-nosql-injection-returns-private-information/"
                 }
              ],
              "Authors": ["Kuldeep Pandya (@kuldeepdotexe)"],
              "Programs": ["-"],
              "Bugs": ["NoSQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "MacOS SUHelper Root Privilege Escalation Vulnerability: A Deep Dive Into CVE-2022-22639",
                    "Link": "https://www.trendmicro.com/en_us/research/22/d/macos-suhelper-root-privilege-escalation-vulnerability-a-deep-di.html"
                 },
                 {
                    "Title": "PoC",
                    "Link": "https://github.com/jhftss/CVE-2022-22639"
                 }
              ],
              "Authors": ["Mickey Jin (@patch1t)"],
              "Programs": ["Apple"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacked Nokia With Reflected Cross-site Scripting Vulnerability….",
                    "Link": "https://amit-lt.medium.com/hacked-nokia-with-reflected-cross-site-scripting-vulnerability-327daa8e62fb"
                 }
              ],
              "Authors": ["Amit Kumar (@Amitlt2)"],
              "Programs": ["Nokia"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cloud SSRF Exploitation",
                    "Link": "https://medium.com/stolabs/cloud-ssrf-exploitation-1f256bdc145f"
                 }
              ],
              "Authors": ["Dan Barros"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline",
                    "Link": "https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability"
                 }
              ],
              "Authors": ["Noam Dotan"],
              "Programs": ["GitHub"],
              "Bugs": ["Privilege escalation", "CI/CD"],
              "Bounty": "-",
              "PublicationDate": "2022-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting a double-edged SSRF for server and client-side impact",
                    "Link": "https://www.yassineaboukir.com/blog/exploiting-a-double-edged-SSRF-for-server-and-client-side-impact/"
                 }
              ],
              "Authors": ["Yassine Aboukir (@Yassineaboukir)", "Surajjjj (@ninetyn1ne_)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-04-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacked Instagram Handle Of Samsung….",
                    "Link": "https://amit-lt.medium.com/hacked-instagram-handle-of-samsung-cb1a35990a90"
                 }
              ],
              "Authors": ["Amit Kumar (@Amitlt2)"],
              "Programs": ["Samsung"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2022-04-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables",
                    "Link": "https://blog.dbouman.nl/2022/04/02/How-The-Tables-Have-Turned-CVE-2022-1015-1016/"
                 }
              ],
              "Authors": ["David Bouman (@pqlqpql)"],
              "Programs": ["Linux Kernel Organization"],
              "Bugs": ["Memory corruption", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "View Friends List of any users using “View as” | Facebook Bug bounty",
                    "Link": "https://ph-hitachi.medium.com/view-friends-list-of-any-users-using-view-as-facebook-bug-bounty-edeb6af5640b"
                 }
              ],
              "Authors": ["Ph.Hitachi"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Times I Hacked Duke University With RXSS Vulnerability!!!",
                    "Link": "https://amit-lt.medium.com/multiple-times-i-hacked-duke-university-with-rxss-vulnerability-7e291aad043a"
                 }
              ],
              "Authors": ["Amit Kumar (@Amitlt2)"],
              "Programs": ["Duke University"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Design Flaw : A Tale of Permanent DOS (Informative -> Triaged)",
                    "Link": "https://akashhamal0x01.medium.com/design-flaw-a-tale-of-permanent-dos-a9ef05181083"
                 }
              ],
              "Authors": ["Akash Hamal (@AkashHamal0x01)"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up – Finapi (Open Banking API) Oauth Credentials Exposed In Plain Text In Android App",
                    "Link": "https://omespino.com/write-up-finapi-open-banking-api-oauth-credentials-exposed-in-plain-text-in-android-app/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["-"],
              "Bugs": ["Hardcoded credentials", "Android"],
              "Bounty": "-",
              "PublicationDate": "2022-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Debugging the undebuggable and finding a CVE in Microsoft Defender for Endpoint",
                    "Link": "https://medium.com/falconforce/debugging-the-undebuggable-and-finding-a-cve-in-microsoft-defender-for-endpoint-ce36f50bb31"
                 }
              ],
              "Authors": ["Gijs Hollestelle"],
              "Programs": ["Microsoft"],
              "Bugs": ["Endpoint spoofing"],
              "Bounty": "-",
              "PublicationDate": "2022-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Small bugs are more dangerous than you think",
                    "Link": "https://medium.com/@terminatorLM/small-bugs-are-more-dangerous-than-you-think-9411618191ab"
                 }
              ],
              "Authors": ["Liv Matan (@terminatorLM)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "Stored XSS", "Open redirect", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwning a Cisco RV340 with a 4 bug chain exploit",
                    "Link": "https://blog.relyze.com/2022/04/pwning-cisco-rv340-with-4-bug-chain.html"
                 }
              ],
              "Authors": ["Liv (@terminatorLM)"],
              "Programs": ["Cisco"],
              "Bugs": ["Local Privilege Escalation", "OS command injection", "RCE", "Session management issue"],
              "Bounty": "-",
              "PublicationDate": "2022-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Large-scale and Longitudinal Measurement Study of DKIM Deployment",
                    "Link": "https://shenkaiwen.com/publication/2022-dkim/"
                 }
              ],
              "Authors": ["Chuhan Wang", "Kaiwen Shen (@m0xiaoxi)", "Minglei Guo", "Yuxuan Zhao", "Mingming Zhang", "Jianjun Chen", "Baojun Liu", "Xiaofeng Zheng", "Haixin Duan", "Yanzhong Lin", "Qingfeng Pan"],
              "Programs": ["Google", "Mailchimp", "Sendgrid", "Salesforce"],
              "Bugs": ["Email spoofing", "Phishing"],
              "Bounty": "-",
              "PublicationDate": "2022-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Race condition in Tendermint’s StarPort",
                    "Link": "https://blog.credshields.com/race-condition-in-tendermints-starport-7cebe176d935"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["Cosmos"],
              "Bugs": ["Race condition"],
              "Bounty": "5,000",
              "PublicationDate": "2022-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Critical SSRF on Evernote",
                    "Link": "https://blog.neolex.dev/13/"
                 }
              ],
              "Authors": ["Neolex (@NeolexSecurity)"],
              "Programs": ["Evernote"],
              "Bugs": ["SSRF"],
              "Bounty": "5,000",
              "PublicationDate": "2022-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Got Access To Dota 2 Admin Panel By Exploiting In-game Feature",
                    "Link": "https://abdilahrf.github.io/bugbounty/got-access-to-dota-2-admin-panel-by-exploiting-in-game-feature"
                 }
              ],
              "Authors": ["Abdillah Muhamad (@abdilahrf)"],
              "Programs": ["Valve"],
              "Bugs": ["XSS"],
              "Bounty": "900",
              "PublicationDate": "2022-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-27643 - NETGEAR R6700v3 upnpd Buffer Overflow Remote Code Execution Vulnerability",
                    "Link": "https://blog.relyze.com/2022/03/cve-2022-27643-netgear-r6700v3-upnpd.html"
                 }
              ],
              "Authors": ["Relyze (@relyze)"],
              "Programs": ["Netgear"],
              "Bugs": ["Memory corruption", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated Remote Code Execution in Cisco Nexus Dashboard Fabric Controller (formerly DCNM)",
                    "Link": "https://github.com/pedrib/PoC/blob/master/advisories/Cisco/DCNMPwn.md"
                 }
              ],
              "Authors": ["Pedro Ribeiro (@pedrib1337)"],
              "Programs": ["Cisco"],
              "Bugs": ["Insecure deserialization", "Local Privilege Escalation", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GitHub Cache Poisoning",
                    "Link": "https://scribesecurity.com/blog/github-cache-poisoning"
                 }
              ],
              "Authors": ["Scribe Security (@ScribeSecurity)"],
              "Programs": ["GitHub"],
              "Bugs": ["Cache poisoning attack", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-03-30",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "CVE-2022-22948: Sensitive Information Disclosure in VMware vCenter",
                  "Link": "https://pentera.io/blog/information-disclosure-in-vmware-vcenter/"
               }
            ],
            "Authors": ["Yuval Lazar"],
            "Programs": ["VMware"],
            "Bugs": ["Information disclosure"],
            "Bounty": "-",
            "PublicationDate": "2022-03-29",
            "AddedDate": "2023-01-11"
         },
           {
            "Links": [
               {
                  "Title": "Joomla! <= 4.1.0 (Tar.php) Zip Slip Vulnerability",
                  "Link": "https://karmainsecurity.com/KIS-2022-05"
               }
            ],
            "Authors": ["Egidio Romano / EgiX"],
            "Programs": ["Joomla!"],
            "Bugs": ["Zip Slip attack", "Path traversal", "Source code disclosure"],
            "Bounty": "-",
            "PublicationDate": "2022-03-29",
            "AddedDate": "2022-12-20"
         },
           {
              "Links": [
                 {
                    "Title": "How I bypassed 403 forbidden domain using a simple trick",
                    "Link": "https://janmuhammadzaidi.medium.com/how-i-bypassed-403-forbidden-domain-using-a-simple-trick-c2d538de04b8"
                 }
              ],
              "Authors": ["Jan Muhammad Zaidi (@hasanakajan)"],
              "Programs": ["-"],
              "Bugs": ["403 bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-03-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ABC-Code Execution for Veeam (CVE-2022-26503)",
                    "Link": "https://www.mdsec.co.uk/2022/03/abc-code-execution-for-veeam/"
                 }
              ],
              "Authors": ["Sina Kheirkhah (@SinSinology)"],
              "Programs": ["Veeam"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-03-29",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Your NAS is not your NAS !",
                  "Link": "https://devco.re/blog/2022/03/28/your-NAS-is-not-your-NAS-en/"
               }
            ],
            "Authors": ["Angelboy (@scwuaptx)"],
            "Programs": ["Synology"],
            "Bugs": ["RCE", "Memory corruption", "Buffer Overflow"],
            "Bounty": "-",
            "PublicationDate": "2022-03-28",
            "AddedDate": "2022-10-24"
         },
           {
              "Links": [
                 {
                    "Title": "Ruby Deserialization - Gadget on Rails",
                    "Link": "https://httpvoid.com/Ruby-Deserialization-Gadget-On-Rails.md"
                 }
              ],
              "Authors": ["HTTPVoid (@httpvoid0x2f)"],
              "Programs": ["Ruby on Rails"],
              "Bugs": ["Insecure deserialization", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwning Microsoft Azure Defender for IoT | Multiple Flaws Allow Remote Code Execution for All",
                    "Link": "https://www.sentinelone.com/labs/pwning-microsoft-azure-defender-for-iot-multiple-flaws-allow-remote-code-execution-for-all/"
                 }
              ],
              "Authors": ["Kasif Dekel (@kasifdekel)", "Ronen Shustin (@ronenshh)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE", "Memory corruption", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-03-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to rick roll every users on root-me.org",
                    "Link": "https://mizu.re/post/how-i-was-able-to-rick-roll-every-users-on-root-me.org"
                 }
              ],
              "Authors": ["Mizu (@kevin_mizu)"],
              "Programs": ["Root-Me"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing cookies from subdomain leads to takeover user accounts at redacted.com",
                    "Link": "https://web.archive.org/web/20220329163747/https://pwnsec.ninja/2022/03/27/stealing-cookies-from-subdomain-leads-to-takeover-user-accounts-at-redacted-com/"
                 }
              ],
              "Authors": ["Bijan Murmu (@0xBijan)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Deleting account via support ticket",
                    "Link": "https://web.archive.org/web/20220405093345/https://pwnsec.ninja/2022/03/26/deleting-account-via-support-ticket/"
                 }
              ],
              "Authors": ["Bijan Murmu (@0xBijan)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-03-26",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Broken Access Control - IDOR",
                  "Link": "https://machevalia.blog/blog/broken-access-control-idor"
               }
            ],
            "Authors": ["Nick Berrie (@machevalia)"],
            "Programs": ["-"],
            "Bugs": ["IDOR"],
            "Bounty": "104",
            "PublicationDate": "2022-03-25",
            "AddedDate": "2023-01-11"
         },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty Adventures: A NodeBB 0-day",
                    "Link": "https://blogs.opera.com/security/2022/03/bug-bounty-adventures-a-nodebb-0-day/"
                 }
              ],
              "Authors": ["Marouane Mouhtadi (@Mar0_0uane)"],
              "Programs": ["Opera"],
              "Bugs": ["CSRF", "Account takeover", "SSO", "Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2022-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Clipboard hazard with Google Sheets",
                    "Link": "https://irsl.medium.com/clipboard-hazard-with-google-sheets-1c1f3d566907"
                 }
              ],
              "Authors": ["Imre Rad (@ImreRad)"],
              "Programs": ["Google"],
              "Bugs": ["Phishing"],
              "Bounty": "-",
              "PublicationDate": "2022-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding bugs to trigger Unauthenticated Command Injection in a NETGEAR router (PSV-2022–0044)",
                    "Link": "https://flattsecurity.medium.com/finding-bugs-to-trigger-unauthenticated-command-injection-in-a-netgear-router-psv-2022-0044-2b394fb9edc"
                 }
              ],
              "Authors": ["stypr (@stereotype32)"],
              "Programs": ["Netgear"],
              "Bugs": ["XSS", "Arbitrary file read", "Authentication bypass", "OS command injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwn2Own Austin 2021 : Defeating The Netgear R6700V3",
                    "Link": "https://www.synacktiv.com/publications/pwn2own-austin-2021-defeating-the-netgear-r6700v3.html"
                 }
              ],
              "Authors": ["Antide Petit (@xarkes_)", "Mitsurugi Heishiro (@0xmitsurugi)"],
              "Programs": ["Netgear"],
              "Bugs": ["RCE", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Token Misconfiguration can lead to takeover account",
                    "Link": "https://cryptograph3r.blogspot.com/2022/03/how-token-misconfiguration-can-lead-to.html"
                 }
              ],
              "Authors": ["Cryptographer (@justluthra)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-03-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Code Execution on Western Digital PR4100 NAS (CVE-2022-23121)",
                    "Link": "https://research.nccgroup.com/2022/03/24/remote-code-execution-on-western-digital-pr4100-nas-cve-2022-23121/"
                 }
              ],
              "Authors": ["Alex Plaskett (@alexjplaskett)", "Cedric Halbronn (@saidelike)", "Aaron Adams (@fidgetingbits)"],
              "Programs": ["Western Digital"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Was Able To TakeOver Any Account On One Of Europe's Largest Media Companies",
                    "Link": "https://medium.com/@tobydavenn/how-i-was-able-to-takeover-any-account-on-one-of-europes-largest-media-companies-e8d25e59c08"
                 }
              ],
              "Authors": ["Tobydavenn"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-03-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "When Equal is Not, Another WebView Takeover Story",
                    "Link": "https://valsamaras.medium.com/when-equal-is-not-another-webview-takeover-story-730be8d6e202"
                 }
              ],
              "Authors": ["Dimitrios Valsamaras (@Ch0pin)"],
              "Programs": ["-"],
              "Bugs": ["Android"],
              "Bounty": "-",
              "PublicationDate": "2022-03-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authentication bypass using root array",
                    "Link": "https://infosecwriteups.com/authentication-bypass-using-root-array-4a179242b9f7"
                 }
              ],
              "Authors": ["Eslam Akl (@eslam3kll)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-03-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Basic recon to RCE II",
                    "Link": "https://www.jomar.fr/posts/2022/basic_recon_to_rce_ii/"
                 }
              ],
              "Authors": ["Joshua Martinelle (@J0_mart)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story about more than 3.5 million PII leakage in Yahoo!!!",
                    "Link": "https://dhakalbibek.medium.com/story-about-more-than-3-5-million-pii-leakage-in-yahoo-3a530210dcc6"
                 }
              ],
              "Authors": ["dhakal_bibek (@dhakal__bibek)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["IDOR", "Information disclosure", "iOS"],
              "Bounty": "9,500",
              "PublicationDate": "2022-03-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Maps API Key Unauthorized Use Case",
                    "Link": "https://cupc4k3.co/caso-de-uso-não-autorizados-de-chave-da-api-do-google-maps-89498752cf7d"
                 }
              ],
              "Authors": ["Dan Barros"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "100",
              "PublicationDate": "2022-03-22",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "iTop – Template Injection inside customer Portal",
                  "Link": "https://markus-krell.de/itop-template-injection-inside-customer-portal/"
               }
            ],
            "Authors": ["Markus Krell (@MarkusKrell)"],
            "Programs": ["Combodo (iTop)"],
            "Bugs": ["SSTI", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2022-03-21",
            "AddedDate": "2022-10-24"
         },
           {
              "Links": [
                 {
                    "Title": "Targeting Visual Studio Code for macOS: File Discovery and a TCC bypass (kinda)",
                    "Link": "https://ajpc500.github.io/macos/Targeting-Visual-Studio-Code-For-macOS/"
                 },
                 {
                    "Title": "PoC",
                    "Link": "https://twitter.com/patch1t/status/1511210634939023360"
                 }
              ],
              "Authors": ["Alfie Champion (@ajpc500)"],
              "Programs": ["Apple", "Microsoft"],
              "Bugs": ["Local Privilege Escalation", "TCC bypass", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "($$$) Broken Authentication and IDOR at [REDACTED]",
                    "Link": "https://wahaz.medium.com/broken-authentication-and-idor-at-redacted-646de8d508e6"
                 }
              ],
              "Authors": ["Rizaldi Wahaz (@wah_haz)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken session control leads to access private videos using the shared link even after revoking the access for specific time!! — #GoogleVRP",
                    "Link": "https://naveenroy008.medium.com/broken-session-control-leads-to-access-private-videos-using-the-shared-link-even-after-revoking-the-84e31ac16fe4"
                 }
              ],
              "Authors": ["Naveenroy"],
              "Programs": ["Google"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-03-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty catches part -1",
                    "Link": "https://web.archive.org/web/20200928015008/https://pwnsec.ninja/2020/03/04/bug-bounty-catches-part-1/"
                 }
              ],
              "Authors": ["Bijan Murmu (@0xBijan)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "Information disclosure", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-03-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-0337 System environment variables leak on Google Chrome, Microsoft Edge and Opera",
                    "Link": "https://github.com/Puliczek/CVE-2022-0337-PoC-Google-Chrome-Microsoft-Edge-Opera"
                 }
              ],
              "Authors": ["Maciej Pulikowski (@pulik_io)"],
              "Programs": ["Google", "Microsoft", "Opera"],
              "Bugs": ["Browser hacking"],
              "Bounty": "10,000",
              "PublicationDate": "2022-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Files.app Symbolic Link Following",
                    "Link": "https://breakpoint.sh/posts/files.app-symbolic-link-following"
                 }
              ],
              "Authors": ["Ron Masas (@RonMasas)"],
              "Programs": ["Apple"],
              "Bugs": ["iOS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Adobe bug bounty using IDOR, Confidential data leaks",
                    "Link": "https://debprasadbanerjee502.medium.com/adobe-bug-bounty-using-idor-confidential-data-leaks-f6c55e5143d0"
                 }
              ],
              "Authors": ["Debprasad Banerjee"],
              "Programs": ["Adobe"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors",
                    "Link": "https://mearegtu.medium.com/insecure-direct-object-reference-exposes-all-users-of-microsoft-azure-independent-software-vendors-bed3b45e509"
                 }
              ],
              "Authors": ["Meareg"],
              "Programs": ["Microsoft"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-03-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "For the first Bounty, it takes a few challenging months, but only a few days for the second.",
                    "Link": "https://medium.com/@interc3pt3r/for-the-first-bounty-it-takes-a-few-challenging-months-but-only-a-few-days-for-the-second-7b53259b0199"
                 }
              ],
              "Authors": ["Aneesha D (@interc3pt3r)"],
              "Programs": ["-"],
              "Bugs": ["Old components with known vulnerabilities"],
              "Bounty": "250",
              "PublicationDate": "2022-03-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass confirmation to add payment method.",
                    "Link": "https://yajdesu.medium.com/bypass-confirmation-to-add-payment-method-df2772a36561"
                 }
              ],
              "Authors": ["Yaj Desu"],
              "Programs": ["-"],
              "Bugs": ["Email verification bypass", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-03-18",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Abusing Arbitrary File Deletes To Escalate Privilege And Other Great Tricks",
                  "Link": "https://www.zerodayinitiative.com/blog/2022/3/16/abusing-arbitrary-file-deletes-to-escalate-privilege-and-other-great-tricks"
               }
            ],
            "Authors": ["Abdelhamid Naceri", "Simon Zuckerbraun"],
            "Programs": ["Microsoft (Windows)"],
            "Bugs": ["Local Privilege Escalation"],
            "Bounty": "-",
            "PublicationDate": "2022-03-17",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Abusing Azure Hybrid Workers for Privilege Escalation – Part 1",
                    "Link": "https://www.netspi.com/blog/technical/cloud-penetration-testing/abusing-azure-hybrid-workers-for-privilege-escalation/"
                 }
              ],
              "Authors": ["Josh Magri (@passthehashbrwn)"],
              "Programs": ["Microsoft (Azure)"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Blind SQL Injection",
                    "Link": "https://medium.com/@vamshivaran110/my-first-blind-sql-injection-7db4b5e5c66d"
                 }
              ],
              "Authors": ["T VAMSHI"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Parameter Pollution - Zero Day",
                    "Link": "https://shahjerry33.medium.com/parameter-pollution-zero-day-3feb86ee8a02"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)", "ethicalbughunter (@ethicalbughuntr)"],
              "Programs": ["Discourse"],
              "Bugs": ["HTTP parameter pollution"],
              "Bounty": "-",
              "PublicationDate": "2022-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From XSS to RCE (dompdf 0day)",
                    "Link": "https://positive.security/blog/dompdf-rce"
                 }
              ],
              "Authors": ["Positive Security (@positive_sec)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Git honours embedded bare repos, and exploitation via core.fsmonitor in a directory's .git/config affects IDEs, shell prompts and Git pillagers",
                    "Link": "https://github.com/justinsteven/advisories/blob/main/2022_git_buried_bare_repos_and_fsmonitor_various_abuses.md"
                 }
              ],
              "Authors": ["Justin Steven (@justinsteven)"],
              "Programs": ["GitHub", "Microsoft", "JetBrains"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to find 50+ Cross-site scripting (XSS) Security Vulnerabilities on Bugcrowd Public Program?",
                    "Link": "https://infosecwriteups.com/how-i-was-able-to-find-50-cross-site-scripting-xss-security-vulnerabilities-on-bugcrowd-public-ba33db2b0ab1"
                 },
                 {
                    "Title": "frequest",
                    "Link": "https://github.com/takshal/freq"
                 }
              ],
              "Authors": ["akshal(tojojo)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSD Advisory – Exchange Server GetWacInfo Information Disclosure Vulnerability",
                    "Link": "https://ssd-disclosure.com/ssd-advisory-exchange-server-getwacinfo-information-disclosure-vulnerability/"
                 }
              ],
              "Authors": ["Alex Birnberg (@alexbirnberg)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XXE", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Securing Developer Tools: Git Integrations",
                    "Link": "https://blog.sonarsource.com/securing-developer-tools-git-integrations"
                 }
              ],
              "Authors": ["Sonar (@SonarSource)"],
              "Programs": ["Microsoft", "JetBrains", "GitHub"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Technical Advisory – Apple macOS XAR – Arbitrary File Write (CVE-2022-22582)",
                    "Link": "https://research.nccgroup.com/2022/03/15/technical-advisory-apple-macos-xar-arbitrary-file-write-cve-2022-22582/"
                 }
              ],
              "Authors": ["Richard Warren (@buffaloverflow)"],
              "Programs": ["Apple"],
              "Bugs": ["Arbitrary file write"],
              "Bounty": "-",
              "PublicationDate": "2022-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I managed to trigger XSS automatically to get critical account takeover",
                    "Link": "https://c4rrilat0r.medium.com/how-i-managed-to-trigger-xss-automatically-to-get-critical-account-takeover-92ea3abcaf9"
                 }
              ],
              "Authors": ["c4rrilat0r (@c4rrilat0r)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "3,000",
              "PublicationDate": "2022-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-22616: Simple way to bypass GateKeeper, hidden for years",
                    "Link": "https://jhftss.github.io/CVE-2022-22616-Gatekeeper-Bypass/"
                 }
              ],
              "Authors": ["Mickey Jin (@patch1t)"],
              "Programs": ["Apple"],
              "Bugs": ["Local Privilege Escalation", "GateKeeper bypass", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020-24427: Adobe Reader CJK Codecs Memory Disclosure Vulnerability",
                    "Link": "https://blog.haboob.sa/blog/adobe-reader-cjk-codecs-memory-disclosure-vulnerability"
                 }
              ],
              "Authors": ["Haboob Research Team (@HaboobSa)"],
              "Programs": ["Adobe"],
              "Bugs": ["Memory disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Bug on VDP & BBP - Bug Bounty",
                    "Link": "https://www.cyberick.com/post/my-first-bug-on-vdp-bbp-bug-bounty"
                 }
              ],
              "Authors": ["Aditya Singh / rook1337 (@imrook1337)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-15",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "How a macOS bug could have allowed for a serious phishing attack against users",
                  "Link": "https://rambo.codes/posts/2022-03-15-how-a-macos-bug-could-have-allowed-for-a-serious-phishing-attack-against-users"
               }
            ],
            "Authors": ["Guilherme Rambo (@_inside)"],
            "Programs": ["Apple"],
            "Bugs": ["MacOS", "Phishing"],
            "Bounty": "5,000",
            "PublicationDate": "2022-03-14",
            "AddedDate": "2022-11-01"
         },
           {
              "Links": [
                 {
                    "Title": "From Recon via Censys and DNSdumpster, to Getting P1 by Login Using Weak Password – “password”",
                    "Link": "http://www.firstsight.me/2022/03/from-recon-via-censys-and-dnsdumpster-to-getting-p1-by-login-using-weak-password-password/"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://medium.com/@YoKoKho/from-recon-via-censys-and-dnsdumpster-to-getting-p1-by-login-using-weak-password-password-504e617956ce"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["-"],
              "Bugs": ["WAF bypass", "Weak credentials"],
              "Bounty": "2,500",
              "PublicationDate": "2022-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Achieving Remote Code Execution via Unrestricted File Upload",
                    "Link": "https://medium.com/@haroonhameed_76621/achieving-remote-code-execution-via-unrestricted-file-upload-6050f360c218"
                 }
              ],
              "Authors": ["Haroon Hameed (@HaroonHameed40)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "3,000",
              "PublicationDate": "2022-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection at Spotify",
                    "Link": "https://web.archive.org/web/20220315141258/https://eslam3kl.medium.com/sql-injection-at-spotify-d19e0861ddf0"
                 }
              ],
              "Authors": ["Eslam Akl (@eslam3kll)"],
              "Programs": ["Spotify"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I access other domains in infinityfree.net using Directory Traversal",
                    "Link": "https://xkurtph.medium.com/how-i-access-other-domains-in-infinityfree-net-using-directory-traversal-4625692d6a2d"
                 }
              ],
              "Authors": ["Kurt Russelle Marmol"],
              "Programs": ["InfinityFree"],
              "Bugs": ["Directory traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Made The BBC Hall Of Fame 3 Times",
                    "Link": "https://medium.com/@tobydavenn/how-i-made-the-bbc-hall-of-fame-3-times-2c816fa515d7"
                 }
              ],
              "Authors": ["Tobydavenn"],
              "Programs": ["BBC"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-03-14",
              "AddedDate": "2022-09-15"
   },
           {
            "Links": [
               {
                  "Title": "Party time: Injecting code into Teleparty extension",
                  "Link": "https://palant.info/2022/03/14/party-time-injecting-code-into-teleparty-extension/"
               }
            ],
            "Authors": ["Wladimir Palant (@WPalant)"],
            "Programs": ["Teleparty"],
            "Bugs": ["HTML injection", "Open redirect", "Browser extension hacking"],
            "Bounty": "-",
            "PublicationDate": "2022-03-14",
            "AddedDate": "2022-12-09"
         },
           {
              "Links": [
                 {
                    "Title": "How I bypassed disable_functions in php to get a remote shell",
                    "Link": "https://melotover.medium.com/how-i-bypassed-disable-functions-in-php-to-get-a-remote-shell-48b827d54979"
                 }
              ],
              "Authors": ["Asem Eleraky (@melotover)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open Redirect via Sendgrid Email Misconfiguration",
                    "Link": "https://medium.com/@rifqihz/open-redirect-via-sendgrid-email-misconfiguration-cec4ccb07f9a"
                 }
              ],
              "Authors": ["Rifqi Hilmy Zhafrant"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "250",
              "PublicationDate": "2022-03-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Tale of Open Redirection to Stored XSS",
                    "Link": "https://medium.com/@tushar.tilak.sharma/a-tale-of-open-redirection-to-stored-xss-6ad426ae9d43"
                 }
              ],
              "Authors": ["Tushar Sharma (@tusharSharma_0)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2022-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS through base64 encoded JSON",
                    "Link": "https://apth3hack3r.medium.com/xss-through-base64-encoded-json-4b0d96e5ccd4"
                 }
              ],
              "Authors": ["Aman Pareek (@aman_notsogreat)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I can see the dislikes count even though is hidden by YouTube | YouTube ($500)",
                    "Link": "https://bloggerrando.blogspot.com/2022/03/13-1.html"
                 }
              ],
              "Authors": ["R ando (@Rando02355205)"],
              "Programs": ["-"],
              "Bugs": ["Broken Access Control", "IDOR"],
              "Bounty": "500",
              "PublicationDate": "2022-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I have Found Microsoft Subdomain Website database list, database username, password",
                    "Link": "https://medium.com/@botami143/i-have-found-microsoft-subdomain-website-database-list-database-username-password-1dab07d0c8ea"
                 }
              ],
              "Authors": ["Bot Ami (@Botami143)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Did I Leak 5.2k Customer Data From a Large Company? (via Broken Access Control)",
                    "Link": "https://canmustdie.medium.com/how-did-i-leak-5-2k-customer-data-from-a-large-company-via-broken-access-control-709eb4027409"
                 }
              ],
              "Authors": ["can1337 (@canmustdie)"],
              "Programs": ["-"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-24696 – Glance By Mirametrix Privilege Escalation",
                    "Link": "https://www.trustedsec.com/blog/cve-2022-24696-glance-by-mirametrix-privilege-escalation/"
                 }
              ],
              "Authors": ["Oddvar Moe (@Oddvarmoe)"],
              "Programs": ["Lenovo"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to takeover any users account on a major telecoms website",
                    "Link": "https://medium.com/@tobydavenn/how-i-was-able-to-takeover-any-users-account-on-a-major-telecoms-website-2cd5aa43e3d6"
                 }
              ],
              "Authors": ["Tobydavenn"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Rate Limit Bypass at Readme.com",
                    "Link": "https://medium.com/@girishbo58/rate-limit-bypass-at-readme-com-35c4fb0c7f85"
                 }
              ],
              "Authors": ["Girishbo"],
              "Programs": ["Readme.com"],
              "Bugs": ["Lack of rate limiting", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2022-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to read any users confidential reports on a public level domain",
                    "Link": "https://medium.com/@tobydavenn/how-i-was-able-to-read-any-users-confidential-reports-on-a-public-level-domain-1e563857b0b9"
                 }
              ],
              "Authors": ["Tobydavenn"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-03-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating from Logic App Contributor to Root Owner in Azure",
                    "Link": "https://www.netspi.com/blog/technical/cloud-penetration-testing/azure-logic-app-contributor-escalation-to-root-owner/"
                 }
              ],
              "Authors": ["Josh Magri (@passthehashbrwn)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Was Able To Wipe Any Registered Account",
                    "Link": "https://medium.com/@tobydavenn/how-i-was-able-to-wipe-any-registered-account-3b738afc389"
                 }
              ],
              "Authors": ["Tobydavenn"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Demographic Misconfiguration on Facebook live",
                    "Link": "https://prajwoldhungana487.medium.com/demographic-misconfiguration-9359910c6fcf"
                 }
              ],
              "Authors": ["Prajwol Dhungana (@PrajwolDhunga14)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSD Advisory – NETGEAR DGND3700v2 PreAuth Root Access",
                    "Link": "https://ssd-disclosure.com/ssd-advisory-netgear-dgnd3700v2-preauth-root-access/"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["Netgear"],
              "Bugs": ["Authentication bypass", "OS command injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Oracle Access Manager Pre-Auth RCE (CVE-2021–35587 Analysis)",
                    "Link": "https://testbnull.medium.com/oracle-access-manager-pre-auth-rce-cve-2021-35587-analysis-1302a4542316"
                 }
              ],
              "Authors": ["Nguyễn Tiến Giang (@testanull)", "peterjson (@peterjson)"],
              "Programs": ["Oracle"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Container Escape to Shadow Admin: GKE Autopilot Vulnerabilities",
                    "Link": "https://unit42.paloaltonetworks.com/gke-autopilot-vulnerabilities/"
                 }
              ],
              "Authors": ["Unit 42 (@Unit42_Intel)"],
              "Programs": ["Google"],
              "Bugs": ["Privilege escalation", "Container escape", "Kubernetes"],
              "Bounty": "-",
              "PublicationDate": "2022-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Log4shell in google $1337.00",
                    "Link": "https://medium.com/@amnotacat/log4shell-in-google-1337-00-144684269bf8"
                 }
              ],
              "Authors": ["amnotacat (@Amnotacat1)"],
              "Programs": ["Google"],
              "Bugs": ["Log4shell", "RCE"],
              "Bounty": "1,337",
              "PublicationDate": "2022-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I managed to make a DDoS attack by exploiting a company’s service — Bug Bounty",
                    "Link": "https://medium.com/@mrempy/how-i-managed-to-make-a-ddos-attack-by-exploiting-a-companys-service-bug-bounty-bfd25a178b45"
                 }
              ],
              "Authors": ["Mr Empy (@mr_empy)"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Circumventing Browser Security Mechanisms For SSRF",
                    "Link": "https://httpvoid.com/Circumventing-Browser-Security-Mechanisms-For-SSRF.md"
                 }
              ],
              "Authors": ["HTTPVoid (@httpvoid0x2f)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AutoWarp: Critical Cross-Account Vulnerability in Microsoft Azure Automation Service",
                    "Link": "https://orca.security/resources/blog/autowarp-microsoft-azure-automation-service-vulnerability/"
                 }
              ],
              "Authors": ["Yanir Tsarimi (@Yanir_)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Cross-tenant vulnerability", "Account takeover"],
              "Bounty": "40,000",
              "PublicationDate": "2022-03-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Bad Twin: a peculiar case of JWT exploitation scenario",
                    "Link": "https://medium.com/@sandh0t/the-bad-twin-a-peculiar-case-of-jwt-exploitation-scenario-1efa03e891c0"
                 }
              ],
              "Authors": ["Sandh0t (@sandh0t)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "3,000",
              "PublicationDate": "2022-03-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Some critical vulnerabilities found with passive analysis on bug bounty programs explained",
                    "Link": "https://infosecwriteups.com/some-critical-vulnerabilities-found-with-passive-analysis-on-bug-bounty-programs-explained-1da8b01c11ad"
                 }
              ],
              "Authors": ["Daniel V. (@d4niel_v)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-03-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WhatsApp Bug Bounty: Bypassing biometric authentication using voip",
                    "Link": "https://infosecwriteups.com/whatsapp-bug-bounty-bypassing-biometric-authentication-using-voip-87548ef7a0ba"
                 }
              ],
              "Authors": ["Arvind (@ar_arv1nd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-03-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked A Crypto Company And Could Steal 1 Million Dollars Worth of Bitcoin",
                    "Link": "https://zoidsec.medium.com/how-i-hacked-a-crypto-company-and-could-steal-1-million-dollars-worth-of-bitcoin-3174434b382c"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://cyberlix.io/how-i-hacked-a-crypto-company-and-could-steal-1-million-dollars-worth-of-bitcoin/"
                 }
              ],
              "Authors": ["zoid (@z0idsec)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "9,000",
              "PublicationDate": "2022-03-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "More secure Facebook Canvas Part 2: More Account Takeovers",
                    "Link": "https://ysamm.com/?p=742"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "98,250",
              "PublicationDate": "2022-03-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-4191: GitLab GraphQL API User Enumeration (FIXED)",
                    "Link": "https://www.rapid7.com/blog/post/2022/03/03/cve-2021-4191-gitlab-graphql-api-user-enumeration-fixed/"
                 }
              ],
              "Authors": ["Jacob Baines (@junior_baines)"],
              "Programs": ["GitLab"],
              "Bugs": ["Username enumeration", "GraphQL"],
              "Bounty": "-",
              "PublicationDate": "2022-03-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "4300$ Instagram IDOR Bug (2022)",
                    "Link": "https://medium.com/@nvmeeet/4300-instagram-idor-bug-2022-5386cf492cad"
                 }
              ],
              "Authors": ["Nawaf Alkhaldi (@nvmeeet)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "4,300",
              "PublicationDate": "2022-03-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Moodle 2nd Order Sqli",
                    "Link": "https://muffsec.com/blog/moodle-2nd-order-sqli/"
                 }
              ],
              "Authors": ["mufinnnnnnn (@mufinnnnnnn)"],
              "Programs": ["Moodle"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-03-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR in support.mozilla.org through Code Review",
                    "Link": "https://noob3xploiter.medium.com/idor-in-support-mozilla-org-through-code-review-ff2aa8ea1201"
                 }
              ],
              "Authors": ["Brandon Roldan"],
              "Programs": ["Mozilla"],
              "Bugs": ["IDOR"],
              "Bounty": "1,500",
              "PublicationDate": "2022-03-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-24948: Apache JSPWiki preauth Stored XSS to ATO",
                    "Link": "https://octagon.net/blog/2022/03/02/apache-jspwiki-preauth-xss-to-ato/"
                 }
              ],
              "Authors": ["Paulos Yibelo (@PaulosYibelo)"],
              "Programs": ["Apache"],
              "Bugs": ["Stored XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-03-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "webOS Revisited - Even More Mistaken Identities",
                    "Link": "https://blog.recurity-labs.com/2022-03-02/webOS_Pt2.html"
                 }
              ],
              "Authors": ["Andreas Lindh (@addelindh)"],
              "Programs": ["LG"],
              "Bugs": ["Local Privilege Escalation", "Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2022-03-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[ Directory Traversal attack ] How did I find it using GitHub",
                    "Link": "https://web.archive.org/web/20220306040035/https://medium.com/@1337Fenrir/how-did-i-find-directory-traversal-attack-using-github-9b051ed749ca"
                 }
              ],
              "Authors": ["Fenrir (@leetibrahim)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-03-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Skype extension: All functionality broken? Still exploitable!",
                    "Link": "https://palant.info/2022/03/01/skype-extension-all-functionality-broken-still-exploitable/"
                 }
              ],
              "Authors": ["Wladimir Palant (@WPalant)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure", "Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2022-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Password Reset to Admin Access",
                    "Link": "https://medium.com/techiepedia/password-reset-to-admin-access-3b2a649bdc3"
                 }
              ],
              "Authors": ["Jesse Clark (@Hogarth45_)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Authentication bypass", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2022-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HDiff: A Semi-automatic Framework for Discovering Semantic Gap Attack in HTTP Implementations",
                    "Link": "https://shenkaiwen.com/publication/2022-hdiff/"
                 }
              ],
              "Authors": ["Kaiwen Shen (@m0xiaoxi)", "Jianyu Lu", "Yaru Yang", "Jianjun Chen", "Mingming Zhang", "Haixin Duan", "Jia Zhang", "Xiaofeng Zheng"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling", "DoS", "Semantic gap attacks"],
              "Bounty": "-",
              "PublicationDate": "2022-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwning a Server using Markdown",
                    "Link": "https://blog.dixitaditya.com/pwning-a-server-using-markdown"
                 }
              ],
              "Authors": ["Aditya Dixit (@zombie007o)"],
              "Programs": ["Hashnode"],
              "Bugs": ["LFI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BrokenPrint: A Netgear stack overflow",
                    "Link": "https://research.nccgroup.com/2022/02/28/brokenprint-a-netgear-stack-overflow/"
                 }
              ],
              "Authors": ["Alex Plaskett (@alexjplaskett)", "Cedric Halbronn (@saidelike)", "Aaron Adams (@fidgetingbits)"],
              "Programs": ["Netgear"],
              "Bugs": ["Memory corruption", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Subscription Plans for free service.",
                    "Link": "https://blog.securitybreached.org/2022/02/27/hacking-subscription-plans-for-free-service/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["-"],
              "Bugs": ["Payment bypass", "OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-02-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-22947: SpEL Casting And Evil Beans",
                    "Link": "https://web.archive.org/web/20221128044142/https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/"
                 }
              ],
              "Authors": ["Wyatt Dahlenburg (@wdahlenb)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Java Beans"],
              "Bounty": "-",
              "PublicationDate": "2022-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF & LFI In Uploads Feature",
                    "Link": "https://web.archive.org/web/20220315080229/https://medium.com/@raymond-lind/ssrf-lfi-in-uploads-feature-321d83b93ec0"
                 }
              ],
              "Authors": ["Raymond Lind"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "LFI", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2022-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Catching bugs in VMware: Carbon Black Cloud Workload Appliance and vRealize Operations Manager",
                    "Link": "https://swarm.ptsecurity.com/catching-bugs-in-vmware-carbon-black-cloud-workload-appliance-and-vrealize-operations-manager/"
                 }
              ],
              "Authors": ["Egor Dimitrenko (@elk0kc)"],
              "Programs": ["VMware"],
              "Bugs": ["Authentication bypass", "RCE", "SSRF", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Weird Price Tampering Vulnerability",
                    "Link": "https://medium.com/@vflexo/a-weird-price-tampering-vulnerability-1251dfe8d2a1"
                 }
              ],
              "Authors": ["vFlexo (@vflexo)"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering", "Logic flaw"],
              "Bounty": "200",
              "PublicationDate": "2022-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing default visibility for newly-added email in Facebook(Part I - Submitting I.D)",
                    "Link": "https://medium.com/@Kntjrld/bypassing-default-visibility-for-newly-added-email-in-facebook-part-i-submitting-i-d-da78142f032d"
                 },
                 {
                    "Title": "Part II - Trusted Contacts",
                    "Link": "https://medium.com/@Kntjrld/bypassing-default-visibility-for-newly-added-email-in-facebook-part-ii-trusted-contacts-36176eeb103"
                 }
              ],
              "Authors": ["Kent Jarold Abulag (@wkemenhehehegsg)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,500",
              "PublicationDate": "2022-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Instagram App Access Token",
                    "Link": "https://philippeharewood.com/instagram-app-access-token/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "38,300",
              "PublicationDate": "2022-02-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Piercing the Cloud Armor - The 8KB bypass in Google Cloud Platform WAF",
                    "Link": "https://kloudle.com/blog/piercing-the-cloud-armor-the-8kb-bypass-in-google-cloud-platform-waf"
                 }
              ],
              "Authors": ["Kloudle (@Kloudleinc)"],
              "Programs": ["Google"],
              "Bugs": ["WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-02-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked the Dutch Government with SQLi and Won the Famous T-Shirt?",
                    "Link": "https://goktugkaya.medium.com/how-i-hacked-the-dutch-government-and-won-the-famous-t-shirt-b45cdf5dfaa1"
                 }
              ],
              "Authors": ["Göktuğ Kaya (@g0ktugkaya)"],
              "Programs": ["Dutch Government"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-02-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing a few more GitHub Actions secrets",
                    "Link": "https://blog.teddykatz.com/2022/02/23/ghosts-of-branches-past.html"
                 }
              ],
              "Authors": ["Teddy Katz (@not_aardvark)"],
              "Programs": ["GitHub"],
              "Bugs": ["Logic flaw"],
              "Bounty": "7,500",
              "PublicationDate": "2022-02-23",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "CVE-2021-45467: CWP CentOS Web Panel – preauth RCE",
                  "Link": "https://octagon.net/blog/2022/01/22/cve-2021-45467-cwp-centos-web-panel-preauth-rce/"
               }
            ],
            "Authors": ["Paulos Yibelo (@PaulosYibelo)"],
            "Programs": ["Centos Web Panel (CWP)"],
            "Bugs": ["RCE", "LFI", "Arbitrary file write"],
            "Bounty": "-",
            "PublicationDate": "2022-01-22",
            "AddedDate": "2023-03-02"
         },
           {
              "Links": [
                 {
                    "Title": "Write Up – Android Application Screen Lock Bypass Via ADB Brute Forcing",
                    "Link": "https://omespino.com/write-up-private-bug-bounty-bypass-redacted-android-application-screen-lock-via-local-brute-forcing/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["-"],
              "Bugs": ["Android", "Bruteforce", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-02-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook android vulnerability: Launching internal/tighten deeplink onbehalf of user",
                    "Link": "https://servicenger.com/mobile/facebook-android-vulnerability-launching-internal-tighten-deeplink-onbehalf-of-user/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["-"],
              "Bugs": ["Android", "Insecure deeplink"],
              "Bounty": "3,525",
              "PublicationDate": "2022-02-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OAuth and PostMessage - Chaining misconfigurations for your access token.",
                    "Link": "https://ninetyn1ne.github.io/2022-02-21-oauth-postmessage-misconfig/"
                 }
              ],
              "Authors": ["Suraj Disoja (@ninetyn1ne_)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "postMessage", "Token leak"],
              "Bounty": "-",
              "PublicationDate": "2022-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could’ve bypassed the 2FA security of Instagram once again?",
                    "Link": "https://infosecwriteups.com/how-i-couldve-bypassed-the-2fa-security-of-instagram-once-again-43c05cc9b755"
                 }
              ],
              "Authors": ["Samip Aryal (@samiparyal_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["2FA / MFA bypass", "Logic flaw"],
              "Bounty": "3,150",
              "PublicationDate": "2022-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding an unseen SQL Injection by bypassing escape functions in mysqljs/mysql",
                    "Link": "https://flattsecurity.medium.com/finding-an-unseen-sql-injection-by-bypassing-escape-functions-in-mysqljs-mysql-90b27f6542b4"
                 }
              ],
              "Authors": ["stypr (@stereotype32)"],
              "Programs": ["Oracle (MySQL)"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "What an injection into jQuery-selector can lead to",
                    "Link": "https://systemweakness.com/what-an-injection-into-jquery-selector-can-lead-to-1fcaabfd51e5"
                 }
              ],
              "Authors": ["Anton Subbotin (@ska_vans)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in hidden input field",
                    "Link": "https://f4t7.medium.com/xss-in-hidden-input-field-1b98a5fece26"
                 }
              ],
              "Authors": ["Faizan Elahi"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Send a Email to me and get kicked out of Google Groups !! — #GoogleVRP — A Feature that almost broke Google Groups !!",
                    "Link": "https://infosecwriteups.com/send-a-email-to-me-and-get-kicked-out-of-google-groups-29b5c2c60e95"
                 }
              ],
              "Authors": ["Sriram Kesavan (@sriramoffcl)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "3,133.7",
              "PublicationDate": "2022-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Case Study of API Vulnerabilities",
                    "Link": "https://monke.ie/api-vulns-casestudy/"
                 }
              ],
              "Authors": ["Monke (@pmofcats)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Account takeover", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-02-20",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Access Control Violation - Sensitive Data Exposure",
                  "Link": "https://machevalia.blog/blog/access-control-violation-sensitive-data-exposure"
               }
            ],
            "Authors": ["Nick Berrie (@machevalia)"],
            "Programs": ["-"],
            "Bugs": ["Directory listing"],
            "Bounty": "444.50",
            "PublicationDate": "2022-02-19",
            "AddedDate": "2023-01-11"
         },
           {
              "Links": [
                 {
                    "Title": "Bypassing Cloudflare’s WAF!",
                    "Link": "https://medium.com/@friendly_/bypassing-cloudflares-waf-b1b83a50fb2f"
                 }
              ],
              "Authors": ["Friendly (@SkeletorKeys)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-02-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-23835: A security analysis of Visual Voicemail",
                    "Link": "https://gitlab.com/kop316/vvm-disclosure"
                 }
              ],
              "Authors": ["Chris Talbot"],
              "Programs": ["AT&T", "T-Mobile"],
              "Bugs": ["Voicemail hacking"],
              "Bounty": "-",
              "PublicationDate": "2022-02-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Experience of Hacking Dutch Government",
                    "Link": "https://remonsec.com/posts/hacking-dutch-gov/"
                 }
              ],
              "Authors": ["remonsec (@remonsec)"],
              "Programs": ["Dutch Government"],
              "Bugs": ["-"],
              "Bounty": "-",
              "PublicationDate": "2022-02-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Passive Recon with Spyse (Part-II)",
                    "Link": "https://remonsec.com/posts/passive-recon-with-spyse-part-II/"
                 },
                 {
                    "Title": "Part-I",
                    "Link": "https://remonsec.com/posts/passive-recon-with-spyse-part-I/"
                 }
              ],
              "Authors": ["remonsec (@remonsec)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover", "AWS misconfiguration"],
              "Bounty": "2,100",
              "PublicationDate": "2022-02-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I get my first SWAG from SIDN (Sensitive Data Exposer)",
                    "Link": "https://remonsec.com/posts/getting-first-swag-SIDN/"
                 }
              ],
              "Authors": ["remonsec (@remonsec)"],
              "Programs": ["SIDN"],
              "Bugs": ["Directory listing", "Information disclosure", "403 bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-02-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE in GitHub Desktop < 2.9.4",
                    "Link": "https://github.com/Metnew/write-ups/tree/main/rce-github-desktop-2.9.3"
                 }
              ],
              "Authors": ["Vladimir Metnew (@vladimir_metnew)"],
              "Programs": ["GitHub"],
              "Bugs": ["RCE"],
              "Bounty": "2,000",
              "PublicationDate": "2022-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in message.alibaba.com ($2,000)",
                    "Link": "https://web.archive.org/web/20220220072733/https://bloggerrando.blogspot.com/2022/02/stored-xss-on-messagealibabacom-alibaba.html"
                 }
              ],
              "Authors": ["R ando (@Rando02355205)"],
              "Programs": ["Alibaba"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2022-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Analyzing a PJL directory traversal vulnerability – exploiting the Lexmark MC3224i printer (part 2)",
                    "Link": "https://research.nccgroup.com/2022/02/18/analyzing-a-pjl-directory-traversal-vulnerability-exploiting-the-lexmark-mc3224i-printer-part-2/"
                 }
              ],
              "Authors": ["Cedric Halbronn (@saidelike)", "Aaron Adams (@fidgetingbits)", "Alex Plaskett (@alexjplaskett)"],
              "Programs": ["Lexmark"],
              "Bugs": ["Arbitrary file write", "Race condition", "Printer hacking"],
              "Bounty": "-",
              "PublicationDate": "2022-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Recon and YouTube, is that a thing?",
                    "Link": "https://medium.com/@720922/recon-and-youtube-is-that-a-thing-5523b48c32e3"
                 }
              ],
              "Authors": ["Marcos IAF / Rohit (@marcos_iaf)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "403 forbidden bypass & Accessing config files using a header",
                    "Link": "https://medium.com/@vishnurajr/403-forbidden-bypass-accessing-config-files-using-a-header-4bd172c25ff1"
                 }
              ],
              "Authors": ["vishnurajr"],
              "Programs": ["-"],
              "Bugs": ["403 bypass", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Advisory: Cisco RV340 Dual WAN Gigabit VPN Router (RCE over LAN)",
                    "Link": "https://www.iot-inspector.com/blog/advisory-cisco-rv340-dual-wan-gigabit-vpn-router-rce-over-lan/"
                 }
              ],
              "Authors": ["Quentin Kaiser (@QKaiser)"],
              "Programs": ["Cisco"],
              "Bugs": ["RCE", "Unrestricted file upload", "OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2022-02-17",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "CVE-2022-0478 - WooCommerce Event-Manager Plugin SQL Injection",
                  "Link": "https://web.archive.org/web/20220217212342/https://castilho101.github.io/posts/cve-2022-0478-woocommerce-event-manager-plugin-sql-injection/"
               }
            ],
            "Authors": ["Castilho (@castilho101)"],
            "Programs": ["Automattic (WooCommerce)"],
            "Bugs": ["SQL injection", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2022-02-16",
            "AddedDate": "2023-05-08"
         },
           {
              "Links": [
                 {
                    "Title": "How I earned $9000 with Privilege escalations",
                    "Link": "https://junoonbro.medium.com/how-i-earned-9000-with-privilege-escalations-b187d1f8f4fe"
                 }
              ],
              "Authors": ["Junaid Khan (@JunoonBro)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "9,000",
              "PublicationDate": "2022-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first report on HackerOne: A logic flaw in npm",
                    "Link": "https://elinfosec.com/2022/my-first-report-on-hackerone-a-logic-flaw-in-npm/"
                 }
              ],
              "Authors": ["ElSec (@ElSec_)"],
              "Programs": ["GitHub"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Reflected XSS Bug Bounty — Google Dork — $xxx",
                    "Link": "https://infosecwriteups.com/my-first-reflected-xss-bug-bounty-google-dork-xxx-92ac1180e0d0"
                 }
              ],
              "Authors": ["Proviesec (@proviesec)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacked Dutch Government Website. All I got was this l̶o̶u̶s̶y̶ cool T-Shirt.",
                    "Link": "https://medium.com/@chander.romesh/hacked-dutch-government-website-all-i-got-was-this-l̶o̶u̶s̶y̶-cool-t-shirt-4fd62ed3e734"
                 }
              ],
              "Authors": ["Romesh chander"],
              "Programs": ["Dutch Government"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Report; Bypassing Weekly Limits In Basic (Free) LinkedIn Account",
                    "Link": "https://ashok314.medium.com/bug-report-bypassing-weekly-limits-in-basic-free-linkedin-account-f5265ac0418a"
                 }
              ],
              "Authors": ["Ashok Acharya"],
              "Programs": ["LinkedIn"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting for bugs in VMware: View Planner and vRealize Business for Cloud",
                    "Link": "https://swarm.ptsecurity.com/hunting-for-bugs-in-vmware-view-planner-and-vrealize-business-for-cloud/"
                 }
              ],
              "Authors": ["Mikhail Klyuchnikov (@__Mn1__)", "Egor Dimitrenko (@elk0kc)"],
              "Programs": ["VMware"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Trim private live videos and access them (Meta bug bounty)",
                    "Link": "https://medium.com/@yaala/trim-private-live-videos-and-access-them-a331447cc82a"
                 }
              ],
              "Authors": ["abdellah yaala (@yaalaab)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "7,500",
              "PublicationDate": "2022-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Static Taint Analysis Using Binary Ninja: A Case Study Of MySQL Cluster Vulnerabilities",
                    "Link": "https://www.zerodayinitiative.com/blog/2022/2/14/static-taint-analysis-using-binary-ninja-a-case-study-of-mysql-cluster-vulnerabilities"
                 }
              ],
              "Authors": ["Reno Robert (@renorobertr)"],
              "Programs": ["Oracle (MySQL)"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Advisory: Western Digital My Cloud Pro Series PR4100 RCE",
                    "Link": "https://www.iot-inspector.com/blog/advisory-western-digital-my-cloud-pro-series-pr4100-rce/"
                 }
              ],
              "Authors": ["Quentin Kaiser (@QKaiser)"],
              "Programs": ["Western Digital"],
              "Bugs": ["RCE", "OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2022-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BigQuery SQL Injection Cheat Sheet",
                    "Link": "https://ozguralp.medium.com/bigquery-sql-injection-cheat-sheet-65ad70e11eac"
                 }
              ],
              "Authors": ["Ozgur Alp (@ozgur_bbh)", "Anil Yuksel (@anilyukk)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Bounty and How I Got It",
                    "Link": "https://medium.com/@interc3pt3r/my-first-bounty-and-how-i-got-it-a6dba459c652"
                 }
              ],
              "Authors": ["Aneesha D (@interc3pt3r)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "132",
              "PublicationDate": "2022-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking AWS Cognito Misconfiguration to Zero Click Account Takeover",
                    "Link": "https://infosecwriteups.com/hacking-aws-cognito-misconfiguration-to-zero-click-account-takeover-36a209a0bd8a"
                 }
              ],
              "Authors": ["Preetham Bomma (@cyber01_)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i made 15k$ from Remote Code Execution Vulnerability",
                    "Link": "https://amakki.me/how-i-made-15k-from-remote-code-execution-vulnerability-2e1b14b3902a"
                 },
                 {
                    "Title": "Demo",
                    "Link": "https://www.youtube.com/watch?v=O1uK_b1Tmts"
                 }
              ],
              "Authors": ["Abdulrahman Makki (@AMakki1337)"],
              "Programs": ["-"],
              "Bugs": ["Code injection", "RCE", "Self-XSS"],
              "Bounty": "15,000",
              "PublicationDate": "2022-02-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Link Hijacking - Mr. User-Agent",
                    "Link": "https://shahjerry33.medium.com/broken-link-hijacking-mr-user-agent-cd124297f6e6"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2022-02-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A tale of 0-Click Account Takeover and 2FA Bypass.",
                    "Link": "https://infosecwriteups.com/a-tale-of-0-click-account-takeover-and-2fa-bypass-b369cd70e42f"
                 }
              ],
              "Authors": ["Firas Fatnassi (@Fatnass1F1ras)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset", "2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-02-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "\"Zero-Days\" Without Incident - Compromising Angular via Expired npm Publisher Email Domains",
                    "Link": "https://thehackerblog.com/zero-days-without-incident-compromising-angular-via-expired-npm-publisher-email-domains-7kZplW4x/"
                 }
              ],
              "Authors": ["Matthew Bryant (@IAmMandatory)"],
              "Programs": ["GitHub"],
              "Bugs": ["Supply chain attack"],
              "Bounty": "-",
              "PublicationDate": "2022-02-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "QRCDR ZeroDay Path Traversal Vulnerability",
                    "Link": "https://n0lsec.medium.com/qrcdr-path-traversal-vulnerability-bb89acc0c100"
                 }
              ],
              "Authors": ["Farhad Karimi (@n0lsec)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-02-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "flashback_connects (Cisco RV340 SSL VPN Unauthenticated Remote Code Execution as root)",
                    "Link": "https://twitter.com/FlashbackPwn/status/1492074441450397698"
                 }
              ],
              "Authors": ["Pedro Ribeiro (@pedrib1337)", "Radek Domanski (@RabbitPro)"],
              "Programs": ["Cisco"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-02-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover via Leadpages Services on Tiktok",
                    "Link": "https://twitter.com/m7mdharon/status/1492204287295897600"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["TikTok"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-02-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Mindshare: When Mysql Cluster Encounters Taint Analysis",
                    "Link": "https://www.zerodayinitiative.com/blog/2022/2/10/mindshare-when-mysql-cluster-encounters-taint-analysis"
                 }
              ],
              "Authors": ["Lucas Leong (@_wmliang_)"],
              "Programs": ["Oracle (MySQL)"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-02-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Team’s Unpatched URL Spoofing Vulnerability",
                    "Link": "https://priyankraval.medium.com/microsoft-teams-unpatched-url-spoofing-vulnerability-c58f5949fac8"
                 }
              ],
              "Authors": ["Priyank Raval"],
              "Programs": ["Microsoft"],
              "Bugs": ["URL spoofing"],
              "Bounty": "-",
              "PublicationDate": "2022-02-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked Google to read files from their servers for free!",
                    "Link": "https://medium.com/@harishhacker3010/how-i-hacked-google-to-read-files-from-their-servers-for-free-e0486a674912"
                 }
              ],
              "Authors": ["Harish SG (@CoderHarish)"],
              "Programs": ["Google"],
              "Bugs": ["Arbitrary file read"],
              "Bounty": "-",
              "PublicationDate": "2022-02-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ICMAD SAP Vulnerabilities (CVE-2022-22536, CVE-2022-22532 & CVE-2022-22533)",
                    "Link": "https://onapsis.com/threat-report/icmad-sap-vulnerabilities"
                 }
              ],
              "Authors": ["SAP Product Security Response team", "Onapsis Research Labs"],
              "Programs": ["SAP"],
              "Bugs": ["HTTP request smuggling", "Memory leak", "DoS", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Oracle Server Side Request Forgery (SSRF) Metadata",
                    "Link": "https://orca.security/resources/blog/oracle-server-side-request-forgery-ssrf-attack-metadata/"
                 }
              ],
              "Authors": ["Lidor Ben Shitrit"],
              "Programs": ["Oracle"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of critical security flaws I found in Glints",
                    "Link": "https://tech-blog.cymetrics.io/en/posts/huli/how-i-hacked-glints-and-your-resume-en/"
                 }
              ],
              "Authors": ["huli (@aszx87410)"],
              "Programs": ["Glints"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "1,200",
              "PublicationDate": "2022-02-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WordPress < 5.8.3 - Object Injection Vulnerability",
                    "Link": "https://blog.sonarsource.com/wordpress-object-injection-vulnerability"
                 }
              ],
              "Authors": ["Simon Scannell (@scannell_simon)", "Karim El Ouerghemmi"],
              "Programs": ["WordPress"],
              "Bugs": ["Object injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022-21999)",
                    "Link": "https://research.ifcr.dk/spoolfool-windows-print-spooler-privilege-escalation-cve-2022-22718-bf7752b68d81"
                 }
              ],
              "Authors": ["Olivier Lyak (@ly4k_)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Docker Made Me More Capable and the Host Less Secure",
                    "Link": "https://www.cyberark.com/resources/threat-research-blog/how-docker-made-me-more-capable-and-the-host-less-secure"
                 }
              ],
              "Authors": ["Alon Zahavi (@Alon_Z4)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2022-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-21703: cross-origin request forgery against Grafana",
                    "Link": "https://jub0bs.com/posts/2022-02-08-cve-2022-21703-writeup/"
                 }
              ],
              "Authors": ["Julien Cretel (@jub0bs)", "abrahack (@theabrahack)"],
              "Programs": ["Grafana Labs"],
              "Bugs": ["CSRF", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection, Reflected XSS and Information Disclosure in one subdomain in just 10 minutes",
                    "Link": "https://web.archive.org/web/20220214063345/https://7odamo.medium.com/sql-injection-reflected-xss-and-information-disclosure-in-one-subdomain-in-just-10-minutes-f2ce877b43d4"
                 }
              ],
              "Authors": ["Mahmoud Hamed (@7odamo_)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "XSS", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full Account takeover (ATO) — a tale of two bugs 🐛",
                    "Link": "https://medium.com/@kojodaprogrammer/full-account-takeover-ato-a-tale-of-two-bugs-d1b3765ff1de"
                 }
              ],
              "Authors": ["Kwadwo Amoako"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Security Misconfiguration Leads to Account Takeover !",
                    "Link": "https://medium.com/@harshbanshpal/you-can-takeover-any-google-account-f6f2d012466f"
                 }
              ],
              "Authors": ["Harsh Banshpal"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw", "Spoofing"],
              "Bounty": "-",
              "PublicationDate": "2022-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "What I Found on Sony Vulnerability Disclosure Program",
                    "Link": "https://www.cyberick.com/post/what-i-found-on-sony-vulnerability-disclosure-program"
                 }
              ],
              "Authors": ["Aditya Singh / rook1337 (@imrook1337)"],
              "Programs": ["Sony"],
              "Bugs": ["Information disclosure", "Lack of rate limiting", "Open redirect", "IDOR", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-02-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How can I access the members-only video comment? | YouTube ($5,000)",
                    "Link": "https://bloggerrando.blogspot.com/2022/02/how-can-i-access-members-only-video.html"
                 }
              ],
              "Authors": ["R ando (@Rando02355205)"],
              "Programs": ["Google"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "5,000",
              "PublicationDate": "2022-02-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Insecure Bootstrap Process in Oracle Cloud CLI",
                    "Link": "https://wwws.nightwatchcybersecurity.com/2022/02/06/insecure-bootstrap-process-in-oracle-cloud-cli/"
                 }
              ],
              "Authors": ["Nightwatch Cybersecurity (@nightwatchcyber)"],
              "Programs": ["Oracle"],
              "Bugs": ["Supply chain attack"],
              "Bounty": "-",
              "PublicationDate": "2022-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Auth Bypass in Google Assistant",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0012"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["Information disclosure", "Authentication bypass"],
              "Bounty": "2674",
              "PublicationDate": "2022-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Auth Bypass in com.google.android.googlequicksearchbox",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0013"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "1,337",
              "PublicationDate": "2022-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found a critical P1 bug in 5 minutes using a cellphone — Bug Bounty",
                    "Link": "https://medium.com/@mrempy/how-i-found-a-critical-p1-bug-in-5-minutes-using-a-cellphone-bug-bounty-303ebec3edd6"
                 }
              ],
              "Authors": ["Mr Empy (@mr_empy)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Oauth bypass",
                    "Link": "https://medium.com/@yaala/facebook-oauth-bypass-446a073e687d"
                 }
              ],
              "Authors": ["abdellah yaala (@yaalaab)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["OAuth"],
              "Bounty": "7,500",
              "PublicationDate": "2022-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "What Bypassing Razer's DOM-based XSS Patch Can Teach Us",
                    "Link": "https://edoverflow.com/2022/bypassing-razers-dom-based-xss-filter/"
                 }
              ],
              "Authors": ["EdOverflow (@EdOverflow)"],
              "Programs": ["Razer"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I bypassed PHP functions to read sensitive files on server",
                    "Link": "https://kailashbohara.com.np/blog/2022/02/04/bypassing-PHP-functions-to-read-system-file-copy/"
                 }
              ],
              "Authors": ["Kailash (@corrupted_brain)"],
              "Programs": ["-"],
              "Bugs": ["Components with known vulnerabilities", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing the AWS WAF protection with an 8KB bullet",
                    "Link": "https://kloudle.com/blog/the-infamous-8kb-aws-waf-request-body-inspection-limitation"
                 }
              ],
              "Authors": ["Kloudle (@Kloudleinc)"],
              "Programs": ["AWS"],
              "Bugs": ["WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up – Private Bug Bounty: RCE In EC2 Instance Via SSH With Private Key Exposed On Public Github Repository – $xx,000 USD",
                    "Link": "https://omespino.com/write-up-private-bug-bounty-rce-in-ec2-instance-via-ssh-with-private-key-exposed-on-public-github-repository-xx000-usd/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Solving DOM XSS Puzzles",
                    "Link": "https://spaceraccoon.dev/solving-dom-xss-puzzles"
                 }
              ],
              "Authors": ["Eugene Lim (@spaceraccoonsec)"],
              "Programs": ["-"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HigherLogic Community RCE Vulnerability",
                    "Link": "https://blog.sorcery.ie/posts/higherlogic_rce/"
                 }
              ],
              "Authors": ["0daystolive (@0daystolive)"],
              "Programs": ["8x8", "IBM"],
              "Bugs": ["Insecure deserialization", "RCE"],
              "Bounty": "1,250",
              "PublicationDate": "2022-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Malicious Kubernetes Helm Charts can be used to steal sensitive information from Argo CD deployments",
                    "Link": "https://apiiro.com/blog/malicious-kubernetes-helm-charts-can-be-used-to-steal-sensitive-information-from-argo-cd-deployments/"
                 }
              ],
              "Authors": ["Apiiro’s Security Research"],
              "Programs": ["Argo CD"],
              "Bugs": ["Supply chain attack", "CI/CD"],
              "Bounty": "-",
              "PublicationDate": "2022-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A technique to semi-automatically find vulnerabilities in WordPress plugins",
                    "Link": "https://kazet.cc/2022/02/03/fuzzing-wordpress-plugins.html"
                 }
              ],
              "Authors": ["kazet (@kazet1234)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "SQL injection", "Open redirect", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Tracked You Around The Globe 🌎",
                    "Link": "https://web.archive.org/web/20220612235502/https://bugs.0xdroopy.live/bugs/how-i-tracked-you-around-the-globe/"
                 }
              ],
              "Authors": ["0xdroopy (@NikhilK50866227)"],
              "Programs": ["Google (Waze)"],
              "Bugs": ["Information disclosure", "Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2022-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing Facebooks `Call To Action` To Launch Internal Deeplinks",
                    "Link": "https://www.ash-king.co.uk/blog/abusing-Facebooks-call-to-action-to-launch-internal-deeplinks"
                 }
              ],
              "Authors": ["Ashley King (@AshleyKingUK)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF", "Android", "iOS"],
              "Bounty": "4,000",
              "PublicationDate": "2022-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first bounty, IDOR + Self XSS [€3000]",
                    "Link": "https://medium.com/@ladecruze/my-first-bounty-idor-self-xss-3000-cde89cbbc1b1"
                 }
              ],
              "Authors": ["Ladecruze (@ladecruze)"],
              "Programs": ["Intigriti"],
              "Bugs": ["Self-XSS", "IDOR"],
              "Bounty": "3,000",
              "PublicationDate": "2022-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A misconfigured Apache Airflow to AWS Account Compromise",
                    "Link": "https://logicbomb.medium.com/a-misconfigured-apache-airflow-to-aws-account-compromise-c905dc49998d"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["Outdated component with a known vulnerability", "Privilege escalation", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My experience of Hacking The Dutch Government",
                    "Link": "https://sanyamchawla1999.medium.com/my-experience-of-hacking-the-dutch-government-8c219c61c795"
                 }
              ],
              "Authors": ["Phenomenal (@Chawla12111)"],
              "Programs": ["Dutch Government"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "No Rate Limiting on OTP sending",
                    "Link": "https://medium.com/@noob_master/no-rate-limiting-on-otp-sending-39a3a9fc93f6"
                 }
              ],
              "Authors": ["nOOb_mAsTeR"],
              "Programs": ["-"],
              "Bugs": ["Bruteforce", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2022-02-02",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "IDOR vulnerability on invoice and weak password reset leads to account take over",
                  "Link": "https://medium.com/@damaidec/idor-vulnerability-on-invoice-and-weak-password-reset-leads-to-account-take-over-603b42143a8c"
               }
            ],
            "Authors": ["Damaidec"],
            "Programs": ["-"],
            "Bugs": ["IDOR", "Password reset", "Account takeover", "Payment tampering", "Logic flaw"],
            "Bounty": "-",
            "PublicationDate": "2022-02-01",
            "AddedDate": "2022-11-30"
         },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-44142: Details On A Samba Code Execution Bug Demonstrated At Pwn2Own Austin",
                    "Link": "https://www.zerodayinitiative.com/blog/2022/2/1/cve-2021-44142-details-on-a-samba-code-execution-bug-demonstrated-at-pwn2own-austin"
                 }
              ],
              "Authors": ["Nguyễn Hoàng Thạch (@hi_im_d4rkn3ss)", "Billy Jheng Bing-Jhong (@st424204)"],
              "Programs": ["-"],
              "Bugs": ["Memory corruption", "RCE"],
              "Bounty": "45,000",
              "PublicationDate": "2022-02-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Peculiar Case of XSS and my first bug",
                    "Link": "https://systemweakness.com/a-peculiar-case-of-xss-and-my-first-bug-19f2132390b6"
                 }
              ],
              "Authors": ["Aman Pareek (@aman_notsogreat)"],
              "Programs": ["Bentley Systems"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-02-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A story of leaking uninitialized memory from Fastly",
                    "Link": "https://medium.com/@emil.lerner/leaking-uninitialized-memory-from-fastly-83327bcbee1f"
                 }
              ],
              "Authors": ["Emil Lerner (@emil_lerner)"],
              "Programs": ["Fastly"],
              "Bugs": ["HTTP/3", "Memory leak", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-02-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I approached Dependency Confusion!",
                    "Link": "https://hetroublemakr.medium.com/how-i-approached-dependency-confusion-272b46f66907"
                 }
              ],
              "Authors": ["Aditya Soni (@hetroublemakr)"],
              "Programs": ["-"],
              "Bugs": ["Dependency confusion"],
              "Bounty": "-",
              "PublicationDate": "2022-02-01",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Microsoft accidentally exposed their private Xbox game developer forums",
                  "Link": "https://eaton-works.com/2022/01/31/microsoft-accidentally-exposed-their-private-xbox-game-developer-forums/"
               }
            ],
            "Authors": ["Eaton Z. (@XeEaton)"],
            "Programs": ["Microsoft (Xbox)"],
            "Bugs": ["Missing authentication"],
            "Bounty": "-",
            "PublicationDate": "2022-01-31",
            "AddedDate": "2024-02-06"
         },
         {
            "Links": [
               {
                  "Title": "Flask Security",
                  "Link": "https://btlfry.gitlab.io/notes/posts/flask-security/"
               }
            ],
            "Authors": ["Zakhar Fedotkin / d4d (@d4d89704243)"],
            "Programs": ["-"],
            "Bugs": ["OIDC", "Session management issue"],
            "Bounty": "-",
            "PublicationDate": "2022-01-31",
            "AddedDate": "2024-02-06"
         },
           {
              "Links": [
                 {
                    "Title": "Hacking Google Drive Integrations",
                    "Link": "https://httpvoid.com/Hacking-Google-Drive-Integrations.md"
                 }
              ],
              "Authors": ["Harsh Jaiswal (@rootxharsh)"],
              "Programs": ["Dropbox"],
              "Bugs": ["SSRF"],
              "Bounty": "17,576",
              "PublicationDate": "2022-01-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft OneDrive For Macos Local Privilege Escalation",
                    "Link": "https://www.offensive-security.com/offsec/microsoft-onedrive-macos-local-privesc/"
                 }
              ],
              "Authors": ["Offensive Security (@offsectraining)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2022-01-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Missing rate-limiting. How I was able to add any unowned phone number to my Facebook account? (Bounty: 5000 USD)",
                    "Link": "https://theshubh77.medium.com/write-up-missing-rate-limiting-how-i-was-able-to-add-any-unowned-phone-number-to-my-fb-account-fe4d7e67cf10"
                 }
              ],
              "Authors": ["Shubham Bhamare (@theshubh77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["OTP bruteforce", "Lack of rate limiting"],
              "Bounty": "5,000",
              "PublicationDate": "2022-01-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Code Execution in .tgz File Upload",
                    "Link": "https://machevalia.blog/blog/remote-code-execution-in-tgz-file-upload"
                 }
              ],
              "Authors": ["Nick Berrie (@machevalia)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Unrestricted file upload"],
              "Bounty": "3,100",
              "PublicationDate": "2022-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored Cross-Site Scripting in MediaWiki",
                    "Link": "https://machevalia.blog/blog/stored-cross-site-scripting-in-mediawiki"
                 }
              ],
              "Authors": ["Nick Berrie (@machevalia)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,090",
              "PublicationDate": "2022-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Access Control Violation – Wiki Page Creation",
                    "Link": "https://web.archive.org/web/20221228134225/https://machevalia.blog/access-control-violation-wiki-page-creation/"
                 }
              ],
              "Authors": ["Nick Berrie (@machevalia)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "522.50",
              "PublicationDate": "2022-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS via X-Forwarded-Host header",
                    "Link": "https://medium.com/@abhijeetbiswas_/xss-cross-site-scripting-via-x-forwarded-host-header-20be114d4254"
                 },
                 {
                    "Title": "HackerOne report",
                    "Link": "https://hackerone.com/reports/1392935"
                 }
              ],
              "Authors": ["Abhijeet Biswas (@abhijeetbiswas_)"],
              "Programs": ["Omise"],
              "Bugs": ["XSS", "Host header injection"],
              "Bounty": "200",
              "PublicationDate": "2022-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2fa Bypass by changing Request method",
                    "Link": "https://medium.com/@arthbajpai277/2fa-bypass-by-changing-request-method-to-delete-500fd0ed12b8"
                 }
              ],
              "Authors": ["Arth Bajpai (@arth_bajpai)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked my way to the top of DARPA’s hardware bug bounty",
                    "Link": "https://readme.security/how-i-hacked-my-way-to-the-top-of-darpas-hardware-bug-bounty-b66ec53b1973"
                 }
              ],
              "Authors": ["Malcolm Stagg (@malcolmst)"],
              "Programs": ["DARPA FETT"],
              "Bugs": ["Hardware hacking"],
              "Bounty": "-",
              "PublicationDate": "2022-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Made $16,500 Hacking CDN Caching Servers — Part 1",
                    "Link": "https://bxmbn.medium.com/how-i-made-15-000-by-hacking-caching-servers-part-1-5541712a61c3"
                 },
                 {
                    "Title": "Part 2",
                    "Link": "https://bxmbn.medium.com/how-i-made-16-500-hacking-cdn-caching-servers-part-2-4995ece4c6e6"
                 },
                 {
                    "Title": "Part 3",
                    "Link": "https://infosecwriteups.com/how-i-made-16-500-hacking-cdn-caching-servers-part-3-91f9d836e046"
                 }
              ],
              "Authors": ["Kevin (@bxmbn)"],
              "Programs": ["-"],
              "Bugs": ["Web cache poisoning", "Stored XSS", "Web cache deception"],
              "Bounty": "16,500",
              "PublicationDate": "2022-01-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Paytm-Broken Link Hijacking",
                    "Link": "https://lohigowda.medium.com/paytm-broken-link-hijacking-11624e4e9eef"
                 }
              ],
              "Authors": ["Lohith Gowda M (@lohigowda_in)"],
              "Programs": ["Paytm"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2022-01-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple HTTP Redirects to Bypass SSRF Protections",
                    "Link": "https://infosecwriteups.com/multiple-http-redirects-to-bypass-ssrf-protections-45c894e5d41c"
                 }
              ],
              "Authors": ["ne555"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-01-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Command Injection in Google Cloud Shell",
                    "Link": "https://docs.google.com/document/d/1-TTCS6fS6kvFUkoJmX4Udr-czQ79lSUVXiWsiAED_bs/edit"
                 }
              ],
              "Authors": ["Ademar Nowasky Junior"],
              "Programs": ["Google"],
              "Bugs": ["RCE", "OS command injection"],
              "Bounty": "5,000",
              "PublicationDate": "2022-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Story of a RCE on a Java Web Application",
                    "Link": "https://medium.com/@LIL__NIX/the-story-of-a-rce-on-a-java-web-application-2e400cddcd1e"
                 }
              ],
              "Authors": ["LIL NIX (@Lil__Nix)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2022-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing SSRF Protection to Exfiltrate AWS Metadata from LarkSuite",
                    "Link": "https://sirleeroyjenkins.medium.com/bypassing-ssrf-protection-to-exfiltrate-aws-metadata-from-larksuite-bf99a3599462"
                 }
              ],
              "Authors": ["SirLeeroyJenkins (@SirLeeroyJenkin)"],
              "Programs": ["Lark Technologies"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Story of an RCE on a Java Web Application",
                    "Link": "https://infosecwriteups.com/the-story-of-a-rce-on-a-java-web-application-2e400cddcd1e"
                 }
              ],
              "Authors": ["LIL NIX (@Lil__Nix)"],
              "Programs": ["-"],
              "Bugs": ["Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2022-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing administrative JWT's through post auth SSRF (CVE-2021-22056)",
                    "Link": "https://www.signal-labs.com/blog/vmware-driver-0day-reversing"
                 }
              ],
              "Authors": ["Christopher (@Kharosx0)"],
              "Programs": ["VMware"],
              "Bugs": ["Windows Driver hacking", "Kernel DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020-0696 - Microsoft Outlook Security Feature Bypass Vulnerability",
                    "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2020-0696-microsoft-outlook-security-feature-bypass-vulnerability/"
                 }
              ],
              "Authors": ["Reegun Jayapaul (@reegun21)"],
              "Programs": ["Microsoft"],
              "Bugs": ["URL validation bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Technical Analysis of CVE-2022-22583: Bypassing macOS System Integrity Protection (SIP)",
                    "Link": "https://perception-point.io/technical-analysis-of-cve-2022-22583-bypassing-macos-system-integrity-protection/"
                 }
              ],
              "Authors": ["Perception Point"],
              "Programs": ["Apple"],
              "Bugs": ["MacOS", "SIP bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Auth Bypass in ADOdb CVE-2021-3850",
                    "Link": "https://blog.sorcery.ie/posts/adodb_auth_bypass/"
                 }
              ],
              "Authors": ["Emmet Leah"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-01-26",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Exploiting: Buffer overflow in Xiongmai DVRs",
                  "Link": "https://blog.ret2.me/post/2022-01-26-exploiting-xiongmai-dvrs/"
               }
            ],
            "Authors": ["Chris Leech"],
            "Programs": ["Xiongmai"],
            "Bugs": ["Memory corruption", "Buffer Overflow"],
            "Bounty": "-",
            "PublicationDate": "2022-01-26",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-0185 - Winning a $31337 Bounty after Pwning Ubuntu and Escaping Google's KCTF Containers",
                    "Link": "https://www.willsroot.io/2022/01/cve-2022-0185.html"
                 }
              ],
              "Authors": ["Crusaders of Rust (@cor_ctf)"],
              "Programs": ["Google"],
              "Bugs": ["Container escape", "Kubernetes"],
              "Bounty": "31,337",
              "PublicationDate": "2022-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could have read your confidential bug reports by simple mail?",
                    "Link": "https://infosecwriteups.com/how-i-could-have-read-your-confidential-bug-reports-by-simple-mail-cfd2e4f8e25c"
                 }
              ],
              "Authors": ["Sudhakar Muthumani (@Sudhakarmuthu04)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking the Apple Webcam (again)",
                    "Link": "https://www.ryanpickren.com/safari-uxss"
                 }
              ],
              "Authors": ["Ryan Pickren"],
              "Programs": ["Apple"],
              "Bugs": ["Universal XSS", "Browser hacking"],
              "Bounty": "100,500",
              "PublicationDate": "2022-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HOW I hacked thousand of subdomains",
                    "Link": "https://medium.com/@moSec/how-i-hacked-thousand-of-subdomains-6aa43b92282c"
                 }
              ],
              "Authors": ["MoSec (@moe1n1)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "5,000",
              "PublicationDate": "2022-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to take over accounts in websites deal with Github as an SSO provider",
                    "Link": "https://infosecwriteups.com/how-i-was-able-to-takeover-accounts-in-websites-deal-with-github-as-a-sso-provider-294290358e0c"
                 }
              ],
              "Authors": ["Khaled Mohamed"],
              "Programs": ["-"],
              "Bugs": ["Bruteforce", "Lack of rate limiting", "SSO", "Email verification bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "First Valid BUG Finding At Microsoft And I Got the Acknowledgments Page Microsoft",
                    "Link": "https://aidilarf.medium.com/first-valid-bug-finding-at-microsoft-and-i-got-the-acknowledgments-page-microsoft-a2c185c53074"
                 }
              ],
              "Authors": ["Aidil Arief"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2022-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-44790: Code Execution On Apache Via An Integer Underflow",
                    "Link": "https://www.zerodayinitiative.com/blog/2022/1/25/cve-2021-44790-code-execution-on-apache-via-an-integer-underflow"
                 }
              ],
              "Authors": ["Chamal"],
              "Programs": ["Apache"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got access to 25+ Tesla’s around the world. By accident. And curiosity.",
                    "Link": "https://medium.com/@david_colombo/how-i-got-access-to-25-teslas-around-the-world-by-accident-and-curiosity-8b9ef040a028"
                 }
              ],
              "Authors": ["David Colombo (@david_colombo_)"],
              "Programs": ["Tesla"],
              "Bugs": ["Default credentials"],
              "Bounty": "-",
              "PublicationDate": "2022-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Solarwinds Web Help Desk: When the Helpdesk is too Helpful",
                    "Link": "https://blog.assetnote.io/2022/01/23/solarwinds-webhelpdesk-hsql-eval-harcoded-creds/"
                 }
              ],
              "Authors": ["Assetnote Security Research Team (@assetnote)"],
              "Programs": ["SolarWinds"],
              "Bugs": ["Information disclosure", "Hardcoded credentials"],
              "Bounty": "-",
              "PublicationDate": "2022-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Path Traversal Paradise",
                    "Link": "https://kuldeep.io/posts/path-traversal-paradise/"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://www.synack.com/blog/path-traversal-paradise/"
                 }
              ],
              "Authors": ["Kuldeep Pandya (@kuldeepdotexe)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2022-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to find multiple vulnerabilities of a Symfony Web Framework web application",
                    "Link": "https://infosecwriteups.com/how-i-was-able-to-find-multiple-vulnerabilities-of-a-symfony-web-framework-web-application-2b82cd5de144"
                 }
              ],
              "Authors": ["Abid Ahmad (@RootIntrud3r)"],
              "Programs": ["-"],
              "Bugs": ["Debug mode enabled", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2022-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "120 Days of Frequent Hacking",
                    "Link": "https://coffeejunkie.me//120-Days-Of-Frequent-Hacking/"
                 }
              ],
              "Authors": ["Kuldeep Pandya (@kuldeepdotexe)", "Sam Paredes (@caffeinevulns)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "LFI", "Information disclosure", "XSS", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-01-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook room deep linking vulnerability, allow malicious user to know the code for anyone’s meeting.",
                    "Link": "https://medium.com/@quelperlado/facebook-room-deep-linking-vulnerability-allow-malicious-user-to-know-the-code-for-anyones-4761b93481f1"
                 }
              ],
              "Authors": ["Quel (@RootIntrud3r)"],
              "Programs": ["-"],
              "Bugs": ["Insecure deeplink", "Android"],
              "Bounty": "-",
              "PublicationDate": "2022-01-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hashing the Favicon.ico",
                    "Link": "https://medium.com/@SkiMask0/hashing-the-favicon-ico-a498fc3d665b"
                 }
              ],
              "Authors": ["Ski Mask (@Ski_Mask0)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "100",
              "PublicationDate": "2022-01-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ZohOwned :: A Critical Authentication Bypass on Zoho ManageEngine Desktop Central",
                    "Link": "https://srcincite.io/blog/2022/01/20/zohowned-a-critical-authentication-bypass-on-zoho-manageengine-desktop-central.html"
                 }
              ],
              "Authors": ["Steven Seeley (@steventseeley)"],
              "Programs": ["Zoho"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-01-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I messed up my own profile data",
                    "Link": "https://medium.com/@himmat1005/how-i-messed-up-my-own-profile-data-94a4b09cb54c"
                 }
              ],
              "Authors": ["Himmat Singh"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-01-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Tale of a Click leading to RCE",
                    "Link": "https://medium.com/manomano-tech/the-tale-of-a-click-leading-to-rce-8f68fe93545d"
                 }
              ],
              "Authors": ["Roni Carta (@0xLupin)"],
              "Programs": ["CatchPoint"],
              "Bugs": ["RCE", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-01-18",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                 {
                    "Title": "Finding vulnerabilities in Swiss Post’s future e-voting system - Part 1",
                    "Link": "https://www.reversemode.com/2022/01/finding-vulnerabilities-in-swiss-posts.html"
                 }
              ],
              "Authors": ["Ruben Santamarta (@reversemode)"],
              "Programs": ["Swiss Post"],
              "Bugs": ["Insecure deserialization", "Cryptographic issues"],
              "Bounty": "-",
              "PublicationDate": "2022-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2022-21661: Exposing Database Info Via Wordpress SQL Injection",
                    "Link": "https://www.zerodayinitiative.com/blog/2022/1/18/cve-2021-21661-exposing-database-info-via-wordpress-sql-injection"
                 }
              ],
              "Authors": ["ngocnb", "khuyenn"],
              "Programs": ["WordPress"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zooming in on Zero-click Exploits",
                    "Link": "https://googleprojectzero.blogspot.com//2022/01/zooming-in-on-zero-click-exploits.html"
                 }
              ],
              "Authors": ["Natalie Silvanovich (@natashenka)"],
              "Programs": ["Zoom"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2022-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Mixed Messages: Busting Box’s MFA Methods",
                    "Link": "https://www.varonis.com/blog/box-mfa-bypass-sms"
                 }
              ],
              "Authors": ["Tal Peleg"],
              "Programs": ["Box"],
              "Bugs": ["OTP bypass", "2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing administrative JWT's through post auth SSRF (CVE-2021-22056)",
                    "Link": "https://blog.assetnote.io/2022/01/17/workspace-one-access-ssrf/"
                 }
              ],
              "Authors": ["Shubham Shah (@infosec_au)", "Keiran Sampson (@hpy_downunder)"],
              "Programs": ["VMware"],
              "Bugs": ["SSRF", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-01-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up – Private Bug Bounty: Firebase Database Exposed By Misconfiguration – $2,000 USD",
                    "Link": "https://omespino.com/write-up-private-bug-bounty-firebase-database-exposed-by-misconfiguration-2000-usd/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["-"],
              "Bugs": ["Android", "Insecure Firebase database"],
              "Bounty": "2,000",
              "PublicationDate": "2022-01-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Critical XSS in chrome extension",
                    "Link": "https://medium.com/@p3rr0x22/critical-xss-in-chrome-extension-b55757a2074"
                 }
              ],
              "Authors": ["p3rr0 (@Hperalta89)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "postMessage"],
              "Bounty": "1,500",
              "PublicationDate": "2022-01-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i found “Broken Access Control Through out-of-sync setup” and got $1000",
                    "Link": "https://medium.com/@robert0/how-i-found-broken-access-control-through-out-of-sync-setup-and-got-1000-9143fc5febdd"
                 }
              ],
              "Authors": ["Mr Robert | Ahmed M Hassan (@Mr_Robert20)"],
              "Programs": ["-"],
              "Bugs": ["Broken Access Control", "Broken authorization"],
              "Bounty": "1,000",
              "PublicationDate": "2022-01-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XXE in SAML SSO Writeup - Bug Bounty",
                    "Link": "https://www.cyberick.com/post/xxe-in-saml-sso-writeup-bug-bounty"
                 }
              ],
              "Authors": ["Aditya Singh / rook1337 (@imrook1337)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2022-01-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Moodle: Blind SQL Injection (CVE-2021-36393) and Broken Access Control (CVE-2021-36397)",
                    "Link": "https://0xkasper.com/articles/moodle-sql-injection-broken-access-control.html"
                 }
              ],
              "Authors": ["0xkasper (@0xkasper)"],
              "Programs": ["Moodle"],
              "Bugs": ["SQL injection", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2022-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "120 Days of High Frequency Hunting",
                    "Link": "https://kuldeep.io/posts/120-days-of-high-frequency-hunting/"
                 }
              ],
              "Authors": ["Kuldeep Pandya (@kuldeepdotexe)", "Sam Paredes (@caffeinevulns)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "LFI", "Information disclosure", "Broken Access Control", "Authentication bypass", "XSS", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE In Adobe Acrobat Reader For Android(CVE-2021-40724)",
                    "Link": "https://hulkvision.github.io/blog/post1/"
                 }
              ],
              "Authors": ["sunny (@hulkvision)"],
              "Programs": ["Google", "Adobe"],
              "Bugs": ["RCE", "Path traversal", "Android"],
              "Bounty": "10,000",
              "PublicationDate": "2022-01-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "FB Lite All Users Active Status Changed",
                    "Link": "https://nmochea.medium.com/fb-lite-all-user-active-status-changed-99c5c36029e5"
                 }
              ],
              "Authors": ["Neil Mark Ochea (@nmochea)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-01-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Filter Evasion + IDOR",
                    "Link": "https://systemweakness.com/xss-filter-evasion-idor-3d4624758ff0"
                 }
              ],
              "Authors": ["JM Sanchez / 0xEchidonut (@jmrcsnchz)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "IDOR"],
              "Bounty": "800",
              "PublicationDate": "2022-01-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Xiaomi Execute Arbitrary JavaScript",
                    "Link": "https://nmochea.medium.com/xiaomi-arbitrary-javascript-vulnerability-327a6f3a9b0e"
                 }
              ],
              "Authors": ["Neil Mark Ochea (@nmochea)"],
              "Programs": ["Xiaomi"],
              "Bugs": ["XSS", "HTML injection", "Android"],
              "Bounty": "-",
              "PublicationDate": "2022-01-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969)",
                    "Link": "https://medium.com/@frycos/searching-for-deserialization-protection-bypasses-in-microsoft-exchange-cve-2022-21969-bfa38f63a62d"
                 }
              ],
              "Authors": ["Florian Hauser (@frycos)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2022-01-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "C.S.T.I Lead To Account Takeover $$$",
                    "Link": "https://systemweakness.com/c-s-t-i-lead-to-account-takeover-f21ea07d9141"
                 }
              ],
              "Authors": ["M7.Arman (@ArmanSecurity)"],
              "Programs": ["-"],
              "Bugs": ["CSTI", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-01-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwning the portal: from database dump to session hijacking",
                    "Link": "https://www.bitcrack.net/pwning-the-portal-from-database-dump-to-session-hijacking/"
                 }
              ],
              "Authors": ["Bitcrack (@bitcrack_cyber)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2022-01-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I downed acronis.com in 2 minutes — Lucky bug write up",
                    "Link": "https://medium.com/@veletisleri/how-i-downed-acronis-com-in-2-minutes-lucky-bug-write-up-a563bcdb563d"
                 }
              ],
              "Authors": ["Ugroon (@veletisleri)"],
              "Programs": ["Acronis"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-01-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Attacking RDP from Inside: How we abused named pipes for smart-card hijacking, unauthorized file system access to client machines and more",
                    "Link": "https://www.cyberark.com/resources/threat-research-blog/attacking-rdp-from-inside"
                 }
              ],
              "Authors": ["Gabriel Sztejnworcel (@sztejnworcel)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-01-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting URL Parsers: The Good, Bad, And Inconsistent",
                    "Link": "https://web-assets.claroty.com/exploiting-url-parsing-confusion.pdf"
                 }
              ],
              "Authors": ["Noam Moshe", "Sharon Brizinov", "Raul Onitza-Klugman (@supriza0)", "Kirill Efimov (@byte89)"],
              "Programs": ["-"],
              "Bugs": ["URL parsing issue", "Parsing differentials"],
              "Bounty": "-",
              "PublicationDate": "2022-01-10",
              "AddedDate": "2022-10-08"
           },
           {
              "Links": [
                 {
                    "Title": "Cross-Origin Resource Sharing (CORS) Misconfiguration leads to User’s PII leaks.",
                    "Link": "https://sa1tama0.medium.com/cross-origin-resource-sharing-cors-misconfiguration-leads-to-users-pii-leaks-b31fd3246e64"
                 }
              ],
              "Authors": ["Tarikul Islam (@sa1tama0)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2022-01-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle's Shibboleth",
                    "Link": "https://haxolot.com/posts/2022/moodle_pre_auth_shibboleth_rce_part2/"
                 }
              ],
              "Authors": ["Johannes Moritz", "Robin Peraglie"],
              "Programs": ["Moodle"],
              "Bugs": ["Session hijacking", "Session management issue", "Account takeover", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-01-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "New macOS vulnerability, “powerdir,” could lead to unauthorized user data access",
                    "Link": "https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access/"
                 }
              ],
              "Authors": ["Microsoft 365 Defender Research Team"],
              "Programs": ["Apple"],
              "Bugs": ["Privacy issue", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2022-01-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How did I find Log4j vulnerability via Static Code Analysis and receive €€€ bounty?",
                    "Link": "https://medium.com/@pranav-gajjar/how-did-i-find-log4j-vulnerability-via-static-code-analysis-and-received-bounty-94f4d86cea88"
                 }
              ],
              "Authors": ["Pranav Gajjar (@Pranav_Gajjar_)"],
              "Programs": ["-"],
              "Bugs": ["Log4shell", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-01-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Host Header Injection Lead To Account Takeovers",
                    "Link": "https://systemweakness.com/host-header-injection-lead-to-account-takeover-2f025a645d13"
                 }
              ],
              "Authors": ["M7.Arman (@ArmanSecurity)"],
              "Programs": ["-"],
              "Bugs": ["Host header injection", "Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-01-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2FA bypass by reading the documentation",
                    "Link": "https://noob3xploiter.medium.com/2fa-bypass-by-reading-the-documentation-3260a372d8a8"
                 }
              ],
              "Authors": ["tomorrowisnew (@tomorrowisnew_)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "100",
              "PublicationDate": "2022-01-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Tale Of 5250$: How I Accessed Millions Of User’s Data Including Their National ID’s",
                    "Link": "https://infosecwriteups.com/a-tale-of-5250-how-i-accessed-millions-of-users-data-including-their-national-id-s-fd48ca7ca0bf"
                 }
              ],
              "Authors": ["Sam (@__Sam0_0)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration", "Information disclosure"],
              "Bounty": "5,250",
              "PublicationDate": "2022-01-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A phishing document signed by Microsoft – part 2",
                    "Link": "https://outflank.nl/blog/2022/01/07/a-phishing-document-signed-by-microsoft-part-2/"
                 }
              ],
              "Authors": ["Pieter Ceelen (@ptrpieter)", "Dima van de Wouw (@_DaWouw)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Phishing", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-01-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Redash instances with CVE-2021-41192",
                    "Link": "https://ian.sh/redash"
                 }
              ],
              "Authors": ["Ian Carroll (@iangcarroll)", "Tuan Anh Nguyen (@haxor31337)", "Gal Nagli (@naglinagli)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Session management issue", "SSRF"],
              "Bounty": "90,000",
              "PublicationDate": "2022-01-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to spoof any Instagram username on Instagram shop",
                    "Link": "https://medium.com/@nvmeeet/how-i-was-able-to-spoof-any-instagram-username-on-instagram-shop-b4d6abdb474a"
                 }
              ],
              "Authors": ["Nawaf Alkhaldi (@nvmeeet)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "1,050",
              "PublicationDate": "2022-01-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authorization bypass — Gmail",
                    "Link": "https://infosecwriteups.com/authorization-bypass-gmail-2949af041fb"
                 }
              ],
              "Authors": ["7𝖍3𝖍4𝖈kv157 (@7h3h4ckv157)"],
              "Programs": ["Google"],
              "Bugs": ["Spoofing"],
              "Bounty": "-",
              "PublicationDate": "2022-01-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accessing GoDaddy internal instance through an email logic bug.",
                    "Link": "https://systemweakness.com/accessing-godaddy-internal-instance-through-an-email-logic-bug-fdbea7b23542"
                 }
              ],
              "Authors": ["Mostafa Mamdoh"],
              "Programs": ["GoDaddy"],
              "Bugs": ["Logic flaw", "Privilege escalation", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2022-01-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Breaking Parser Logic: Gain Access To NGINX Plus API — Read/Write Upstreams.",
                    "Link": "https://zoidsec.medium.com/breaking-parse-logic-gain-access-to-nginx-api-read-write-upstreams-1cb062aa44ca"
                 },
                 {
                  "Title": "Alternative link",
                  "Link": "https://cyberlix.io/breaking-parser-logic-gain-access-to-nginx-plus-api-read-write-upstreams/"
                 }
               ],
              "Authors": ["zoid (@z0idsec)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2022-01-05",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "thisclosed_#1 - Full Account Takeover of ANY user via Insecure Direct Object Reference (IDOR) on reset password functionality",
                  "Link": "https://blog.hckrt.com/blog/thisclosed_1/"
               }
            ],
            "Authors": ["Samuele Gugliotta (@indevi0us)"],
            "Programs": ["-"],
            "Bugs": ["IDOR", "Password reset", "Account takeover"],
            "Bounty": "-",
            "PublicationDate": "2022-01-04",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "SQL Injection - The File Upload Playground",
                    "Link": "https://shahjerry33.medium.com/sql-injection-the-file-upload-playground-6580b089d013"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2022-01-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook android webview vulnerability : Execute arbitrary javascript (xss) and load arbitrary website",
                    "Link": "https://servicenger.com/mobile/facebook-android-webview-vulnerability/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS", "Android"],
              "Bounty": "1,075",
              "PublicationDate": "2022-01-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "NPM might be executing malicious code in your CI without your knowledge",
                    "Link": "https://medium.com/cider-sec/npm-might-be-executing-malicious-code-in-your-ci-without-your-knowledge-e5e45bab2fed"
                 }
              ],
              "Authors": ["Rotem Bar (@rotembar)"],
              "Programs": ["GitHub"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2022-01-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "P5 to P1: Interesting Account Takeover",
                    "Link": "https://medium.com/@tushar.tilak.sharma/p5-to-p1-intresting-account-takeover-6e59b879494b"
                 }
              ],
              "Authors": ["Tushar Sharma (@tusharSharma_0)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Session expiration issue", "Password reset"],
              "Bounty": "1,000",
              "PublicationDate": "2022-01-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR leads to leak Private Details",
                    "Link": "https://infosecwriteups.com/idor-leads-to-leak-private-details-866563365490"
                 }
              ],
              "Authors": ["annonymous"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-01-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to bypass a Pin code Protection",
                    "Link": "https://xko2x.medium.com/how-i-was-able-to-bypass-a-pin-code-protection-8352295bb4fb"
                 }
              ],
              "Authors": ["Kerolos sameh (@xko2xx)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2022-01-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of YouTube’s Unfixable Ads Bypass",
                    "Link": "https://medium.com/@mrmax4o4/story-of-youtubes-unfixable-ads-bypass-b3bb7016c14e"
                 }
              ],
              "Authors": ["MrMax4o4"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-01-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Story Of How I Bypass SSO Login",
                    "Link": "https://systemweakness.com/the-story-of-how-i-bypass-sso-login-6b93370196cf"
                 }
              ],
              "Authors": ["zer0d"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2022-01-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "doorLock: Apple HomeKit Denial of Service",
                    "Link": "https://trevorspiniolas.com/doorlock/doorlock.html"
                 }
              ],
              "Authors": ["Trevor Spiniolas"],
              "Programs": ["Apple"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2022-01-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A tale of zero click account takeover",
                    "Link": "https://medium.com/pentesternepal/a-tale-of-zero-click-account-takeover-56b51fdbd7ae"
                 }
              ],
              "Authors": ["Veshraj Ghimire (@GhimireVeshraj)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2022-01-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing Business Logic of an Application to create backdoor in a form APP",
                    "Link": "https://snapsec.co/blog/Abusing-Business-logic-of-an-application-to-create-backdoor-in-APP/"
                 }
              ],
              "Authors": ["Snap Sec (@snap_sec)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2022-01-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One Click To Account Takeover",
                    "Link": "https://m7-arman.medium.com/one-click-to-account-takeover-1f78c6003eba"
                 }
              ],
              "Authors": ["M7.Arman (@ArmanSecurity)"],
              "Programs": ["-"],
              "Bugs": ["Mass assignment"],
              "Bounty": "-",
              "PublicationDate": "2022-01-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fixing the Unfixable: Story of a Google Cloud SSRF",
                    "Link": "https://bugs.xdavidhu.me/google/2021/12/31/fixing-the-unfixable-story-of-a-google-cloud-ssrf/"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["SSRF"],
              "Bounty": "4,133.70",
              "PublicationDate": "2021-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Hunting Journey of 2021",
                    "Link": "https://infosecwriteups.com/bug-hunting-journey-of-2021-1fa60b28d949"
                 }
              ],
              "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "Open redirect", "Token leak", "CSRF", "Logic flaw", "Information disclosure", "IDOR", "Account takeover"],
              "Bounty": "3,200",
              "PublicationDate": "2021-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first Google HOF",
                    "Link": "https://rv09.medium.com/my-first-google-hof-b66c54f6acfd"
                 }
              ],
              "Authors": ["RV Sharma"],
              "Programs": ["Google"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "1,337",
              "PublicationDate": "2021-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Here’s How I Could Read Anyone’s Apple ID Metrics Remotely.",
                    "Link": "https://faizanwrites.medium.com/heres-how-i-could-read-anyone-s-iphone-metrics-remotely-28459943b898"
                 }
              ],
              "Authors": ["Faizan Ahmad Wani"],
              "Programs": ["Apple"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Identity-Aware Proxy - Google Cloud Vulnerability",
                    "Link": "https://www.seblu.de/2021/12/iap-bypass.html"
                 }
              ],
              "Authors": ["SebLu"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization", "Token leak", "OAuth"],
              "Bounty": "5,000",
              "PublicationDate": "2021-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WhatsApp for Android Retains Deleted Contacts Locally",
                    "Link": "https://wwws.nightwatchcybersecurity.com/2021/12/30/whatsapp-for-android-retains-deleted-contacts-locally/"
                 }
              ],
              "Authors": ["Nightwatch Cybersecurity (@nightwatchcyber)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2021-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Am Able To Crash Anyone’s Mozilla Firefox Browser By Sending An Email",
                    "Link": "https://medium.com/@sam0-0/how-i-am-able-to-crash-anyones-mozilla-firefox-browser-by-sending-an-email-a12563cc8d79"
                 }
              ],
              "Authors": ["Sam"],
              "Programs": ["Mozilla"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Cloud Shell XSS",
                    "Link": "https://ndevtk.github.io/writeups/2021/12/30/cloud-shell-xss/"
                 }
              ],
              "Authors": ["NDevTK (@ndevtk)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2021-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[IDOR] add or remove the linked publications from Author Publisher settings — Facebook Bug Bounty",
                    "Link": "https://servicenger.com/mobile/idor-add-or-remove-the-linked-publications-from-author-publisher-settings-facebook-bug-bounty/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "863",
              "PublicationDate": "2021-12-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of a weird CSRF bug",
                    "Link": "https://infosecwriteups.com/story-of-a-weird-csrf-bug-bde1129c106e"
                 }
              ],
              "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-12-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Code Execution in Google Cloud Dataflow",
                    "Link": "https://mbrancato.github.io/2021/12/28/rce-dataflow.html"
                 }
              ],
              "Authors": ["Mike Brancato (@meatballninja)"],
              "Programs": ["Google"],
              "Bugs": ["RCE"],
              "Bounty": "3,333.70",
              "PublicationDate": "2021-12-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full account takeover vulnerability in Minecraft",
                    "Link": "https://amakki.me/full-account-takeover-vulnerability-in-minecraft-f56076c8287d"
                 }
              ],
              "Authors": ["Abdulrahman Makki (@AMakki1337)"],
              "Programs": ["Minecraft"],
              "Bugs": ["Account takeover"],
              "Bounty": "5,000",
              "PublicationDate": "2021-12-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bounty Evaluation GitHub = $15,000 US Dollars | Rate Limit",
                    "Link": "https://medium.com/@taniyatesting11/bounty-evaluation-github-15-000-us-dollars-rate-limit-d6c07d73c948"
                 }
              ],
              "Authors": ["Taniya Agarwal"],
              "Programs": ["GitHub"],
              "Bugs": ["Bruteforce", "Email verification bypass", "Account takeover"],
              "Bounty": "15,000",
              "PublicationDate": "2021-12-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Common Nginx Misconfiguration leads to Path Traversal",
                    "Link": "https://systemweakness.com/common-nginx-misconfiguration-leads-to-path-traversal-d58701e997bc"
                 }
              ],
              "Authors": ["MikeChan"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2021-12-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bi/ug Bounties and HyperV RCE Research",
                    "Link": "https://rezer0dai.github.io/biug-bounties/"
                 }
              ],
              "Authors": ["Peter Hlavaty (@rezer0dai)"],
              "Programs": ["Microsoft Hyper-V"],
              "Bugs": ["RCE"],
              "Bounty": "100,000",
              "PublicationDate": "2021-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS via file upload",
                    "Link": "https://sharmajijvs.medium.com/xss-via-file-upload-a2bcc1e5d7f7"
                 }
              ],
              "Authors": ["Jay Sharma"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2021-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Bypassed Netflix Profile Lock?",
                    "Link": "https://infosecwriteups.com/how-i-bypassed-netflix-profile-lock-43901be1307c"
                 }
              ],
              "Authors": ["Krishnadev P Melevila (@Krishnadev_P_M)"],
              "Programs": ["Netflix"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Turning bad SSRF to good SSRF: Websphere Portal",
                    "Link": "https://blog.assetnote.io/2021/12/26/chained-ssrf-websphere/"
                 }
              ],
              "Authors": ["Shubham Shah (@infosec_au)"],
              "Programs": ["HCL Technologies"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-12-26",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "XSS through image proxy using SVG image",
                  "Link": "https://3bodymo.medium.com/xss-through-image-proxy-using-svg-image-49cdf955cf4f"
               }
            ],
            "Authors": ["Abdullah Mohamed (@3bodymo_)"],
            "Programs": ["-"],
            "Bugs": ["XSS"],
            "Bounty": "-",
            "PublicationDate": "2021-12-25",
            "AddedDate": "2023-06-25"
         },
           {
              "Links": [
                 {
                    "Title": "How I Saved Christmas for Google 🎄",
                    "Link": "https://web.archive.org/web/20220325063636/https://bugs.0xdroopy.live/bugs/how-i-saved-the-christmas-for-google/"
                 }
              ],
              "Authors": ["0xdroopy (@NikhilK50866227)"],
              "Programs": ["Google (Waze)"],
              "Bugs": ["Dependency confusion"],
              "Bounty": "-",
              "PublicationDate": "2021-12-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Massive Users Account Takeovers(Chaining Vulnerabilities to IDOR)😲",
                    "Link": "https://infosecwriteups.com/massive-users-account-takeovers-chaining-vulnerabilities-to-idor-ea4e1b6407d2"
                 }
              ],
              "Authors": ["Anurag__Verma"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "IDOR", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2021-12-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Information Disclosure leads to sensitive credential($$$)",
                    "Link": "https://medium.com/@mamunwhh/information-disclosure-leads-to-sensitive-credential-35e779f6f4db"
                 }
              ],
              "Authors": ["khan mamun (@mamunwhh)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "150",
              "PublicationDate": "2021-12-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found (and fixed) a vulnerability in Python",
                    "Link": "https://www.tldr.engineering/how-i-found-and-fixed-a-vulnerability-in-python/"
                 }
              ],
              "Authors": ["Adam Goldschmidt (@AdamGolds)"],
              "Programs": ["Python"],
              "Bugs": ["Web cache poisoning"],
              "Bounty": "-",
              "PublicationDate": "2021-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cache Poisoning at Scale",
                    "Link": "https://youst.in/posts/cache-poisoning-at-scale/"
                 }
              ],
              "Authors": ["Youstin (@iustinBB)"],
              "Programs": ["GitHub", "GitLab", "HackerOne", "Shopify", "Cloudflare"],
              "Bugs": ["Web cache poisoning"],
              "Bounty": "40,000",
              "PublicationDate": "2021-12-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "MS Teams: 1 feature, 4 vulnerabilities",
                    "Link": "https://positive.security/blog/ms-teams-1-feature-4-vulns"
                 }
              ],
              "Authors": ["Fabian Bräunlein"],
              "Programs": ["Microsoft"],
              "Bugs": ["SSRF", "Information disclosure", "DoS", "Spoofing"],
              "Bounty": "-",
              "PublicationDate": "2021-12-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to bypass WAF and find the origin IP and a few sensitive files",
                    "Link": "https://janmuhammadzaidi.medium.com/how-i-was-able-to-bypass-waf-and-find-the-origin-ip-and-a-few-sensitive-files-fc445180adb7"
                 }
              ],
              "Authors": ["Jan Muhammad Zaidi (@hasanakajan)"],
              "Programs": ["-"],
              "Bugs": ["WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-12-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sandbox escape + privilege escalation in StorePrivilegedTaskService",
                    "Link": "https://sector7.computest.nl/post/2021-12-storeprivilegedtaskservice/"
                 }
              ],
              "Authors": ["Sector 7 (@sector7_nl)"],
              "Programs": ["Apple"],
              "Bugs": ["Local Privilege Escalation", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2021-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "NotLegit: Azure App Service vulnerability exposed hundreds of source code repositories",
                    "Link": "https://www.wiz.io/blog/azure-app-service-source-code-leak"
                 }
              ],
              "Authors": ["Wiz (@wiz_io)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Security misconfiguration", ".git folder disclosure"],
              "Bounty": "7,500",
              "PublicationDate": "2021-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found (P2) Broken Authentication with Zero Skill of Hacking",
                    "Link": "https://medium.com/@yoshimlutfi/how-i-found-p2-broken-authentication-with-zero-skill-of-hacking-c40b5643fe4a"
                 }
              ],
              "Authors": ["yoshi m lutfi (@yoshiahmadlutfi)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSD Advisory – Rocket.Chat Client-side Remote Code Execution",
                    "Link": "https://ssd-disclosure.com/ssd-advisory-rocket-chat-client-side-remote-code-execution/"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["Rocket.Chat"],
              "Bugs": ["RCE", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2021-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned $$$ by bypassing 2FA",
                    "Link": "https://medium.com/@mohamedtaha_42562/how-i-earned-by-bypassing-2fa-b5487942a86d"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://motaha22.github.io/bugbounty/2fa-bounty/"
                 }
              ],
              "Authors": ["Mohamed Taha (@Mohamed12742780)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass", "Forced browsing"],
              "Bounty": "-",
              "PublicationDate": "2021-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bring Your Own SSRF – The Gateway Actuator",
                    "Link": "https://web.archive.org/web/20221128052252/https://wya.pl/2021/12/20/bring-your-own-ssrf-the-gateway-actuator/"
                 }
              ],
              "Authors": ["Wyatt Dahlenburg (@wdahlenb)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-12-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blackbox Cookie Testing — How I Cracked The Admin’s Cookie",
                    "Link": "https://web.archive.org/web/20220128200941/https://saeeds.medium.com/blackbox-cookie-testing-how-i-cracked-the-admins-cookie-c817dd4281c8"
                 }
              ],
              "Authors": ["Saeed Balquizi"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-12-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit",
                    "Link": "https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-codes-remote-wsl-for-fun-and-negative-profit/"
                 }
              ],
              "Authors": ["Parsia Hackerman (@cryptogangsta)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-12-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to reveal page admin of almost any page on Facebook",
                    "Link": "https://medium.com/pentesternepal/how-i-was-able-to-reveal-page-admin-of-almost-any-page-on-facebook-5a8d68253e0c"
                 }
              ],
              "Authors": ["Sudip Shah"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "4,500",
              "PublicationDate": "2021-12-20",
              "AddedDate": "2022-09-15"
           },
      {
              "Links": [
                 {
                    "Title": "Stored XSS by bypassing signature",
                    "Link": "https://amakki.me/stored-xss-by-bypassing-signature-61ebd83ece6"
                 }
              ],
              "Authors": ["Abdulrahman Makki (@AMakki1337)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Unrestricted file upload"],
              "Bounty": "3,500",
              "PublicationDate": "2021-12-20",
              "AddedDate": "2022-09-15"
      },
      {
         "Links": [
            {
               "Title": "Yes, fun browser extensions can have vulnerabilities too!",
               "Link": "https://palant.info/2021/12/20/yes-fun-browser-extensions-can-have-vulnerabilities-too/"
            }
         ],
         "Authors": ["Wladimir Palant (@WPalant)"],
         "Programs": ["Meow"],
         "Bugs": ["XSS", "Browser extension hacking", "postMessage"],
         "Bounty": "-",
         "PublicationDate": "2021-12-20",
         "AddedDate": "2022-12-09"
      },
      {
              "Links": [
                 {
                    "Title": "Flickr Account Takeover",
                    "Link": "https://security.lauritz-holtmann.de/advisories/flickr-account-takeover/"
                 }
              ],
              "Authors": ["Lauritz Holtmann (@_lauritz_)"],
              "Programs": ["Flickr"],
              "Bugs": ["Account takeover", "Broken authentication"],
              "Bounty": "7,550",
              "PublicationDate": "2021-12-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacked Google-Meet…??!",
                    "Link": "https://infosecwriteups.com/hacked-google-meet-40f364bb8368"
                 }
              ],
              "Authors": ["7𝖍3𝖍4𝖈kv157 (@7h3h4ckv157)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-12-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploitation Of CVE-2021-21220 – From Incorrect JIT Behavior To RCE",
                    "Link": "https://www.zerodayinitiative.com/blog/2021/12/15/exploitation-of-cve-2021-21220-from-incorrect-jit-behavior-to-rce"
                 }
              ],
              "Authors": ["Bruno Keith (@bkth_)", "Niklas Baumstark(@_niklasb)"],
              "Programs": ["Google", "Microsoft"],
              "Bugs": ["Browser hacking", "Memory corruption", "RCE"],
              "Bounty": "100,000",
              "PublicationDate": "2021-12-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Access Control",
                    "Link": "https://mearegtu.medium.com/broken-access-control-cc6cfd793b15"
                 }
              ],
              "Authors": ["Meareg"],
              "Programs": ["Microsoft"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-12-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GHSL-2021-1053: Path traversal in Grafana REST API - CVE-2021-43813, CVE-2021-43815",
                    "Link": "https://securitylab.github.com/advisories/GHSL-2021-1053_Grafana/"
                 }
              ],
              "Authors": ["Alvaro Muñoz (@pwntester)"],
              "Programs": ["Grafana Labs"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2021-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Gumtree – leaking your data and not really listening",
                    "Link": "https://www.pentestpartners.com/security-blog/gumtree-leaking-your-data-and-not-really-listening/"
                 }
              ],
              "Authors": ["Alan Monie (@AlanMonie)"],
              "Programs": ["Gumtree"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found the Authentication Bypass bug and Earn $$$$",
                    "Link": "https://medium.com/@thedarkwayg/bypass-authentication-1bfab09332fe"
                 }
              ],
              "Authors": ["Thedarkwayg (@shadow_CLAY)"],
              "Programs": ["-"],
              "Bugs": ["Session expiration issue"],
              "Bounty": "1,000",
              "PublicationDate": "2021-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing the macOS Gatekeeper",
                    "Link": "https://breakpoint.sh/posts/bypassing-the-macos-gatekeeper"
                 }
              ],
              "Authors": ["Ron Masas (@RonMasas)"],
              "Programs": ["Apple"],
              "Bugs": ["Local Privilege Escalation", "Gatekeeper bypass", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2021-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found XSS vulnerability in Amazon in 5 minutes using shodan",
                    "Link": "https://medium.com/@mohamedtaha_42562/how-i-found-xss-vulnerability-in-amazon-in-5-minutes-using-shodan-50b583655297"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://motaha22.github.io/bugbounty/bounty/"
                 }
              ],
              "Authors": ["Mohamed Taha (@Mohamed12742780)"],
              "Programs": ["Amazon"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Bypassed Incapsula WAF By Imperva",
                    "Link": "https://medium.com/@daudmalik06/how-i-bypassed-incapsula-waf-db0498b3a021"
                 }
              ],
              "Authors": ["Dawood Ikhlaq"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-12-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zero Click To Account Takeover",
                    "Link": "https://m7-arman.medium.com/zero-click-to-account-takeover-d764e12bee4b"
                 }
              ],
              "Authors": ["M7.Arman (@ArmanSecurity)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2021-12-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SVG based Stored XSS",
                    "Link": "https://prashantbhatkal2000.medium.com/svg-based-stored-xss-ee6e9b240dee"
                 }
              ],
              "Authors": ["xaonan44"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-12-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A story about a not-so-direct SSRF",
                    "Link": "https://infosecwriteups.com/a-story-about-a-not-so-direct-ssrf-b2b98e128af0"
                 }
              ],
              "Authors": ["Preetham Bomma (@cyber01_)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-12-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open Redirection - QR Code Magic",
                    "Link": "https://shahjerry33.medium.com/open-redirection-qr-code-magic-18ace1a0170f"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2021-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Deserialization Bug in Microsoft's RDP Client through Smart Card Extension (CVE-2021-38666)",
                    "Link": "https://thalium.github.io/blog/posts/deserialization-bug-through-rdp-smart-card-extension/"
                 }
              ],
              "Authors": ["Valentino Ricotta"],
              "Programs": ["Microsoft"],
              "Bugs": ["Memory corruption"],
              "Bounty": "5,000",
              "PublicationDate": "2021-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote ASLR Leak in Microsoft's RDP Client through Printer Cache Registry (CVE-2021-38665)",
                    "Link": "https://thalium.github.io/blog/posts/leaking-aslr-through-rdp-printer-cache-registry/"
                 }
              ],
              "Authors": ["Valentino Ricotta"],
              "Programs": ["Microsoft"],
              "Bugs": ["Memory corruption"],
              "Bounty": "1,000",
              "PublicationDate": "2021-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ProtoBuffer ReUtilization “New Way to Security Test GoogleCaptcha”",
                    "Link": "https://medium.com/@Cho0k/protobuffer-reutilization-new-way-to-security-test-googlecaptcha-b3e0fc6cf7c4"
                 }
              ],
              "Authors": ["ChooK"],
              "Programs": ["Rapid7"],
              "Bugs": ["Captcha bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Don’t Reply: A Clever Phishing Method In Apple’s Mail App",
                    "Link": "https://jonbottarini.com/2021/12/09/dont-reply-a-clever-phishing-method-in-apples-mail-app/"
                 }
              ],
              "Authors": ["Jon Bottarini (@jon_bottarini)"],
              "Programs": ["Apple"],
              "Bugs": ["Phishing"],
              "Bounty": "5,000",
              "PublicationDate": "2021-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A phishing document signed by Microsoft – part 1",
                    "Link": "https://outflank.nl/blog/2021/12/09/a-phishing-document-signed-by-microsoft/"
                 }
              ],
              "Authors": ["Pieter Ceelen (@ptrpieter)", "Dima van de Wouw"],
              "Programs": ["Microsoft"],
              "Bugs": ["Phishing", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "File Upload to RCE",
                    "Link": "https://ahmed8magdy.medium.com/file-upload-to-rce-538bb4128062"
                 }
              ],
              "Authors": ["Ahmed Magdy (@8Ahmed88Magdy8)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2021-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting S3 bucket with path folder to Access PII info of A BANK",
                    "Link": "https://notifybugme.medium.com/exploiting-s3-bucket-with-path-folder-to-access-pii-info-of-a-bank-91d8563cb45"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Finding AWS S3 Bucket to Sensitive Data Exposure",
                    "Link": "https://www.r29k.com/articles/bb/s3-sensitive-data-exposure"
                 }
              ],
              "Authors": ["Demon (@R29k_)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2021-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover via Stored XSS",
                    "Link": "https://www.r29k.com/articles/bb/priv-esc-via-stored-xss"
                 }
              ],
              "Authors": ["Demon (@R29k_)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2021-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-43798 - Path Traversal Vulnerability In Grafana",
                    "Link": "https://j0vsec.com/post/cve-2021-43798/"
                 },
                 {
                    "Title": "How I found the Grafana zero-day Path Traversal exploit that gave me access to your logs",
                    "Link": "https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/"
                 }
              ],
              "Authors": ["Jordy Versmissen / J0VSEC (@j0v0x0)"],
              "Programs": ["Grafana Labs"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2021-12-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Another Admin panel",
                    "Link": "https://rizwansiddiqu1.medium.com/another-admin-panel-e0489dc76678"
                 }
              ],
              "Authors": ["Rizwan_siddiqui (@Rizwan_SiDdiqu1)"],
              "Programs": ["-"],
              "Bugs": ["HTTP response manipulation", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-12-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Vancouver leaking website credentials via overlooked DS_STORE file",
                    "Link": "https://web.archive.org/web/20220823110821/https://cybernews.com/security/microsoft-vancouver-leaking-website-credentials-via-overlooked-ds-store-file/"
                 }
              ],
              "Authors": ["CyberNews Team"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-12-08",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Privilege Escalation in Microsoft Teams",
                  "Link": "https://blog.agilehunt.com/blogs/security/privilege-escalation-in-microsoft-teams-2021"
               }
            ],
            "Authors": ["Vikas Anil Sharma (@vikzsharma)"],
            "Programs": ["Microsoft"],
            "Bugs": ["Privilege escalation", "Broken Access Control"],
            "Bounty": "-",
            "PublicationDate": "2021-12-07",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Windows 10 RCE: The exploit is in the link",
                    "Link": "https://positive.security/blog/ms-officecmd-rce"
                 }
              ],
              "Authors": ["Fabian Bräunlein", "Lukas Euler"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "5,000",
              "PublicationDate": "2021-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to change Reddit acquired Dubsmash’s music library sound tracks.",
                    "Link": "https://web.archive.org/web/20240304202752/https://appsecure.security/how-i-was-able-to-change-reddit-acquired-dubsmashs-music-library-sound-tracks/"
                 }
              ],
              "Authors": ["Sandeep Hodkasia (@sandeephodkasia)"],
              "Programs": ["Reddit"],
              "Bugs": ["IDOR"],
              "Bounty": "3,000",
              "PublicationDate": "2021-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking into Admin Panel of U.S Federal government system C.A.R.S — without credentials.",
                    "Link": "https://medium.com/@7azimo/hacking-into-admin-panel-of-u-s-federal-government-system-c-a-r-s-without-credentials-9117b865ba58"
                 }
              ],
              "Authors": ["Hazem Brini (@ImJungsuu)"],
              "Programs": ["U.S. General Services Administration"],
              "Bugs": ["Client-side enforcement of server-side security", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Azure Portal – CSV Injection",
                    "Link": "https://www.y-security.de/news-en/microsoft-azure-portal-csv-injection/index.html"
                 }
              ],
              "Authors": ["Christian Becker (@0xchrisb)"],
              "Programs": ["Microsoft"],
              "Bugs": ["CSV injection"],
              "Bounty": "-",
              "PublicationDate": "2021-12-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF vulnerability in AppSheet - Google VRP",
                    "Link": "https://nechudav.blogspot.com/2021/12/ssrf-vulnerability-in-appsheet-google.html"
                 }
              ],
              "Authors": ["David Nechuta (@david_nechuta)"],
              "Programs": ["Google"],
              "Bugs": ["SSRF"],
              "Bounty": "6,267.4",
              "PublicationDate": "2021-12-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accidental IDOR in eLearnSecurity to Knowing Your Address and Cert You Bought.",
                    "Link": "https://www.p1boom.com/2021/12/accidental-idor-in-elearnsecurity-to.html"
                 }
              ],
              "Authors": ["Anugrah SR (@cyph3r_asr)"],
              "Programs": ["INE"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-12-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This is how i was able to See and Delete your Private Facebook Portal photos",
                    "Link": "https://pathleax.medium.com/this-is-how-i-was-able-to-see-and-delete-your-private-facebook-portal-photos-a93ed22f875b"
                 }
              ],
              "Authors": ["Abhishek Pathak (@pathleax)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-12-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I managed to hack User accounts of a billion-dollar sport platform",
                    "Link": "https://medium.com/@vishnu0002/how-i-managed-to-hack-into-a-billion-dollar-sport-platform-7cc667081229"
                 }
              ],
              "Authors": ["Vishnuraj"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass", "Bruteforce", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2021-12-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My mindset while hunting on Yandex and my SSRF",
                    "Link": "https://infosecwriteups.com/how-i-hacked-yandex-with-ssrf-vulnerability-e19af20ed4d"
                 }
              ],
              "Authors": ["Momen Ali (Cyber Guy) (@theCyberGuy0)"],
              "Programs": ["Yandex"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-12-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I accessed the Sensitive document which I had already deleted",
                    "Link": "https://pawanchhabria.medium.com/how-i-accessed-the-sensitive-document-which-i-had-already-deleted-adbc1e6fbb25"
                 }
              ],
              "Authors": ["Pawan Chhabria (@heybenchmarkkk)"],
              "Programs": ["-"],
              "Bugs": ["Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2021-12-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up – XSS Stored In files.slack.com Via XML/SVG File (iOS) – $1,000 USD",
                    "Link": "https://omespino.com/write-up-xss-stored-in-files-slack-com-via-xml-svg-file-ios-1000-usd/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Slack"],
              "Bugs": ["XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2021-12-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose Ad Accounts linked with Instagram Accounts",
                    "Link": "https://www.yesnaveen.com/Instagram-ad-account-disclosure"
                 }
              ],
              "Authors": ["Naveen (@NaveenHax)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw", "GraphQL"],
              "Bounty": "1,500",
              "PublicationDate": "2021-12-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Box’s Time-based One-Time Password MFA",
                    "Link": "https://www.varonis.com/blog/box-mfa-bypass-totp/"
                 }
              ],
              "Authors": ["Tal Peleg"],
              "Programs": ["Box"],
              "Bugs": ["OTP bypass", "2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-12-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AWS SageMaker Jupyter Notebook Instance Takeover",
                    "Link": "https://blog.lightspin.io/aws-sagemaker-notebook-takeover-vulnerability"
                 }
              ],
              "Authors": ["Gafnit Amiga (@gafnitav)"],
              "Programs": ["AWS"],
              "Bugs": ["Self-XSS", "CSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-12-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploring Container Security: A Storage Vulnerability Deep Dive",
                    "Link": "https://security.googleblog.com/2021/12/exploring-container-security-storage.html"
                 }
              ],
              "Authors": ["Fabricio Voznika", "Mark Wolters"],
              "Programs": ["Kubernetes"],
              "Bugs": ["Race condition", "Kubernetes"],
              "Bounty": "-",
              "PublicationDate": "2021-12-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Easy SQLi in Amazon subsidiary using Sqlmap",
                    "Link": "https://hector0x.medium.com/easy-sqli-in-amazon-subsidiary-using-sqlmap-ff469013671b"
                 }
              ],
              "Authors": ["Mostafa Mamdoh"],
              "Programs": ["Amazon"],
              "Bugs": ["SQL injection"],
              "Bounty": "1,500",
              "PublicationDate": "2021-12-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This shouldn't have happened: A vulnerability postmortem",
                    "Link": "https://googleprojectzero.blogspot.com/2021/12/this-shouldnt-have-happened.html"
                 }
              ],
              "Authors": ["Tavis Ormandy (@taviso)"],
              "Programs": ["Mozilla"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2021-12-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to bypass Cloudflare WAF for SQLi payload",
                    "Link": "https://cyberguy0xd1.medium.com/how-i-was-able-to-bypass-cloudflare-waf-for-sqli-payload-b9e7a4260026"
                 }
              ],
              "Authors": ["Momen Ali (Cyber Guy) (@theCyberGuy0)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-12-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "P1 _Bug in Apple that phase “old is Gold",
                    "Link": "https://web.archive.org/web/20211202081008/https://medium.com/@saurabhsankhwar3/p1-bug-in-apple-that-phase-old-is-gold-6eb99da5bbca"
                 }
              ],
              "Authors": ["Saurabh Sankhwar (@mr_encryption)"],
              "Programs": ["Apple"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-12-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Teams – CSV Injection",
                    "Link": "https://www.y-security.de/news-en/microsoft-teams-csv-injection/index.html"
                 }
              ],
              "Authors": ["Christian Becker (@0xchrisb)"],
              "Programs": ["Microsoft"],
              "Bugs": ["CSV injection"],
              "Bounty": "-",
              "PublicationDate": "2021-12-01",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Exploiting Vulnerabilities in a TLD Registrar to Takeover Tether, Google, and Amazon",
                  "Link": "https://palisade.consulting/blog/tld-hacking"
               }
            ],
            "Authors": ["Sam Curry (@samwcyo)"],
            "Programs": ["-"],
            "Bugs": ["TLD hacking"],
            "Bounty": "-",
            "PublicationDate": "2021-11-30",
            "AddedDate": "2024-09-18"
         },
           {
            "Links": [
               {
                  "Title": "HTTP Header Injection In Citrix ADC And Citrix Gateway (CVE-2020-8300, CVE-2021-22927)",
                  "Link": "https://certitude.consulting/blog/en/citrix-header-injection-2/"
               }
            ],
            "Authors": ["Wolfgang Ettlinger"],
            "Programs": ["Citrix Systems"],
            "Bugs": ["Host header injection", "XSS"],
            "Bounty": "-",
            "PublicationDate": "2021-11-30",
            "AddedDate": "2022-12-09"
         },
           {
              "Links": [
                 {
                    "Title": "VMware vCenter earlier versions (7.0.2.00100) has unauthorized arbitrary file read + ssrf + xss vulnerability",
                    "Link": "https://github.com/l0ggg/VMware_vCenter"
                 }
              ],
              "Authors": ["Khoa Dinh (@_l0gg)"],
              "Programs": ["VMware"],
              "Bugs": ["LFI", "SSRF", "XSS", "Arbitrary file read"],
              "Bounty": "-",
              "PublicationDate": "2021-11-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My write-up in hacking IBM’s administration panel and getting SQLi on it",
                    "Link": "https://cyberguy0xd1.medium.com/my-write-up-in-hacking-ibms-administration-panel-and-getting-sqli-on-it-51404c7bee27"
                 }
              ],
              "Authors": ["Momen Ali (Cyber Guy) (@theCyberGuy0)"],
              "Programs": ["IBM"],
              "Bugs": ["SQL injection", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2021-11-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "NodeBB 1.18.4 - Remote Code Execution With One Shot",
                    "Link": "https://blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot"
                 }
              ],
              "Authors": ["Sonar (@SonarSource)"],
              "Programs": ["NodeBB"],
              "Bugs": ["RCE", "XSS", "Authentication bypass", "Arbitrary file read"],
              "Bounty": "1,536",
              "PublicationDate": "2021-11-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This Microsoft Windows RCE Vulnerability Gives an Attacker Complete Control",
                    "Link": "https://www.synack.com/blog/this-microsoft-windows-rce-vulnerability-gives-an-attacker-complete-control/"
                 }
              ],
              "Authors": ["Malcolm Stagg (@malcolmst)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2021-11-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Play The Opera Please",
                    "Link": "https://www.inputzero.io/2021/04/play-the-opera-please.html"
                 }
              ],
              "Authors": ["Dhiraj (@RandomDhiraj)"],
              "Programs": ["Opera"],
              "Bugs": ["Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2021-11-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Price Manipulation Bypass Using Integer Overflow Method",
                    "Link": "https://marxchryz.medium.com/price-manipulation-bypass-using-integer-overflow-method-36ff23ebe91d"
                 }
              ],
              "Authors": ["Marx Chryz"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2021-11-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[socket.io] Cross-Site Websockets Hijacking",
                    "Link": "https://sh1yo.art/post/websocket_hijacking/"
                 }
              ],
              "Authors": ["sh1yo (@sh1yo_)"],
              "Programs": ["Node.js third-party modules"],
              "Bugs": ["Cross-Site Websocket Hijacking (CSWH)"],
              "Bounty": "-",
              "PublicationDate": "2021-11-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SEC-596",
                    "Link": "https://sh1yo.art/post/sec-596/"
                 }
              ],
              "Authors": ["sh1yo (@sh1yo_)"],
              "Programs": ["cPanel"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-11-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got my first bounty on financial sector gateway site by using Previous GraphQL vulnerabilities.",
                    "Link": "https://medium.com/@thenighthawk0/how-i-got-my-first-bounty-on-financial-sector-gateway-site-by-using-previous-graphql-462cca7389ca"
                 }
              ],
              "Authors": ["Night Hawk"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "GraphQL"],
              "Bounty": "2,500",
              "PublicationDate": "2021-11-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSD Advisory – Chrome Ad Heavy Bypass (via history.back())",
                    "Link": "https://ssd-disclosure.com/ssd-advisory-chrome-ad-heavy-bypass-via-history-back/"
                 }
              ],
              "Authors": ["Alesandro Ortiz (@AlesandroOrtizR)"],
              "Programs": ["Google (Chrome)"],
              "Bugs": ["Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2021-11-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WordPress Plugin Confusion: How an update can get you pwned",
                    "Link": "https://vavkamil.cz/2021/11/25/wordpress-plugin-confusion-update-can-get-you-pwned/"
                 },
                 {
                    "Title": "Wordpress Plugin Update Confusion - The full guide how to scan and mitigate the next big Supply Chain Attack",
                    "Link": "https://web.archive.org/web/20221001151628/https://galnagli.com/Wordpress_Plugin_Update_Confusion/"
                 }
              ],
              "Authors": ["Kamil Vavra (@vavkamil)", "Gal Nagli (@naglinagli)"],
              "Programs": ["-"],
              "Bugs": ["Supply chain attack", "WordPress plugin confusion", "WordPress theme confusion"],
              "Bounty": "-",
              "PublicationDate": "2021-11-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RocketChat - Monitor User Messages",
                    "Link": "https://securifyinc.com/disclosures/rocketchat-monitor-messages"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Rocket.Chat"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-11-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found My First XSS Bug",
                    "Link": "https://medium.com/@thedarkwayg/how-i-found-my-first-xss-bug-96fb8e85a24c"
                 }
              ],
              "Authors": ["Thedarkwayg (@shadow_CLAY)"],
              "Programs": ["Atlassian"],
              "Bugs": ["XSS"],
              "Bounty": "600",
              "PublicationDate": "2021-11-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated Sensitive Information Disclosure at [REDACTED]",
                    "Link": "https://wahaz.medium.com/unauthenticated-sensitive-information-disclosure-at-redacted-2702224098c"
                 }
              ],
              "Authors": ["Rizaldi Wahaz (@wah_haz)"],
              "Programs": ["-"],
              "Bugs": ["Old components with known vulnerabilities", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-11-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Vulnerabilities In Concrete CMS – Part2 (PrivEsc/SSRF/etc)",
                    "Link": "https://fortbridge.co.uk/research/multiple-vulnerabilities-in-concrete-cms-part2/"
                 }
              ],
              "Authors": ["FORTBRIDGE (@FORTBRIDGE1)"],
              "Programs": ["Concrete CMS"],
              "Bugs": ["Privilege escalation", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-11-25",
              "AddedDate": "2022-09-26"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover in $Million Company?",
                    "Link": "https://web.archive.org/web/20220119155429/https://0xgodson.medium.com/account-takeover-in-million-company-report-rejected-whats-wrong-60041f1815fb"
                 }
              ],
              "Authors": ["0xGodson (@0xGodson_)"],
              "Programs": ["Fastmail"],
              "Bugs": ["Account takeover", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2021-11-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ModSecurity DoS Vulnerability in JSON Parsing (CVE-2021-42717)",
                    "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-dos-vulnerability-in-json-parsing-cve-2021-42717/"
                 }
              ],
              "Authors": ["theMiddle (@AndreaTheMiddle)"],
              "Programs": ["ModSecurity"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-11-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding XSS on .apple.com and building a proof of concept to leak your PII information",
                    "Link": "https://zseano.medium.com/finding-xss-on-apple-com-and-building-a-proof-of-concept-to-leak-your-pii-information-d7bc93cff2df"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://blog.bugbountyhunter.com/xss-on-apple/"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["Apple"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-11-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Moodle Blind SQL injection via MNet authentication",
                    "Link": "https://r0.haxors.org/posts?id=26"
                 }
              ],
              "Authors": ["rekter0 (@rekter0)"],
              "Programs": ["Moodle"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-11-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A business logic error bug worth 600$",
                    "Link": "https://itsdeepceh.medium.com/a-business-logic-error-bug-worth-600-a0050720bfee"
                 }
              ],
              "Authors": ["Deep Patidar (@itsdeepceh)"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering"],
              "Bounty": "600",
              "PublicationDate": "2021-11-23",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "From Intigriti challenge to a Vue.js script gadget",
                  "Link": "https://blog.xss.am/2021/11/vuejs-script-gadget-intigriti/"
               }
            ],
            "Authors": ["Davit (@davwwwx)"],
            "Programs": ["-"],
            "Bugs": ["XSS", "CSP bypass"],
            "Bounty": "-",
            "PublicationDate": "2021-11-22",
            "AddedDate": "2024-07-08"
         },
           {
              "Links": [
                 {
                    "Title": "GoSecure Investigates Abusing Windows Server Update Services (WSUS) to Enable NTLM Relaying Attacks",
                    "Link": "https://www.gosecure.net/blog/2021/11/22/gosecure-investigates-abusing-windows-server-update-services-wsus-to-enable-ntlm-relaying-attacks/"
                 }
              ],
              "Authors": ["Romain Carnus", "Maxime Nadeau", "Julien Pineault", "Mathieu Novis"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-11-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[BugBounty] XSS with Markdown — Exploit & Fix on OpenSource",
                    "Link": "https://lethanhphuc-pk.medium.com/bugbounty-xss-with-markdown-exploit-fix-on-opensource-1baecebe9645"
                 }
              ],
              "Authors": ["Lê Thành Phúc"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-11-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Peeping through a Web-Socket",
                    "Link": "https://cirius.medium.com/peeping-through-a-web-socket-936ed55a2c31"
                 }
              ],
              "Authors": ["Aditya Verma (@0cirius0)"],
              "Programs": ["-"],
              "Bugs": ["Cross-Site Websocket Hijacking (CSWH)"],
              "Bounty": "-",
              "PublicationDate": "2021-11-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open Redirect Vulnerability On Zapier: An Accidental Find",
                    "Link": "https://monish-basaniwal.medium.com/open-redirect-vulnerability-on-zapier-an-accidental-find-4cbbf029956c"
                 }
              ],
              "Authors": ["Monish Basaniwal"],
              "Programs": ["Zapier"],
              "Bugs": ["Open redirect"],
              "Bounty": "100",
              "PublicationDate": "2021-11-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Apple Security Report System",
                    "Link": "https://hackrzvijay.medium.com/hacking-apple-security-report-system-db84850002fb"
                 }
              ],
              "Authors": ["HackrzVijay (@hackrzvijay)"],
              "Programs": ["Apple"],
              "Bugs": ["Logic flaw", "Social engineering"],
              "Bounty": "-",
              "PublicationDate": "2021-11-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting OAuth: Journey to Account Takeover",
                    "Link": "https://blog.dixitaditya.com/2021/11/19/account-takeover-chain.html"
                 }
              ],
              "Authors": ["Aditya Dixit (@zombie007o)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "OAuth", "XSS", "Weak CSP", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud",
                    "Link": "https://krevetk0.medium.com/how-i-accidentally-hacked-many-companies-using-n-a-vulnerability-in-atlassian-cloud-d4ff8e7dbef1"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["Atlassian"],
              "Bugs": ["Information disclosure", "Broken authentication"],
              "Bounty": "15,000",
              "PublicationDate": "2021-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Story of an Epic Blind Remote Code Execution(RCE)",
                    "Link": "https://www.p1boom.com/2021/11/a-story-of-epic-blind-remote-code.html"
                 }
              ],
              "Authors": ["Akash Solanki (@MAALP1225)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2021-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A common defect in java system-Memory DoS (include CVE-2021-2344, CVE-2021-2371, CVE-2021-2376, CVE-2021-2378)",
                    "Link": "https://threedr3am.github.io/2021/11/18/一种普遍存在于java系统的缺陷-Memory%20DoS/"
                 }
              ],
              "Authors": ["threedr3am (@threedr3am1)"],
              "Programs": ["Oracle"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "URL whitelist bypass in https://cxl-services.appspot.com",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0008"
                 },
                 {
                    "Title": "Reacting to myself finding an SSRF vulnerability in Google Cloud",
                    "Link": "https://www.youtube.com/watch?v=UyemBjyQ4qA"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["Privilege escalation", "URL validation bypass", "SSRF"],
              "Bounty": "10,401.1",
              "PublicationDate": "2021-11-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-42306 CredManifest: App Registration Certificates Stored in Azure Active Directory",
                    "Link": "https://www.netspi.com/blog/technical/cloud-penetration-testing/azure-cloud-vulnerability-credmanifest/"
                 }
              ],
              "Authors": ["Karl Fosaaen (@kfosaaen)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-11-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up – Apple N/A: PII Information, Full Contact List, Main Phone No. And Main Icloud Email Extracted; Bug Patched: Arbitrary Local File Read Via Zip File And Symlinks On Ios Files App.",
                    "Link": "https://omespino.com/write-up-apple-bug-bounty-n-a-arbitrary-local-file-read-via-zip-file-and-symlinks-usd/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Apple"],
              "Bugs": ["Arbitrary file read"],
              "Bounty": "-",
              "PublicationDate": "2021-11-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The tale of CVE-2021–34479 (VSCode XSS)",
                    "Link": "https://medium.com/techiepedia/the-tale-of-cve-2021-34479-vscode-xss-b336ba6cf3d6"
                 }
              ],
              "Authors": ["Daniel Santos (@bananabr)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS", "CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-11-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Keybase App Vulnerability: Incomplete Cleanup of Messages In Keybase for Android/iOS, CVE-2021-34421",
                    "Link": "https://www.oliviaohara.com/keybase"
                 }
              ],
              "Authors": ["Olivia O’Hara (@oliviaohara)", "Jackson Henry (@JacksonHHax)", "John Jackson (@johnjhacking)", "Robert Willis (@rej_ex)"],
              "Programs": ["Keybase"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-11-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding Zero-Day Vulnerabilities in the Supply Chain",
                    "Link": "https://medium.com/manomano-tech/finding-zero-day-vulnerabilities-in-the-supply-chain-28afa43b0f6e"
                 }
              ],
              "Authors": ["Roni Carta (@0xLupin)"],
              "Programs": ["Adaxes"],
              "Bugs": ["CSTI", "Signature bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-11-16",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                 {
                    "Title": "Diving into Open-source LMS Codebases",
                    "Link": "https://starlabs.sg/blog/2021/11-diving-into-open-source-lms-ccodebases/"
                 }
              ],
              "Authors": ["Poh Jia Hao (@Chocologicall)"],
              "Programs": ["Moodle", "Chamilo LMS"],
              "Bugs": ["Insecure file upload", "Insecure deserialization", "RCE", "CSRF", "SQL injection", "Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOS attack in Yahoo, How i was able to deny new users from service?",
                    "Link": "https://hector0x.medium.com/dos-attack-in-yahoo-how-i-was-able-to-deny-new-users-from-service-6b222e744e61"
                 }
              ],
              "Authors": ["Mostafa Mamdoh"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["DoS", "Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2021-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full account takeover through referral code.",
                    "Link": "https://hector0x.medium.com/broken-authentication-through-referral-code-25cd0e8bccc2"
                 }
              ],
              "Authors": ["Mostafa Mamdoh"],
              "Programs": ["Shipt"],
              "Bugs": ["Broken authentication", "Account takeover"],
              "Bounty": "700",
              "PublicationDate": "2021-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "T-Reqs: HTTP Request Smuggling with Differential Fuzzing",
                    "Link": "https://bahruz.me/publications/11847"
                 }
              ],
              "Authors": ["Bahruz Jabiyev (@BahruzJabiyev)", "Steven Sprecher (@StevenSprecher)", "Kaan Onarlioglu", "Engin Kirda"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "-",
              "PublicationDate": "2021-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOS attack in Yahoo, How i was able to deny new users from service?",
                    "Link": "https://hector0x.medium.com/dos-attack-in-yahoo-how-i-was-able-to-deny-new-users-from-service-6b222e744e61"
                 }
              ],
              "Authors": ["Mostafa Mamdoh"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["DoS"],
              "Bounty": "1,000",
              "PublicationDate": "2021-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found P1 bug Due to Sensitive data exposure And Earn $$$$",
                    "Link": "https://piyushshuklabug.medium.com/how-i-found-p1-bug-due-to-sensitive-data-exposer-and-earn-99ebcb342bcd"
                 }
              ],
              "Authors": ["Piyush shukla (@PiyushShukla__)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Link Hijacking — 404 Google Play Store— xxx$ Bounty",
                    "Link": "https://proviesec.medium.com/broken-link-hijacking-404-google-play-store-xxx-bounty-96e79a8dfd71"
                 }
              ],
              "Authors": ["Proviesec (@proviesec)"],
              "Programs": ["-"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2021-11-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting CSP in Webkit to Break Authentication & Authorization",
                    "Link": "https://threatnix.io/blog/exploiting-csp-in-webkit-to-break-authentication-authorization/"
                 }
              ],
              "Authors": ["Sachin  Thakuri (@sachinnthakuri)", "Prakash (@1lastBr3ath)"],
              "Programs": ["Apple"],
              "Bugs": ["Information disclosure", "CSP leak", "Account takeover"],
              "Bounty": "100,000",
              "PublicationDate": "2021-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Impact of an Insecure Deep Link",
                    "Link": "https://securityflow.io/impact-of-an-insecure-deep-link/"
                 }
              ],
              "Authors": ["Yashar Shahinzadeh (@YShahinzadeh)", "Аli Dinifаr (@binb4sh)"],
              "Programs": ["CafeBazaar"],
              "Bugs": ["Insecure deeplink"],
              "Bounty": "-",
              "PublicationDate": "2021-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Never leave this tip while you hunting Broken Access Control",
                    "Link": "https://secureitmania.medium.com/never-leave-this-tip-while-you-hunting-broken-access-control-f63c00b1e96a"
                 }
              ],
              "Authors": ["secureITmania (@secureitmania)"],
              "Programs": ["-"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2021-11-13",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Privilege Escalation, worth of €300",
                  "Link": "https://medium.com/@kashyapherry147/privilege-escalation-worth-of-300-b9a6eac3b0fa"
               }
            ],
            "Authors": ["Hemant Kumar"],
            "Programs": ["-"],
            "Bugs": ["Broken Access Control", "IDOR", "Privilege escalation"],
            "Bounty": "300",
            "PublicationDate": "2021-11-12",
            "AddedDate": "2022-09-16"
         },
           {
              "Links": [
                 {
                    "Title": "How I got $200 in 30 Seconds.",
                    "Link": "https://medium.com/@yashhunter772/how-i-got-200-in-30-seconds-3dd742f60186"
                 }
              ],
              "Authors": ["Yash__ HackZ (@HackzYash)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "200",
              "PublicationDate": "2021-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "chaining improper authentication to idor and no rate limit for mass account takeover",
                    "Link": "https://tox7cv3nom.github.io/2021/11/12/chaining-of-csrf-token-misconfiguration-and-no-rate-limit-leads-to-mass-account-takeover.html"
                 }
              ],
              "Authors": ["mohit (@mohit29295572)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Lack of rate limiting", "CSRF", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From URL dumps digging to IDOR , BAC, Massive Phishing in Udemy",
                    "Link": "https://hector0x.medium.com/from-url-dumps-digging-to-idor-bac-massive-phishing-in-udemy-6fa7f94ef256"
                 }
              ],
              "Authors": ["Mostafa Mamdoh"],
              "Programs": ["Udemy"],
              "Bugs": ["Broken Access Control", "Information disclosure", "IDOR", "HTML injection"],
              "Bounty": "1,300",
              "PublicationDate": "2021-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Simple SSRF Allows Access To Internal Assets",
                    "Link": "https://coffeejunkie.me/Simple-SSRF/"
                 }
              ],
              "Authors": ["Sam Paredes (@caffeinevulns)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-11-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up – Google VRP Bug Bounty: /etc/environment Local Variables Exfiltrated On Linux Google Earth Pro Desktop App – $1,337 USD",
                    "Link": "https://omespino.com/write-up-google-vrp-bug-bounty-etc-environment-local-variables-exfiltrated-on-linux-google-earth-pro-desktop-app-1337-usd/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "1,337",
              "PublicationDate": "2021-11-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unrestricted File Upload Leads to SSRF and RCE",
                    "Link": "https://itsfading.github.io/posts/Unrestricted-File-Upload-Leads-to-SSRF-and-RCE/"
                 }
              ],
              "Authors": ["Muhammad Adel (@ItsFadinG_)"],
              "Programs": ["-"],
              "Bugs": ["ImageTragick", "Unrestricted file upload", "SSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-11-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fuzzing Microsoft's RDP Client using Virtual Channels: Overview & Methodology",
                    "Link": "https://thalium.github.io/blog/posts/fuzzing-microsoft-rdp-client-using-virtual-channels/"
                 }
              ],
              "Authors": ["Valentino Ricotta"],
              "Programs": ["Microsoft"],
              "Bugs": ["Memory corruption"],
              "Bounty": "6,000",
              "PublicationDate": "2021-11-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough",
                    "Link": "https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-vulnerability-walkthrough"
                 }
              ],
              "Authors": ["Nir Ohfeld (@nirohfeld)", "Sagi Tzadik (@sagitz_)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Cross-tenant vulnerability", "Account takeover", "Privilege escalation"],
              "Bounty": "40,000",
              "PublicationDate": "2021-11-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond",
                    "Link": "https://www.intruder.io/research/practical-http-header-smuggling"
                 }
              ],
              "Authors": ["Daniel Thatcher (@_danielthatcher)"],
              "Programs": ["-"],
              "Bugs": ["HTTP Header Smuggling", "HTTP request smuggling"],
              "Bounty": "-",
              "PublicationDate": "2021-11-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "400$ Bounty again using Google Dorks",
                    "Link": "https://medium.com/@fcwdbrqmr/400-bounty-again-using-google-dorks-6dc8e438f017"
                 }
              ],
              "Authors": ["Haris M (@hrsm321)"],
              "Programs": ["-"],
              "Bugs": ["Directory listing", "Information disclosure"],
              "Bounty": "400",
              "PublicationDate": "2021-11-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Becoming A Super Admin In Someone Elses Gsuite Organization And Taking It Over",
                    "Link": "https://secreltyhiddenwriteups.blogspot.com/2021/11/becoming-super-admin-in-someone-elses.html"
                 }
              ],
              "Authors": ["Cam (@SecretlyHidden1)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-11-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass Chrome Ad-Heavy detection mechanism",
                    "Link": "https://0x0021h.medium.com/bypass-chrome-ad-heavy-detection-mechanism-25c9e2e4a0c4"
                 }
              ],
              "Authors": ["0x0021h (@0x0021h)"],
              "Programs": ["Google (Chrome)"],
              "Bugs": ["Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2021-11-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found multiple SQL Injection with FFUF and Sqlmap in a few minutes",
                    "Link": "https://0xmahmoudjo0.medium.com/how-i-found-multiple-sql-injection-with-ffuf-and-sqlmap-in-a-few-minutes-9c3bb3780e8f"
                 }
              ],
              "Authors": ["Mahmoud Youssef (@0xmahmoudjo0)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-11-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SONY Hunting I: Discovering Hidden Parameters (5x SWAG)",
                    "Link": "https://infosecwriteups.com/sony-hunting-i-discovering-hidden-parameters-5x-swag-c3396c0064bc"
                 }
              ],
              "Authors": ["can1337 (@canmustdie)"],
              "Programs": ["Sony"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2021-11-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Insufficient Redirect URI validation: The risk of allowing to dynamically add arbitrary query parameters and fragments to the redirect_uri",
                    "Link": "https://security.lauritz-holtmann.de/post/sso-security-redirect-uri-ii/"
                 }
              ],
              "Authors": ["Lauritz Holtmann (@_lauritz_)"],
              "Programs": ["GitHub", "Microsoft", "StackExchange"],
              "Bugs": ["OAuth", "Prototype pollution"],
              "Bounty": "-",
              "PublicationDate": "2021-11-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "4 Crits in 48 hours: Unicorn Programs",
                    "Link": "https://web.archive.org/web/20211106100048/https://monke.ie/unicorn-programs/"
                 }
              ],
              "Authors": ["Monke (@pmofcats)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Information disclosure", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-11-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass video capture limit on Ray-Ban Stories",
                    "Link": "https://philippeharewood.com/bypass-video-capture-limit-on-ray-ban-stories/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Android"],
              "Bounty": "1,500",
              "PublicationDate": "2021-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated Access To Cloud Portal — A 🚪 Without 🗝️",
                    "Link": "https://medium.com/techiepedia/unauthenticated-access-to-cloud-portal-a-without-%EF%B8%8F-9f29c387b937"
                 }
              ],
              "Authors": ["Yukesh Kumar (@3th1c_yuk1)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Concrete CMS Vulnerabilities ( Part1 – RCE )",
                    "Link": "https://fortbridge.co.uk/research/multiple-vulnerabilities-in-concrete-cms-part1-rce/"
                 }
              ],
              "Authors": ["FORTBRIDGE (@FORTBRIDGE1)"],
              "Programs": ["Concrete CMS"],
              "Bugs": ["RCE", "Race condition"],
              "Bounty": "-",
              "PublicationDate": "2021-11-05",
              "AddedDate": "2022-09-26"
           },
           {
              "Links": [
                 {
                    "Title": "HacktoberFest2k21 vulnerability: How users metadata can be changed via Auth JWT tokens leaking from waybackurls",
                    "Link": "https://medium.com/@varmaanu001/hacktoberfest2k21-vulnerability-how-users-metadata-can-be-changed-via-auth-jwt-tokens-leaking-from-3028f8ad6991"
                 }
              ],
              "Authors": ["Anurag__Verma"],
              "Programs": ["DigitalOcean"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-11-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fiverr email restriction bypassed | Bounty 100$",
                    "Link": "https://thinkermaruf.medium.com/fiverr-email-restriction-bypassed-36b797cb7e9"
                 }
              ],
              "Authors": ["Maruf Hosan"],
              "Programs": ["Fiverr"],
              "Bugs": ["Logic flaw"],
              "Bounty": "100",
              "PublicationDate": "2021-11-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Technical Analysis of CVE-2021-30864: Bypassing App Sandbox Restrictions",
                    "Link": "https://perception-point.io/a-technical-analysis-of-cve-2021-30864-bypassing-app-sandbox-restrictions/"
                 }
              ],
              "Authors": ["Perception Point (@PerceptionPo1nt)"],
              "Programs": ["Apple"],
              "Bugs": ["Local Privilege Escalation", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2021-11-03",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Sitecore Experience Platform Pre-Auth RCE - CVE-2021-42237",
                  "Link": "https://blog.assetnote.io/2021/11/02/sitecore-rce/"
               }
            ],
            "Authors": ["Shubham Shah (@infosec_au)"],
            "Programs": ["Sitecore"],
            "Bugs": ["RCE", "Insecure deserialization", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2021-11-01",
            "AddedDate": "2023-05-11"
         },
           {
              "Links": [
                 {
                    "Title": "How i made 500$ with XSS",
                    "Link": "https://nassimchami.medium.com/stored-xss-to-account-take-over-45a7e09116a7"
                 }
              ],
              "Authors": ["Nassim Chami (@nvccim)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Account takeover"],
              "Bounty": "500",
              "PublicationDate": "2021-11-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Never Give Up — Story of Hacking Dutch Government and Earning that Dutch Swag.",
                    "Link": "https://medium.com/@bababounty99/never-give-up-story-of-hacking-dutch-government-and-earning-that-swag-b518cca81c78"
                 }
              ],
              "Authors": ["BabaBounty (@Rohan96867358)"],
              "Programs": ["Dutch Government"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-10-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This is how i was able to Permanently Crash all Mapillary users within minutes",
                    "Link": "https://pathleax.medium.com/this-is-how-i-was-able-to-permanently-crash-all-mapillary-users-within-minutes-c7276def5a94"
                 }
              ],
              "Authors": ["Abhishek Pathak (@pathleax)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Application-level DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-10-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found Command Injection via Obsolete PHPThumb",
                    "Link": "https://sushant-kamble.medium.com/how-i-found-command-injection-via-obsolete-phpthumb-p1-vulnerability-e4811248ce12"
                 }
              ],
              "Authors": ["Sushant Kamble"],
              "Programs": ["-"],
              "Bugs": ["OS command injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One misconfiguration to rule them all",
                    "Link": "https://medium.com/@saurabh5392/one-misconfiguration-to-rule-them-all-b45f50fd3df4"
                 }
              ],
              "Authors": ["Sushant Soni (@sushantsoni5392)", "Varun (@varun0x1)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Debug mode enabled"],
              "Bounty": "5,000",
              "PublicationDate": "2021-10-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to access a properly Configured S3 Bucket",
                    "Link": "https://pawanchhabria.medium.com/how-i-was-able-to-access-a-properly-configured-s3-bucket-a0e949446341"
                 }
              ],
              "Authors": ["Pawan Chhabria (@heybenchmarkkk)"],
              "Programs": ["-"],
              "Bugs": ["Leaked AWS keys", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-10-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft finds new macOS vulnerability, Shrootless, that could bypass System Integrity Protection",
                    "Link": "https://www.microsoft.com/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"
                 }
              ],
              "Authors": ["Microsoft Security Vulnerability Research (MSVR)"],
              "Programs": ["Apple"],
              "Bugs": ["SIP bypass", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-10-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up – XSS Stored In api.media.atlassian.com Via Doc File (iOS)",
                    "Link": "https://omespino.com/write-up-xss-stored-in-api-media-atlassian-com-via-doc-file-ios/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Atlassian"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-10-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A journey from XML External Entity (XXE) to NTLM hashes!",
                    "Link": "https://shubhamchaskar.com/xxe-to-ntlm/"
                 }
              ],
              "Authors": ["Shubham Chaskar (@chaskar_shubham)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2021-10-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Apple XAR – Arbitrary File Write (CVE-2021-30833)",
                    "Link": "https://research.nccgroup.com/2021/10/28/technical-advisory-apple-xar-arbitrary-file-write-cve-2021-30833/"
                 }
              ],
              "Authors": ["Richard Warren (@buffaloverflow)"],
              "Programs": ["Apple"],
              "Bugs": ["Arbitrary file write"],
              "Bounty": "-",
              "PublicationDate": "2021-10-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated Cache Purge",
                    "Link": "https://medium.com/@priyanshbansal25/unauthenticated-cache-purge-c56fac8569e8"
                 }
              ],
              "Authors": ["Priyansh Bansal (@PriyanshB25)"],
              "Programs": ["Lenovo"],
              "Bugs": ["Unauthenticated cache purge"],
              "Bounty": "-",
              "PublicationDate": "2021-10-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthorized access to any user’s account.",
                    "Link": "https://medium.com/@vikramroot/unauthorized-access-to-any-users-account-600e8efe7de0"
                 }
              ],
              "Authors": ["vikram naidu (@ImVikram7msd)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Authentication bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-10-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Agent 007: Pre-Auth Takeover of Build Pipelines in GoCD",
                    "Link": "https://blog.sonarsource.com/gocd-pre-auth-pipeline-takeover"
                 }
              ],
              "Authors": ["Sonar (@SonarSource)"],
              "Programs": ["GoCD"],
              "Bugs": ["Broken authentication", "Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2021-10-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Easy SSRF from Wayback Machine",
                    "Link": "https://web.archive.org/web/20211216032639/https://xelkomy.medium.com/easy-ssrf-from-wayback-machine-edf946486120"
                 }
              ],
              "Authors": ["Khaled Mohamed (@0xElkomy)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-10-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Use-After-Free in Voice Control: CVE-2021-30902 Write-up",
                    "Link": "https://blog.zecops.com/research/use-after-free-in-voice-control-cve-2021-30902/"
                 }
              ],
              "Authors": ["08Tc3wBB (@08Tc3wBB)"],
              "Programs": ["Apple"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2021-10-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zimbra “zmslapd” Local Root Exploit.",
                    "Link": "https://darrenmartyn.ie/2021/10/27/zimbra-zmslapd-local-root-exploit/"
                 }
              ],
              "Authors": ["Darren Martyn (@_darrenmartyn)"],
              "Programs": ["Zimbra"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-10-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An Effective 5 min recon leads to a Hall of Fame",
                    "Link": "https://renganathanofficial.medium.com/an-effective-5-min-recon-leads-to-a-hall-of-fame-ae7f20e5cf1a"
                 }
              ],
              "Authors": ["Renganathan (@IamRenganathan)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-10-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zimbra “nginx” Local Root Exploit",
                    "Link": "https://darrenmartyn.ie/2021/10/25/zimbra-nginx-local-root-exploit/"
                 }
              ],
              "Authors": ["Darren Martyn (@_darrenmartyn)"],
              "Programs": ["Zimbra"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-10-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A 7500$ Google sites IDOR",
                    "Link": "https://r0ckinxj3.wordpress.com/2021/10/24/a-7500-google-sites-idor/"
                 }
              ],
              "Authors": ["Jalal (@r0ckin_)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "7,500",
              "PublicationDate": "2021-10-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover via improper input validation",
                    "Link": "https://gauravnarwani.com/account-takeover-via-improper-input-validation/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)", "Verneet (@err0rrrrr)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "Token leak", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-10-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to revoke your Instagram 2FA",
                    "Link": "https://dhiyaneshgeek.github.io/web/security/2021/10/23/how-i-was-able-to-revoke-your-instagram-2fa/"
                 }
              ],
              "Authors": ["Dhiyaneshwaran (@DhiyaneshDK)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Bruteforce", "Rate limiting bypass"],
              "Bounty": "5,000",
              "PublicationDate": "2021-10-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Chrome Vulnerability Worth for $6K: Use After Free (CVE-2021-30573)",
                    "Link": "https://securityforeveryone.com/blog/google-chrome-zero-day-vulnerability-cve-2021-30573"
                 }
              ],
              "Authors": ["Security For Everyone / S4E Team (@secforeveryone)"],
              "Programs": ["Google"],
              "Bugs": ["Memory corruption"],
              "Bounty": "6,000",
              "PublicationDate": "2021-10-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Discourse SNS webhook RCE",
                    "Link": "https://0day.click/recipe/discourse-sns-rce/"
                 }
              ],
              "Authors": ["joernchen (@joernchen)"],
              "Programs": ["Discourse"],
              "Bugs": ["RCE", "Signature validation bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-10-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tagged User Could Delete Facebook Story",
                    "Link": "https://mrkrhy-xyz.medium.com/tagged-user-could-delete-facebook-story-d7f9cdde92aa"
                 }
              ],
              "Authors": ["Mark Rhoy (@mrkrhy_xyz)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Android", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-10-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i Got 3 SQL injection in just 10 minutes.",
                    "Link": "https://xdev05.github.io/How-i-Got-3-SQLI-in-just-10-minutes/"
                 }
              ],
              "Authors": ["Ahmed Fatouh (@XDev05)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-10-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A story of another awesome old school hacking that lead to a cool P1 bug",
                    "Link": "https://infosecwriteups.com/a-story-of-another-awesome-old-school-hacking-that-lead-to-a-cool-p1-bug-f88da04b1ecf"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["403 bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Moodle - Stored XSS and blind SSRF possible via feedback answer text",
                    "Link": "https://r0.haxors.org/posts?id=20"
                 }
              ],
              "Authors": ["rekter0 (@rekter0)", "Holme (@holme_sec)"],
              "Programs": ["Moodle"],
              "Bugs": ["Stored XSS", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "All Your (d)Base Are Belong To Us, Part 2: Code Execution in Microsoft Office (CVE-2021-38646)",
                    "Link": "https://spaceraccoon.dev/all-your-d-base-are-belong-to-us-part-2-code-execution-in-microsoft-office"
                 }
              ],
              "Authors": ["Eugene Lim (@spaceraccoonsec)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2021-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthorized access to any Facebook user’s draft profile picture frames",
                    "Link": "https://web.archive.org/web/20231004134528/https://appsecure.security/unauthorized-access-to-any-face-book-users-draft-profile-picture-frames/"
                 }
              ],
              "Authors": ["Sandeep Hodkasia (@sandeephodkasia)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-2471 MySQL JDBC XXE",
                    "Link": "https://pyn3rd.github.io/2021/10/22/mysql-jdbc-xxe/"
                 }
              ],
              "Authors": ["pyn3rd (@pyn3rd)"],
              "Programs": ["Oracle (MySQL)"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2021-10-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From staging to 0 click account takeover",
                    "Link": "https://med-mahmoudi26.medium.com/from-staging-to-0-click-account-takeover-528a5ecaa3eb"
                 }
              ],
              "Authors": ["mohamad mahmoudi (@Lotus_619)"],
              "Programs": ["Pinterest"],
              "Bugs": ["Account takeover", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-10-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Request forgery on Mobile Applications.",
                    "Link": "https://dphoeniixx.medium.com/exploiting-request-forgery-on-mobile-applications-e1d196d187b3"
                 }
              ],
              "Authors": ["Sayed Abdelhafiz (@dPhoeniixx)"],
              "Programs": ["Pinterest"],
              "Bugs": ["CSRF", "Account takeover", "Android", "iOS"],
              "Bounty": "-",
              "PublicationDate": "2021-10-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Scientific Notation Bug in MySQL left AWS WAF Clients Vulnerable to SQL Injection",
                    "Link": "https://www.gosecure.net/blog/2021/10/19/a-scientific-notation-bug-in-mysql-left-aws-waf-clients-vulnerable-to-sql-injection/"
                 }
              ],
              "Authors": ["Marc Olivier Bergeron"],
              "Programs": ["AWS"],
              "Bugs": ["SQL injection", "WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-10-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Shells And SOAP: Websphere Deserialization To RCE",
                    "Link": "https://web.archive.org/web/20221128060608/https://wya.pl/2021/10/18/shells-and-soap-websphere-deserialization-to-rce/"
                 }
              ],
              "Authors": ["Wyatt Dahlenburg (@wdahlenb)"],
              "Programs": ["IBM"],
              "Bugs": ["RCE", "Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2021-10-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Speckle Umbrella story — part 2",
                    "Link": "https://irsl.medium.com/the-speckle-umbrella-story-part-2-fcc0193614ea"
                 }
              ],
              "Authors": ["Imre Rad (@ImreRad)"],
              "Programs": ["Google"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-10-18",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Independently Secure, Together Not So Much – A Story Of 2 WP Plugins",
                  "Link": "https://fortbridge.co.uk/research/independently-secure-together-not-so-much-a-story-of-2-wp-plugins/"
               }
            ],
            "Authors": ["Adrian Tiron (@Adrian__T)"],
            "Programs": ["-"],
            "Bugs": ["RCE", "Race condition", "Unrestricted file upload", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2021-10-17",
            "AddedDate": "2023-05-04"
         },
           {
              "Links": [
                 {
                    "Title": "How I Escalated a Time-Based SQL Injection to RCE",
                    "Link": "https://infosecwriteups.com/how-i-escalated-a-time-based-sql-injection-to-rce-bbf0d68cb398"
                 }
              ],
              "Authors": ["JM Sanchez / 0xEchidonut (@jmrcsnchz)"],
              "Programs": ["Sony"],
              "Bugs": ["SQL injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-10-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business Logic Errors - A Logic Destruction",
                    "Link": "https://shahjerry33.medium.com/business-logic-errors-a-logic-destruction-477c4ebc824b"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-10-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploitation of file’s download parameters to create potential risk of malware delivery: $200 bug!",
                    "Link": "https://muhammad-aamir.medium.com/exploitation-of-files-download-parameters-to-create-potential-risk-of-malware-delivery-200-bug-e2bcce0e737"
                 }
              ],
              "Authors": ["Muhammad Aamir (@Muhammad__Aamir)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "RCE"],
              "Bounty": "200",
              "PublicationDate": "2021-10-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote code execution in Managed Anthos Service Mesh control plane",
                    "Link": "https://lf.lc/vrp/203177829/"
                 }
              ],
              "Authors": ["Anthony Weems"],
              "Programs": ["Google"],
              "Bugs": ["RCE"],
              "Bounty": "6,000",
              "PublicationDate": "2021-10-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up – Google VRP N/A: Arbitrary Local File Read (Macos) Via &#x3c;&#x61;&#x3e; Tag And Null Byte (&#x25;&#x30;&#x30;) In Google Earth Pro Desktop App",
                    "Link": "https://omespino.com/write-up-google-vrp-n-a-arbitrary-local-file-read-macos-via-a-tag-and-null-byte-in-google-earth-pro-desktop-app/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Google"],
              "Bugs": ["Local File Read"],
              "Bounty": "-",
              "PublicationDate": "2021-10-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "500$ Bug: Sensitive Data Exposure to Broken Access Control leads, How I able to take over any account of India’s Biggest College Ever.👨‍💻",
                    "Link": "https://gowtham-naidu.medium.com/500-bug-sensitive-data-exposure-to-broken-access-control-leads-how-i-able-to-take-over-any-33658f16e265"
                 }
              ],
              "Authors": ["Gowtham_Naidu (@NaiduPonnana)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass", "Account takeover", "Password reset"],
              "Bounty": "500",
              "PublicationDate": "2021-10-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing Slack’s file-sharing functionality to de-anonymise fellow workspace members",
                    "Link": "https://jub0bs.com/posts/2021-10-12-xsleak-stack/"
                 }
              ],
              "Authors": ["Julien Cretel (@jub0bs)"],
              "Programs": ["Slack"],
              "Bugs": ["XSLeaks"],
              "Bounty": "-",
              "PublicationDate": "2021-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ESET Endpoint Security credentials theft",
                    "Link": "https://medium.com/@mehdi.alouache/eset-endpoint-security-credentials-theft-90082dfdf474"
                 }
              ],
              "Authors": ["Mehdi Alouache"],
              "Programs": ["ESET"],
              "Bugs": ["Credentials sent over unencrypted channel"],
              "Bounty": "-",
              "PublicationDate": "2021-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing required reviews using GitHub Actions",
                    "Link": "https://medium.com/cider-sec/bypassing-required-reviews-using-github-actions-6e1b29135cc7"
                 }
              ],
              "Authors": ["Omer Gil (@omer_gil)"],
              "Programs": ["GitHub"],
              "Bugs": ["Privilege escalation", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                {
                   "Title": "Stealing all your secrets using IPFS Mounts",
                   "Link": "https://joranhonig.nl/stealing-info-using-ipfs-fuse/"
                }
               ],
              "Authors": ["Joran Honig (@joranhonig)"],
              "Programs": ["Filecoin Security"],
              "Bugs": ["Web3 hacking", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-10-12",
              "AddedDate": "2022-10-10"
            },
            {
               "Links": [
                 {
                    "Title": "ESET Endpoint Security credentials theft",
                    "Link": "https://medium.com/@mehdi.alouache/eset-endpoint-security-credentials-theft-90082dfdf474"
                 }
                ],
               "Authors": ["Mehdi Alouache"],
               "Programs": ["ESET"],
               "Bugs": ["Credentials sent over unencrypted channel", "MiTM"],
               "Bounty": "-",
               "PublicationDate": "2021-10-12",
               "AddedDate": "2022-11-08"
             },
             {
               "Links": [
                 {
                    "Title": "Pulse Secure version number disclosure in error messages",
                    "Link": "https://medium.com/@mehdi.alouache/pulse-secure-version-number-disclosure-in-error-messages-143aa76c90cd"
                 }
                ],
               "Authors": ["Mehdi Alouache"],
               "Programs": ["Pulse Secure"],
               "Bugs": ["Information disclosure"],
               "Bounty": "-",
               "PublicationDate": "2021-10-12",
               "AddedDate": "2022-11-08"
             },
             {
              "Links": [
                 {
                    "Title": "Hacking YouTube With MP4",
                    "Link": "https://realkeyboardwarrior.github.io/security/2021/10/11/hacking-youtube.html"
                 }
              ],
              "Authors": ["KeyboardWarrior (@Keyb0ardWarr10r)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-10-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting HTML-to-PDF Converters through HTML Imports",
                    "Link": "https://mhmdiaa.com/blog/exploiting-html-imports/"
                 }
              ],
              "Authors": ["Mohammed Diaa (@mhmdiaa)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2021-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked Billion Android Users Social And 3rd Party Account | A Story About 5000$ Bug",
                    "Link": "https://medium.com/@cappriciosec/how-i-hacked-billion-android-users-social-and-3rd-party-account-a-story-about-5000-bug-c422ca43bd2"
                 }
              ],
              "Authors": ["Karthikeyan.V (@karthithehacker)"],
              "Programs": ["Google"],
              "Bugs": ["Android"],
              "Bounty": "5,000",
              "PublicationDate": "2021-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got $500 with Open redirect",
                    "Link": "https://medium.com/@mamunwhh/how-i-got-500-with-open-redirect-48fd80c82631"
                 }
              ],
              "Authors": ["khan mamun (@mamunwhh)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "500",
              "PublicationDate": "2021-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stumbling across a DOM XSS on google.com",
                    "Link": "https://svennergr.github.io/writeups/google/ads_dom_xss/"
                 }
              ],
              "Authors": ["tkiela (@svennergr)"],
              "Programs": ["Google"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover — Story of 2 same issues in a single program but different sub-domains.",
                    "Link": "https://hunter-55.medium.com/account-takeover-story-of-2-same-issues-in-a-single-program-but-different-sub-domains-in-10-minutes-840b2701db91"
                 }
              ],
              "Authors": ["Himanshu Pdy (@himanshu_pdy)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Auth Bypass in Google Assistant",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0011"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["Insecure deeplink"],
              "Bounty": "8,133.70",
              "PublicationDate": "2021-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Power of Your Own Wordlist — Fuzz for Log File Leads to Information Leakage",
                    "Link": "https://mikekitckchan.medium.com/power-of-your-own-wordlist-fuzz-for-log-file-leads-to-information-leakage-ad46958b4729"
                 }
              ],
              "Authors": ["MikeChan"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Request Smuggling In Major Crypto Site — road to disappointment",
                    "Link": "https://medium.com/@oxygenne/request-smuggling-in-major-crypto-site-road-to-disappointment-a71a461f3b1f"
                 }
              ],
              "Authors": ["CeloIme Prezime"],
              "Programs": ["-"],
              "Bugs": ["HTTP Header Smuggling"],
              "Bounty": "-",
              "PublicationDate": "2021-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accessing Apple’s internal UAT Slackbot for fun and non-profit",
                    "Link": "https://shail-official.medium.com/accessing-apples-internal-uat-slackbot-for-fun-and-non-profit-25b167605f38"
                 }
              ],
              "Authors": ["Shail Patel (@shail_official)", "Ashish Kunwar (@D0rkerDevil)"],
              "Programs": ["Apple"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-10-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-26420: Remote Code Execution In Sharepoint Via Workflow Compilation",
                    "Link": "https://www.zerodayinitiative.com/blog/2021/10/5/cve-2021-26420-remote-code-execution-in-sharepoint-via-workflow-compilation"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-10-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Netflix Eureka!",
                    "Link": "https://medium.com/@mfocuz/hacking-netflix-eureka-8e5957b2f539"
                 }
              ],
              "Authors": ["Maxim Tyukov (@maxtyukov)"],
              "Programs": ["Netflix"],
              "Bugs": ["SSRF", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-10-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF to one tray Red-bull",
                    "Link": "https://medium.com/@saneem7/csrf-to-one-tray-red-bull-6564cd884a47"
                 }
              ],
              "Authors": ["Mohammed Saneem"],
              "Programs": ["Redbull"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-10-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in the administrator’s panel due to misuse of MarkupSafe",
                    "Link": "https://www.aeth.cc/public/Article-Pass-Culture/stored-xss-article-en.html"
                 }
              ],
              "Authors": ["Aethlios (@AethliosIK)"],
              "Programs": ["pass Culture"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-10-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got access to many PIIs through a source code leak",
                    "Link": "https://supras.io/how-i-got-access-to-many-piis-through-a-source-code-leak/"
                 }
              ],
              "Authors": ["Supras (@LdrTom)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-10-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-26084",
                    "Link": "https://github.com/snowyyowl/writeups/blob/main/CVE-2021-26084/CVE-2021-26084.md"
                 }
              ],
              "Authors": ["snowyyowl (@bennyyjacob)"],
              "Programs": ["Atlassian"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-10-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-43136 – FormaLMS – The evil default value that leads to Authentication Bypass",
                    "Link": "https://blog.hacktivesecurity.com/index.php/2021/10/05/cve-2021-43136-formalms-the-evil-default-value-that-leads-to-authentication-bypass/"
                 }
              ],
              "Authors": ["Cristian Giustini"],
              "Programs": ["Forma LMS"],
              "Bugs": ["Authentication bypass", "Security code review"],
              "Bounty": "-",
              "PublicationDate": "2021-10-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing 403 Protection To Get Pagespeed Admin Access",
                    "Link": "https://sapt.medium.com/bypassing-403-protection-to-get-pagespeed-admin-access-822fab64c0b3"
                 }
              ],
              "Authors": ["Prajit Sindhkar (@PrajitSindhkar)"],
              "Programs": ["-"],
              "Bugs": ["403 bypass"],
              "Bounty": "200",
              "PublicationDate": "2021-10-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$600 for IDOR (File or Folder Download)",
                    "Link": "https://encodedguy.medium.com/600-for-idor-file-or-folder-download-243166452dad"
                 }
              ],
              "Authors": ["Inderjeet Singh - encodedguy (@3nc0d3dGuY)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "600",
              "PublicationDate": "2021-10-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A short story of Content Spoofing to HTML Injection in Apple using Dangling Markup Injection",
                    "Link": "https://rishuranjanofficial.medium.com/html-injection-in-itunesconnect-apple-com-3f8a898f21ee"
                 }
              ],
              "Authors": ["Rishu Ranjan (@tweetit_rrj)"],
              "Programs": ["Apple"],
              "Bugs": ["HTML injection", "Dangling Markup Injection"],
              "Bounty": "-",
              "PublicationDate": "2021-10-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pre-Auth SSRF To Full MailBox Access (Microsoft Exchange Server Exploit)",
                    "Link": "https://vanshal.medium.com/pre-auth-ssrf-to-full-mailbox-access-microsoft-exchange-server-exploit-a62c8ac04b47"
                 }
              ],
              "Authors": ["Vanshal Gaur (@VanshalG)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Discovery Of Gatekeeper Bypass CVE-2021-1810",
                    "Link": "https://labs.f-secure.com/blog/the-discovery-of-cve-2021-1810/"
                 },
                 {
                    "Title": "Analysis Of CVE-2021-1810 Gatekeeper Bypass",
                    "Link": "https://labs.f-secure.com/blog/analysis-of-cve-2021-1810-gatekeeper-bypass/"
                 }
              ],
              "Authors": ["Rasmus Sten (@pajp)"],
              "Programs": ["Apple"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-10-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                {
                   "Title": "Privilege Escalation to stored XSS",
                   "Link": "https://rohit443.medium.com/privilege-escalation-to-stored-xss-dff01314bc7e"
                }
               ],
              "Authors": ["Rohit Kumar (Rohit_443)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "HTTP response manipulation", "Stored XSS"],
              "Bounty": "500",
              "PublicationDate": "2021-10-01",
              "AddedDate": "2022-10-10"
            },
            {
               "Links": [
                  {
                     "Title": "vScalation (CVE-2021-22015)- Local Privilege Escalation in VMware vCenter",
                     "Link": "https://pentera.io/blog/vscalation-cve-2021-22015-local-privilege-escalation-in-vmware-vcenter-pentera-labs/"
                  }
               ],
               "Authors": ["Yuval Lazar"],
               "Programs": ["VMware"],
               "Bugs": ["Local Privilege Escalation"],
               "Bounty": "-",
               "PublicationDate": "2021-11-30",
               "AddedDate": "2023-01-11"
            },
            {
               "Links": [
                  {
                     "Title": "Improper Spring @Query Usage Allows N1QL Injection",
                     "Link": "https://www.gremwell.com/spring-n1ql-injection"
                  }
               ],
               "Authors": ["Pavel Nakonechnyi"],
               "Programs": ["-"],
               "Bugs": ["N1QL injection", "NoSQL injection"],
               "Bounty": "-",
               "PublicationDate": "2021-09-30",
               "AddedDate": "2022-09-15"
            },
            {
              "Links": [
                 {
                    "Title": "Ping'ing XMLSec",
                    "Link": "https://blog.tint0.com/2021/09/pinging-xmlsec.html"
                 }
              ],
              "Authors": ["An Trinh (@_tint0)"],
              "Programs": ["Ping", "Netflix", "Paypal"],
              "Bugs": ["XSLT", "XXE"],
              "Bounty": "-",
              "PublicationDate": "2021-09-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Expect The Unexpected: Discovering fresh ZeroDay for Bounty",
                    "Link": "https://sinsinology.medium.com/expect-the-unexpected-discovering-fresh-zeroday-for-bounty-d074f3175847"
                 }
              ],
              "Authors": ["Sina Kheirkhah (@SinSinology)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-09-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found bug on Google Cloud",
                    "Link": "https://medium.com/@anuragbhoir06/hello-everyone-this-is-anurag-bhoir-and-its-my-first-writeup-d8904d539ad2"
                 }
              ],
              "Authors": ["Anuragbhoir11"],
              "Programs": ["Google"],
              "Bugs": ["OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-09-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple bugs allowed malicious Android Applications to takeover Facebook/Workplace accounts",
                    "Link": "https://ysamm.com/?p=729"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Account takeover", "Android"],
              "Bounty": "10,000",
              "PublicationDate": "2021-09-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Force Browsing bug at Facebook business plan ($500 Bounty)",
                    "Link": "https://dewcode.medium.com/force-browsing-bug-at-facebook-business-plan-500-bounty-73d1bb4883af"
                 }
              ],
              "Authors": ["Dewanand Vishal (@dewcode91)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Forced browsing"],
              "Bounty": "500",
              "PublicationDate": "2021-09-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Telegram users' privacy has been violated again. Messenger representatives demand not to disclose details",
                    "Link": "https://habr.com/en/post/580582/"
                 }
              ],
              "Authors": ["ne555"],
              "Programs": ["Telegram"],
              "Bugs": ["Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2021-09-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "\"A tale of making internet pollution free\" - Exploiting Client-Side Prototype Pollution in the wild",
                    "Link": "https://blog.s1r1us.ninja/research/PP"
                 }
              ],
              "Authors": ["Sergey Bobrov (@black2fan)",  "s1r1us (@s1r1u5_)", "Terjanq (@terjanq)", "Beomjin Lee (@po6ix)", "Masato Kinugawa (@kinugawamasato)", "Nikita Stupin (@_nikitastupin)", "Rahul Maini (@iamnoooob)", "Harsh Jaiswal (@rootxharsh)", "Mikhail Egorov (@0ang3el)", "Melar Dev (@melardev)"],
              "Programs": ["Apple", "Atlassian", "Mozilla", "HubSpot", "Segment Analytics"],
              "Bugs": ["Prototype pollution", "XSS"],
              "Bounty": "12,600",
              "PublicationDate": "2021-09-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zero-Day: Hijacking iCloud Credentials with Apple Airtags (Stored XSS)",
                    "Link": "https://medium.com/@bobbyrsec/zero-day-hijacking-icloud-credentials-with-apple-airtags-stored-xss-6997da43a216"
                 }
              ],
              "Authors": ["Bobby Rauch / Bobbyr"],
              "Programs": ["Apple"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-09-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DeepSurface Security Advisory: LPE in Firefox on Windows",
                    "Link": "https://deepsurface.com/deepsurface-security-advisory-lpe-in-firefox-on-windows/"
                 }
              ],
              "Authors": ["Robert Chen"],
              "Programs": ["Mozilla"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-09-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass of biometrics & password security functionality for Android",
                    "Link": "https://medium.com/@dheerajkmadhukar/bypass-of-biometrics-password-security-functionality-for-android-8e0174ac7cac"
                 }
              ],
              "Authors": ["Dheeraj Madhukar (@Dheerajmadhukar)"],
              "Programs": ["CoinDCX"],
              "Bugs": ["Authentication bypass", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-09-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-39246 – Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack excessive verbose logging – Windows, macOS, Linux",
                    "Link": "https://sick.codes/sick-2021-111/"
                 }
              ],
              "Authors": ["sickcodes (@sickcodes)"],
              "Programs": ["Tor"],
              "Bugs": ["Verbose logging"],
              "Bounty": "-",
              "PublicationDate": "2021-09-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Improper phone number validation to account takeover",
                    "Link": "https://sheshasai.medium.com/improper-phone-number-validation-to-account-takeover-f8b78b08ed05"
                 }
              ],
              "Authors": ["shesha sai_c (@Cyb3r_4ss4s1n)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "OTP bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-09-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Attack Surface Analysis - Part 3 - Resurrected Code Execution",
                    "Link": "https://parsiya.net/blog/2021-09-26-attack-surface-analysis-part-3-resurrected-code-execution/"
                 }
              ],
              "Authors": ["Parsia Hackerman (@cryptogangsta)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-09-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Telegram bug in terminated sessions",
                    "Link": "https://hack5.dev/telegram/bug/2021/09/24/telegram-sessions-bug.html"
                 }
              ],
              "Authors": ["Hackintosh5"],
              "Programs": ["Telegram"],
              "Bugs": ["Session expiration issue"],
              "Bounty": "-",
              "PublicationDate": "2021-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Command Execution in Visual Studio Code Remote Development Extension",
                    "Link": "https://www.shielder.it/advisories/remote-command-execution-in-visual-studio-code-remote-development-extension/"
                 }
              ],
              "Authors": ["Abdel Adim `smaury` Oisfi (@smaury92)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program",
                    "Link": "https://habr.com/en/post/579714/"
                 }
              ],
              "Authors": ["Denis Tokarev / illusionofchaos"],
              "Programs": ["Apple"],
              "Bugs": ["Information disclosure", "Local Privilege Escalation", "Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2021-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$8,000 Bug Bounty Highlight: XSS to RCE in the Opera Browser",
                    "Link": "https://blogs.opera.com/security/2021/09/8000-bug-bounty-highlight-xss-to-rce-in-the-opera-browser"
                 }
              ],
              "Authors": ["Renwa (@RenwaX23)"],
              "Programs": ["Opera"],
              "Bugs": ["XSS", "RCE"],
              "Bounty": "8,000",
              "PublicationDate": "2021-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug-Bounty | FASTMAIL [pobox.com : account takeover]",
                    "Link": "https://medium.com/@the.white.soul.0/bug-bounty-fastmail-pobox-com-account-takeover-e1e2fd190a2"
                 }
              ],
              "Authors": ["Mohammed ELdawody"],
              "Programs": ["Fastmail"],
              "Bugs": ["Account takeover", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2021-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug-Bounty | FASTMAIL [topicbox.com: Privileges Escalation > Organization Takeover]",
                    "Link": "https://medium.com/@the.white.soul.0/bug-bounty-fastmail-topicbox-com-privileges-escalation-organization-takeover-815466876ad4"
                 }
              ],
              "Authors": ["Mohammed ELdawody"],
              "Programs": ["Fastmail"],
              "Bugs": ["Privilege escalation", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Messenger for MacOS contained valid hardcoded FB access token (employee's token?)",
                    "Link": "https://www.vulnano.com/2021/09/facebook-messenger-for-macos-contained.html"
                 }
              ],
              "Authors": ["Dzmitry Lukyanenka (@vulnano)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Hardcoded credentials"],
              "Bounty": "625",
              "PublicationDate": "2021-09-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwn2Own 2021: Parallels Desktop Guest To Host Escape",
                    "Link": "https://trenchant.io/pwn2own-2021-parallels-desktop-guest-to-host-escape/"
                 }
              ],
              "Authors": ["Benjamin McBride (@bdmcbri)"],
              "Programs": ["Parallels"],
              "Bugs": ["VM escape"],
              "Bounty": "-",
              "PublicationDate": "2021-09-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Super Admin panel without Credentials 😎",
                    "Link": "https://rizwansiddiqu1.medium.com/super-admin-panel-without-credentials-c2022a23bb35"
                 }
              ],
              "Authors": ["Rizwan_siddiqui (@Rizwan_SiDdiqu1)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-09-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Autodiscovering the Great Leak",
                    "Link": "https://www.akamai.com/blog/security/autodiscovering-the-great-leak"
                 }
              ],
              "Authors": ["Amit Serper (@0xAmit)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Domain name collision"],
              "Bounty": "-",
              "PublicationDate": "2021-09-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "mXSS in support.mozilla.org",
                    "Link": "https://gccybermonks.com/posts/mxss/"
                 }
              ],
              "Authors": ["Guilherme Keerok (@k33r0k)", "Luan Herrera (@lbherrera_)"],
              "Programs": ["Mozilla"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-09-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A fever Worth 750$- [Accessing Private Projects ]",
                    "Link": "https://medium.com/@shakti.gtp/a-fever-worth-750-accessing-private-projects-d113c561311f"
                 }
              ],
              "Authors": ["Shakti Mohanty (@3ncryptSaan)"],
              "Programs": ["Mozilla"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "750",
              "PublicationDate": "2021-09-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cookie Stealing via Clickjacking using Burp collaborator",
                    "Link": "https://medium.com/@varmaanu001/cookie-stealing-via-clickjacking-using-burp-collaborator-ff6f4ac1c18b"
                 }
              ],
              "Authors": ["Anurag__Verma"],
              "Programs": ["-"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2021-09-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE in Citrix ShareFile Storage Zones Controller (CVE-2021-22941) – A Walk-Through",
                    "Link": "https://codewhitesec.blogspot.com/2021/09/citrix-sharefile-rce-cve-2021-22941.html"
                 }
              ],
              "Authors": ["Markus Wulftange (@mwulftange)"],
              "Programs": ["Citrix Systems"],
              "Bugs": ["RCE", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2021-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Mama Always Told Me Not to Trust Strangers without Certificates",
                    "Link": "https://blog.grimm-co.com/2021/09/mama-always-told-me-not-to-trust.html"
                 }
              ],
              "Authors": ["Adam (@AdamOfDc949)"],
              "Programs": ["Netgear"],
              "Bugs": ["MiTM", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "5 RCEs in npm for $15,000",
                    "Link": "https://robertchen.cc/blog/2021/09/20/npm-rce"
                 }
              ],
              "Authors": ["Robert Chen (@NotDeGhost)", "Philip"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "15,000",
              "PublicationDate": "2021-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unlimited report user in Instagram (Facebook) leads to abuse risk.",
                    "Link": "https://infosecwriteups.com/unlimited-report-user-in-instagram-facebook-leads-to-abuse-risk-efcca325aada"
                 }
              ],
              "Authors": ["Mano Prasanth"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2021-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining bugs for better bounties",
                    "Link": "https://manasharsh.medium.com/chaining-bugs-for-better-bounties-f14d6b2129de"
                 }
              ],
              "Authors": ["Manas Harsh (@ManasH4rsh)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "XSS", "Information disclosure"],
              "Bounty": "600",
              "PublicationDate": "2021-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Admin access !!",
                    "Link": "https://dewangpanchal98.medium.com/admin-access-799b50694965"
                 }
              ],
              "Authors": ["th3.d1p4k (@DipakPanchal05)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2021-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A small change, and things go in your hand : Story of a $250 bounty",
                    "Link": "https://fardeen-ahmed.medium.com/a-small-change-and-things-go-in-your-hand-story-of-a-250-bounty-5ddc43c31463"
                 }
              ],
              "Authors": ["Fardeen Ahmed (@fardeenahmed411)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "250",
              "PublicationDate": "2021-09-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From phpinfo page to many P1 bugs and RCE. [Symfony]",
                    "Link": "https://u-itachi.medium.com/from-phpinfo-page-to-many-p1-bugs-and-rce-symfony-bce432605662"
                 }
              ],
              "Authors": ["Abdelrahman Khaled"],
              "Programs": ["-"],
              "Bugs": ["File disclosure", "Information disclosure", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-09-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Google Dorking to Information Disclosure",
                    "Link": "https://mikekitckchan.medium.com/from-google-dorking-to-information-disclosure-5da4f1d771e5"
                 }
              ],
              "Authors": ["MikeChan"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2021-09-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "All Your (d)Base Are Belong To Us, Part 1: Code Execution in Apache OpenOffice (CVE-2021–33035)",
                    "Link": "https://medium.com/csg-govtech/all-your-d-base-are-belong-to-us-part-1-code-execution-in-apache-openoffice-cve-2021-33035-767fc7d6daf7"
                 }
              ],
              "Authors": ["Eugene Lim (@spaceraccoonsec)"],
              "Programs": ["Apache"],
              "Bugs": ["RCE", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2021-09-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to have free Internet WIFI on United Airlines flights",
                    "Link": "https://medium.com/hacking-info-sec/how-to-have-free-internet-wifi-on-united-airlines-flights-65ead4087bc9"
                 }
              ],
              "Authors": ["Philippe Delteil (@PhilippeDelteil)"],
              "Programs": ["United Airlines"],
              "Bugs": ["Payment tampering", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-09-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Small Tale of Account Takeover …",
                    "Link": "https://medium.com/@sarveshblogs/a-small-tale-of-account-takeover-2eba07a6ef5f"
                 }
              ],
              "Authors": ["Sarvesh Salgaonkar"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-09-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weaponizing Reflected XSS to Account Takeover",
                    "Link": "https://pwnsauc3.medium.com/weaponizing-reflected-xss-to-account-takeover-ae8aeea7aca3"
                 }
              ],
              "Authors": ["Hassan Shahid (@pwnsauc3)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-09-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to find 100+ XSS in United nations Bug Bounty Program",
                    "Link": "https://mrpentestguy.medium.com/how-i-was-able-to-find-100-xss-in-united-nations-bug-bounty-program-a675573c006d"
                 }
              ],
              "Authors": ["mrpentestguy (@MR_iambatman)"],
              "Programs": ["United Nations"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-09-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This is why you shouldn’t trust your Federated Identity Provider",
                    "Link": "https://medium.com/@soufianehabti/this-is-why-you-shouldnt-trust-your-federated-identity-provider-62160f50d8b2"
                 }
              ],
              "Authors": ["Soufiane Habti (@wld_basha)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "Account takeover", "Authentication bypass"],
              "Bounty": "1,500",
              "PublicationDate": "2021-09-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Facebook bug that exposes email/phone number to your friends",
                    "Link": "https://iamsaugat.medium.com/a-facebook-bug-that-exposes-email-phone-number-to-your-friends-a980d24e5ea8"
                 }
              ],
              "Authors": ["Saugat Pokharel (@saugatscript)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "19,250",
              "PublicationDate": "2021-09-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Was Able To Send SMS From Google To Anyone | $$$ Google Vulnerability:",
                    "Link": "https://asterfiester.medium.com/how-i-was-able-to-send-sms-from-google-to-anyone-google-vulnerability-3277ea0cc9d1"
                 }
              ],
              "Authors": ["Raidh Ĥere (@asterfiest)"],
              "Programs": ["Google"],
              "Bugs": ["Content spoofing"],
              "Bounty": "-",
              "PublicationDate": "2021-09-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked worldwide Tiktok users",
                    "Link": "https://s3c.medium.com/how-i-hacked-world-wide-tiktok-users-24e794d310d2"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://web.archive.org/web/20210914214020/https://s3c.medium.com/how-i-hacked-world-wide-tiktok-users-24e794d310d2"
                 }
              ],
              "Authors": ["s3c (@s3c_krd)"],
              "Programs": ["TikTok"],
              "Bugs": ["IDOR"],
              "Bounty": "7500",
              "PublicationDate": "2021-09-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Azure Portal – Persistent Cross-Site Scripting",
                    "Link": "https://www.y-security.de/news-en/microsoft-azure-portal-persistent-cross-site-scripting/index.html"
                 }
              ],
              "Authors": ["Christian Becker (@0xchrisb)", "Sven Schlüter (@secsven)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-09-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OMIGOD: Critical Vulnerabilities in OMI Affecting Countless Azure Customers",
                    "Link": "https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure"
                 }
              ],
              "Authors": ["Nir Ohfeld (@nirohfeld)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-09-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "10 golden minutes for taking over a Chess.com account",
                    "Link": "https://infosecwriteups.com/10-golden-minutes-for-taking-over-a-chess-com-account-56e73f7c5f0d"
                 }
              ],
              "Authors": ["Seqrity (@seqrity9)"],
              "Programs": ["Chess.com"],
              "Bugs": ["Lack of rate limiting", "Bruteforce", "Session expiration issue"],
              "Bounty": "400",
              "PublicationDate": "2021-09-14",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "PowerShell script, Unicode quotes and ウィンドウズ - a story of uncommon command injection",
                  "Link": "https://blog.stmcyber.com/powershell-unicode-quotes-and-command-injection/"
               }
            ],
            "Authors": ["Krzysztof Andrusiak", "Marcin Ogorzelski"],
            "Programs": ["Zoho (ManageEngine ADSelfService Plus)"],
            "Bugs": ["PowerShell injection", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2021-09-14",
            "AddedDate": "2021-09-14"
         },
           {
              "Links": [
                 {
                    "Title": "Hacking CloudKit - How I accidentally deleted your Apple Shortcuts",
                    "Link": "https://labs.detectify.com/2021/09/13/hacking-cloudkit-how-i-accidentally-deleted-your-apple-shortcuts/"
                 }
              ],
              "Authors": ["Frans Rosén (@fransrosen)"],
              "Programs": ["Apple"],
              "Bugs": ["Logic flaw"],
              "Bounty": "64,000",
              "PublicationDate": "2021-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating Azure Privileges with the Log Analytics Contributor Role",
                    "Link": "https://www.netspi.com/blog/technical/cloud-penetration-testing/escalating-azure-privileges-with-the-log-analystics-contributor-role/"
                 }
              ],
              "Authors": ["Karl Fosaaen (@kfosaaen)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$3133.70 Google Dialogflow IDOR Vulnerability",
                    "Link": "https://asterfiester.medium.com/3133-70-google-dialogflow-idor-vulnerability-7a72771678dd"
                 }
              ],
              "Authors": ["Raidh Ĥere (@asterfiest)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "3,133.70",
              "PublicationDate": "2021-09-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exposing Millions of IRCTC Passengers' ticket details.",
                    "Link": "https://infosecwriteups.com/exposing-millions-of-irctc-passengers-ticket-details-53338280fb9e"
                 }
              ],
              "Authors": ["Renganathan (@IamRenganathan)"],
              "Programs": ["IRCTC"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-09-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$5000 Google IDOR Vulnerability Writeup",
                    "Link": "https://asterfiester.medium.com/5000-google-idor-vulnerability-writeup-c7b45926abe9"
                 }
              ],
              "Authors": ["Raidh Ĥere (@asterfiest)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "5,000",
              "PublicationDate": "2021-09-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found my first AEM related bug.",
                    "Link": "https://vedanttekale20.medium.com/how-i-found-my-first-aem-related-bug-5ea901aad3f4"
                 }
              ],
              "Authors": ["Vedant Tekale (@_justYnot)"],
              "Programs": ["-"],
              "Bugs": ["LFR"],
              "Bounty": "-",
              "PublicationDate": "2021-09-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing GCP Org Policy with Custom Metadata",
                    "Link": "https://kattraxler.github.io/gcp/hacking/2021/09/10/gcp-org-policy-bypass-ai-notebooks.html"
                 },
                 {
                    "Title": "GCP AI Notebooks Vulnerability - Remediation",
                    "Link": "https://kattraxler.github.io/gcp/hacking/2021/09/11/gcp-ai-notebooks-vulnerability-remediation-update.html"
                 }
              ],
              "Authors": ["Kat Traxler (@NightmareJS)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "1,337",
              "PublicationDate": "2021-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Was Able to delete any facebook story where am I mentioned or tagged",
                    "Link": "https://sank-dahal.medium.com/how-i-was-able-to-delete-any-facebook-story-where-am-i-mentioned-or-tagged-10c38a50e55c"
                 }
              ],
              "Authors": ["Sank Dahal (@sank68034756)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2021-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Mistuned Part 1: Client-side XSS to Calculator and More",
                    "Link": "https://blog.chichou.me/2021/08/04/mistuned-part-i/"
                 },
                 {
                    "Title": "Mistuned Part 2: Butterfly Effect",
                    "Link": "https://blog.chichou.me/2021/08/05/mistuned-part-ii/"
                 },
                 {
                    "Title": "Part 3",
                    "Link": "https://blog.chichou.me/2021/09/10/mistuned-part-iii/"
                 }
              ],
              "Authors": ["CodeColorist (@codecolorist)"],
              "Programs": ["Apple"],
              "Bugs": ["XSS", "Memory corruption", "iOS"],
              "Bounty": "-",
              "PublicationDate": "2021-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding Azurescape – Cross-Account Container Takeover in Azure Container Instances",
                    "Link": "https://unit42.paloaltonetworks.com/azure-container-instances/"
                 }
              ],
              "Authors": ["Unit 42 (@Unit42_Intel)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Container takeover", "Container escape", "Privilege escalation", "Cloud"],
              "Bounty": "-",
              "PublicationDate": "2021-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Change home directory and bypass TCC aka CVE-2020-27937",
                    "Link": "https://wojciechregula.blog/post/change-home-directory-and-bypass-tcc-aka-cve-2020-27937/"
                 }
              ],
              "Authors": ["Wojciech Reguła (@_r3ggi)"],
              "Programs": ["Apple"],
              "Bugs": ["Privacy issue", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2021-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GitHub Actions check-spelling community workflow - GITHUB_TOKEN leakage via advice.txt symlink",
                    "Link": "https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md"
                 }
              ],
              "Authors": ["Justin Steven (@justinsteven)"],
              "Programs": ["GitHub"],
              "Bugs": ["Logic flaw", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spook.js: Attacking Google Chrome's Strict Site Isolation via Speculative Execution and Type Confusion",
                    "Link": "https://www.spookjs.com"
                 }
              ],
              "Authors": ["Ayush Agarwal", "Sioli O'Connell", "Jason Kim", "Shaked Yehezke", "Daniel Genkin", "Eyal Ronen", "Yuval Yarom"],
              "Programs": ["Google"],
              "Bugs": ["Browser hacking", "Side-channel attack", "Site Isolation bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover via XSS in e-signature feature worth 2500$",
                    "Link": "https://medium.com/@gguzelkokar.mdbf15/xss-via-account-takeover-in-e-signature-feature-worth-2500-435f3f8325bf"
                 }
              ],
              "Authors": ["Gökhan Güzelkokar (@gkhck_)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Account takeover"],
              "Bounty": "2,500",
              "PublicationDate": "2021-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook email disclosure and account takeover",
                    "Link": "https://rikeshbaniyaaa.medium.com/facebook-email-disclosure-and-account-takeover-ecdb44ee12e9"
                 }
              ],
              "Authors": ["Rikesh Baniya (@rikeshbaniya)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty Guest Post: Local File Read via Stored XSS in The Opera Browser",
                    "Link": "https://blogs.opera.com/security/2021/09/bug-bounty-guest-post-local-file-read-via-stored-xss-in-the-opera-browser/"
                 }
              ],
              "Authors": ["Renwa (@RenwaX23)"],
              "Programs": ["Opera"],
              "Bugs": ["Stored XSS", "Local File Read"],
              "Bounty": "4,000",
              "PublicationDate": "2021-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accessing Grofers Grafana Instance Using Shodan",
                    "Link": "https://infosecwriteups.com/accessing-grofers-grafana-instance-using-shodan-52c585ada797"
                 }
              ],
              "Authors": ["Lohith Gowda M (@lohigowda_in)"],
              "Programs": ["Grofers"],
              "Bugs": ["Weak credentials"],
              "Bounty": "25,000",
              "PublicationDate": "2021-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "5 Different Vulnerabilities in Google’s Threadit",
                    "Link": "https://websecblog.com/vulns/google-threadit/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Google"],
              "Bugs": ["DOM XSS", "Clickjacking", "Privilege escalation", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF in PDF export with PhantomJs",
                    "Link": "https://xhzeem.me/posts/SSRF-in-PDF-export-with-PhantomJs/read"
                 }
              ],
              "Authors": ["أنس روبي (@xhzeem)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "XSS", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2021-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full structure takeover to many brands of company",
                    "Link": "https://u-itachi.medium.com/full-structure-takeover-to-many-brands-of-company-e0ca434890ee"
                 }
              ],
              "Authors": ["Abdelrahman Khaled"],
              "Programs": ["-"],
              "Bugs": ["Directory listing", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-09-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSD Advisory – NETGEAR D7000 Authentication Bypass",
                    "Link": "https://ssd-disclosure.com/ssd-advisory-netgear-d7000-authentication-bypass/"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["Netgear"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-09-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2 CSRF 1 IDOR on Google Marketing Platform",
                    "Link": "https://apapedulimu.click/story-of-idor-on-google-product/"
                 }
              ],
              "Authors": ["apapedulimu / Nosa Shandy (@LocalHost31337)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR", "CSRF"],
              "Bounty": "3,633.70",
              "PublicationDate": "2021-09-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I can take over any user’s account with their mobile number",
                    "Link": "https://medium.com/@katikitala.sushmitha078/how-i-can-take-over-any-users-account-with-their-mobile-number-6d820a364cad"
                 }
              ],
              "Authors": ["Sushmitha Katikitala"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "OTP bypass", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-09-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Anti-crawler Burp Suite RCE",
                    "Link": "https://web.archive.org/web/20211025081016/http://noahblog.360.cn/burp-suite-rce/"
                 }
              ],
              "Authors": ["Wfox"],
              "Programs": ["PortSwigger"],
              "Bugs": ["RCE", "Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2021-09-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Eye for an eye: Unusual single click JWT token takeover",
                    "Link": "https://infosecwriteups.com/eye-for-an-eye-unusual-single-click-jwt-token-takeover-2e58f88cf44d"
                 }
              ],
              "Authors": ["Yurii Sanin (@SaninYurii)"],
              "Programs": ["JetBrains"],
              "Bugs": ["Open redirect", "JWT", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business Logic Errors - Must Vote",
                    "Link": "https://shahjerry33.medium.com/business-logic-errors-must-vote-68f642b60fb7"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassed! and uploaded a sweet reverse shell",
                    "Link": "https://infosecwriteups.com/bypassed-and-uploaded-a-sweet-reverse-shell-d15e1bbf5836"
                 }
              ],
              "Authors": ["Ajay Sharma (@security_donut)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2021-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i hacked BBC mail servers",
                    "Link": "https://cyberguy0xd1.medium.com/how-i-hacked-bbc-mail-servers-e61bb6faed2d"
                 }
              ],
              "Authors": ["Momen Ali (Cyber Guy) (@theCyberGuy0)"],
              "Programs": ["BBC"],
              "Bugs": ["Information disclosure", "Open mail relay"],
              "Bounty": "-",
              "PublicationDate": "2021-09-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "More secure Facebook Canvas : Tale of $126k worth of bugs that lead to Facebook Account Takeovers",
                    "Link": "https://ysamm.com/?p=708"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Account takeover"],
              "Bounty": "126,000",
              "PublicationDate": "2021-09-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How @Mailru traeted my report on their program",
                    "Link": "https://aob-89072.medium.com/how-mailru-handled-with-my-report-on-their-program-5e1f587ecaa"
                 }
              ],
              "Authors": ["Aý Oùb (@Yukusawa18)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "150",
              "PublicationDate": "2021-09-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR Vulnerability In GraphQL Api On Website",
                    "Link": "https://aidilarf.medium.com/idor-vulnerability-in-graphql-api-on-website-bc45e050d1d3"
                 }
              ],
              "Authors": ["Aidil Arief"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "GraphQL"],
              "Bounty": "-",
              "PublicationDate": "2021-09-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Cloud Build — under the hood",
                    "Link": "https://irsl.medium.com/google-cloud-build-under-the-hood-bc00c68ad9de"
                 }
              ],
              "Authors": ["Imre Rad (@ImreRad)"],
              "Programs": ["Google"],
              "Bugs": ["gRPC"],
              "Bounty": "-",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Play the music and bypass TCC aka CVE-2020-29621",
                    "Link": "https://wojciechregula.blog/post/play-the-music-and-bypass-tcc-aka-cve-2020-29621/"
                 }
              ],
              "Authors": ["Wojciech Reguła (@_r3ggi)"],
              "Programs": ["Apple"],
              "Bugs": ["Privacy issue", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE By Code Injection | Perl Reverse Shell",
                    "Link": "https://4bdoz.medium.com/rce-by-code-injection-perl-reverse-shell-a2e90181b10"
                 }
              ],
              "Authors": ["Abdulrahman-Kamel"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Code injection"],
              "Bounty": "-",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ZDI-21-1053: Bypassing Windows Lock Screen",
                    "Link": "https://halove23.blogspot.com/2021/09/zdi-21-1053-bypassing-windows-lock.html"
                 }
              ],
              "Authors": ["Abdelhamid Naceri (@KLINIX5)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Authentication bypass", "Lock screen bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Your Vulnerability Is In Another OEM!",
                    "Link": "https://www.synacktiv.com/publications/your-vulnerability-is-in-another-oem.html"
                 }
              ],
              "Authors": ["Lucas Georges", "Julient Boutet", "Thomas Chauchefoin (@swapgs)"],
              "Programs": ["Western Digital"],
              "Bugs": ["Memory corruption", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL injection in harvard subdomain",
                    "Link": "https://noob3xploiter.medium.com/sql-injection-in-harvard-subdomain-be67a5dbf664"
                 }
              ],
              "Authors": ["Brandon Roldan (@tomorrowisnew_)"],
              "Programs": ["Harvard University"],
              "Bugs": ["XSS", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Breaking Application’s Logic to DOS Attack",
                    "Link": "https://medium.com/nerd-for-tech/breaking-applications-logic-to-dos-attack-88326cd0dd82"
                 }
              ],
              "Authors": ["Abhijeet Singh (@abhiunix)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "chaining bugs from self XSS to account takeover",
                    "Link": "https://medium.com/@behnam.yazdanpanah/chaining-bugs-from-self-xss-to-account-takeover-82d572136bdf"
                 }
              ],
              "Authors": ["Behnam Yazdanpanah (@abhiunix)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "WAF bypass", "CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found Multiple XSS in Hidden Legacy Pages",
                    "Link": "https://marxchryz.medium.com/how-i-found-multiple-xss-in-hidden-legacy-pages-a57a25d8ff1f"
                 }
              ],
              "Authors": ["Marx Chryz"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Dutch Government For a lousy T-shirt",
                    "Link": "https://medium.com/pentesternepal/hacking-dutch-government-for-a-lousy-t-shirt-8e1fd1b56deb"
                 }
              ],
              "Authors": ["Veshraj Ghimire (@GhimireVeshraj)"],
              "Programs": ["Dutch Government"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-2429: A Heap-based Buffer Overflow Bug In The Mysql Innodb Memcached Plugin",
                    "Link": "https://www.zerodayinitiative.com/blog/2021/9/2/cve-2021-2429-a-heap-based-buffer-overflow-bug-in-the-mysql-innodb-memcached-plugin"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["Oracle (MySQL)"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2021-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL injection in harvard subdomain",
                    "Link": "https://tomorrowisnew.com/posts/sql-injection-in-harvard-subdomain/"
                 }
              ],
              "Authors": ["Brandon Roldan (@tomorrowisnew_)"],
              "Programs": ["Harvard University"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-09-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Now Patched Vulnerability in WhatsApp could have led to data exposure of users",
                    "Link": "https://research.checkpoint.com/2021/now-patched-vulnerability-in-whatsapp-could-have-led-to-data-exposure-of-users/"
                 }
              ],
              "Authors": ["Dikla Barda", "Gal Elbaz"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2021-09-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full PoC | Metasploit Pro Trial License Request Limit Bypass",
                    "Link": "https://cho0k.com/wp-content/uploads/2021/08/FullPoC.pdf"
                 }
              ],
              "Authors": ["ChooK"],
              "Programs": ["Rapid7"],
              "Bugs": ["Privilege escalation", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dropping root shell in a Crypto Exchange for Fun and Profitn't",
                    "Link": "https://www.tnirmal.com.np/2021/08/dropping-root-shell-in-crypto-exchange.html"
                 }
              ],
              "Authors": ["Nirmal Thapa (@tnirmalz)"],
              "Programs": ["ChangeNOW"],
              "Bugs": ["RCE"],
              "Bounty": "1,000",
              "PublicationDate": "2021-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing 2-Factor Authentication for Facebook Business Manager (Bounty: 1000 USD)",
                    "Link": "https://theshubh77.medium.com/bypassing-2-factor-authentication-for-facebook-business-manager-bounty-1000-usd-c78c858459d6"
                 }
              ],
              "Authors": ["Shubham Bhamare (@theshubh77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "1,000",
              "PublicationDate": "2021-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Access Control Leads To Change Of Admin Details",
                    "Link": "https://v3d.medium.com/broken-access-control-leads-to-change-of-admin-details-a783e31729c4"
                 }
              ],
              "Authors": ["V3D (@v3d_bug)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Client-side enforcement of server-side security"],
              "Bounty": "-",
              "PublicationDate": "2021-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-39165: A Bug Bounty Journey from a Laravel SQL Injection Vulnerability",
                    "Link": "https://translate.google.com/translate?hl=en&sl=zh-CN&u=https://www.leavesongs.com/PENETRATION/cachet-from-laravel-sqli-to-bug-bounty.html&prev=search&pto=aue"
                 }
              ],
              "Authors": ["Xuan Tuyen"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-08-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Proxytoken: An Authentication Bypass In Microsoft Exchange Server",
                    "Link": "https://www.zerodayinitiative.com/blog/2021/8/30/proxytoken-an-authentication-bypass-in-microsoft-exchange-server"
                 }
              ],
              "Authors": ["Xuan Tuyen"],
              "Programs": ["Microsoft"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-08-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I owe your Request | HTTP Request Smuggling leads to Full Accounts takeover",
                    "Link": "https://itsfading.github.io/posts/I-owe-your-Request-HTTP-Request-Smuggling-leads-to-Full-Accounts-takeover/"
                 }
              ],
              "Authors": ["Muhammad Adel (@ItsFadinG_)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "-",
              "PublicationDate": "2021-08-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Two account takeover bugs worth $4300 🎁",
                    "Link": "https://blog.usamav.dev/two-account-takeover-bugs-worth-4300-dollar-bounty"
                 }
              ],
              "Authors": ["Usama Varikkottil (@usama_dev)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Privilege escalation", "403 bypass", "IDOR"],
              "Bounty": "4,300",
              "PublicationDate": "2021-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How MarkMonitor left >60,000 domains for the taking",
                    "Link": "https://ian.sh/markmonitor"
                 }
              ],
              "Authors": ["Ian Carroll (@iangcarroll)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting for XSS with CodeQL",
                    "Link": "https://medium.com/codex/hunting-for-xss-with-codeql-57f70763b938"
                 }
              ],
              "Authors": ["Daniel Santos (@bananabr)"],
              "Programs": ["GitLab"],
              "Bugs": ["XSS"],
              "Bounty": "500",
              "PublicationDate": "2021-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "What would you do if Oracle’s mailing server sent you this?",
                    "Link": "https://medium.com/@iambroot/what-would-you-do-if-oracles-mailing-server-sent-you-this-bc275b1bf967"
                 }
              ],
              "Authors": ["I am Broot"],
              "Programs": ["Oracle"],
              "Bugs": ["HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2021-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ATO of WordPress Website “4 digits €€€€ Bounty in 5 Minute!”",
                    "Link": "https://riteshgohil-25.medium.com/ato-of-wordpress-website-4-digits-bounty-in-5-minute-cc888c4054c9"
                 }
              ],
              "Authors": ["Ritesh Gohil (@RiteshG37659480)"],
              "Programs": ["-"],
              "Bugs": ["Exposed registration page", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Information disclosure via api misconfiguration",
                    "Link": "https://rizwansiddiqu1.medium.com/information-disclosure-via-api-misconfiguration-c05ed327f9d2"
                 }
              ],
              "Authors": ["Rizwan_siddiqui (@Rizwan_SiDdiqu1)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty: “My Remote Code Execution”",
                    "Link": "https://0xjin.medium.com/bug-bounty-my-remote-code-execution-da7bbd00925a"
                 }
              ],
              "Authors": ["0xJin (@0xJin)"],
              "Programs": ["-"],
              "Bugs": ["Default credentials", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cache Poisoning via SelfXSS + Path Parameter",
                    "Link": "https://web.archive.org/web/20210829191303/https://0u.ma/5"
                 }
              ],
              "Authors": ["ElMahdi Mrhassel (@ElMrhassel)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Web cache poisoning"],
              "Bounty": "-",
              "PublicationDate": "2021-08-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF External Service Interaction for Find Real IP CloudFlare and Leads to SQL Injection",
                    "Link": "https://caesarevan23.medium.com/ssrf-external-service-interaction-for-find-real-ip-cloudflare-and-leads-to-sql-injection-c22c02243299"
                 }
              ],
              "Authors": ["Caesar Evan Santoso"],
              "Programs": ["-"],
              "Bugs": ["WAF bypass", "SSRF", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-08-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Devops -Leak Source codes",
                    "Link": "https://medium.com/@hackrider/exploiting-devops-get-source-code-d4f5825eb373"
                 }
              ],
              "Authors": ["Shivbihari Pandey (@ninja_pandit_)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-08-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Scored 2K Bounty via an IDOR",
                    "Link": "https://infosecwriteups.com/how-i-scored-2k-bounty-via-an-idor-32eb2fa8aa1e"
                 }
              ],
              "Authors": ["Sicksec (@OriginalSicksec)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["IDOR"],
              "Bounty": "2,000",
              "PublicationDate": "2021-08-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How did I earned 6000$ from tokens and scopes in one day",
                    "Link": "https://infosecwriteups.com/how-did-i-earned-6000-from-tokens-and-scopes-in-one-day-12f95c6bf8aa"
                 }
              ],
              "Authors": ["Corraldev (@javier_corralg)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization", "Privilege escalation"],
              "Bounty": "6,000",
              "PublicationDate": "2021-08-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ChaosDB: Critical Vulnerability in Microsoft Azure Cosmos DB",
                    "Link": "https://chaosdb.wiz.io"
                 }
              ],
              "Authors": ["Nir Ohfeld (@nirohfeld)", "Sagi Tzadik (@sagitz_)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Account takeover", "Local Privilege Escalation"],
              "Bounty": "40,000",
              "PublicationDate": "2021-08-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Oauth client secret leak and possible IDOR leading to PII Disclosure",
                    "Link": "https://web.archive.org/web/20210920030213/https://pmoc.netsoc.cloud/oauth-idor-pii/"
                 }
              ],
              "Authors": ["Monke (@pmofcats)", "Bend Theory (@bendtheory)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "OAuth", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-08-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflective XSS via search box [Bypassing Cloudflare WAF].",
                    "Link": "https://medium.com/@friendly_/reflective-xss-via-search-box-bypassing-cloudflare-waf-841ed420b7f"
                 }
              ],
              "Authors": ["Friendly (@SkeletorKeys)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-08-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "‘Websocket Hijacking’ to steal Session_ID of victim users",
                    "Link": "https://sunilyedla.medium.com/websocket-hijacking-to-steal-session-id-of-victim-users-bca84243830"
                 }
              ],
              "Authors": ["Sunil Yedla (@sunilyedla2)"],
              "Programs": ["-"],
              "Bugs": ["Cross-Site WebSocket Hijacking (CSWH)"],
              "Bounty": "-",
              "PublicationDate": "2021-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwn2Own Vancouver 2021 :: Microsoft Exchange Server Remote Code Execution",
                    "Link": "https://srcincite.io/blog/2021/08/25/pwn2own-vancouver-2021-microsoft-exchange-server-remote-code-execution.html"
                 }
              ],
              "Authors": ["Steven Seeley (@steventseeley)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE", "MiTM"],
              "Bounty": "-",
              "PublicationDate": "2021-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business Logic Ratings Bug",
                    "Link": "https://maxwelldulin.com/BlogPost?post=7676291072"
                 }
              ],
              "Authors": ["Maxwell Dulin (@Dooflin5)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Retrieve Archived Stories Of Any Public Instagram Account.",
                    "Link": "https://web.archive.org/web/20210826141443/https://medium.com/@navnz/retrieve-archived-stories-of-any-public-instagram-account-b3f5a26851f5"
                 }
              ],
              "Authors": ["Naveen"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "GraphQL"],
              "Bounty": "-",
              "PublicationDate": "2021-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerability in Bumble dating app reveals any user's exact location",
                    "Link": "https://robertheaton.com/bumble-vulnerability/"
                 }
              ],
              "Authors": ["Robert Heaton (@RobJHeaton)"],
              "Programs": ["Bumble"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "2,000",
              "PublicationDate": "2021-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Nomulus rift",
                    "Link": "https://irsl.medium.com/the-nomulus-rift-935a3c4d9300"
                 }
              ],
              "Authors": ["Imre Rad (@ImreRad)"],
              "Programs": ["Google (Nomulus)"],
              "Bugs": ["Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2021-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "“How Companies Need to Widen There Scopes”",
                    "Link": "https://medium.com/@amnotacat/how-companies-need-to-widen-there-scopes-75ba19ac50c7"
                 }
              ],
              "Authors": ["amnotacat"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Components with known vulnerabilities"],
              "Bounty": "-",
              "PublicationDate": "2021-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One Endpoint, Two Account Takeovers",
                    "Link": "https://web.archive.org/web/20211207210720/https://securityflow.io/one-endpoint-two-account-takeovers/"
                 }
              ],
              "Authors": ["Yashar Shahinzadeh (@YShahinzadeh)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[$5K] Misconfigured Reset password that leads to Account Takeover (No user Interaction ATO)",
                    "Link": "https://medium.com/@noob.assassin/5k-misconfigured-reset-password-that-leads-to-account-takeover-no-user-interaction-ato-e6a36b8ef183"
                 }
              ],
              "Authors": ["Aditya Sharma (@Assass1nmarcos)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset", "Information disclosure"],
              "Bounty": "5,000",
              "PublicationDate": "2021-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to steal private files of any user on Larksuite",
                    "Link": "https://web.archive.org/web/20210825045217/https://medium.com/@imunissar786/how-i-was-able-to-steal-private-files-of-any-user-on-larksuite-c0e2757429e2"
                 }
              ],
              "Authors": ["Imran Nissar (@Imrannissar3)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "By Design: How Default Permissions on Microsoft Power Apps Exposed Millions",
                    "Link": "https://www.upguard.com/breaches/power-apps"
                 }
              ],
              "Authors": ["UpGuard Team (@upguard)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-08-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hey Google ! - Delete my Data Properly — #GoogleVRP",
                    "Link": "https://medium.com/techiepedia/hey-google-delete-my-data-properly-googlevrp-83349ca8e0e1"
                 }
              ],
              "Authors": ["Sriram Kesavan (@sriramoffcl)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-08-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zoom RCE from Pwn2Own 2021",
                    "Link": "https://sector7.computest.nl/post/2021-08-zoom/"
                 }
              ],
              "Authors": ["Thijs Alkemade (@xnyhps)", "Daan Keuper"],
              "Programs": ["Zoom"],
              "Bugs": ["RCE", "Memory corruption"],
              "Bounty": "200,000",
              "PublicationDate": "2021-08-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Server Side Request Forgery with huge impact in production application",
                    "Link": "https://medium.com/@gguzelkokar.mdbf15/huge-impact-server-side-request-forgery-in-production-app-20bf0cc5731"
                 }
              ],
              "Authors": ["Gökhan Güzelkokar (@gkhck_)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-08-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story Of Unexpected Bugs",
                    "Link": "https://medium.com/@nehpatel/story-of-unexpected-bugs-75734d51ac57"
                 }
              ],
              "Authors": ["Neh Patel (@thecyberneh)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-08-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "MonkeyType.com Stored Cross-Site Scripting",
                    "Link": "https://web.archive.org/web/20210909040725/https://obsrva.org/2021/08/22/monkeytype-disclosure.html"
                 }
              ],
              "Authors": ["Tyle Butler (@tbutler0x90)"],
              "Programs": ["MonkeyType.com"],
              "Bugs": ["Stored XSS", "Authentication bypass", "IDOR"],
              "Bounty": "40",
              "PublicationDate": "2021-08-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to get 1000$ bounty from a ds-store file?",
                    "Link": "https://xelkomy.medium.com/how-i-was-able-to-get-1000-bounty-from-a-ds-store-file-dc2b7175e92c"
                 }
              ],
              "Authors": ["Khaled Mohamed (@0xElkomy)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Debugging enabled"],
              "Bounty": "1,000",
              "PublicationDate": "2021-08-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Playing With s3 Leaks",
                    "Link": "https://aswinthambi.blogspot.com/2021/08/recon-for-bug-bounty.html"
                 }
              ],
              "Authors": ["Aswin Thambi Panikulangara (@r0074g3n7)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2021-08-21",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Timing Attack on SQL Queries Through Lobste.rs Password Reset",
                  "Link": "https://soatok.blog/2021/08/20/lobste-rs-password-reset-vulnerability/"
               }
            ],
            "Authors": ["Soatok (@SoatokDhole)"],
            "Programs": ["Lobste.rs"],
            "Bugs": ["Timing attack", "Password reset"],
            "Bounty": "-",
            "PublicationDate": "2021-08-20",
            "AddedDate": "2023-08-21"
         },
           {
              "Links": [
                 {
                    "Title": "How I found my first Subdomain Takeover vulnerability",
                    "Link": "https://monish-basaniwal.medium.com/how-i-found-my-first-subdomain-takeover-vulnerability-b7d5c17b61fd"
                 }
              ],
              "Authors": ["Monish Basaniwal"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover", "CSRF"],
              "Bounty": "375",
              "PublicationDate": "2021-08-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got RCE In The World Largest Russian Company",
                    "Link": "https://infosecwriteups.com/how-i-got-rce-in-the-world-largest-russian-company-8e6e8288bc4e"
                 }
              ],
              "Authors": ["Sicksec (@OriginalSicksec)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-08-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose WhatsApp Number of Instagram Accounts Despite Setting Set to be Hidden",
                    "Link": "https://www.yesnaveen.com/whatsapp-number-disclosure"
                 }
              ],
              "Authors": ["Naveen (@NaveenHax)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2021-08-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover via Access Token Leakage",
                    "Link": "https://tuhin1729.medium.com/account-takeover-via-access-token-leakage-687276953408"
                 }
              ],
              "Authors": ["Tuhin Bose (@tuhin1729_)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Information disclosure", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-08-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
               {
                  "Title": "A New Attack Surface on MS Exchange Part 1 - ProxyLogon!",
                  "Link": "https://devco.re/blog/2021/08/06/a-new-attack-surface-on-MS-exchange-part-1-ProxyLogon/"
               },
               {
                  "Title": "Part 2 - ProxyOracle!",
                  "Link": "https://devco.re/blog/2021/08/06/a-new-attack-surface-on-MS-exchange-part-2-ProxyOracle/"
               },
               {
                  "Title": "Part 3 - ProxyShell!",
                  "Link": "https://devco.re/blog/2021/08/22/a-new-attack-surface-on-MS-exchange-part-3-ProxyShell/"
               },
               {
                    "Title": "From Pwn2Own 2021: A New Attack Surface On Microsoft Exchange - Proxyshell!",
                    "Link": "https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell"
                 }
              ],
              "Authors": ["Orange Tsai (@orange_8361)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE", "Privilege escalation"],
              "Bounty": "200,000",
              "PublicationDate": "2021-08-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to Hack Apple ID",
                    "Link": "https://zemnmez.medium.com/how-to-hack-apple-id-f3cc9b483a41"
                 }
              ],
              "Authors": ["Zemnmez (@zemnmez)"],
              "Programs": ["Apple"],
              "Bugs": ["XSS", "Account takeover"],
              "Bounty": "10,000",
              "PublicationDate": "2021-08-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Confirming any new Email Address bug in Facebook (Part-4)",
                    "Link": "https://lokeshdlk77.medium.com/confirming-any-new-email-address-bug-in-facebook-part-4-70cfe1b4dca5"
                 }
              ],
              "Authors": ["Lokesh Kumar (@lokeshdlk77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Rate limiting bypass"],
              "Bounty": "3,449",
              "PublicationDate": "2021-08-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dangling DNS: Announcekit",
                    "Link": "https://blog.melbadry9.xyz/dangling-dns/xyz-services/ddns-announcekit"
                 }
              ],
              "Authors": ["Mohamed Elbadry (@_melbadry9)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-08-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Two weeks of securing Samsung devices: Part 2",
                    "Link": "https://blog.oversecured.com/Two-weeks-of-securing-Samsung-devices-Part-2/"
                 }
              ],
              "Authors": ["Oversecured (@OversecuredInc)"],
              "Programs": ["Samsung"],
              "Bugs": ["Arbitrary file write", "Arbitrary file read", "Vulnerable Android content provider", "Android"],
              "Bounty": "18,040",
              "PublicationDate": "2021-08-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-22929 – Brave Browser 1.27 and below permanently logs the server connection time for all v2 tor domains to ~/.config/BraveSoftware /Brave-Browser/tor/data/tor.log",
                    "Link": "https://sick.codes/sick-2021-109/"
                 }
              ],
              "Authors": ["sickcodes (@sickcodes)"],
              "Programs": ["Brave Software"],
              "Bugs": ["Privacy issue", "Information disclosure"],
              "Bounty": "400",
              "PublicationDate": "2021-08-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Bug's Life: CVE-2021-21225",
                    "Link": "https://tiszka.com/blog/CVE_2021_21225.html"
                 },
                 {
                    "Title": "Exploiting CVE-2021-21225 and disabling W^X",
                    "Link": "https://tiszka.com/blog/CVE_2021_21225_exploit.html"
                 }
              ],
              "Authors": ["Brendon Tiszka (@btiszka)"],
              "Programs": ["Google"],
              "Bugs": ["Browser hacking"],
              "Bounty": "22,000",
              "PublicationDate": "2021-08-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Why u should use burp to test Path Traversal Vulnerability and also get RXSS",
                    "Link": "https://infosecwriteups.com/why-u-should-use-burp-to-test-path-traversal-vulnerability-and-also-get-rxss-2743cbb16a3c"
                 }
              ],
              "Authors": ["Yasser Mohammed (@boomneroli)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal", "XSS", "CSRF", "Account takeover"],
              "Bounty": "700",
              "PublicationDate": "2021-08-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Second Order Subdomain Takeovers – They DO Exist!",
                    "Link": "https://blogs.msmvps.com/alunj/2021/08/15/second-order-subdomain-takeovers-they-do-exist/"
                 }
              ],
              "Authors": ["Alun Jones (@ftp_alun)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Subdomain takeover", "Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2021-08-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "1st Bug Bounty WriteUp: Open Redirect To XSS on Login Page",
                    "Link": "https://nassimchami.medium.com/1st-bug-bounty-writeup-open-redirect-to-xss-on-login-page-313221da2879"
                 }
              ],
              "Authors": ["Nassim Chami (@nvccim)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-08-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Simple HTML Injection to $250",
                    "Link": "https://ahmdhalabi.medium.com/taking-over-employee-accounts-by-managers-with-zero-employee-interaction-b60784c3ad84"
                 }
              ],
              "Authors": ["Ahmad Halabi (@Ahmad_Halabi_)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Mass assignment"],
              "Bounty": "600",
              "PublicationDate": "2021-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding multiple SSRF with aws metadata access on A BANK system",
                    "Link": "https://notifybugme.medium.com/finding-multiple-ssrf-with-aws-metadata-access-on-a-bank-system-7e73ac28e50a"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass Google Captcha+Parameter Pollution Leads to send email to any user on behalf of “Organization” with any desired content",
                    "Link": "https://medium.com/@viralbhatt100/bypass-google-captcha-parameter-pollution-leads-to-send-email-to-any-user-on-behalf-of-9013aebbabae"
                 }
              ],
              "Authors": ["viral bhatt (@viralbhatt100)"],
              "Programs": ["-"],
              "Bugs": ["HTTP parameter pollution", "Captcha bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Bug:Invite user to Like a Page even after they decline the Page Like Invite",
                    "Link": "https://medium.com/bug-bounty-hunting/facebook-bug-invite-user-to-like-a-page-even-after-they-decline-the-page-like-invite-f83d9ec845b3"
                 }
              ],
              "Authors": ["Circle Ninja (@circleninja)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How we was able to takeover whole organization via Privilege Escalation",
                    "Link": "https://infosecwriteups.com/how-we-was-able-to-takeover-whole-organization-via-privilege-escalation-4f74b31a84a6"
                 }
              ],
              "Authors": ["Yasser Mohammed (@boomneroli)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2021-08-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found read/write access to the personal data of 3 million users of an E-commerce website?",
                    "Link": "https://medium.com/@psr595bro/how-i-found-read-write-access-to-the-personal-data-of-3-million-users-of-an-e-commerce-website-b9026b0d4bd3"
                 }
              ],
              "Authors": ["Prashant Singh / SecGeek_one0one"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-08-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind SSRF in URL Validator",
                    "Link": "https://yasshk.medium.com/blind-ssrf-in-url-validator-93cbe7521c68"
                 }
              ],
              "Authors": ["Yash Kandekar (@Neutron__)"],
              "Programs": ["-"],
              "Bugs": ["Blind SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Taking Over Employee Accounts by Managers with Zero Employee Interaction",
                    "Link": "https://medium.com/@chaitanyarajhans024/simple-html-injection-to-250-895b760409ed"
                 }
              ],
              "Authors": ["Chaitanya Rajhans (@Chaitanya_024)"],
              "Programs": ["-"],
              "Bugs": ["HTML injection"],
              "Bounty": "250",
              "PublicationDate": "2021-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weaponizing Middleboxes for TCP Reflected Amplification",
                    "Link": "https://www.usenix.org/conference/usenixsecurity21/presentation/bock"
                 }
              ],
              "Authors": ["Kevin Bock", "Abdulrahman Alaraj", "Yair Fax", "Kyle Hurley", "Eric Wustrow", "Dave Levin"],
              "Programs": ["Check Point", "Cisco", "F5", "Fortinet", "Juniper", "Netscout", "Palo Alto", "SonicWall", "Sucuri"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-08-12",
              "AddedDate": "2022-10-02"
           },
           {
              "Links": [
                 {
                    "Title": "How I Bought a £240.00 Annual Subscription for Bargain £0.01",
                    "Link": "https://craighays.com/how-i-bought-a-240-pound-annual-subscription-for-bargain-1-penny/"
                 }
              ],
              "Authors": ["Craig Hays (@craighays)"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-08-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OVE-20210809-0001 Visual Studio Code .ipynb Jupyter Notebook XSS (Arbitrary File Read)",
                    "Link": "https://github.com/justinsteven/advisories/blob/master/2021_vscode_ipynb_xss_arbitrary_file_read.md"
                 }
              ],
              "Authors": ["Justin Steven (@justinsteven)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS", "Arbitrary file read"],
              "Bounty": "-",
              "PublicationDate": "2021-08-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Vulnerabilities In cPanel/WHM",
                    "Link": "https://www.fortbridge.co.uk/research/multiple-vulnerabilities-in-cpanel-whm/"
                 }
              ],
              "Authors": ["Adrian Tiron (@adrian__t)"],
              "Programs": ["cPanel"],
              "Bugs": ["XXE", "Stored XSS", "Privilege escalation", "CSRF", "Cross-Site WebSocket Hijacking (CSWH)"],
              "Bounty": "-",
              "PublicationDate": "2021-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fuzzing + IDOR = Admin TakeOver",
                    "Link": "https://medium.com/@gonzalocarrascosec/fuzzing-idor-admin-takeover-5343bb8f436e"
                 }
              ],
              "Authors": ["Gonzalo Carrasco (@0xCGonzalo)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "What is BOLA? 3-digit bounty from Topcoder ($$$)",
                    "Link": "https://infosecwriteups.com/what-is-bola-3-digit-bounty-from-topcoder-a25e7fae0d64"
                 }
              ],
              "Authors": ["can1337 (@canmustdie)"],
              "Programs": ["Topcoder"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-25738",
                    "Link": "https://j0vsec.com/post/cve-2021-25738/"
                 }
              ],
              "Authors": ["Jordy Versmissen / J0VSEC (@j0v0x0)"],
              "Programs": ["Kubernetes"],
              "Bugs": ["RCE"],
              "Bounty": "1,000",
              "PublicationDate": "2021-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-0090: Intel Driver & Support Assistant (DSA) Elevation Of Privilege (EOP)",
                    "Link": "https://bohops.com/2021/08/07/cve-2021-0090-intel-driver-support-assistant-dsa-elevation-of-privilege-eop/"
                 }
              ],
              "Authors": ["bohops (@bohops)"],
              "Programs": ["Intel"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Size Matters — CVE-2021–0485 (High)",
                    "Link": "https://valsamaras.medium.com/size-matters-cve-2021-0485-cfa0a291f903"
                 }
              ],
              "Authors": ["Dimitrios Valsamaras (@Ch0pin)"],
              "Programs": ["Google"],
              "Bugs": ["Local Privilege Escalation", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Access to CrowdTangle Deletion Framework API",
                    "Link": "https://philippeharewood.com/access-to-crowdtangle-deletion-framework-api/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "GraphQL"],
              "Bounty": "-",
              "PublicationDate": "2021-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "View the country of a private Instagram User",
                    "Link": "https://philippeharewood.com/view-the-country-of-a-private-instagram-user/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Access to CrowdTangle Deletion Framework API",
                    "Link": "https://philippeharewood.com/access-to-crowdtangle-deletion-framework-api/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw", "GraphQL"],
              "Bounty": "-",
              "PublicationDate": "2021-08-07",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "How I got Reflected Cross Site Scripting(RXSS) on Manchester Metropolitan University",
                  "Link": "https://santoshdbobade.medium.com/how-i-got-reflected-cross-site-scripting-rxss-on-manchester-metropolitan-university-700b36cb4f53"
               }
            ],
            "Authors": ["Santosh Bobade (@Santosh88267387)"],
            "Programs": ["Manchester Metropolitan University"],
            "Bugs": ["XSS"],
            "Bounty": "-",
            "PublicationDate": "2021-08-07",
            "AddedDate": "2022-11-08"
         },
           {
              "Links": [
                 {
                    "Title": "Do you like to read? I can take over your Kindle with an e-book",
                    "Link": "https://research.checkpoint.com/2021/i-can-take-over-your-kindle/"
                 }
              ],
              "Authors": ["Slava Makkaveev"],
              "Programs": ["Amazon"],
              "Bugs": ["Memory corruption", "RCE", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover (User + Admin) Via Password Reset",
                    "Link": "https://infosecwriteups.com/account-takeover-user-admin-via-password-reset-322b8020ea6"
                 }
              ],
              "Authors": ["Hemant Patidar (@HemantSolo)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset", "Logic flaw"],
              "Bounty": "200",
              "PublicationDate": "2021-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found Open Redirect on Hashnode.com",
                    "Link": "https://gonzx.medium.com/how-i-found-open-redirect-on-hashnode-com-5f3e9ecb8dc6"
                 }
              ],
              "Authors": ["Jefferson Gonzales (@gonzxph)"],
              "Programs": ["Hashnode"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2021-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PostMessage Xss vulnerability on private program",
                    "Link": "Youghourta Ghannei (@YoughartaG)"
                 }
              ],
              "Authors": ["Youghourta Ghannei (@YoughartaG)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "postMessage"],
              "Bounty": "-",
              "PublicationDate": "2021-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How the use of hidden form fields lead to Email verification bypass",
                    "Link": "https://yashswarup12.medium.com/how-the-use-of-hidden-form-fields-lead-to-email-verification-bypass-3c8d7c25bd31"
                 }
              ],
              "Authors": ["Yash Swarup (@wazirsec)"],
              "Programs": ["-"],
              "Bugs": ["Email verification bypass", "Client-side enforcement of server-side security"],
              "Bounty": "-",
              "PublicationDate": "2021-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Scored 1K Bounty Using Waybackurls",
                    "Link": "https://infosecwriteups.com/how-i-scored-1k-bounty-using-waybackurls-717d9673ca52"
                 }
              ],
              "Authors": ["Sicksec (@OriginalSicksec)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,000",
              "PublicationDate": "2021-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Detecting Jackson deserialization vulnerabilities with CodeQL",
                    "Link": "https://blog.gypsyengineer.com/en/security/detecting-jackson-deserialization-vulnerabilities-with-codeql.html"
                 }
              ],
              "Authors": ["Artem Smotrakov (@artem_smotrakov)"],
              "Programs": ["GitHub"],
              "Bugs": ["Insecure deserialization"],
              "Bounty": "4,500",
              "PublicationDate": "2021-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Messenger for android indirect thread deletion vulnerability.",
                    "Link": "https://servicenger.com/blog/mobile/android/facebook-messenger-for-android-indirect-thread-deletion/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Insecure deeplink"],
              "Bounty": "-",
              "PublicationDate": "2021-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "how to be popular",
                    "Link": "https://blog.azuki.vip/csrf/"
                 }
              ],
              "Authors": ["yan (@bcrypt)"],
              "Programs": ["OkCupid"],
              "Bugs": ["CSRF", "Type confusion"],
              "Bounty": "-",
              "PublicationDate": "2021-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "~/BugBounty/IDOR/”How I was able to exfiltrate any user’s credit coupons”",
                    "Link": "https://ja1sharma.medium.com/bugbounty-idor-how-i-was-able-to-exfiltrate-any-users-credit-coupons-49631d9f3bc8"
                 }
              ],
              "Authors": ["Jai Sharma (@ja1sharma)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation | stealing user’s point | Bugcrowd",
                    "Link": "https://medium.com/@abhinda1996/privilege-escalation-private-program-bugcrowd-831a7eb58b6c"
                 }
              ],
              "Authors": ["Abhind Abhi"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tale of XSS in Angular",
                    "Link": "https://medium.com/@sicks3c/tale-of-xss-in-angular-c5c057a56156"
                 }
              ],
              "Authors": ["Sicksec (@OriginalSicksec)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-08-02",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Bug bounty - PHI/PII critical data exposure",
                  "Link": "https://molx32.github.io/blog/2021/Bug-bounty-00/"
               }
            ],
            "Authors": ["Molx32"],
            "Programs": ["-"],
            "Bugs": ["Information disclosure"],
            "Bounty": "150",
            "PublicationDate": "2021-08-01",
            "AddedDate": "2023-04-27"
         },
           {
              "Links": [
                 {
                    "Title": "Blind XXE Leads to Internal Port Scanning Through SSRF",
                    "Link": "https://coffeejunkie.me/Blind-XXE-Port-Scanning/"
                 }
              ],
              "Authors": ["Sam Paredes (@caffeinevulns)"],
              "Programs": ["-"],
              "Bugs": ["XXE", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multi Domain DOM Cross Site Scripting",
                    "Link": "https://coffeejunkie.me/Multi-Domain-DOM-Cross-Site-Scripting/"
                 }
              ],
              "Authors": ["Sam Paredes (@caffeinevulns)"],
              "Programs": ["-"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The journey from Google Honorable Mention to Hall of Fame.",
                    "Link": "https://medium.com/pentesternepal/the-journey-from-google-honorable-mention-to-hall-of-fame-f62d9d5882ea"
                 }
              ],
              "Authors": ["Akash basnet (@noneofyou007)"],
              "Programs": ["Google"],
              "Bugs": ["Referer leakage", "Information disclosure", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2021-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Missing permission check for Facebook gaming community invites",
                    "Link": "https://philippeharewood.com/missing-permission-check-for-facebook-gaming-community-invites/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty Stories #1: Tale of CSP bypass in an electron app!",
                    "Link": "https://web.archive.org/web/20220303093431/https://securitygoat.medium.com/bug-bounty-stories-1-tale-of-csp-bypass-in-an-electron-app-f669f6ecefc9"
                 }
              ],
              "Authors": ["SecurityGOAT (@RuntimeSecurity)"],
              "Programs": ["-"],
              "Bugs": ["CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Hobby to Hacking",
                    "Link": "https://medium.com/@mumeido/from-hobby-to-hacking-5d8befb3adde"
                 }
              ],
              "Authors": ["Muhammad Syahrul Haniawan (@b0x_in)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE", "Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2021-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I escalate my Self-Stored XSS to Account Takeover with the help of IDOR",
                    "Link": "https://gonzx.medium.com/how-i-escalate-my-self-stored-xss-to-account-takeover-with-the-help-of-idor-f20733ecdbe9"
                 }
              ],
              "Authors": ["Jefferson Gonzales (@gonzxph)"],
              "Programs": ["HackerEarth"],
              "Bugs": ["Self-XSS", "IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I bypassed website using Akamai waf",
                    "Link": "https://web.archive.org/web/20210824230504/https://medium.com/@yusifceferov_/how-i-bypassed-website-using-akamai-waf-e4e907aeb161"
                 }
              ],
              "Authors": ["Yusif Cəfərov (@yusifceferov_)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Vulnerability: Expose Group Member — $3000",
                    "Link": "https://medium.com/@muhammadsholikhin/facebook-vulnerability-expose-group-member-3000-cca809a53f6b"
                 }
              ],
              "Authors": ["Muhammad Sholikhin (@MuhammadLikhin)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "3,000",
              "PublicationDate": "2021-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XXE in Public Transport Ticketing Mobile APP",
                    "Link": "https://blog.niksthehacker.com/xxe-in-public-transport-ticketing-mobile-app-81ae245c01a1"
                 }
              ],
              "Authors": ["Nikhil (niks) (@niksthehacker)"],
              "Programs": ["-"],
              "Bugs": ["XXE", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account takeover via stored xss",
                    "Link": "https://medium.com/@vikramroot/account-takeover-via-stored-xss-b774f7a2a3ab"
                 }
              ],
              "Authors": ["vikram naidu (@ImVikram7msd)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2021-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Bug Bounty: $500 worth client-side DoS on Google Keep",
                    "Link": "https://infosecwriteups.com/google-bug-bounty-500-worth-client-side-dos-on-google-keep-35aab6aef279"
                 }
              ],
              "Authors": ["Tommaso De Ponti (@heytdep)"],
              "Programs": ["Google"],
              "Bugs": ["Application-level DoS"],
              "Bounty": "500",
              "PublicationDate": "2021-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Gaining Access To GCP Of Google Stadia — 500$ Bounty",
                    "Link": "https://medium.com/@sebastien.kaul/gaining-access-to-gcp-of-google-stadia-500-bounty-22f76ecc8e60"
                 }
              ],
              "Authors": ["Sebastien Kaul"],
              "Programs": ["Google"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2021-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found my first IDOR in HackerOne",
                    "Link": "https://n1ghtmar3.medium.com/how-i-found-my-first-idor-in-hackerone-5d5f17bb431"
                 }
              ],
              "Authors": ["N1GHTMAR3 (@n1ghtmar3_2421)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could have hacked your medium account by phishing your FB, Twitter & Google credentials.",
                    "Link": "https://infosecwriteups.com/how-i-could-have-hacked-your-medium-account-by-phishing-your-fb-twitter-google-credentials-d53bf7096da7"
                 }
              ],
              "Authors": ["Renganathan (@IamRenganathan)"],
              "Programs": ["Medium"],
              "Bugs": ["Open redirect", "OAuth"],
              "Bounty": "-",
              "PublicationDate": "2021-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining Open Redirect with XSS to Account Takeover",
                    "Link": "https://radianid.medium.com/chaining-open-redirect-with-xss-to-account-takeover-36acf218a6d5"
                 }
              ],
              "Authors": ["Radian ID"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned $$$$ by Amazon S3 Bucket misconfigurations?",
                    "Link": "https://3bodymo.medium.com/how-i-earned-by-amazon-s3-bucket-misconfigurations-29d51ee510de"
                 }
              ],
              "Authors": ["Abdullah Mohamed (@3bodymo_)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration", "Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Information Disclosure to Account Takeover",
                    "Link": "https://sunilyedla.medium.com/information-disclosure-to-account-takeover-a21b2b54147a"
                 }
              ],
              "Authors": ["Sunil Yedla (@sunilyedla2)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "OAuth", "Account takeover", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pre-Auth RCE in Moodle Part I - PHP Object Injection in Shibboleth",
                    "Link": "https://haxolot.com/posts/2021/moodle_pre_auth_shibboleth_rce_part1/"
                 }
              ],
              "Authors": ["Johannes Moritz", "Robin Peraglie"],
              "Programs": ["Moodle"],
              "Bugs": ["RCE", "PHP object injection"],
              "Bounty": "-",
              "PublicationDate": "2021-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS-Special-Cases: XSS That Works only in mobile Devices",
                    "Link": "https://web.archive.org/web/20210927021132/https://0xdln.ml/XSS-Special-Cases/"
                 }
              ],
              "Authors": ["0xdln (@0xdln)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing JSON Web Token to steal accounts — 3000$",
                    "Link": "https://filipaze.medium.com/abusing-json-web-token-to-steal-accounts-3000-b9f7daeaef81"
                 }
              ],
              "Authors": ["Filipe Azevedo (@filipaze_)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "3,000",
              "PublicationDate": "2021-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Telegram Report: SSRF leads to DOS attack [Reports that didn't make it]",
                    "Link": "https://medium.com/bug-bounty/telegram-report-ssrf-leads-to-dos-attack-908bea5f5802"
                 }
              ],
              "Authors": ["Philippe Delteil (@PhilippeDelteil)"],
              "Programs": ["Telegram"],
              "Bugs": ["SSRF", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "You’ve Got (a Reset) Mail: A Security Analysis of Email-Based Password Reset Procedures",
                    "Link": "https://innotommy.com/You’ve%20Got%20%28a%20Reset%29%20Mail.pdf"
                 },
                 {
                    "Title": "Slides",
                    "Link": "https://innotommy.com/You’ve_Got_(a_Reset)_Mail-Slide.pdf"
                 }
              ],
              "Authors": ["Tommaso Innocenti (@innotommy)", "Ali Mirheidari", "Amin Kharraz (@amin_kharaz)", "Bruno Crispo", "Engin Kirda"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Host header injection", "CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XXE Case Studies",
                    "Link": "https://cinzinga.com/XXE-Case-Studies/"
                 }
              ],
              "Authors": ["cinzinga (@cinzinga_)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2021-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Apple Hall Of Fame for a Small Misconfiguration || Unauth Cache Purging",
                    "Link": "https://sapt.medium.com/apple-hall-of-fame-for-a-small-misconfiguration-unauth-cache-purging-faf81b19419b"
                 }
              ],
              "Authors": ["Prajit Sindhkar (@PrajitSindhkar)"],
              "Programs": ["Apple"],
              "Bugs": ["Unauthenticated cache purge"],
              "Bounty": "-",
              "PublicationDate": "2021-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Mattermost Server v5.32 > v5.36 Reflected XSS in OAuth flow",
                    "Link": "https://www.shielder.it/advisories/mattermost-server-reflected-xss-oauth/"
                 },
                 {
                    "Title": "HackerOne report",
                    "Link": "https://hackerone.com/reports/1216203"
                 }
              ],
              "Authors": ["zi0Black (@zi0Black)"],
              "Programs": ["Mattermost"],
              "Bugs": ["Reflected XSS", "OAuth"],
              "Bounty": "900",
              "PublicationDate": "2021-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Chain leads to Mass Account Takeover!",
                    "Link": "https://medium.com/@shubhayumajumdar/bug-chain-leads-to-mass-account-takeover-25dc76205f5d"
                 }
              ],
              "Authors": ["Shubhayu Majumdar (@shubhayu64)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Easy Bounty With Exposed Buckets & Blobs",
                    "Link": "https://mrd0x.com/easy-bounty-with-exposed-buckets-and-blobs/"
                 }
              ],
              "Authors": ["mr.d0x (@mrd0x)"],
              "Programs": ["-"],
              "Bugs": ["Cloud storage misconfiguration"],
              "Bounty": "1,450",
              "PublicationDate": "2021-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found a bug in Apple within just in 5min.",
                    "Link": "https://medium.com/pentesternepal/how-i-found-a-bug-in-apple-within-just-in-5min-d7357237d7a0"
                 }
              ],
              "Authors": ["Akash basnet (@noneofyou007)"],
              "Programs": ["Apple"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Not valid bug that leads to us a multiple Valid Report in Facebook",
                    "Link": "https://medium.com/@Kntjrld/not-valid-bug-that-leads-to-us-a-multiple-valid-report-in-facebook-25a3fb8cb51"
                 }
              ],
              "Authors": ["Kent Jarold Abulag (@wkemenhehehegsg)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,000",
              "PublicationDate": "2021-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "eBay XSS demo and guide to spear phishing",
                    "Link": "https://0x80dotblog.wordpress.com/2021/07/24/ebay-xss-demo-and-guide-to-spear-phishing/"
                 }
              ],
              "Authors": ["MLT (@0dayWizard)"],
              "Programs": ["Ebay"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found Multiple Bugs On FaceBook In 1 Month And a Part For My Methodology & Tools",
                    "Link": "https://orwaatyat.medium.com/how-i-found-multiple-bugs-on-facebook-in-1-month-and-a-part-for-my-methodology-tools-58a677a9040c"
                 }
              ],
              "Authors": ["Orwa Atyat (@GodfatherOrwa)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["SSTI", "SQL injection", "Authentication bypass", "Privilege escalation", "Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story OF MY 3RD Bounty From Facebook",
                    "Link": "https://imajk.medium.com/story-of-my-3rd-bounty-from-facebook-fef352853d1b"
                 }
              ],
              "Authors": ["Aashish Jung Kunwar (@WhoisAasis)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2021-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "FragAttacks",
                    "Link": "https://github.com/vanhoefm/fragattacks#fragattacks-fragmentation--aggregation-attacks"
                 },
                 {
                    "Title": "HackerOne report",
                    "Link": "https://hackerone.com/reports/1238470"
                 }
              ],
              "Authors": ["Mathy Vanhoef (@vanhoefm)"],
              "Programs": ["Internet Bug Bounty"],
              "Bugs": ["Wifi"],
              "Bounty": "750",
              "PublicationDate": "2021-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pre-Account Takeover by Reversing a Weak Email Verification Token Algorithm",
                    "Link": "https://craighays.com/pre-account-takeover-by-reversing-a-weak-email-verification-token-algorithm/"
                 }
              ],
              "Authors": ["Craig Hays (@craighays)"],
              "Programs": ["-"],
              "Bugs": ["Weak crypto"],
              "Bounty": "-",
              "PublicationDate": "2021-07-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated Access To MongoDB Database of Oracle Corporation",
                    "Link": "https://pratikkhalane91.medium.com/unauthenticated-access-to-mongodb-database-of-oracle-corporation-d825c271267a"
                 }
              ],
              "Authors": ["Pratikkhalane (@KhalanePratik)"],
              "Programs": ["Oracle"],
              "Bugs": ["Missing authentication", "Exposed administrative interface"],
              "Bounty": "-",
              "PublicationDate": "2021-07-22",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Forgot password? Taking over user accounts Kaminsky style",
                  "Link": "https://sec-consult.com/blog/detail/forgot-password-taking-over-user-accounts-kaminsky-style/"
               }
            ],
            "Authors": ["Timo Longin (@timolongin)"],
            "Programs": ["-"],
            "Bugs": ["IP fragmentation attack", "Kaminsky attack", "Password reset", "Account takeover", "DNS"],
            "Bounty": "-",
            "PublicationDate": "2021-07-21",
            "AddedDate": "2023-12-26"
         },
           {
              "Links": [
                 {
                    "Title": "Escalating Self-XSS To Stored XSS via Image injection + IDOR",
                    "Link": "https://www.r29k.com/articles/bb/self-xss-to-stored-xss"
                 }
              ],
              "Authors": ["Demon (@R29k_)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "Stored XSS", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Guest Blog Post - Attacking the DevTools",
                    "Link": "https://microsoftedge.github.io/edgevr/posts/attacking-the-devtools/"
                 }
              ],
              "Authors": ["David Erceg (@david_erceg)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Browser hacking"],
              "Bounty": "36,000",
              "PublicationDate": "2021-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS-Through-Fuzzing-Default-IIS",
                    "Link": "https://web.archive.org/web/20210924032932/https://0xdln.ml/XSS-Through-Fuzzing-Default-IIS/"
                 }
              ],
              "Authors": ["0xdln (@0xdln)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able Find mass leaked AWS s3 bucket from js File",
                    "Link": "https://notifybugme.medium.com/how-i-was-able-find-mass-leaked-aws-s3-bucket-from-js-file-6064a5c247f8"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2021-07-20",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "IBM HMC Exploit CVE-2021-29707",
                  "Link": "https://tomcope.com/exploit/2021/07/19/ibm-hmc-exploit-cve-2021-29707.html"
               }
            ],
            "Authors": ["Thomas Cope"],
            "Programs": ["IBM"],
            "Bugs": ["Local Privilege Escalation"],
            "Bounty": "-",
            "PublicationDate": "2020-10-21",
            "AddedDate": "2023-03-02"
         },
           {
              "Links": [
                 {
                    "Title": "Hacking Xiaomi'S Android Apps - Part 1",
                    "Link": "https://blog.takemyhand.xyz/2021/07/hacking-on-xiaomis-android-apps.html"
                 }
              ],
              "Authors": ["Ameya (@iamTakeMyHand)"],
              "Programs": ["Xiaomi"],
              "Bugs": ["Android", "Information disclosure", "Open redirect", "Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2021-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Bypassed a tough WAF to steal user cookies using XSS!",
                    "Link": "https://melotover.medium.com/how-i-bypassed-a-tough-waf-to-steal-user-cookies-using-xss-da75f28108e4"
                 }
              ],
              "Authors": ["Asem Eleraky (@melotover)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Vulnerability: $1500 for Removing Document Cover",
                    "Link": "https://medium.com/@muhammadsholikhin/facebook-vulnerability-1500-for-removing-document-cover-9ffd0173877b"
                 }
              ],
              "Authors": ["Muhammad Sholikhin (@MuhammadLikhin)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "IDOR"],
              "Bounty": "1,500",
              "PublicationDate": "2021-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover + A Bonus Vulnerability",
                    "Link": "https://medium.com/@kalvik/account-takeover-a-bonus-vulnerability-3c2dc4e607ea"
                 }
              ],
              "Authors": ["Vikash Maurya"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Session fixation"],
              "Bounty": "-",
              "PublicationDate": "2021-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE via WebDav - Power Of PUT",
                    "Link": "https://shahjerry33.medium.com/rce-via-webdav-power-of-put-7e1c06c71e60"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Default credentials", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IIS-Default-Page-to-Information-Disclosure",
                    "Link": "https://web.archive.org/web/20211017061704/https://0xdln.ml/IIS-Default-Page-to-Information-Disclosure/"
                 }
              ],
              "Authors": ["0xdln (@0xdln)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote code execution in cdnjs of Cloudflare",
                    "Link": "https://blog.ryotak.me/post/cdnjs-remote-code-execution-en/"
                 }
              ],
              "Authors": ["RyotaK (@ryotkak)"],
              "Programs": ["Cloudflare"],
              "Bugs": ["RCE", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2021-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Logical Flaw Resulting Path Hijacking",
                    "Link": "https://infosecwriteups.com/logical-flaw-resulting-path-hijacking-dd4d1e1e832f"
                 }
              ],
              "Authors": ["Veshraj Ghimire (@GhimireVeshraj)"],
              "Programs": ["-"],
              "Bugs": ["Namespace attack"],
              "Bounty": "-",
              "PublicationDate": "2021-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to bypass Cloudflare for XSS!",
                    "Link": "https://infosecwriteups.com/how-i-was-able-to-bypass-cloudflare-for-xss-e94cd827a5d6"
                 }
              ],
              "Authors": ["hosein vita (@HoseinVita)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RFD Vulnerability And Content-Disposition Header Bypass Story!",
                    "Link": "https://kabilan1290.medium.com/rfd-vulnerability-and-content-disposition-header-bypass-story-f8f962f54c7d"
                 }
              ],
              "Authors": ["Kabilan S (@kabilan1290)"],
              "Programs": ["-"],
              "Bugs": ["Reflected File Download"],
              "Bounty": "-",
              "PublicationDate": "2021-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in Google Doubleclick Studio [Google Research Grant]",
                    "Link": "https://jasminderpalsingh.info/stored-xss-in-google-doubleclick-studio-google-research-grant/"
                 }
              ],
              "Authors": ["Jasminder Pal Singh (@Singh_Jasminder)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found Blind SQL Injection just by browsing and getting a unique URL",
                    "Link": "https://medium.com/@jawadmahdi/how-i-found-blind-sql-injection-just-by-browsing-and-getting-a-unique-url-ed87fa1f35ed"
                 }
              ],
              "Authors": ["Jawad Mahdi (@hunter0x1)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Credential stuffing in Bug bounty hunting",
                    "Link": "https://krevetk0.medium.com/credential-stuffing-in-bug-bounty-hunting-7168dc1d3153"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["-"],
              "Bugs": ["Credential stuffing"],
              "Bounty": "8,300",
              "PublicationDate": "2021-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "($380) XSS STORED in Bigo Bug Bounty Program",
                    "Link": "https://aidilarf.medium.com/380-xss-stored-in-bigo-bug-bounty-program-a8b9529adcc4"
                 }
              ],
              "Authors": ["Aidil Arief"],
              "Programs": ["Bigo"],
              "Bugs": ["XSS"],
              "Bounty": "380",
              "PublicationDate": "2021-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Forced Browsing to Access Admin Panel",
                    "Link": "https://vijetareigns.medium.com/forced-browsing-to-access-admin-panel-214a7defa2a5"
                 }
              ],
              "Authors": ["the_unluck_guy (@7he_unlucky_guy)"],
              "Programs": ["-"],
              "Bugs": ["Forced browsing"],
              "Bounty": "-",
              "PublicationDate": "2021-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unencrypted HTTP Links to Google Scholar in Search",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0010"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["MiTM"],
              "Bounty": "-",
              "PublicationDate": "2021-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Part 2: Dive into Zoom Applications",
                    "Link": "https://rakesh-thodupunoori.medium.com/part-2-dive-into-zoom-applications-1b01091345c1"
                 }
              ],
              "Authors": ["Rakesh Thodupunoori (@rakesh_3895)"],
              "Programs": ["Zoom"],
              "Bugs": ["CSRF", "Account takeover", "Information disclosure", "Session expiration issue", "Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Apple Security Bounty: A personal experience",
                    "Link": "https://medium.com/macoclock/apple-security-bounty-a-personal-experience-fe9a57a81943"
                 }
              ],
              "Authors": ["Nicolas Brunner"],
              "Programs": ["Apple"],
              "Bugs": ["Permission bypass", "iOS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Access control bug : Bypassing 403’s by finding another endpoint that do the same thing.",
                    "Link": "https://tomorrowisnew.com/posts/broken-access-control-bug-bypassing-403-s-by-finding-another-endpoint-that-do-the-same-thing/"
                 }
              ],
              "Authors": ["tomorrowisnew (@tomorrowisnew_)"],
              "Programs": ["-"],
              "Bugs": ["Broken Access Control", "403 bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Trick to bypass rate limit of password reset functionality",
                    "Link": "https://4bdoz.medium.com/trick-to-bypass-rate-limit-of-password-reset-functionality-a9923d3d7c4b"
                 }
              ],
              "Authors": ["Abdulrahman-Kamel"],
              "Programs": ["-"],
              "Bugs": ["Rate limiting bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pre-Denial Of Service (set-up 2FA on unverified account)",
                    "Link": "https://medium.com/@kalvik/pre-denial-of-service-set-up-2fa-on-unverified-account-8399af52ea2d"
                 }
              ],
              "Authors": ["Vikash Maurya"],
              "Programs": ["-"],
              "Bugs": ["Application-level DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Critical Bug Bounty Reports: Part 1",
                    "Link": "https://infosecwriteups.com/critical-bug-bounty-reports-part-1-6fd9aef4b486"
                 }
              ],
              "Authors": ["Greg Gibson"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset", "RCE", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-07-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS Through Insecure Dynamic Loading",
                    "Link": "https://infosecwriteups.com/reflected-xss-through-insecure-dynamic-loading-dbf4d33611e0"
                 }
              ],
              "Authors": ["Greg Gibson"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Whose app are you downloading? Link hijacking Binance’s shortlinks through AppsFlyer",
                    "Link": "https://web.archive.org/web/20210711090831/https://palisade.consulting/blog/link-hijacking-binances-shortlinks-through-appsflyer"
                 }
              ],
              "Authors": ["Sam Curry (@samwcyo)"],
              "Programs": ["Chess.com"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2021-07-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeovers — Believe the Unbelievable",
                    "Link": "https://infosecwriteups.com/account-takeovers-believe-the-unbelievable-bb98a0c251a4"
                 }
              ],
              "Authors": ["Nikhil (niks) (@niksthehacker)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Session management issue", "Weak credentials", "Components with known vulnerabilities", "Password reset"],
              "Bounty": "5,751",
              "PublicationDate": "2021-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Email/phone disclosure using Binary search",
                    "Link": "https://medium.com/pentesternepal/facebook-email-phone-disclosure-using-binary-search-d50430758c54"
                 }
              ],
              "Authors": ["Rikesh Baniya (@rikeshbaniya)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Password reset", "Information disclosure", "Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2021-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Discovering Zero-Day Vulnerabilities in McAfee Products",
                    "Link": "https://mrd0x.com/discovering-mcafee-products-zero-day-vulnerabilities/"
                 }
              ],
              "Authors": ["mr.d0x (@mrd0x)"],
              "Programs": ["McAfee"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR on clientauthconfig.googleapis.com",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0009"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-07-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-22555: Turning \\x00\\x00 into 10000$",
                    "Link": "https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html"
                 }
              ],
              "Authors": ["Andy Nguyen (@theflow0)"],
              "Programs": ["Google"],
              "Bugs": ["Memory corruption", "Local Privilege Escalation"],
              "Bounty": "10,000",
              "PublicationDate": "2021-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Let’s cancel the subscription (informative)",
                    "Link": "https://adnanmalik.info/blog/lets-cancel-the-subscription/"
                 }
              ],
              "Authors": ["Adnan Malik (@adnanmalikinfo)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2021-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Kaspersky Password Manager: All your passwords are belong to us",
                    "Link": "https://donjon.ledger.com/kaspersky-password-manager/"
                 }
              ],
              "Authors": ["Jean-Baptiste Bédrune"],
              "Programs": ["Kaspersky"],
              "Bugs": ["Weak crypto"],
              "Bounty": "-",
              "PublicationDate": "2021-07-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Auto-save Functionality To Steal Login Credentials",
                    "Link": "https://saadahmedx.medium.com/exploiting-auto-save-functionality-to-steal-login-credentials-bf4c7e1594da"
                 }
              ],
              "Authors": ["Saad Ahmed (@XSaadAhmedX)"],
              "Programs": ["-"],
              "Bugs": ["HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2021-07-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Solarwinds Serv-U 15.2.3 Share URL XSS (CVE-2021-32604)",
                    "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/solarwinds-serv-u-1523-share-url-xss-cve-2021-32604/"
                 }
              ],
              "Authors": ["Victor Kahan"],
              "Programs": ["SolarWinds"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-07-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind XSS in Apple School- Enrollment Data Disclosure",
                    "Link": "https://hackrzvijay.medium.com/blind-xss-in-apple-school-enrollment-data-disclosure-a94c1da5bf54"
                 }
              ],
              "Authors": ["hackrzvijay (@hackrzvijay)"],
              "Programs": ["Apple"],
              "Bugs": ["Blind XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2021-07-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "View Other User Private Livestream Data",
                    "Link": "https://gevakun.medium.com/view-other-user-private-livestream-data-e30a0acb5972"
                 }
              ],
              "Authors": ["Geva (@Geva_7)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-07-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bulletin.com email address leak",
                    "Link": "https://philippeharewood.com/bulletin-com-email-address-leak/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "GraphQL"],
              "Bounty": "3,750",
              "PublicationDate": "2021-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Testing Cookies worth $500",
                    "Link": "https://sankalpa02.medium.com/testing-cookies-worth-500-8fc2310e6d7e"
                 }
              ],
              "Authors": ["Sankalpa Acharya (@sankalpa_02)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "IDOR"],
              "Bounty": "500",
              "PublicationDate": "2021-06-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding DOM Polyglot XSS in PayPal the Easy Way",
                    "Link": "https://portswigger.net/research/finding-dom-polyglot-xss-in-paypal-the-easy-way"
                 }
              ],
              "Authors": ["Gareth Heyes (@garethheyes)"],
              "Programs": ["Paypal"],
              "Bugs": ["DOM XSS", "CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-06-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464)",
                    "Link": "https://portswigger.net/research/pre-auth-rce-in-forgerock-openam-cve-2021-35464"
                 }
              ],
              "Authors": ["Michael Stepankin (@artsploit)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2021-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to Takeover Accounts on Foxit.com",
                    "Link": "https://medium.com/techiepedia/how-i-was-able-to-takeover-any-account-on-foxit-com-7a08efa0144f"
                 }
              ],
              "Authors": ["Jefferson Gonzales (@gonzxph)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "gcp-dhcp-takeover-code-exec",
                    "Link": "https://github.com/irsl/gcp-dhcp-takeover-code-exec"
                 }
              ],
              "Authors": ["Imre Rad (@ImreRad)"],
              "Programs": ["Google"],
              "Bugs": ["DHCP flood", "VM takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found my first Chrome bug (CVE-2021–21210)",
                    "Link": "https://vovohelo.medium.com/how-i-found-my-first-chrome-bug-cve-2021-21210-248a21272248"
                 }
              ],
              "Authors": ["Daniel Santos (@bananabr)"],
              "Programs": ["Google (Chrome)"],
              "Bugs": ["NAT Slipstreaming"],
              "Bounty": "-",
              "PublicationDate": "2021-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Diving into Dependabot along with a bug in npm",
                    "Link": "https://blog.tyage.net/posts/2021-06-27-dependabot-rce/"
                 }
              ],
              "Authors": ["tyage (@tyage)"],
              "Programs": ["GitHub"],
              "Bugs": ["SSRF", "RCE"],
              "Bounty": "8,117",
              "PublicationDate": "2021-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Taking over Uber accounts through voicemail",
                    "Link": "https://web.archive.org/web/20210706150728/https://blog.assetnote.io/2021/06/27/uber-account-takeover-voicemail/"
                 }
              ],
              "Authors": ["Shubham Shah (@infosec_au)"],
              "Programs": ["Uber"],
              "Bugs": ["Account takeover", "Voicemail hacking"],
              "Bounty": "-",
              "PublicationDate": "2021-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Misconfigured $3 Bucket - A Semi Opened Environment",
                    "Link": "https://medium.com/techiepedia/misconfigured-3-bucket-a-semi-opened-environment-9cfb9dee782d"
                 }
              ],
              "Authors": ["Yukesh Kumar (@3th1c_yuk1)"],
              "Programs": ["Redbull"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2021-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating XSS to Arbitrary File Read",
                    "Link": "https://www.pethuraj.com/blog/escalating-xss-to-arbitrary-file-read/"
                 }
              ],
              "Authors": ["Pethuraj (@Pethuraj)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2021-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Oversightboard.com site-wide CSRF due to missing checking",
                    "Link": "https://ysamm.com/?p=702"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "500",
              "PublicationDate": "2021-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose unconfirmed email/phone of a Facebook user",
                    "Link": "https://ysamm.com/?p=700"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2021-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Some ways to find more IDOR",
                    "Link": "https://16521092.medium.com/some-ways-to-find-more-idor-da16c93954e5"
                 }
              ],
              "Authors": ["Thái Vũ  (@thaivd98)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-06-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Gaining access to protected components",
                    "Link": "https://blog.mzfr.me/posts/2021-06-24-unexported-component/"
                 }
              ],
              "Authors": ["DavMehtab Zafar (@0xmzfr)"],
              "Programs": ["-"],
              "Bugs": ["Vulnerable Android content provider", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-06-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Information Disclosure to interesting Privilege Escalation",
                    "Link": "https://dudy2kk.medium.com/from-information-disclosure-to-interesting-privilege-escalation-61ed3aaaf218"
                 }
              ],
              "Authors": ["David Shaul (@dudy2kk)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Account takeover", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-06-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PII Leakage - Revealing Secrets",
                    "Link": "https://shahjerry33.medium.com/pii-leakage-revealing-secrets-8b617071bd1c"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-06-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A supply-chain breach: Taking over an Atlassian account",
                    "Link": "https://research.checkpoint.com/2021/a-supply-chain-breach-taking-over-an-atlassian-account/"
                 }
              ],
              "Authors": ["Dikla Barda, Yaara Shriki", "Roman Zaikin (@R0m4nZ41k1n)", "Oded Vanunu (@Od3dV)"],
              "Programs": ["Atlassian"],
              "Bugs": ["XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Flywheel Subdomain Takeover",
                    "Link": "https://smaranchand.com.np/2021/06/flywheel-subdomain-takeover/"
                 }
              ],
              "Authors": ["Smaran Chand (@smaranchand)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "MSRC is confused! 😕",
                    "Link": "https://web.archive.org/web/20210910154714/https://ricardoiramar.medium.com/msrc-is-confused-5d86b23c2e88"
                 }
              ],
              "Authors": ["Ricardo Iramar dos Santos (@ricardo_iramar)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Dependency confusion"],
              "Bounty": "-",
              "PublicationDate": "2021-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Store free purschase vulnerabilites",
                    "Link": "https://gccybermonks.com/posts/msstorebypass/"
                 }
              ],
              "Authors": ["Marlon Fabiano (@astrounder)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Payment tampering", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Three Microsoft Store vulnerabilites",
                    "Link": "https://gccybermonks.com/posts/msstore/"
                 }
              ],
              "Authors": ["Marlon Fabiano (@astrounder)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Payment tampering", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to get Appreciation from the organization of a website just by changing a sign..!!!",
                    "Link": "https://fardeen-ahmed.medium.com/how-i-was-able-to-get-appreciation-from-the-organization-of-a-website-just-by-changing-a-sign-661042c97a98"
                 }
              ],
              "Authors": ["Fardeen Ahmed (@fardeenahmed411)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Source code disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-06-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Generate online votes using Race Condition Vulnerability in Woobox Web Application (Write Up)",
                    "Link": "https://blog.evanricafort.com/2021/06/generate-online-votes-using-race.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Woobox"],
              "Bugs": ["Race condition"],
              "Bounty": "-",
              "PublicationDate": "2021-06-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cracking Encrypted Credit Card Numbers Exposed By API",
                    "Link": "https://craighays.com/cracking-encrypted-credit-card-numbers-exposed-by-api/"
                 }
              ],
              "Authors": ["Craig Hays (@craighays)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Weak crypto"],
              "Bounty": "-",
              "PublicationDate": "2021-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS via Invite leading to Mass Account Takeover at Opera.",
                    "Link": "https://sm4rty.medium.com/stored-xss-via-invite-leading-to-mass-account-takeover-at-opera-a85ed257dd12"
                 }
              ],
              "Authors": ["Samrat Gupta (@Sm4rty_)"],
              "Programs": ["Opera"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unprivileged User with Read/Write permission to `User Access` can escalate their role to ADMIN — Privilege Escalation",
                    "Link": "https://ertugrull.medium.com/unprivileged-user-with-read-write-permission-to-user-access-can-escalate-their-role-to-admin-a217d2d280a8"
                 }
              ],
              "Authors": ["Ertugrul Ozdemir  (@ertugrulphp)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found A Vulnerability To Hack iCloud Accounts and How Apple Reacted To It",
                    "Link": "https://thezerohack.com/apple-vulnerability-bug-bounty"
                 }
              ],
              "Authors": ["Laxman Muthiyah (@laxmanmuthiyah)"],
              "Programs": ["Apple"],
              "Bugs": ["Account takeover", "2FA / MFA bypass", "Rate limiting bypass", "Race condition"],
              "Bounty": "18,000",
              "PublicationDate": "2021-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full Local File Read via Error Based XXE using XLIFF File",
                    "Link": "https://pwn.vg/articles/2021-06/local-file-read-via-error-based-xxe"
                 }
              ],
              "Authors": ["pwn.vg / Tomi (@mastomii)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2021-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zero Click account Takeover",
                    "Link": "https://medium.com/@zahirtariq/zero-click-account-takeover-32e888d13e73"
                 }
              ],
              "Authors": ["Zahir Tariq (@ZahirTariq3)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2021-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting File Upload Functionality in Unique Way.",
                    "Link": "https://rohit-soni.medium.com/exploiting-file-upload-functionality-in-unique-way-6081b8f658dd"
                 }
              ],
              "Authors": ["Rohit Soni (@streetofhacker)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2021-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accessing Restricted Documents With Extra JSON Body Content",
                    "Link": "https://imranhudaa.medium.com/accessing-restricted-documentswith-extra-json-body-content-c59bc7224189"
                 }
              ],
              "Authors": ["Imran Huda (@imranHudaA)"],
              "Programs": ["-"],
              "Bugs": ["Mass assignment", "Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2021-06-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account takeover via stored XSS with arbitrary file upload",
                    "Link": "https://0xbadb00da.medium.com/account-takeover-via-stored-xss-with-arbitrary-file-upload-2774ec6cff51"
                 }
              ],
              "Authors": ["0xbadb00da (@0xbadb00da)"],
              "Programs": ["-"],
              "Bugs": ["Insecure file upload", "XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-06-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "M1 Macs GateKeeper bypass aka CVE-2021-30658",
                    "Link": "https://wojciechregula.blog/post/m1-macs-gatekeeper-bypass-aka-cve-2021-30658/"
                 }
              ],
              "Authors": ["Wojciech Reguła (@_r3ggi)"],
              "Programs": ["Apple"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-06-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How We Are Able To Hack Any Company By Sending Message - $20,000 Bounty [CVE-2021–34506]",
                    "Link": "https://cyberxplore.medium.com/how-we-are-able-to-hack-any-company-by-sending-message-including-facebook-google-microsoft-b7773626e447"
                 },
                 {
                    "Title": "Video PoC",
                    "Link": "https://www.youtube.com/watch?v=XfTN7fPtB1s"
                 }
              ],
              "Authors": ["Vansh Devgan (@Th3Pr0xyB0y)", "Shivam Kumar Singh (@MrRajputHacker)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Universal XSS"],
              "Bounty": "20,000",
              "PublicationDate": "2021-06-18",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Certified Pre-Owned",
                  "Link": "https://posts.specterops.io/certified-pre-owned-d95910965cd2"
               }
            ],
            "Authors": ["Will Schroeder (@harmj0y)", "Lee Christensen (@tifkin_)"],
            "Programs": ["Microsoft"],
            "Bugs": ["Active Directory Privilege Escalation", "ADCS", "Windows"],
            "Bounty": "-",
            "PublicationDate": "2021-06-17",
            "AddedDate": "2022-11-17"
         },
         {
              "Links": [
                 {
                    "Title": "HTML Injection and a dream in Google Chrome for Linux (Write Up)",
                    "Link": "https://blog.evanricafort.com/2021/06/html-injection-and-a-dream.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Google"],
              "Bugs": ["HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2021-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Crashing your LinkedIn app with a connection request.",
                    "Link": "https://infosecwriteups.com/crashing-your-linkedin-app-with-a-connection-request-257f9b484550"
                 }
              ],
              "Authors": ["Renganathan (@IamRenganathan)"],
              "Programs": ["LinkedIn"],
              "Bugs": ["Application-level DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Why dynamic code loading could be dangerous for your apps: a Google example",
                    "Link": "https://blog.oversecured.com/Why-dynamic-code-loading-could-be-dangerous-for-your-apps-a-Google-example/"
                 }
              ],
              "Authors": ["Oversecured (@OversecuredInc)"],
              "Programs": ["Google"],
              "Bugs": ["Arbitrary file write", "Insecure intent", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Part-1 Dive into Zoom Applications",
                    "Link": "https://rakesh-thodupunoori.medium.com/part-1-dive-into-zoom-applications-d70f3de53ec5"
                 }
              ],
              "Authors": ["Rakesh Thodupunoori (@rakesh_3895)"],
              "Programs": ["Zoom"],
              "Bugs": ["CSRF", "Payment bypass", "Logic flaw", "Account takeover", "Privilege escalation"],
              "Bounty": "22,000",
              "PublicationDate": "2021-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of Google Hall of Fame and Private program bounty worth $$$$",
                    "Link": "https://infosecwriteups.com/story-of-google-hall-of-fame-and-private-program-bounty-worth-53559a95c468"
                 }
              ],
              "Authors": ["Basavaraj Banakar (@basu_banakar)"],
              "Programs": ["Google"],
              "Bugs": ["Exposed registration page"],
              "Bounty": "-",
              "PublicationDate": "2021-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One-click DOS via Response Manipulation",
                    "Link": "https://inakcf.medium.com/one-click-dos-via-response-manipulation-2f08da421104"
                 }
              ],
              "Authors": ["Akhil"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authentication Bypass | Easy P1 in 10 minutes",
                    "Link": "https://infosecwriteups.com/authentication-bypass-easy-p1-in-10-minutes-54d5a2093e54"
                 }
              ],
              "Authors": ["Anirudh Makkar (@anirudhmakkar)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "Forced browsing"],
              "Bounty": "-",
              "PublicationDate": "2021-06-16",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Unauthenticated Gitlab SSRF",
                  "Link": "https://vin01.github.io/piptagole/gitlab/ssrf/security/bugbounty/2021/06/15/gitlab-ssrf.html"
               }
            ],
            "Authors": ["Vin01"],
            "Programs": ["GitLab"],
            "Bugs": ["SSRF", "CI/CD"],
            "Bounty": "-",
            "PublicationDate": "2021-06-15",
            "AddedDate": "2024-02-06"
         },
           {
            "Links": [
               {
                  "Title": "How We Are Able To Hack Any Company By Sending Message – $20,000 Bounty [CVE-2021–34506]",
                  "Link": "https://blog.cyberxplore.com/how-we-are-able-to-hack-any-company-by-sending-message-20000-bounty-cve-2021-34506/"
               }
            ],
            "Authors": ["Shivam Kumar Singh (@MrRajputHacker)", "Vansh Devgan (@Th3Pr0xyB0y)"],
            "Programs": ["Microsoft"],
            "Bugs": ["Universal XSS"],
            "Bounty": "20,000",
            "PublicationDate": "2021-06-15",
            "AddedDate": "2023-02-13"
         },
           {
              "Links": [
                 {
                    "Title": "This is how I was able to see Private, Archived Posts/Stories of users on Instagram without following them",
                    "Link": "https://fartademayur.medium.com/this-is-how-i-was-able-to-see-private-archived-posts-stories-of-users-on-instagram-without-de70ca39165c"
                 }
              ],
              "Authors": ["Mayur Fartade (@mayurfartade)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "GraphQL"],
              "Bounty": "30,000",
              "PublicationDate": "2021-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Importance of burp history analysis to bypass 403",
                    "Link": "https://infosecwriteups.com/importance-of-burp-history-analysis-to-bypass-403-afc7af6c08b"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["403 bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting outdated Apache Airflow instances",
                    "Link": "https://ian.sh/airflow"
                 },
                 {
                    "Title": "Blast Radius: Apache Airflow Vulnerabilities",
                    "Link": "https://securitytrails.com/blog/blast-radius-airflow"
                 }
              ],
              "Authors": ["Ian Carroll (@iangcarroll)"],
              "Programs": ["-"],
              "Bugs": ["Session management issue"],
              "Bounty": "13,000",
              "PublicationDate": "2021-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing tokens, emails, files and more in Microsoft Teams through malicious tabs",
                    "Link": "https://medium.com/tenable-techblog/stealing-tokens-emails-files-and-more-in-microsoft-teams-through-malicious-tabs-a7e5ff07b138"
                 }
              ],
              "Authors": ["Evan Grant (@stargravy)"],
              "Programs": ["Microsoft"],
              "Bugs": ["postMessage", "Token leak"],
              "Bounty": "-",
              "PublicationDate": "2021-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind Command Injection - It hurts",
                    "Link": "https://shahjerry33.medium.com/blind-command-injection-it-hurts-9f396c1f63f2"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Command injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An exciting journey to find SSRF , Bypass Cloudflare , and extract AWS metadata !",
                    "Link": "https://hosein-vita.medium.com/an-exciting-journey-to-find-ssrf-bypass-cloudflare-and-extract-aws-metadata-fdb8be0b5f79"
                 }
              ],
              "Authors": ["hosein vita (@HoseinVita)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "User’s location diclosure in the “Nearby Friends” feature. $15,500 Bounty",
                    "Link": "https://otmastimi.medium.com/users-location-diclosure-in-the-nearby-friends-feature-fabd24be05cb"
                 }
              ],
              "Authors": ["Yavor Rusev / Явор Русев"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,500",
              "PublicationDate": "2021-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Google VRP] Privilege escalation on https://dialogflow.cloud.google.com",
                    "Link": "https://0x01alka.medium.com/google-vrp-privilege-escalation-on-https-dialogflow-cloud-google-com-599af6c4516d"
                 }
              ],
              "Authors": ["lalka (@0x01alka)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "3,133.70",
              "PublicationDate": "2021-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of Account Takeover : Using Social Login with Mass Assignment Vulnerability to hack accounts !",
                    "Link": "https://kaif0x01.medium.com/story-of-account-takeover-using-social-login-with-mass-assignment-vulnerability-to-hack-accounts-21e4d5856f5e"
                 }
              ],
              "Authors": ["Mohammad Kaif"],
              "Programs": ["-"],
              "Bugs": ["Mass assignment", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found the silliest logical vulnerability for $750 that no one found for 3 years",
                    "Link": "https://sinsinology.medium.com/how-i-found-the-silliest-logical-vulnerability-for-750-d4f49e5b8763"
                 }
              ],
              "Authors": ["Sina Kheirkhah (@SinSinology)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "750",
              "PublicationDate": "2021-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to bypass the admin panel without the credentials.",
                    "Link": "https://pratikkhalane91.medium.com/how-i-was-able-to-bypass-the-admin-panel-without-the-credentials-d65f90e0e1e4"
                 }
              ],
              "Authors": ["Pratikkhalane (@KhalanePratik)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2021-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing 2FA using OpenID Misconfiguration",
                    "Link": "https://youst.in/posts/bypassing-2fa-using-openid-misconfiguration/"
                 }
              ],
              "Authors": ["Youstin (@iustinBB)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass", "Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2021-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Two weeks of securing Samsung devices: Part 1",
                    "Link": "https://blog.oversecured.com/Two-weeks-of-securing-Samsung-devices-Part-1/"
                 }
              ],
              "Authors": ["Oversecured (@OversecuredInc)"],
              "Programs": ["Samsung"],
              "Bugs": ["Arbitrary file write", "Insecure intent", "Android"],
              "Bounty": "20,690",
              "PublicationDate": "2021-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Second Order Race Condition",
                    "Link": "https://0xdekster.medium.com/second-order-race-condition-be8aaf774783"
                 }
              ],
              "Authors": ["Prasoon Gupta (@0xdekster)"],
              "Programs": ["-"],
              "Bugs": ["Race condition"],
              "Bounty": "1,000",
              "PublicationDate": "2021-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unexpected IDOR Vulnerability in [REDACTED] - [redacted].net (Write Up)",
                    "Link": "https://blog.evanricafort.com/2021/06/2usd-idor-bug-in-redacted.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "2",
              "PublicationDate": "2021-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Author spoofing in Google Colaboratory",
                    "Link": "https://www.ehpus.com/post/author-spoofing-in-google-colaboratory"
                 }
              ],
              "Authors": ["Zohar Shachar"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2021-06-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to bypass parental pin of showmax",
                    "Link": "https://infosecwriteups.com/how-i-was-able-to-bypass-parental-pin-of-showmax-e6d6ec3af92d"
                 }
              ],
              "Authors": ["abdulsec (@moodiAbdoul)"],
              "Programs": ["Showmax"],
              "Bugs": ["Broken authorization"],
              "Bounty": "200",
              "PublicationDate": "2021-06-09",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Joomla Password Reset Vulnerability And A Stored XSS For Full Compromise",
                  "Link": "https://fortbridge.co.uk/research/joomla-password-reset-vulnerability-and-stored-xss-for-full-compromise/"
               }
            ],
            "Authors": ["Adrian Tiron (@Adrian__T)"],
            "Programs": ["-"],
            "Bugs": ["Password reset", "Stored XSS", "Privilege escalation", "RCE", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2021-06-07",
            "AddedDate": "2023-05-04"
         },
           {
              "Links": [
                 {
                    "Title": "Story of my first cash bounty on hackerone.",
                    "Link": "https://vedanttekale20.medium.com/story-of-my-first-cash-bounty-on-hackerone-acad282ae962"
                 }
              ],
              "Authors": ["Vedant Tekale (@_justYnot)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-06-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could have accessed all your private videos/photos saved inside your device without even unlocking it?",
                    "Link": "https://samiparyal.medium.com/how-i-could-have-accessed-all-your-private-videos-photos-saved-inside-your-device-without-even-1a7e455ddcc8"
                 }
              ],
              "Authors": ["Samip Aryal (@samiparyal_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "3,150",
              "PublicationDate": "2021-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Github recon help me to find NINE FULL SSRF Vulnerability with AWS metadata access",
                    "Link": "https://notifybugme.medium.com/how-github-recon-help-me-to-find-nine-full-ssrf-vulnerability-with-aws-metadata-access-531d931413a5"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Shopify Multipass Misconfiguration",
                    "Link": "https://batee5a.medium.com/shopify-multipass-misconfiguration-2bc85e92ad1d"
                 }
              ],
              "Authors": ["Ahmed A. Sherif"],
              "Programs": ["-"],
              "Bugs": ["Broken authentication", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pop-Ups in a good-world",
                    "Link": "https://gccybermonks.com/posts/popups/"
                 }
              ],
              "Authors": ["Guilherme Keerok (@k33r0k)"],
              "Programs": ["Imgur"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Executing CSRF With Phone Validation",
                    "Link": "https://infosecwriteups.com/executing-csrf-with-phone-validation-103c525dd310"
                 }
              ],
              "Authors": ["Greg Gibson"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "403 Forbidden Bypass",
                    "Link": "https://dewangpanchal98.medium.com/403-forbidden-bypass-fc8b5df109b7"
                 }
              ],
              "Authors": ["th3.d1p4k (@DipakPanchal05)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass", "Exposed registration page", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to see likes and dislikes count even though is hidden by victim | YouTube #3",
                    "Link": "https://bloggerrando.blogspot.com/2021/06/how-many-likes-and-dislikes-that-was.html"
                 }
              ],
              "Authors": ["R ando (@Rando02355205)"],
              "Programs": ["Google"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2021-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Android: Exploring vulnerabilities in WebResourceResponse",
                    "Link": "https://blog.oversecured.com/Android-Exploring-vulnerabilities-in-WebResourceResponse/"
                 }
              ],
              "Authors": ["Oversecured (@OversecuredInc)"],
              "Programs": ["Amazon"],
              "Bugs": ["Arbitrary file read", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-06-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Server Side Request Forgery - A Forged Document",
                    "Link": "https://shahjerry33.medium.com/server-side-request-forgery-a-forged-document-6359ef25058d"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "File upload"],
              "Bounty": "500",
              "PublicationDate": "2021-06-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing LFI (Local File Inclusion)",
                    "Link": "https://medium.com/@abhishake21/bypassing-lfi-local-file-inclusion-ebf4274e7027"
                 }
              ],
              "Authors": ["Abhishek (@abhishake21)"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2021-06-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in the AWS Console",
                    "Link": "https://frichetten.com/blog/xss_in_aws_console/"
                 }
              ],
              "Authors": ["Nick Frichette (@frichette_n)"],
              "Programs": ["AWS"],
              "Bugs": ["XSS", "CSP bypass", "CSTI"],
              "Bounty": "-",
              "PublicationDate": "2021-06-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Open Redirect - Whitelist Bypass Using Salesforce Environment",
                    "Link": "https://payatu.com/blog/gaurav/exploiting-open-redirect"
                 }
              ],
              "Authors": ["Gaurav Nayak (@4auvar)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Token theft", "Salesforce"],
              "Bounty": "-",
              "PublicationDate": "2021-06-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Huawei LTE USB Stick E3372: From File Overwrite to Code Execution",
                    "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/huawei-lte-usb-stick-e3372-file-overwrite-to-code-execution/"
                 }
              ],
              "Authors": ["Martin Rakhmanov (@mrakhmanov)"],
              "Programs": ["Huawei"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-06-02",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Admin Panel? Pwned!",
                  "Link": "https://infosecwriteups.com/admin-panel-pwned-89db333f3836"
               }
            ],
            "Authors": ["Splintersec (@splint3rsec)"],
            "Programs": ["-"],
            "Bugs": ["Information disclosure", "Hardcoded credentials"],
            "Bounty": "-",
            "PublicationDate": "2021-06-02",
            "AddedDate": "2022-11-21"
         },
           {
              "Links": [
                 {
                    "Title": "Escalating SSRF to Accessing all user PII information by aws metadata",
                    "Link": "https://notifybugme.medium.com/escalating-ssrf-to-accessing-all-user-pii-information-by-aws-metadata-aabcfd5a3e0e"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-29084: Exploiting CRLF Header Injection in Synology NAS for Unauthenticated File Downloads",
                    "Link": "https://justintaft.com/blog/2021/06/01/cve-2021-29084-synology-crlf-unauthenticated-file-downloads"
                 }
              ],
              "Authors": ["Justin Taft"],
              "Programs": ["Synology"],
              "Bugs": ["CRLF injection"],
              "Bounty": "-",
              "PublicationDate": "2021-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Page Admin Disclosure",
                    "Link": "https://infosecwriteups.com/facebook-page-admin-disclosure-7d8893a4a674"
                 }
              ],
              "Authors": ["Kunjan Nayak (@kunjannayak5)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2021-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AppCache's forgotten tales",
                    "Link": "https://blog.lbherrera.me/posts/appcache-forgotten-tales/"
                 }
              ],
              "Authors": ["Luan Herrera (@lbherrera_)"],
              "Programs": ["Google (Chrome)"],
              "Bugs": ["Browser hacking"],
              "Bounty": "10,000",
              "PublicationDate": "2021-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating SSRF to Accessing all user PII information by aws metadata",
                    "Link": "https://notifybugme.medium.com/escalating-ssrf-to-accessing-all-user-pii-information-by-aws-metadata-aabcfd5a3e0e"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "runc mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs (CVE-2021-30465)",
                    "Link": "https://github.com/champtar/blog/tree/main/runc-symlink-CVE-2021-30465"
                 }
              ],
              "Authors": ["Etienne Champetier / champtar"],
              "Programs": ["Google"],
              "Bugs": ["Kubernetes", "Container escape"],
              "Bounty": "-",
              "PublicationDate": "2021-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Metadata service MITM allows root privilege escalation (EKS / GKE)",
                    "Link": "https://github.com/champtar/blog/tree/main/Metadata_MITM_root_EKS_GKE"
                 }
              ],
              "Authors": ["Etienne Champetier / champtar"],
              "Programs": ["Google"],
              "Bugs": ["Kubernetes", "Privilege escalation", "MiTM"],
              "Bounty": "-",
              "PublicationDate": "2021-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover via iFrame Injection",
                    "Link": "https://github.com/xbforce/Blog/blob/main/writeup/account-takeover-via-iframe-injection.md"
                 }
              ],
              "Authors": ["xbforce (@xbforce)"],
              "Programs": ["-"],
              "Bugs": ["Iframe injection", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The beauty of chaining client-side bugs",
                    "Link": "https://master-sec.medium.com/the-beauty-of-chaining-client-side-bugs-759e1091eabf"
                 }
              ],
              "Authors": ["Master SEC (@MasterSEC_AR)"],
              "Programs": ["-"],
              "Bugs": ["CRLF injection", "XSS", "CSP bypass", "DoS", "CSTI"],
              "Bounty": "-",
              "PublicationDate": "2021-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CafeBazaar and Subdomain Takeover",
                    "Link": "https://sinsinology.medium.com/cafebazaar-and-subdomain-takeover-a0ab61a19ce8"
                 }
              ],
              "Authors": ["Sina Kheirkhah (@SinSinology)"],
              "Programs": ["CafeBazaar"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Github, The Goldmine for P1s and P2s - Sensitive Information Exposure via Github by a Company Employee",
                    "Link": "https://web.archive.org/web/20210621221618/https://savirsuda.github.io/Github-The-Goldmine-for-P1s-and-P2s-Sensitive-Information-Exposure-via-Github-by-a-Company-Employee/"
                 }
              ],
              "Authors": ["Savir Suda (@savxiety)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hey WAF! Better Luck Next Time! 👽",
                    "Link": "https://akashroxstarz.medium.com/hey-waf-better-luck-next-time-a1df7f444863"
                 }
              ],
              "Authors": ["Akash Rox Starz"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked a Target again and again…",
                    "Link": "https://cirius.medium.com/how-i-hacked-a-target-again-and-again-6db2e462221f"
                 }
              ],
              "Authors": ["Aditya Verma (@0cirius0)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "Account takeover", "XSS", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2021-05-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing restricted port protection in WebKit",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0007"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Apple"],
              "Bugs": ["Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2021-05-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GitLab Arbitrary File Read & Write through Kroki - CVE-2021-22203",
                    "Link": "https://ledz1996.gitlab.io/blog/writeups/CVE-2021-22203-gitlab-arbitrary-file-read-write-through-kroki"
                 }
              ],
              "Authors": ["Anh Duc Nguyen (@ledz1996)"],
              "Programs": ["-"],
              "Bugs": ["Arbitrary file read"],
              "Bounty": "5,600",
              "PublicationDate": "2021-05-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS with two different parameters",
                    "Link": "https://joelmcg1993.medium.com/stored-xss-with-two-different-parameters-d9243cae3e6a"
                 }
              ],
              "Authors": ["Joel Cantu (@InfosecRintox)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-05-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Patch Gapping a Safari Type Confusion",
                    "Link": "https://blog.theori.io/research/webkit-type-confusion/"
                 }
              ],
              "Authors": ["Theori (@theori_io)"],
              "Programs": ["Apple"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2021-05-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining XSS with authentication issues to turn it into full account takeover",
                    "Link": "https://n1ghtmar3.medium.com/chaining-xss-with-authentication-issues-to-turn-it-into-full-account-takeover-ae886ac696bb"
                 }
              ],
              "Authors": ["N1GHTMAR3 (@n1ghtmar3_2421)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-05-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Content Spoofing Vulnerability in Shibboleth Service Provider",
                    "Link": "https://medium.com/fraktal/content-spoofing-vulnerability-in-shibboleth-service-provider-a6619404eaf1"
                 }
              ],
              "Authors": ["Toni Huttunen"],
              "Programs": ["-"],
              "Bugs": ["Content spoofing"],
              "Bounty": "-",
              "PublicationDate": "2021-05-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose leads form details of any Facebook Business Account or Facebook Page (Bug Bounty)",
                    "Link": "https://amineaboud.medium.com/disclose-leads-form-details-of-any-facebook-business-account-or-facebook-page-bug-bounty-7ecae6cff312"
                 }
              ],
              "Authors": ["Amine Aboud (@amineaboud)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "GraphQL"],
              "Bounty": "-",
              "PublicationDate": "2021-05-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CORS misconfig that worths USD200",
                    "Link": "https://mikekitckchan.medium.com/cors-misconfig-that-worths-usd200-4696eda5ab4c"
                 }
              ],
              "Authors": ["MikeChan"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "200",
              "PublicationDate": "2021-05-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding and Exploiting Unintended Functionality in Main Web App APIs",
                    "Link": "https://bendtheory.medium.com/finding-and-exploiting-unintended-functionality-in-main-web-app-apis-6eca3ef000af"
                 }
              ],
              "Authors": ["Bend Theory (@bendtheory)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Information disclosure", "Privilege escalation"],
              "Bounty": "4,000",
              "PublicationDate": "2021-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Victim’s Anti CSRF Token could be exposed to Third-party Applications installed on user’s Device (500$)",
                    "Link": "https://rohitcoder.medium.com/victims-anti-csrf-token-could-be-exposed-to-third-party-applications-installed-on-user-s-device-be8e40d511ba"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2021-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF from which we can create a support ticket in Victim’s Account (500$)",
                    "Link": "https://rohitcoder.medium.com/csrf-from-which-we-can-create-a-support-ticket-in-victims-account-500-c1aa61f99c17"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "500",
              "PublicationDate": "2021-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I turned 0000 into $600: Phone Verification Bypass",
                    "Link": "https://shrirangdiwakar.medium.com/how-i-turned-0000-into-600-phone-verification-bypass-b1c0f6eb568e"
                 }
              ],
              "Authors": ["Shrirang Diwakar"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass"],
              "Bounty": "600",
              "PublicationDate": "2021-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "403 Forbidden Bypass",
                    "Link": "https://dewangpanchal98.medium.com/403-forbidden-bypass-fc8b5df109b7"
                 }
              ],
              "Authors": ["th3.d1p4k (@DipakPanchal05)"],
              "Programs": ["-"],
              "Bugs": ["403 bypass", "Forced browsing"],
              "Bounty": "-",
              "PublicationDate": "2021-05-21",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "13 Nagios Vulnerabilities, #7 will SHOCK you!",
                  "Link": "https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/"
               }
            ],
            "Authors": ["Samir Ghanem (@sam0x21r)"],
            "Programs": ["Nagios"],
            "Bugs": ["RCE", "Local Privilege Escalation", "XSS", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2021-05-20",
            "AddedDate": "2023-02-22"
         },
           {
              "Links": [
                 {
                    "Title": "Oculus SSO “Account Linking” bug leads to account takeover on third party websites and inside VR Games/Apps",
                    "Link": "https://ysamm.com/?p=697"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["SSO", "Broken authentication", "Account takeover"],
              "Bounty": "12,000",
              "PublicationDate": "2021-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS via postMessage in chat.mozilla.org",
                    "Link": "https://keerok.github.io/2021/05/09/XSS-via-postMessage-in-chat-mozilla-org-CVE-2021-21320/"
                 }
              ],
              "Authors": ["Guilherme Keerok (@k33r0k)"],
              "Programs": ["Mozilla"],
              "Bugs": ["XSS", "postMessage"],
              "Bounty": "500",
              "PublicationDate": "2021-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Third-Party Apps were still getting your private Facebook data even after their access expiry.",
                    "Link": "https://infosecwriteups.com/third-party-apps-were-still-getting-your-private-facebook-data-even-after-their-access-expiry-6e4be4880e6e"
                 }
              ],
              "Authors": ["Samip Aryal (@samiparyal_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2021-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Writeups: Facebook Whitehat program(2021): Instagram Live setting bug",
                    "Link": "https://infosecwriteups.com/writeups-facebook-whitehat-program-2021-instagram-live-setting-bug-500-usd-d2d076b3f8bb"
                 }
              ],
              "Authors": ["Takashi Suzuki"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "537",
              "PublicationDate": "2021-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF in PDF Renderer using SVG",
                    "Link": "https://pwn.vg/articles/2021-05/ssrf-in-pdf-renderer-using-svg"
                 }
              ],
              "Authors": ["pwn.vg / Tomi (@mastomii)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "2,150",
              "PublicationDate": "2021-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Time-Based SQL Injection to Dumping the Database",
                    "Link": "https://thevillagehacker.medium.com/time-based-sql-injection-to-dumping-the-database-da0e5bcaa9df"
                 }
              ],
              "Authors": ["Naveen J (@thevillagehackr)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOS & Stored HTML Injection Bug Bounty Writeup",
                    "Link": "https://blog.riotsecurityteam.com/dos-and-stored-html-injection-bug-bounty-writeup"
                 }
              ],
              "Authors": ["RiotSecurityTeam (@RiotSecTeam)"],
              "Programs": ["-"],
              "Bugs": ["DoS", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2021-05-19",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "NoSQL Injections in Rocket.Chat 3.12.1: How A Small Leak Grounds A Rocket",
                  "Link": "https://www.sonarsource.com/blog/nosql-injections-in-rocket-chat/"
               }
            ],
            "Authors": ["Paul Gerste"],
            "Programs": ["Rocket.Chat"],
            "Bugs": ["NoSQL injection", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2021-05-18",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Finding my First Critical Web Cache Poisoning",
                    "Link": "https://n3t-hunt3r.medium.com/finding-my-first-critical-web-cache-poisoning-6f956799371c"
                 }
              ],
              "Authors": ["Yasser Khan (@N3T_hunt3r)"],
              "Programs": ["-"],
              "Bugs": ["Web cache poisoning"],
              "Bounty": "-",
              "PublicationDate": "2021-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Path Traversal in MobileSafari",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0006"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Apple"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2021-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Drupal Insecure Default Leads To Password Reset Poisoning",
                    "Link": "https://www.fortbridge.co.uk/research/drupal-insecure-default-leads-to-password-reset-poisoning/"
                 }
              ],
              "Authors": ["Bogdan Tiron (@Bogdan___T)"],
              "Programs": ["Drupal"],
              "Bugs": ["Password reset", "Host header injection"],
              "Bounty": "-",
              "PublicationDate": "2021-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Just Gopher It: Escalating a Blind SSRF to RCE for $15k",
                    "Link": "https://sirleeroyjenkins.medium.com/just-gopher-it-escalating-a-blind-ssrf-to-rce-for-15k-f5329a974530"
                 }
              ],
              "Authors": ["SirLeeroyJenkins (@SirLeeroyJenkin)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "RCE"],
              "Bounty": "15,000",
              "PublicationDate": "2021-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Clickjacking in Nearby Devices Dashboard",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0005"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2021-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Fourth Account takeover through password reset",
                    "Link": "https://seaman00o.medium.com/my-fourth-account-takeover-through-password-reset-28a36dfebaf"
                 }
              ],
              "Authors": ["Omar Hamdy (@seaman00o)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2021-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i hijacked 12 Subdomains in one Program",
                    "Link": "https://nvk0x.medium.com/how-i-hijacked-12-subdomains-in-one-program-eea468bcd64f"
                 }
              ],
              "Authors": ["Naveen kumawat (@nvk0x)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Auth Bypass in https://nearbydevices-pa.googleapis.com",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0004"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "5,000",
              "PublicationDate": "2021-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "MSSQL Injection In JSON Request",
                    "Link": "https://kailashbohara.com.np/blog/2021/05/16/MSSQL-Injection-in-JSON-request/"
                 }
              ],
              "Authors": ["Kailash (@Corrupted_brain)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Edmodo Bug Bounty Writeup",
                    "Link": "https://www.pethuraj.com/blog/edmodo-bug-bounty-writeup/"
                 }
              ],
              "Authors": ["Pethuraj (@Pethuraj)"],
              "Programs": ["Edmodo"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to prevent more than 200 million users from using Google services",
                    "Link": "https://omar0x01.medium.com/how-to-prevent-more-than-200-million-users-from-using-google-services-136b3b8e221f"
                 }
              ],
              "Authors": ["Omar Hashem (@OmarHashem666)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2FA Bypass via Forced Browsing",
                    "Link": "https://infosecwriteups.com/2fa-bypass-via-forced-browsing-9e511dfdb8df"
                 }
              ],
              "Authors": ["Akhil"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-05-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Mass Assignment exploitation in the wild - Escalating privileges in style",
                    "Link": "https://web.archive.org/web/20221001135941/https://galnagli.com/Mass_Assignment/"
                 }
               ],
              "Authors": ["Gal Nagli (@naglinagli)"],
              "Programs": ["-"],
              "Bugs": ["Mass assignment", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-05-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One-click reflected XSS in www.instagram.com due to unfiltered URI schemes leads to account takeover",
                    "Link": "https://ysamm.com/?p=695"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Reflected XSS", "Account takeover"],
              "Bounty": "9,600",
              "PublicationDate": "2021-05-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind XSS on Google Internal System",
                    "Link": "https://kailashbohara.com.np/blog/2021/05/13/Google-blind-XSS/"
                 }
              ],
              "Authors": ["Kailash (@Corrupted_brain)"],
              "Programs": ["Google"],
              "Bugs": ["Blind XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2021-05-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Counter-Strike Global Offsets: reliable remote code execution",
                    "Link": "https://secret.club/2021/05/13/source-engine-rce-join.html"
                 }
              ],
              "Authors": ["brymko (@brymko)", "dezk (@cffsmith)", "Simon Scannell (@scannell_simon)"],
              "Programs": ["Valve"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-05-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I find my first Stored XSS",
                    "Link": "https://filipaze.medium.com/how-i-find-my-first-stored-xss-c6f57155cc1a"
                 }
              ],
              "Authors": ["Filipe Azevedo (@filipaze_)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-05-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My story of hacking Dutch Government",
                    "Link": "https://tuhin1729.medium.com/story-of-my-hacking-dutch-government-46b7a3c8b75a"
                 }
              ],
              "Authors": ["Tuhin Bose (@tuhin1729_)"],
              "Programs": ["Dutch Government"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-05-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020-35580",
                    "Link": "https://hateshape.github.io/general/2021/05/11/CVE-2020-35580.html"
                 }
              ],
              "Authors": ["hateshape (@hateshaped)"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2021-05-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-27075: Microsoft Azure Vulnerability Allows Privilege Escalation and Leak of Private Data",
                    "Link": "https://www.intezer.com/blog/cloud-security/cve-2021-27075-microsoft-azure-vulnerability-allows-privilege-escalation-and-leak-of-data/"
                 }
              ],
              "Authors": ["Intezer"],
              "Programs": ["Microsoft"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-05-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2FA Verification Bypass in Shapeshift [shapeshift.com] (Write Up)",
                    "Link": "https://blog.evanricafort.com/2021/05/2fa-verification-bypass-in-shapeshift.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Shapeshift"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-05-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS to Organisation Takeover",
                    "Link": "https://infosecwriteups.com/stored-xss-to-organisation-takeover-6eaaa2fdcd5b"
                 }
              ],
              "Authors": ["Zaid Bhat (@zaidozaid)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-05-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Simple logical Bug turned into a bounty",
                    "Link": "https://sndpgiriz.medium.com/simple-logical-bug-turned-into-a-bounty-a3d7ac214606"
                 }
              ],
              "Authors": ["Sndp Giri"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2021-05-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Activity in medium android app",
                    "Link": "https://mrcyberwarrior.medium.com/exploiting-activity-in-medium-android-app-e2e6f3553eef"
                 }
              ],
              "Authors": ["Raju kumar (@MrCyberwarrior)"],
              "Programs": ["Medium"],
              "Bugs": ["Insecure intent", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-05-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthorized access to Django Admin Dashboard by endpoint leaked on GitHub",
                    "Link": "https://notifybugme.medium.com/unauthorized-access-to-django-admin-dashboard-by-endpoint-leaked-on-github-5336969ddbbc"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["Missing authentication", "Forced browsing"],
              "Bounty": "-",
              "PublicationDate": "2021-05-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft bug bounty writeup",
                    "Link": "https://dewangpanchal98.medium.com/microsoft-bug-bounty-writeup-5ee4a7264dbf"
                 }
              ],
              "Authors": ["th3.d1p4k (@DipakPanchal05)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Workplace by Facebook | Unauthorized access to companies environment — $27,5k",
                    "Link": "https://mvinni.medium.com/workplace-by-facebook-unauthorized-access-to-companies-environment-27-5k-a593a57092f1"
                 }
              ],
              "Authors": ["Marcos Ferreira (@mvinni_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw", "IDOR"],
              "Bounty": "27,500",
              "PublicationDate": "2021-05-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Apple Bug bounty writeups XSS(2021)",
                    "Link": "https://takashi-suzuki.medium.com/apple-bug-bounty-xss-2021-78c2f4fc4106"
                 }
              ],
              "Authors": ["Takashi Suzuki"],
              "Programs": ["Apple"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-05-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Identify a Facebook user by his phone number despite privacy settings set",
                    "Link": "https://ysamm.com/?p=691"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Privacy issue", "Information disclosure"],
              "Bounty": "9,000",
              "PublicationDate": "2021-05-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-1815 – MacOS Local Privilege Escalation Via Preferences",
                    "Link": "https://www.offensive-security.com/offsec/macos-preferences-priv-escalation/"
                 }
              ],
              "Authors": ["Offensive Security (@offsectraining)"],
              "Programs": ["Apple"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-05-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked Google App Engine: Anatomy of a Java Bytecode Exploit",
                    "Link": "https://blog.polybdenum.com/2021/05/05/how-i-hacked-google-app-engine-anatomy-of-a-java-bytecode-exploit.html"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["Google"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account takeover of Instagram accounts due to unrestricted permissions of third-party application’s generated tokens",
                    "Link": "https://ysamm.com/?p=684"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["OAuth", "Broken authorization", "Account takeover"],
              "Bounty": "18,000",
              "PublicationDate": "2021-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found Sql Injection on intensedebate.com (h1) in 5 minute $350",
                    "Link": "https://ahmadaabdulla.medium.com/how-i-found-sql-injection-on-intensedebate-com-h1-in-5-minute-350-a36c2890882d"
                 }
              ],
              "Authors": ["Ahmad A Abdulla (@lu3ky13)"],
              "Programs": ["Automattic"],
              "Bugs": ["SQL injection"],
              "Bounty": "350",
              "PublicationDate": "2021-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Through Parameter Pollution",
                    "Link": "https://infosecwriteups.com/xss-through-parameter-pollution-9a55da150ab2"
                 }
              ],
              "Authors": ["Saajan Bhujel (@saajanbhujel11)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "XSS", "HTTP parameter pollution"],
              "Bounty": "-",
              "PublicationDate": "2021-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Injecting Punycode URL Within the Arbitrary Text via Comment Box In Google Photo Sharing Option",
                    "Link": "https://justm0rph3u5.medium.com/injecting-punycode-url-within-the-arbitrary-text-via-comment-box-in-google-photos-sharing-option-8b424065deb3"
                 }
              ],
              "Authors": ["Divyanshu Shukla (@justm0rph3u5)"],
              "Programs": ["Google"],
              "Bugs": ["HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2021-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Through Parameter Pollution",
                    "Link": "https://saajan.bhujel.cyou/blog/web/2021-05-05-xss-through-parameter-pollution"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://infosecwriteups.com/xss-through-parameter-pollution-9a55da150ab2"
                 }
              ],
              "Authors": ["Saajan Bhujel (@saajanbhujel)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "HTTP parameter pollution"],
              "Bounty": "-",
              "PublicationDate": "2021-05-05",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                 {
                    "Title": "ExifTool CVE-2021-22204 - Arbitrary Code Execution",
                    "Link": "https://devcraft.io/2021/05/04/exiftool-arbitrary-code-execution-cve-2021-22204.html"
                 },
                 {
                    "Title": "HackerOne report",
                    "Link": "https://hackerone.com/reports/1154542"
                 }
              ],
              "Authors": ["William Bowling / vakzz (@wcbowling)"],
              "Programs": ["GitLab"],
              "Bugs": ["RCE"],
              "Bounty": "20,000",
              "PublicationDate": "2021-05-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting the Source Engine (Part 2) - Full-Chain Client RCE in Source using Frida",
                    "Link": "https://ctf.re//source-engine/exploitation/2021/05/01/source-engine-2/"
                 },
                 {
                    "Title": "Exploiting the Source Engine (Part 1)",
                    "Link": "https://ctf.re/source-engine/exploitation/reverse-engineering/2018/08/02/source-engine-1/"
                 }
              ],
              "Authors": ["Geebz (@Gbps111)"],
              "Programs": ["Valve"],
              "Bugs": ["RCE"],
              "Bounty": "7,500",
              "PublicationDate": "2021-05-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Deep Dive into Open Source Bug Bounty",
                    "Link": "https://web.archive.org/web/20210728030437/https://ritiksahni.me/open-source-bug-bounty-tutorial"
                 }
              ],
              "Authors": ["Ritik Sahni (@ritiksahni22)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-05-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding known exploits for bugbounties.",
                    "Link": "https://web.archive.org/web/20210620102348/https://ipanda.co.in/blog1.html"
                 }
              ],
              "Authors": ["ipanda (@ipanda915)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-05-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR Leads To Leak Any Uber Eats Restaurant Analytics",
                    "Link": "https://0xprial.com/idor-leads-to-leak-any-uber-eats-restaurant-analytics/"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["Uber"],
              "Bugs": ["IDOR"],
              "Bounty": "2,000",
              "PublicationDate": "2021-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Basic recon to RCE",
                    "Link": "https://www.jomar.fr/posts/2021/basic_recon_to_rce/"
                 }
              ],
              "Authors": ["Joshua Martinelle (@J0_mart)"],
              "Programs": ["-"],
              "Bugs": ["Insecure deserialization", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining CSRF with XSS to deactivate Mass user accounts by single click",
                    "Link": "https://notifybugme.medium.com/chaining-csrf-with-xss-to-deactivate-mass-user-accounts-by-single-click-b463c0d26587"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF Through PDF Generation",
                    "Link": "https://www.jomar.fr/posts/2021/ssrf_through_pdf_generation/"
                 }
              ],
              "Authors": ["Joshua Martinelle (@J0_mart)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-05-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found my first RCE?",
                    "Link": "https://web.archive.org/web/20220922223136/https://ipanda.co.in/blog0.html"
                 }
              ],
              "Authors": ["ipanda (@ipanda915)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-05-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got $400 for my first SSRF bug?",
                    "Link": "https://blog.usamav.dev/how-i-got-400-usd-for-my-first-ssrf-bug"
                 }
              ],
              "Authors": ["Usama Varikkottil (@usama_dev)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "400",
              "PublicationDate": "2021-05-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Password reset code brute-force vulnerability in AWS Cognito",
                    "Link": "https://www.pentagrid.ch/de/blog/password-reset-code-brute-force-vulnerability-in-AWS-Cognito/"
                 }
              ],
              "Authors": ["Pentagrid (@pentagridsec)"],
              "Programs": ["AWS"],
              "Bugs": ["Password reset", "Bruteforce", "Rate limiting bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook account takeover due to unsafe redirects after the OAuth flow",
                    "Link": "https://ysamm.com/?p=667"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["OAuth", "Open redirect", "Account takeover"],
              "Bounty": "28,800",
              "PublicationDate": "2021-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first OOB XXE exploitation",
                    "Link": "https://www.jomar.fr/posts/2021/my_first_oob_xxe_exploitation/"
                 }
              ],
              "Authors": ["Joshua Martinelle (@J0_mart)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2021-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to Retrieve your Personal Documents using the Wayback Machine!",
                    "Link": "https://web.archive.org/web/20210621213025/https://savirsuda.github.io/How-I-was-able-to-Retrieve-your-Personal-Documents-using-the-Wayback-Machine/"
                 }
              ],
              "Authors": ["Savir Suda (@savxiety)"],
              "Programs": ["-"],
              "Bugs": ["Privacy issue", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting memory corruption vulnerabilities on Android",
                    "Link": "https://blog.oversecured.com/Exploiting-memory-corruption-vulnerabilities-on-Android/"
                 }
              ],
              "Authors": ["Oversecured (@OversecuredInc)"],
              "Programs": ["Paypal"],
              "Bugs": ["Memory corruption", "Android"],
              "Bounty": "1,100",
              "PublicationDate": "2021-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                {
                   "Title": "PHP Supply Chain Attack on Composer",
                   "Link": "https://blog.sonarsource.com/php-supply-chain-attack-on-composer/"
                }
               ],
              "Authors": ["Thomas Chauchefoin (@swapgs)"],
              "Programs": ["Packagist"],
              "Bugs": ["Argument injection", "RCE", "Supply chain attack", "Security code review"],
              "Bounty": "-",
              "PublicationDate": "2021-04-29",
              "AddedDate": "2022-10-06"
            },
           {
              "Links": [
                 {
                    "Title": "A tale of Html to Pdf converter ssrf and various bypasses",
                    "Link": "https://bughunter25.medium.com/a-tale-of-html-to-pdf-converter-ssrf-and-various-bypasses-4a3e11030c77"
                 }
              ],
              "Authors": ["Jatin Aesthetic (@techyfreakk)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-04-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "De-anonymising Anonymous Animals in Google Workspace",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0003"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["Privacy issue", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-04-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The False Oracle — Azure Functions Padding Oracle Issue",
                    "Link": "https://polarply.medium.com/the-false-oracle-azure-functions-padding-oracle-issue-2025e0e6b8a"
                 }
              ],
              "Authors": ["polarply (@polarply)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Padding oracle attack", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-04-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How did I earn €€€€ by breaking the back-end logic of the server",
                    "Link": "https://dewcode.medium.com/how-did-i-earn-by-breaking-the-back-end-logic-of-the-server-fd94882cbdf6"
                 }
              ],
              "Authors": ["Dewanand Vishal (@dewcode91)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-04-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected DOM-based XSS on DomaiNesia",
                    "Link": "https://n45ht.or.id/post/reflected-dom-xss-on-domainesia/en"
                 }
              ],
              "Authors": ["N45HT"],
              "Programs": ["DomaiNesia"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting XSS via Markdown on Xiaomi",
                    "Link": "https://n45ht.or.id/post/exploiting-xss-via-markdown-on-xiaomi/en"
                 }
              ],
              "Authors": ["N45HT"],
              "Programs": ["Xiaomi"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WordPress 5.7 XXE Vulnerability",
                    "Link": "https://blog.sonarsource.com/wordpress-xxe-security-vulnerability/"
                 },
                 {
                    "Title": "HackerOne report",
                    "Link": "https://hackerone.com/reports/1095645"
                 }
              ],
              "Authors": ["Sonar (@SonarSource)"],
              "Programs": ["WordPress"],
              "Bugs": ["XXE"],
              "Bounty": "600",
              "PublicationDate": "2021-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Relaying Potatoes: Another Unexpected Privilege Escalation Vulnerability in Windows RPC Protocol",
                    "Link": "https://labs.sentinelone.com/relaying-potatoes-dce-rpc-ntlm-relay-eop/"
                 }
              ],
              "Authors": ["Antonio Cocomazzi (@splinter_code)", "Andrea Pierini (@decoder_it)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-04-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-22204 - Recreating a critical bug in ExifTool, no Perl smarts required.",
                    "Link": "https://blog.bricked.tech/posts/exiftool/"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["Exiftool"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-04-26",
              "AddedDate": "2022-10-06"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS on Microsoft",
                    "Link": "https://n45ht.or.id/post/reflected-xss-on-microsoft/en"
                 }
              ],
              "Authors": ["N45HT"],
              "Programs": ["Microsoft"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Wayback Machine To Account Takeover",
                    "Link": "https://r29k.com/articles/bb/ato"
                 }
              ],
              "Authors": ["Demon (@R29k_)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Account takeover"],
              "Bounty": "800",
              "PublicationDate": "2021-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Supply Chain Attacks via GitHub.com Releases",
                    "Link": "https://wwws.nightwatchcybersecurity.com/2021/04/25/supply-chain-attacks-via-github-com-releases/"
                 }
              ],
              "Authors": ["Nightwatch Cybersecurity (@nightwatchcyber)"],
              "Programs": ["GitHub"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found Cross-Site-Scripting (Reflected) on more than 300 systems!",
                    "Link": "https://mrsinister1501.medium.com/how-i-found-cross-site-scripting-reflected-on-more-than-300-systems-81d8118d9de5"
                 }
              ],
              "Authors": ["MR SINISTER (@KabirSuda)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Wayback Machine To Account Takeover",
                    "Link": "https://www.r29k.com/articles/bb/ato"
                 }
              ],
              "Authors": ["Demon (@R29k_)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2021-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE via Internal Access to Adminer Database Management (Critical)",
                    "Link": "https://infosecwriteups.com/rce-via-internal-access-to-adminer-database-management-critical-d3dc2a1d392a"
                 }
              ],
              "Authors": ["Ahmad Halabi (@Ahmad_Halabi_)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "3,000",
              "PublicationDate": "2021-04-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AWS internal metadata accessed through SSRF by Chaining an Open Redirect bug",
                    "Link": "https://notifybugme.medium.com/aws-internal-metadata-accessed-through-ssrf-by-chaining-an-open-redirect-bug-c4b0e4838dc"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2021-04-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Page Owners Can’t remove or change page roles of deactivated users (or if Attacker blocks the page owner) in Facebook Lite, Facebook for Android and touch.facebook.com",
                    "Link": "https://baibhavjha.com.np/blogs/deactivateduserspageroles/"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "525",
              "PublicationDate": "2021-04-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Brave — Stealing your cookies remotely",
                    "Link": "https://infosecwriteups.com/brave-stealing-your-cookies-remotely-1e09d1184675"
                 }
              ],
              "Authors": ["Pedro Oliveira (@kanytu)"],
              "Programs": ["Brave Software"],
              "Bugs": ["Arbitrary file read"],
              "Bounty": "500",
              "PublicationDate": "2021-04-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Telegram bug bounties: XSS, privacy issues, official bot exploitation and more…",
                    "Link": "https://davtur19.medium.com/telegram-bug-bounties-xss-privacy-issues-official-bot-exploitation-and-more-5277fa78435"
                 }
              ],
              "Authors": ["Davide", "Andrea", "Giuseppe"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Broken authorization", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-04-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Got Nice catch by Google",
                    "Link": "https://parthdeshani.medium.com/got-nice-catch-by-google-5e6a8211371c"
                 }
              ],
              "Authors": ["Parth Desani (@DesaniParth)"],
              "Programs": ["Google"],
              "Bugs": ["OAuth", "Open redirect", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-04-22",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "SSRF in ColdFusion/CFML Tags and Functions",
                  "Link": "https://www.hoyahaxa.com/2021/04/ssrf-in-coldfusioncfml-tags-and.html"
               }
            ],
            "Authors": ["Brian (@hoyahaxa)"],
            "Programs": ["Adobe (ColdFusion)"],
            "Bugs": ["SSRF"],
            "Bounty": "-",
            "PublicationDate": "2021-04-21",
            "AddedDate": "2024-02-06"
         },
           {
              "Links": [
                 {
                    "Title": "PrivateDrop: Breaking and Fixing Apple AirDrop",
                    "Link": "https://privatedrop.github.io"
                 }
              ],
              "Authors": ["Alexander Heinrich", "Matthias Hollick", "Thomas Schneider", "Milan Stute", "Christian Weinert"],
              "Programs": ["Apple"],
              "Bugs": ["Privacy issue", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "New Clubhouse Security Vulnerabilities Could Happen to Any Growing Unicorn",
                    "Link": "https://www.lutasecurity.com/post/new-clubhouse-security-vulnerabilities-could-happen-to-any-growing-unicorn"
                 }
              ],
              "Authors": ["Katie Moussouris (@k8em0)"],
              "Programs": ["Clubhouse"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote code execution in Homebrew by compromising the official Cask repository",
                    "Link": "https://blog.ryotak.me/post/homebrew-security-incident-en/"
                 }
              ],
              "Authors": ["RyotaK (@ryotkak)"],
              "Programs": ["Homebrew"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to inject XSS payload into any user's mailbox",
                    "Link": "https://noobx.in/blogs/how-i-was-able-to-inject-xss-payload-into-any-user-s-mailbox"
                 }
              ],
              "Authors": ["Gaurav Popalghat (@N008x)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-04-21",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "DMCA.COM Hack, Full Disclosure (With Proof-of-Concept)",
                  "Link": "https://websec.nl/blog/606ecfec2f798a048269340e/dmcacom%20hack%20full%20disclosure%20with%20proof-of-concept"
               }
            ],
            "Authors": ["Joël Aviad Ossi"],
            "Programs": ["DMCA"],
            "Bugs": ["Privilege escalation", "Client-side enforcement of server-side security", "Stored XSS", "Broken Access Control"],
            "Bounty": "-",
            "PublicationDate": "2021-04-21",
            "AddedDate": "2022-10-24"
         },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-30481: Source engine remote code execution via game invites",
                    "Link": "https://secret.club/2021/04/20/source-engine-rce-invite.html"
                 }
              ],
              "Authors": ["floesen (@floesen_)"],
              "Programs": ["Valve"],
              "Bugs": ["RCE", "Integer underflow"],
              "Bounty": "8,000",
              "PublicationDate": "2021-04-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Playing With iframes: Bypassing Content-Security-Policy",
                    "Link": "https://jmrcsnchz.medium.com/playing-with-iframes-bypassing-content-security-policy-987c2f0b8e8a"
                 }
              ],
              "Authors": ["JM Sanchez / 0xEchidonut (@jmrcsnchz)"],
              "Programs": ["-"],
              "Bugs": ["CSP bypass", "Open redirect", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2021-04-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Auth Bypass in Google Workspace Real Time Collaboration",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0002"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["Authentication bypass", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-04-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR leads to leaked the likes count even though is hidden by victim | YouTube ($XXXX)",
                    "Link": "https://bloggerrando.blogspot.com/2021/04/idor-leads-to-how-many-likes-that-was.html"
                 }
              ],
              "Authors": ["R ando (@Rando02355205)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-04-20",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Harvesting Active Directory credentials via HTTP Request Smuggling",
                  "Link": "https://tij.me/blog/harvesting-active-directory-credentials-via-http-request-smuggling/"
               }
            ],
            "Authors": ["Tijme Gommers (@tijme)"],
            "Programs": ["-"],
            "Bugs": ["HTTP request smuggling"],
            "Bounty": "-",
            "PublicationDate": "2021-04-19",
            "AddedDate": "2022-03-09"
         },
           {
              "Links": [
                 {
                    "Title": "Blind SSRF to Port Scanning through response time",
                    "Link": "https://pharish4948.medium.com/blind-ssrf-to-port-scanning-through-response-time-d7336667299d"
                 }
              ],
              "Authors": ["Harish"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-04-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthorized access to admin setpassword page BY bypassing 403 Forbidden",
                    "Link": "https://notifybugme.medium.com/unauthorized-access-to-admin-setpassword-page-by-bypass-403-forbidden-f10bbb92ab35"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "(POC) Untrim any live video on Facebook",
                    "Link": "https://edmundaa222.medium.com/poc-untrim-any-live-video-on-facebook-ad6b97bad7c0"
                 }
              ],
              "Authors": ["Ahmad Talahmeh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "2,875",
              "PublicationDate": "2021-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Unrestricted File Upload to achieve Remote Code Execution on a bug bounty program",
                    "Link": "https://mase289.medium.com/exploiting-unrestricted-file-upload-to-achieve-remote-code-execution-on-a-bug-bounty-program-85661516712"
                 }
              ],
              "Authors": ["Jadek Mark (@mase289)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwning your assignments: Stored XSS via GraphQL endpoint",
                    "Link": "https://infosecwriteups.com/pwning-your-assignments-stored-xss-via-graphql-endpoint-6dd36c8a19d5"
                 }
              ],
              "Authors": ["Kartik Sharma (@dominat0r98)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "GraphQL"],
              "Bounty": "2,881",
              "PublicationDate": "2021-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Misconfiguration in Change-password Functionality Leads to Account Takeover",
                    "Link": "https://0x2m.medium.com/misconfiguration-in-change-password-functionality-leads-to-account-takeover-1314b5507abf"
                 }
              ],
              "Authors": ["Mahmoud Radwan (@0x___2m)", "Mahmoud samaha (@0x__2m)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Logic flaw", "Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS via Exif Data - The P2 Elevator",
                    "Link": "https://shahjerry33.medium.com/xss-via-exif-data-the-p2-elevator-d09e7b7fe9b9"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Discoure themes OS Command Injection",
                    "Link": "https://0day.click/recipe/2021-04-18-discourse-themes/"
                 }
              ],
              "Authors": ["joernchen (@joernchen)"],
              "Programs": ["Discourse"],
              "Bugs": ["RCE", "OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2021-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "(POC) Remove any Facebook’s live video ($14,000 bounty)",
                    "Link": "https://edmundaa222.medium.com/poc-remove-any-facebooks-live-video-14-000-bounty-70c8135b7b4c"
                 }
              ],
              "Authors": ["Ahmad Talahmeh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "14,000",
              "PublicationDate": "2021-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Lets Learn English - Hacking 10M+ Users",
                    "Link": "https://aseemshrey.in/lets-learn-english-hacking-10M-Users/"
                 }
              ],
              "Authors": ["Aseem Shrey (@AseemShrey)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration", "Insecure Firebase database", "OTP bypass", "Account takeover", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "(POC) Update business fyi message as Facebook page analyst",
                    "Link": "https://edmundaa222.medium.com/poc-update-business-fyi-message-as-facebook-page-analyst-d36170fdede2"
                 }
              ],
              "Authors": ["Ahmad Talahmeh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "GraphQL"],
              "Bounty": "750",
              "PublicationDate": "2021-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned $$$$ through Stored XSS",
                    "Link": "https://pharish4948.medium.com/how-i-earned-3200-in-4hours-through-stored-xss-38597877d3e1"
                 }
              ],
              "Authors": ["Harish"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "CSTI"],
              "Bounty": "3,205",
              "PublicationDate": "2021-04-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fun sql injection — mod_security bypass",
                    "Link": "https://infosecwriteups.com/fun-sql-injection-mod-security-bypass-644b54b0c445"
                 }
              ],
              "Authors": ["_Y000_ (@_Y000_)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-04-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Allow arbitrary URLs, expect arbitrary code execution",
                    "Link": "https://positive.security/blog/url-open-rce"
                 }
              ],
              "Authors": ["Fabian Bräunlein", "Lukas Euler"],
              "Programs": ["Nextcloud", "Telegram", "VLC"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got 9000 USD by hacking into iCloud",
                    "Link": "https://fernale.blogspot.com/2021/04/how-i-got-9000-usd-by-hacking-into.html"
                 }
              ],
              "Authors": ["Alexandre Fernandes (@fernale)"],
              "Programs": ["Apple"],
              "Bugs": ["XSS"],
              "Bounty": "9,000",
              "PublicationDate": "2021-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote exploitation of a man-in-the-disk vulnerability in WhatsApp (CVE-2021-24027)",
                    "Link": "https://census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/"
                 }
              ],
              "Authors": ["CENSUS"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Man-in-the-Disk attack"],
              "Bounty": "-",
              "PublicationDate": "2021-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerability Spotlight: Multiple remote code execution vulnerabilities in Microsoft Azure Sphere",
                    "Link": "https://blog.talosintelligence.com/2021/04/vuln-spotlight-azure-sphere-april-2021.html"
                 }
              ],
              "Authors": ["Cisco Talos"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Photos : Theft of Database & Arbitrary Files Android Vulnerability",
                    "Link": "https://servicenger.com/blog/mobile/google-photos-theft-of-database-arbitrary-files-android-vulnerability/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Google"],
              "Bugs": ["Improper Export of Android Application Components", "Android"],
              "Bounty": "1,337",
              "PublicationDate": "2021-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Advisory: Cisco RV34X Series – Authentication Bypass and Remote Command Execution",
                    "Link": "https://onekey.com/blog/advisory-cisco-rv34x-authentication-bypass-remote-command-execution/"
                 }
              ],
              "Authors": ["T. Shiomitsu"],
              "Programs": ["Cisco"],
              "Bugs": ["Authentication bypass", "OS command injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty - Information Disclosure through error message + WAF Bypass led to Local File Inclusion",
                    "Link": "https://arben.sh/bugbounty/Local-File-Inclusion/"
                 }
              ],
              "Authors": ["Arben Shala (@arbennsh)", "0xcela (@0xcela)"],
              "Programs": ["-"],
              "Bugs": ["LFI", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-04-13",
              "AddedDate": "2022-09-26"
           },
           {
            "Links": [
               {
                  "Title": "Exploiting Struts RCE on 2.5.26",
                  "Link": "https://mc0wn.blogspot.com/2021/04/exploiting-struts-rce-on-2526.html"
               }
            ],
            "Authors": ["Chris (@mc_0wn)"],
            "Programs": ["Apache Struts"],
            "Bugs": ["RCE", "Double OGNL evaluation"],
            "Bounty": "-",
            "PublicationDate": "2021-04-12",
            "AddedDate": "2022-12-05"
         },
           {
              "Links": [
                 {
                    "Title": "You Talking To Me?",
                    "Link": "https://starlabs.sg/blog/2021/04-you-talking-to-me/"
                 }
              ],
              "Authors": ["Li JianTao (@cursered)"],
              "Programs": ["Google"],
              "Bugs": ["RCE", "Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2021-04-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ELECTRIC CHROME - CVE-2020-6418 on Tesla Model 3",
                    "Link": "https://leethax0.rs/2021/04/ElectricChrome/"
                 }
              ],
              "Authors": ["Chris Williams (@HawaiiFive0day)"],
              "Programs": ["Tesla", "Google"],
              "Bugs": ["RCE", "Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2021-04-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated Account Takeover Through Forget Password",
                    "Link": "https://infosecwriteups.com/unauthenticated-account-takeover-through-forget-password-c120b4c1141d"
                 }
              ],
              "Authors": ["Nikhil (niks) (@niksthehacker)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-04-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on the DuckDuckGo search results page",
                    "Link": "https://monke.ie/duckduckgoxss/"
                 }
              ],
              "Authors": ["Monke (@pmofcats)"],
              "Programs": ["DuckDuckGo"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-04-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cookie poisoning leads to DoS and Privacy Violation",
                    "Link": "https://gatolouco.medium.com/cookie-poisoning-leads-to-dos-and-privacy-violation-8aa773547c96"
                 }
              ],
              "Authors": ["Benjamin Walter"],
              "Programs": ["CS Money"],
              "Bugs": ["DoS", "SSRF"],
              "Bounty": "700",
              "PublicationDate": "2021-04-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Auth Issues",
                    "Link": "https://sites.google.com/securifyinc.com/vrp-writeups/hire-with-google/auth-issues"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authentication", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-04-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "(CRITICAL) Blind Storage XSS — My first Bug Bounty 💰",
                    "Link": "https://gatolouco.medium.com/critical-blind-storage-xss-my-first-bug-bounty-d318f6ba570c/"
                 }
              ],
              "Authors": ["Benjamin Walter"],
              "Programs": ["CS Money"],
              "Bugs": ["Blind XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2021-04-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "What if you could deposit money into your Betting account for free? Oh wait where has this 25k came from…",
                    "Link": "https://mikey96.medium.com/what-if-you-could-deposit-money-into-your-betting-account-for-free-24f6690aff46"
                 }
              ],
              "Authors": ["Mikey (@mikey96_bh)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "10,000",
              "PublicationDate": "2021-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining an Blind SSRF bug to Get an RCE",
                    "Link": "https://notifybugme.medium.com/chaining-an-blind-ssrf-bug-to-get-an-rce-92c09de3c0ba"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["Blind SSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I Built a TV That Plays All of Your Private YouTube Videos",
                    "Link": "https://bugs.xdavidhu.me/google/2021/04/05/i-built-a-tv-that-plays-all-of-your-private-youtube-videos/"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "6,000",
              "PublicationDate": "2021-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Apple TV for Fire OS code execution",
                    "Link": "https://0xra.github.io/posts/apple-tv-code-execution/"
                 }
              ],
              "Authors": ["Razvan Sima (@0xraaz)"],
              "Programs": ["Apple"],
              "Bugs": ["RCE", "Insecure storage", "Man-in-the-Disk attack"],
              "Bounty": "-",
              "PublicationDate": "2021-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cloud Based Storage Misconfigurations -> Critical Bounties",
                    "Link": "https://mikey96.medium.com/cloud-based-storage-misconfigurations-critical-bounties-361647f78a29"
                 }
              ],
              "Authors": ["Mikey (@mikey96_bh)"],
              "Programs": ["-"],
              "Bugs": ["Cloud storage misconfiguration"],
              "Bounty": "7,500",
              "PublicationDate": "2021-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weird and very easy authentication bypass found with Google dorking",
                    "Link": "https://infosecwriteups.com/weird-and-very-easy-authentication-bypass-found-with-google-dorking-c13230a038ed"
                 }
              ],
              "Authors": ["GrumpinouT (@RVerwilghen)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Intro to Open-source Bug Bounty",
                    "Link": "https://huntr.dev/blog/intro-to-open-source-bug-bounty/"
                 }
              ],
              "Authors": ["Arjun Shibu (@0xsegf)"],
              "Programs": ["Mailtrain"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2021-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF in YouTube Leanback API",
                    "Link": "https://feed.bugs.xdavidhu.me/bugs/0001"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Breaking GitHub Private Pages for $35k",
                    "Link": "https://robertchen.cc/blog/2021/04/03/github-pages-xss"
                 }
              ],
              "Authors": ["Robert Chen (@NotDeGhost)", "Philip"],
              "Programs": ["GitHub"],
              "Bugs": ["XSS", "CRLF injection", "Web cache poisoning"],
              "Bounty": "35,000",
              "PublicationDate": "2021-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote code execution through unsafe unserialize in PHP",
                    "Link": "https://www.sjoerdlangkemper.nl/2021/04/04/remote-code-execution-through-unsafe-unserialize/"
                 }
              ],
              "Authors": ["Sjoerd Langkemper"],
              "Programs": ["-"],
              "Bugs": ["Insecure deserialization", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Journeys in Quoteless and Multi Reflection XSS",
                    "Link": "https://bendtheory.medium.com/journeys-in-quoteless-and-multi-reflection-xss-b1d67bb0c5dd"
                 }
              ],
              "Authors": ["Bend Theory (@bendtheory)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "250",
              "PublicationDate": "2021-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE on Starbucks Singapore and more for $5600",
                    "Link": "http://www.kamilonurozkaleli.com/posts/rce-on-starbucks-singapore-and-more/"
                 }
              ],
              "Authors": ["Kamil Onur Özkaleli (@ko2sec)"],
              "Programs": ["Starbucks"],
              "Bugs": ["RCE", "Unrestricted file upload"],
              "Bounty": "5,600",
              "PublicationDate": "2021-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Code execution as root via AT commands on the Quectel EG25-G modem",
                    "Link": "https://nns.ee/blog/2021/04/03/modem-rce.html"
                 }
              ],
              "Authors": ["nns"],
              "Programs": ["Quectel"],
              "Bugs": ["OS command injection", "RCE"],
              "Bounty": "2,000",
              "PublicationDate": "2021-04-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Gain write permission of repositories with a bug in GitHub Actions",
                    "Link": "https://blog.tyage.net/posts/2021-04-02-improper-access-control-github-workflow/"
                 }
              ],
              "Authors": ["tyage (@tyage)"],
              "Programs": ["GitHub"],
              "Bugs": ["Broken Access Control", "Logic flaw"],
              "Bounty": "25,000",
              "PublicationDate": "2021-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Automate Cache Poisoning Vulnerability - Nuclei",
                    "Link": "https://blog.melbadry9.xyz/fuzzing/nuclei-cache-poisoning"
                 }
              ],
              "Authors": ["Mohamed Elbadry (@_melbadry9)"],
              "Programs": ["-"],
              "Bugs": ["Web cache poisoning", "Stored XSS"],
              "Bounty": "1,500",
              "PublicationDate": "2021-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This Man Thought Opening A TXT File Is Fine, He Thought Wrong. MacOS CVE-2019-8761",
                    "Link": "https://www.paulosyibelo.com/2021/04/this-man-thought-opening-txt-file-is.html"
                 }
              ],
              "Authors": ["Paulos Yibelo (@PaulosYibelo)"],
              "Programs": ["Apple"],
              "Bugs": ["MacOS", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2021-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bragging Rights: Let’s head back to bug bucket",
                    "Link": "https://infosecwriteups.com/bragging-rights-lets-head-back-to-bug-bucket-88c94730b6fa"
                 }
              ],
              "Authors": ["Manas Harsh (@ManasH4rsh)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "IDOR", "2FA / MFA bypass"],
              "Bounty": "951",
              "PublicationDate": "2021-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Large Messenger and Payment App - a Shout Out to Parameter Guessing",
                    "Link": "https://security.lauritz-holtmann.de/post/xss-parameter-guessing/"
                 }
              ],
              "Authors": ["Lauritz Holtmann (@_lauritz_)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2021-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Play a game, get Subscribed to my channel - YouTube Clickjacking Bug \\| #GoogleVRP",
                    "Link": "https://sriram-offcl.medium.com/play-a-game-get-subscribed-to-my-channel-youtube-clickjacking-bug-googlevrp-6ce1d15542d3"
                 }
              ],
              "Authors": ["Sriram Kesavan (@sriramoffcl)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "100",
              "PublicationDate": "2021-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Who Contains the Containers?",
                    "Link": "https://googleprojectzero.blogspot.com/2021/04/who-contains-containers.html"
                 }
              ],
              "Authors": ["James Forshaw (@tiraniddo)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook account takeover due to a wide platform bug in ajaxpipe responses",
                    "Link": "https://ysamm.com/?p=654"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Account takeover"],
              "Bounty": "30,000",
              "PublicationDate": "2021-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook account takeover due to a bypass of allowed callback URLs in the OAuth flow",
                    "Link": "https://ysamm.com/?p=646"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Account takeover", "OAuth", "Open redirect"],
              "Bounty": "12,000",
              "PublicationDate": "2021-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zero click vulnerability in Apple’s macOS Mail",
                    "Link": "https://mikko-kenttala.medium.com/zero-click-vulnerability-in-apples-macos-mail-59e0c14b106c"
                 }
              ],
              "Authors": ["Mikko Kenttälä (@Turmio_)"],
              "Programs": ["Apple"],
              "Bugs": ["Account takeover", "Information disclosure", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GKE Autopilot Node Compromise via Race Condition",
                    "Link": "https://lf.lc/vrp/181521559d/"
                 }
              ],
              "Authors": ["Anthony Weems"],
              "Programs": ["Google"],
              "Bugs": ["Container escape"],
              "Bounty": "1,337",
              "PublicationDate": "2021-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Download Facebook internal mobile builds",
                    "Link": "https://philippeharewood.com/download-facebook-internal-mobile-builds/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "6,000",
              "PublicationDate": "2021-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first Bug report at Facebook 2021",
                    "Link": "https://medium.com/@Kntjrld/my-first-bug-report-at-facebook-2021-bab2c2373ee3"
                 }
              ],
              "Authors": ["Kent Jarold Abulag (@wkemenhehehegsg)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Missing CORS leads to Complete Account Takeover",
                    "Link": "https://nirajmodi51.medium.com/missing-cors-leads-to-complete-account-takeover-1ed4b53bf9f2"
                 }
              ],
              "Authors": ["Niraj Modi (@nirajmodi51)"],
              "Programs": ["-"],
              "Bugs": ["Missing CORS", "CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-03-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I felt like there were no more bugs left after winning € 2000 … But an email worth €750 changed my mind",
                    "Link": "https://thexssrat.medium.com/i-felt-like-there-were-no-more-bugs-left-after-winning-2000-but-an-email-worth-750-changed-my-c7a507649060"
                 }
              ],
              "Authors": ["Thexssrat (@theXSSrat)"],
              "Programs": ["-"],
              "Bugs": ["Broken Access Control", "IDOR"],
              "Bounty": "2,750",
              "PublicationDate": "2021-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A weird XSS",
                    "Link": "https://infosecwriteups.com/a-weird-xss-77c13d135c9f"
                 }
              ],
              "Authors": ["gato the wizard"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-03-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF to Full Account Takeover",
                    "Link": "https://medium.com/@ashrafharb997/csrf-to-full-account-takeover-5196cef9d166"
                 }
              ],
              "Authors": ["Ashraf Harb (@ashrafharb97)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-03-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PHP fopen() function to local file inclusion",
                    "Link": "https://xhzeem.me/posts/PHP-fopen-function-to-local-file-inclusion/read/"
                 }
              ],
              "Authors": ["أنس روبي (@xhzeem)"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2021-03-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made to Paypal Bug Bounty $750",
                    "Link": "https://www.pethuraj.com/blog/paypal-bug-bounty-writeup/"
                 }
              ],
              "Authors": ["Pethuraj (@Pethuraj)"],
              "Programs": ["Paypal"],
              "Bugs": ["Open redirect"],
              "Bounty": "750",
              "PublicationDate": "2021-03-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to see likes and dislikes count even though is hidden by victim | YouTube #1",
                    "Link": "https://bloggerrando.blogspot.com/2021/03/bug-bounty-like-and-dislike-count.html"
                 }
              ],
              "Authors": ["R ando (@Rando02355205)"],
              "Programs": ["Google"],
              "Bugs": ["Broken Access Control", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-03-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to bypass CloudFlare bot protection ?",
                    "Link": "https://jychp.medium.com/how-to-bypass-cloudflare-bot-protection-1f2c6c0c36fb"
                 }
              ],
              "Authors": ["jychp (@jychp_fr)"],
              "Programs": ["Cloudflare"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-03-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Increasing impact of Information Disclosure — Full Account Takeover !",
                    "Link": "https://abhisek3122.medium.com/increasing-impact-of-information-disclosure-full-account-takeover-2f12d8963d5c"
                 }
              ],
              "Authors": ["Abhisek R (@abh1sek_r)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2021-03-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to see likes and dislikes count even though is hidden by victim | YouTube #2",
                    "Link": "https://bloggerrando.blogspot.com/2021/03/bug-bounty-idor-in-youtube-bounty.html"
                 }
              ],
              "Authors": ["R ando (@Rando02355205)"],
              "Programs": ["Google"],
              "Bugs": ["Broken Access Control", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-03-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Encrypted Payload -> Decrypted Execution ($600) : Stored XSS",
                    "Link": "https://shrirangdiwakar.medium.com/encrypted-payload-decrypted-execution-600-stored-xss-3e517cea8f13"
                 }
              ],
              "Authors": ["Shrirang Diwakar"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "600",
              "PublicationDate": "2021-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PoC: The easiest 125 Euro’s I Ever made",
                    "Link": "https://thexssrat.medium.com/poc-the-easiest-125-euros-i-ever-made-4dc87f01e286"
                 }
              ],
              "Authors": ["Thexssrat (@theXSSrat)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "125",
              "PublicationDate": "2021-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I leveraged XSS to make Privilege Escalation to be Super Admin!",
                    "Link": "https://melotover.medium.com/how-i-leveraged-xss-to-make-privilege-escalation-to-be-super-admin-e120b6090451"
                 }
              ],
              "Authors": ["Asem Eleraky (@melotover)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Authorization bypass issues in Google's Richmedia Studio",
                    "Link": "https://www.ehpus.com/post/multiple-authorization-bypass-issues-in-google-s-richmedia-studio"
                 }
              ],
              "Authors": ["Zohar Shachar"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "6,000",
              "PublicationDate": "2021-03-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass rate limit to enumeration users through Google Drive",
                    "Link": "https://3bodymo.medium.com/bypass-rate-limit-to-enumeration-users-through-google-drive-ed64e07c879c"
                 }
              ],
              "Authors": ["Abdullah Mohamed (@3bodymo_)"],
              "Programs": ["Google"],
              "Bugs": ["Rate limiting bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-03-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding and exploiting race condition vulnerability on facebook server",
                    "Link": "https://dewcode.in/2021/03/24/Finding-and-exploiting-race-condition-vulnerability-on-facebook-server.html"
                 }
              ],
              "Authors": ["Dewanand Vishal (@dewcode91)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Race condition"],
              "Bounty": "2,000",
              "PublicationDate": "2021-03-24",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "MobileIron MDM Contains Static Key Allowing Account Enumeration",
                  "Link": "https://emptynebuli.github.io/tooling/2021/03/22/rustyiron.html"
               }
            ],
            "Authors": ["Matt Burch (@emptynebuli)"],
            "Programs": ["Ivanti (MobileIron)"],
            "Bugs": ["Android", "Hardcoded API keys", "Username enumeration"],
            "Bounty": "-",
            "PublicationDate": "2021-03-22",
            "AddedDate": "2024-05-11"
         },
           {
              "Links": [
                 {
                    "Title": "How I made it to Google HOF?",
                    "Link": "https://sudhanshur705.medium.com/how-i-made-it-to-google-hof-f1cec85fdb1b"
                 }
              ],
              "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "1,000",
              "PublicationDate": "2021-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding My First Critical Vulnerability",
                    "Link": "https://thexssrat.medium.com/how-i-found-my-first-critical-vulnerability-in-bug-bounties-f890d420764b"
                 }
              ],
              "Authors": ["Thexssrat (@theXSSrat)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "250",
              "PublicationDate": "2021-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OTP brute-force via rate limit bypass",
                    "Link": "https://bilalabdulmuqeet.medium.com/brute-forcing-otp-via-bypassing-rate-limit-c5ee6b25c2a8"
                 }
              ],
              "Authors": ["Bilal Muqeet (@blmqt)"],
              "Programs": ["-"],
              "Bugs": ["Bruteforce", "Lack of rate limiting", "OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cross Site Port Attack - A Stranger’s Call",
                    "Link": "https://shahjerry33.medium.com/cross-site-port-attack-a-strangers-call-c2467f93792f"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["XSPA"],
              "Bounty": "-",
              "PublicationDate": "2021-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OAuth Misconfiguration found in small time-window of attack",
                    "Link": "https://muhammad-aamir.medium.com/oauth-misconfiguration-found-in-small-time-window-of-attack-b585afcb94c6"
                 }
              ],
              "Authors": ["Muhammad Aamir (@Muhammad__Aamir)"],
              "Programs": ["-"],
              "Bugs": ["OAuth"],
              "Bounty": "300",
              "PublicationDate": "2021-03-20",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Subdomain Takeover in AWS: making a PoC",
                  "Link": "https://godiego.co/posts/STO-AWS/"
               }
            ],
            "Authors": ["Diego Bernal Adelantado (@secfaults)"],
            "Programs": ["-"],
            "Bugs": ["Subdomain takeover"],
            "Bounty": "-",
            "PublicationDate": "2021-03-20",
            "AddedDate": "2022-11-02"
         },
           {
              "Links": [
                 {
                    "Title": "A short story about an XSS in chat.mozilla.org (CVE-2021-21320)",
                    "Link": "https://gccybermonks.com/posts/xss-mozilla/"
                 }
              ],
              "Authors": ["Guilherme Keerok (@k33r0k)"],
              "Programs": ["Mozilla"],
              "Bugs": ["XSS"],
              "Bounty": "500",
              "PublicationDate": "2021-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to Harpon Big Blue!",
                    "Link": "https://clarkvoss.medium.com/how-to-harpon-big-blue-c163722638d8"
                 }
              ],
              "Authors": ["Clark Voss (@clark_voss)"],
              "Programs": ["IBM"],
              "Bugs": ["Logic flaw", "Exposed registration page"],
              "Bounty": "-",
              "PublicationDate": "2021-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "H2C Smuggling in the Wild",
                    "Link": "https://blog.assetnote.io/2021/03/18/h2c-smuggling/"
                 }
              ],
              "Authors": ["Sean Yeoh (@seanyeoh)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "-",
              "PublicationDate": "2021-03-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "TikTok for Android 1-Click RCE",
                    "Link": "https://medium.com/@dPhoeniixx/tiktok-for-android-1-click-rce-240266e78105"
                 }
              ],
              "Authors": ["Sayed Abdelhafiz (@dPhoeniixx)"],
              "Programs": ["TikTok"],
              "Bugs": ["RCE", "XSS", "Insecure intent", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-03-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked Facebook: Part Two",
                    "Link": "https://infosecwriteups.com/how-i-hacked-facebook-part-two-ffab96d57b19"
                 }
              ],
              "Authors": ["Alaa Abdulridha (@alaa0x2)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["SSRF", "Account takeover", "Cookie manipulation"],
              "Bounty": "54,580",
              "PublicationDate": "2021-03-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining bugs for the greater good",
                    "Link": "https://med-mahmoudi26.medium.com/chaining-bugs-for-the-greater-good-664412ae85f8"
                 }
              ],
              "Authors": ["mohamad mahmoudi (@Lotus_619)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-03-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing arbitrary GitHub Actions secrets",
                    "Link": "https://blog.teddykatz.com/2021/03/17/github-actions-write-access.html"
                 }
              ],
              "Authors": ["Teddy Katz (@not_aardvark)"],
              "Programs": ["GitHub"],
              "Bugs": ["Logic flaw"],
              "Bounty": "25,000",
              "PublicationDate": "2021-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dangling DNS: Worksites.net",
                    "Link": "https://blog.melbadry9.xyz/dangling-dns/xyz-services/ddns-worksites"
                 }
              ],
              "Authors": ["Mohamed Elbadry (@_melbadry9)"],
              "Programs": ["-"],
              "Bugs": ["Dangling DNS records", "Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing Data Protection Laws For D0xing & Account Takeovers",
                    "Link": "https://hx01.me/Abusing_Data_Protection_Laws_For_D0xing_and_Account_Takeovers.pdf"
                 }
              ],
              "Authors": ["Hx01 (@Hxzeroone)"],
              "Programs": ["-"],
              "Bugs": ["SSTI", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-27076: A Replay-style Deserialization Attack Against Sharepoint",
                    "Link": "https://www.thezdi.com/blog/2021/3/17/cve-2021-27076-a-replay-style-deserialization-attack-against-sharepoint"
                 }
              ],
              "Authors": ["Simon Zuckerbraun (@HexKitchen)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Insecure deserialization", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An unknown Linux secret that turned SSRF to OS Command injection",
                    "Link": "https://secureitmania.medium.com/an-unknown-linux-secret-that-turned-ssrf-to-os-command-injection-6fe2f4edc202"
                 }
              ],
              "Authors": ["secureITmania (@secureitmania)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "Command injection"],
              "Bounty": "-",
              "PublicationDate": "2021-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An Interesting Account Takeover!!",
                    "Link": "https://mayank-01.medium.com/an-interesting-account-takeover-3a33f42d609d"
                 }
              ],
              "Authors": ["Mayank Pandey (@mayank_pandey01)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover", "Weak encryption", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2021-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Voice Confusion When Commenting On Watch Party",
                    "Link": "https://www.pantaprakash.com.np/posts/categories/bugbounty-writeup/5.html"
                 }
              ],
              "Authors": ["Prakash Panta (@prakashpanta268)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,000",
              "PublicationDate": "2021-03-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "API Misconfiguration which leads to unauthorized access to servicedesk tickets",
                    "Link": "https://noobx.in/blogs/API-Misconfiguration-which-leads-to-unauthorized-access-to-servicedesk-tickets"
                 }
              ],
              "Authors": ["Gaurav Popalghat (@N008x)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-03-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "De-anonymize the members of a private Facebook Group as a non-member.",
                    "Link": "https://baibhavjha.com.np/blogs/facebookgroupmemberdisclosure/"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["GraphQL", "Information disclosure"],
              "Bounty": "4,500",
              "PublicationDate": "2021-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Group Members Disclosure.",
                    "Link": "https://spongebhav.medium.com/facebook-group-members-disclosure-e53eb83df39e"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "9,000",
              "PublicationDate": "2021-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR Vulenebility with empty response still exposing sensitive details of customers!",
                    "Link": "https://rahulvarale.medium.com/idor-vulenebility-with-empty-response-still-exposing-sensitive-details-of-customers-bdce0a6a1b07"
                 }
              ],
              "Authors": ["Rahul Varale"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found Sql Injection on 8x8 , Cengage,Comodo,Automattic,20 company",
                    "Link": "https://ahmadaabdulla.medium.com/how-i-found-sql-injection-on-8x8-cengage-comodo-automattic-20-company-c296d1a09f63"
                 }
              ],
              "Authors": ["Ahmad A Abdulla (@lu3ky13)"],
              "Programs": ["Automattic", "IBM", "8x8"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding keys under the door",
                    "Link": "https://naveenprakaasam.medium.com/finding-keys-under-the-door-5cea8758ce86"
                 }
              ],
              "Authors": ["Naveen Prakaasham K S V"],
              "Programs": ["Paytm"],
              "Bugs": ["Stored XSS", "Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2021-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover Via Reset Password Worth 2000$",
                    "Link": "https://ashutoshmishra00x0.medium.com/account-takeover-via-reset-password-worth-2000-de085851d81d"
                 }
              ],
              "Authors": ["Ashutosh mishra (@ashutoshmish_ra)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "2,000",
              "PublicationDate": "2021-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Google VRP] How I Get Blind XSS At Google With Dork (First Bounty and HOF )",
                    "Link": "https://apapedulimu.click/google-vrp-how-i-get-blind-xss-at-google-with-dork-first-bounty-and-hof/"
                 }
              ],
              "Authors": ["Rio Mulyadi (@riomulyadi_)"],
              "Programs": ["Google"],
              "Bugs": ["Blind XSS"],
              "Bounty": "3,133.70",
              "PublicationDate": "2021-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Messing with GitHub's fork collaboration for fun and profit",
                    "Link": "https://blog.teddykatz.com/2021/03/10/fork-collab-abuse.html"
                 }
              ],
              "Authors": ["Teddy Katz (@not_aardvark)"],
              "Programs": ["GitHub"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "30,000",
              "PublicationDate": "2021-03-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business Logic Error on Registration Leads to SMS Validation Bypass",
                    "Link": "https://infosecwriteups.com/business-logic-error-on-registration-leads-to-sms-validation-bypass-80380b3ff629"
                 }
              ],
              "Authors": ["pleorqy (@pleorqy)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-03-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chain of Low Level Bugs and Misconfigurations Leads to Account Takeover",
                    "Link": "https://infosecwriteups.com/chain-of-low-level-bugs-and-misconfigurations-leads-to-account-takeover-de248fc4e481"
                 }
              ],
              "Authors": ["pleorqy (@pleorqy)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "Clickjacking", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-03-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding Basic Authtoken in JAVASCRIPT file BY Full Automation",
                    "Link": "https://notifybugme.medium.com/finding-basic-authtoken-in-javascript-file-by-full-automation-6188ca1b1f56"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-03-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dangling DNS Records on surf-test.xwf.internet.org (Amazon EC2)!",
                    "Link": "https://publish.whoisbinit.me/amazon-ec2-dangling-dns-records-on-surf-test-xwf-internet-org"
                 }
              ],
              "Authors": ["Binit Ghimire (@WHOISbinit)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Subdomain takeover", "Dangling DNS records"],
              "Bounty": "500",
              "PublicationDate": "2021-03-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting HTTP Request Smuggling (TE.CL)— XSS to website takeover",
                    "Link": "https://kleiton0x00.github.io/posts/Exploiting-HTTP-Request-Smuggling-(TE.CL)-XSS-to-website-takeover/"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://infosecwriteups.com/exploiting-http-request-smuggling-te-cl-xss-to-website-takeover-c0fc634a661b"
                 }
              ],
              "Authors": ["Kleiton Kurti (@kleiton0x7e)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up – Google VRP N/A: SSRF Bypass With Quadzero In Google Cloud Monitoring",
                    "Link": "https://omespino.com/write-up-google-vrp-n-a-ssrf-bypass-with-quadzero-in-google-cloud-monitoring/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Google"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dangling DNS: Amazon EC2 IPs (Current State)",
                    "Link": "https://blog.melbadry9.xyz/ddns-ec2-ips-current-state"
                 }
              ],
              "Authors": ["Mohamed Elbadry (@_melbadry9)"],
              "Programs": ["8x8"],
              "Bugs": ["Dangling DNS records", "Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-03-08",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Bypassing Chrome's URL restrictions",
                  "Link": "https://www.bencteux.fr/posts/chrome_bypass_url_restrictions/"
               }
            ],
            "Authors": ["Jeffrey Bencteux (@jeffbencteux)"],
            "Programs": ["Google (Chrome)"],
            "Bugs": ["Browser hacking", "URL validation bypass"],
            "Bounty": "-",
            "PublicationDate": "2021-03-07",
            "AddedDate": "2022-10-28"
         },
         {
            "Links": [
              {
                 "Title": "Partially disable Cybereason EDR as low privileges user on Windows",
                 "Link": "https://medium.com/@mehdi.alouache/partially-disable-cybereason-edr-as-low-privileges-user-on-windows-1405fd53e90e"
              }
             ],
            "Authors": ["Mehdi Alouache"],
            "Programs": ["Cybereason"],
            "Bugs": ["EDR bypass", "Local Privilege Escalation"],
            "Bounty": "-",
            "PublicationDate": "2022-10-28",
            "AddedDate": "2022-11-08"
          },
         {
              "Links": [
                 {
                    "Title": "Stored XSS in Google Ads Android Application— $3133.70",
                    "Link": "https://ashketchum.medium.com/stored-xss-in-google-ads-android-application-3133-70-373f6c361ff3"
                 }
              ],
              "Authors": ["Ashish Dhone (@ashketchum_16)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS", "HTML injection"],
              "Bounty": "3,133.70",
              "PublicationDate": "2021-03-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding Hidden Login Endpoint Exposing Secret `Client ID`",
                    "Link": "https://ahmdhalabi.medium.com/finding-hidden-login-endpoint-exposing-secret-client-id-88c3c2a1af45"
                 }
              ],
              "Authors": ["Ahmad Halabi (@Ahmad_Halabi_)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "700",
              "PublicationDate": "2021-03-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting a hidden and forgotten Bug",
                    "Link": "https://cirius.medium.com/exploiting-a-hidden-and-forgotten-bug-49ce7ad4de39"
                 }
              ],
              "Authors": ["Aditya Verma (@0cirius0)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-03-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The easiest $2500 I got it from bug bounty program",
                    "Link": "https://3bodymo.medium.com/the-easiest-2500-i-got-it-from-bug-bounty-program-8f47ea4aff22"
                 }
              ],
              "Authors": ["Abdullah Mohamed (@3bodymo_)"],
              "Programs": ["Uber"],
              "Bugs": ["Information disclosure"],
              "Bounty": "2,500",
              "PublicationDate": "2021-03-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GKE Autopilot Node Compromise via SSH Metadata",
                    "Link": "https://lf.lc/vrp/181521559c/"
                 }
              ],
              "Authors": ["Anthony Weems"],
              "Programs": ["Google"],
              "Bugs": ["Container escape"],
              "Bounty": "1,337",
              "PublicationDate": "2021-03-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GKE Autopilot Node Compromise via startup-script",
                    "Link": "https://lf.lc/vrp/181521559b/"
                 }
              ],
              "Authors": ["Anthony Weems"],
              "Programs": ["Google"],
              "Bugs": ["Container escape"],
              "Bounty": "1,337",
              "PublicationDate": "2021-03-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leveraging Template injection to takeover an account.",
                    "Link": "https://infosecwriteups.com/leveraging-template-injection-to-takeover-an-account-1dba7c4ae315"
                 }
              ],
              "Authors": ["Akash Methani (@0xAkash)"],
              "Programs": ["-"],
              "Bugs": ["CSTI", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-03-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Low hanging fruits on Facebook Group Room. Unable to remove post on group when post room add with event ($500)",
                    "Link": "https://randyarios.medium.com/low-hanging-fruits-on-facebook-group-room-b8d17c7ea886"
                 }
              ],
              "Authors": ["Randy Arios"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2021-03-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS at Trello.com",
                    "Link": "https://maordayanofficial.medium.com/stored-xss-at-trello-com-ef2e3d1ed24b"
                 }
              ],
              "Authors": ["Maor Dayan (@mord1234)"],
              "Programs": ["Trello"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-03-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Content Injection (RCE) in Yandex Browser for Android [2018]",
                    "Link": "https://wwws.nightwatchcybersecurity.com/2021/03/03/content-injection-rce-in-yandex-browser-for-android-2018/"
                 }
              ],
              "Authors": ["Nightwatch Cybersecurity (@nightwatchcyber)"],
              "Programs": ["Yandex"],
              "Bugs": ["MiTM"],
              "Bounty": "-",
              "PublicationDate": "2021-03-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Invincible Kid",
                    "Link": "https://infosecwriteups.com/the-invincible-kid-7ac1ce2887c0"
                 }
              ],
              "Authors": ["Samip Aryal (@samiparyal_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2021-03-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Might Have Hacked Any Microsoft Account",
                    "Link": "https://thezerohack.com/how-i-might-have-hacked-any-microsoft-account"
                 }
              ],
              "Authors": ["Laxman Muthiyah (@laxmanmuthiyah)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Account takeover", "Password reset", "Bruteforce", "2FA / MFA bypass"],
              "Bounty": "50,000",
              "PublicationDate": "2021-03-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Edge Browser For IOS - Address Bar Spoofing Vulnerability",
                    "Link": "https://www.rafaybaloch.com/2021/02/Microsoft-Edge-Browser-For-IOS-Address-Bar-Spoofing-Vulnerability.html"
                 }
              ],
              "Authors": ["Rafay Baloch (@rafaybaloch)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Address Bar Spoofing"],
              "Bounty": "-",
              "PublicationDate": "2021-03-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GKE Autopilot Node Compromise via local-storage PersistentVolume",
                    "Link": "https://lf.lc/vrp/181521559a/"
                 }
              ],
              "Authors": ["Anthony Weems"],
              "Programs": ["Google"],
              "Bugs": ["Container escape"],
              "Bounty": "1,337",
              "PublicationDate": "2021-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting CORS to perform an IDOR Attack leading to PII Information Disclosure",
                    "Link": "https://notmarshmllow.medium.com/exploiting-cors-to-perform-an-idor-attack-leading-to-pii-information-disclosure-95ef21ecf8ee"
                 }
              ],
              "Authors": ["Harsh Parekh (@notmarshmllow)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Secret Key Exposure in API Config Directory",
                    "Link": "https://ahmdhalabi.medium.com/secret-key-exposure-in-api-config-directory-79cf7e7b976"
                 }
              ],
              "Authors": ["Ahmad Halabi (@Ahmad_Halabi_)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "800",
              "PublicationDate": "2021-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Join Facebook Group With Unpublish Page",
                    "Link": "https://gevakun.medium.com/join-facebook-group-with-unpublish-page-cb649a20fb0e"
                 }
              ],
              "Authors": ["gevakun"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RocketChat - Unauthenticated access to messages",
                    "Link": "https://securifyinc.com/disclosures/rocketchat-unauthenticated-access-to-messages"
                 },
                 {
                  "Title": "Alternative link",
                  "Link": "https://ophionsecurity.com/blog/rockethchat-unauthenticated-messages"
               }
               ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Rocket.Chat"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF to fetch AWS credentials with full access to multiple services",
                    "Link": "https://zonduu.medium.com/ssrf-to-fetch-aws-credentials-with-full-access-to-various-services-18cd08194e91"
                 }
              ],
              "Authors": ["Zonduhackerone (@zonduu1)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Big Bugs: Bitbucket Pipelines Kata Containers Build Container Escape",
                    "Link": "https://www.bugcrowd.com/blog/big-bugs-cve-2020-28914/"
                 }
              ],
              "Authors": ["Alex Chapman (@ajxchapman)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Admin Panel Accessed Via SQL Injection… (Ezy Boooom…😅)",
                    "Link": "https://medium.com/@ratnadip1998/admin-panel-accessed-via-sql-injection-ezy-boooom-57dc60c2815f"
                 }
              ],
              "Authors": ["Ratnadip Gajbhiye (@scspcommunity)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bragging Rights: Killing File Uploads softly",
                    "Link": "https://infosecwriteups.com/bragging-rights-killing-file-uploads-softly-fba35a4e485a"
                 }
              ],
              "Authors": ["Manas Harsh (@ManasH4rsh)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Jira Auth Bypass bug in Google Acquisition (Apigee)",
                    "Link": "https://jayateerthag.medium.com/jira-authenticated-dashboard-access-in-google-acquisition-apigee-ff20cfe11d99"
                 }
              ],
              "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
              "Programs": ["Google"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Somebody Call The Plumber, GraphQL is Leaking Again…",
                    "Link": "https://n0ur5sec.medium.com/somebody-call-the-plumber-graphql-is-leaking-again-654bf1a38d26"
                 }
              ],
              "Authors": ["N0ur5"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "GraphQL"],
              "Bounty": "-",
              "PublicationDate": "2021-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Any Account Takeover Through Privilege Escalation",
                    "Link": "https://shubhamchaskar.com/ato-through-pe/"
                 }
              ],
              "Authors": ["Shubham Chaskar (@chaskar_shubham)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Kubernetes man in the middle using LoadBalancer or ExternalIPs (CVE-2020-8554)",
                    "Link": "https://github.com/champtar/blog/tree/main/K8S_MITM_LoadBalancer_ExternalIPs"
                 },
                 {
                    "Title": "HackerOne report",
                    "Link": "https://hackerone.com/reports/764986"
                 }
              ],
              "Authors": ["Etienne Champetier / champtar"],
              "Programs": ["Kubernetes"],
              "Bugs": ["MiTM"],
              "Bounty": "1,000",
              "PublicationDate": "2021-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Host MITM attack via IPv6 rogue router advertisements (K8S CVE-2020-10749 / Docker CVE-2020-13401 / LXD / WSL2 / ...)",
                    "Link": "https://github.com/champtar/blog/tree/main/IPv6_RA_MITM"
                 },
                 {
                    "Title": "HackerOne report",
                    "Link": "https://hackerone.com/reports/819717"
                 }
              ],
              "Authors": ["Etienne Champetier / champtar"],
              "Programs": ["Kubernetes"],
              "Bugs": ["MiTM"],
              "Bounty": "1,000",
              "PublicationDate": "2021-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story About Stop 10000+ users to get Their job notification",
                    "Link": "https://pallabjyoti218.medium.com/story-about-stop-10000-users-to-get-their-job-notification-6a8aca542c85"
                 }
              ],
              "Authors": ["PJBorah"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-02-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Somebody Call The Plumber, GraphQL is Leaking Again…",
                    "Link": "https://infosecwriteups.com/somebody-call-the-plumber-graphql-is-leaking-again-654bf1a38d26"
                 }
              ],
              "Authors": ["N0ur5"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "GraphQL"],
              "Bounty": "2,000",
              "PublicationDate": "2021-02-27",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
              {
                 "Title": "CVE-2020–13956",
                 "Link": "https://priyankn.github.io/2021-02-26-CVE-2020-13956/"
              }
             ],
            "Authors": ["Priyank (@Rev_Octo)"],
            "Programs": ["Apache HttpClient"],
            "Bugs": ["Blind SSRF","URL parsing issue", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2021-02-26",
            "AddedDate": "2022-11-01"
         },
           {
              "Links": [
                 {
                    "Title": "IDOR which allowed me to view Personal Email Addresses of More than 50K Users!",
                    "Link": "https://web.archive.org/web/20210226210519/https://savirsuda.github.io/IDOR-to-view-personal-email-addresses-of-more-than-50k-users/"
                 }
              ],
              "Authors": ["Savir Suda (@savxiety)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2021-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF: Bypassing hostname restrictions with fuzzing",
                    "Link": "https://blog.deesee.xyz/fuzzing/security/2021/02/26/ssrf-bypassing-hostname-restrictions-fuzzing.html"
                 }
              ],
              "Authors": ["Dominic (@dee__see)"],
              "Programs": ["Elastic"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover - Smoking with ‘null’",
                    "Link": "https://shahjerry33.medium.com/account-takeover-smoking-with-null-e43df2c3bb41"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2021-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Password Reset Token Leak via X-Forwarded-Host",
                    "Link": "https://saajan.bhujel.cyou/blog/web/2021-02-26-password-reset-token-leak-via-x-forwarded-host"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://infosecwriteups.com/password-reset-token-leak-via-x-forwarded-host-4ed3e33dca31"
                 }
              ],
              "Authors": ["Saajan Bhujel (@saajanbhujel)"],
              "Programs": ["-"],
              "Bugs": ["Host header injection", "Account takeover", "Password reset"],
              "Bounty": "1,000",
              "PublicationDate": "2021-02-26",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing user passwords through a VPN’s SSO",
                    "Link": "https://blog.scrt.ch/2021/02/25/stealing-user-passwords-through-a-vpns-sso/"
                 }
              ],
              "Authors": ["Alain Mowat (@plopz0r)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "SSTI"],
              "Bounty": "-",
              "PublicationDate": "2021-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Poisoning your Cache for 1000$ - Approach to Exploitation Walkthrough",
                    "Link": "https://web.archive.org/web/20230726020446/https://galnagli.com/Cache_Poisoning/"
                 }
              ],
              "Authors": ["Gal Nagli (@naglinagli)"],
              "Programs": ["-"],
              "Bugs": ["Web cache poisoning", "Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2021-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hijacking Reset Password Link in https://www.niteflirt.com/ via Host Header Poising (Write Up)",
                    "Link": "https://blog.evanricafort.com/2021/02/hijacking-reset-password-link-in.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Niteflirt"],
              "Bugs": ["Host header injection", "Account takeover", "Password reset"],
              "Bounty": "50",
              "PublicationDate": "2021-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF through URL with # tag parameter",
                    "Link": "https://web.archive.org/web/20210227092343/https://tommysuriel.medium.com/csrf-through-url-with-tag-parameter-c8ef585bded3"
                 }
              ],
              "Authors": ["Tommysuriel"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "100",
              "PublicationDate": "2021-02-25",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Security and Privacy of Social Logins (II): PostMessage Security in Single Sign-On ",
                  "Link": "https://web-in-security.blogspot.com/2021/02/security-and-privacy-of-social-logins-part2.html"
               }
            ],
            "Authors": ["Louis Jannett (@iphoneintosh)"],
            "Programs": ["SAP", "The New York Times", "CNET"],
            "Bugs": ["DOM XSS", "postMessage", "DOM XSS"],
            "Bounty": "-",
            "PublicationDate": "2021-02-22",
            "AddedDate": "2023-01-09"
         },
           {
              "Links": [
                 {
                    "Title": "CVE-2021-23827: Sakura Samurai discover cleartext pictures in Keybase Desktop Client; Windows, macOS, Linux",
                    "Link": "https://johnjhacking.com/blog/cve-2021-23827/"
                 },
                 {
                    "Title": "HackerOne report",
                    "Link": "https://hackerone.com/reports/1074930"
                 }
              ],
              "Authors": ["John Jackson (@johnjhacking)"],
              "Programs": ["Keybase"],
              "Bugs": ["Unencrypted storage"],
              "Bounty": "1,000",
              "PublicationDate": "2021-02-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Grafana Admin Panel bypass in Google Acquisition(VirusTotal)",
                    "Link": "https://jayateerthag.medium.com/grafana-admin-panel-bypass-in-google-acquisition-virustotal-c5ecc9d7b8ae"
                 }
              ],
              "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
              "Programs": ["Google"],
              "Bugs": ["Default credentials"],
              "Bounty": "-",
              "PublicationDate": "2021-02-22",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Web Cache Poisoning to Account Takeover",
                  "Link": "https://jsecu.github.io/2021/02/21/poisoning/"
               }
            ],
            "Authors": ["Josh Fam (@Pullerze)"],
            "Programs": ["-"],
            "Bugs": ["Web cache poisoning", "Account takeover"],
            "Bounty": "-",
            "PublicationDate": "2021-02-21",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Let’s know How I have explored the buried secrets in Xamarin application",
                    "Link": "https://secureitmania.medium.com/lets-know-how-i-have-explored-the-buried-secrets-in-xamarin-application-d6b8c5609c87"
                 }
              ],
              "Authors": ["secureITmania (@secureitmania)"],
              "Programs": ["-"],
              "Bugs": ["Hardcoded API keys", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE On A Laravel Private Program",
                    "Link": "https://zdresearch.com/rce-on-a-laravel-private-program/"
                 }
              ],
              "Authors": ["Yashar Shahinzadeh (@YShahinzadeh)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Is Math.random() Safe? from missing rate limit to bypass 2fa and possible sqli",
                    "Link": "https://neroli.medium.com/is-math-random-safe-from-missing-rate-limit-to-bypass-2fa-and-possible-sqli-2a4ea66f82c5"
                 }
              ],
              "Authors": ["Yasser Mohammed (@boomneroli)"],
              "Programs": ["-"],
              "Bugs": ["Race condition", "Lack of rate limiting", "OTP bypass", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover via Response Manipulation worth 1800$..",
                    "Link": "https://ashutoshmishra00x0.medium.com/account-takeover-via-response-manipulation-worth-1800-ffb242cc55c9"
                 }
              ],
              "Authors": ["Ashutosh mishra (@ashutoshmish_ra)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "OTP bypass", "Account takeover"],
              "Bounty": "1,800",
              "PublicationDate": "2021-02-20",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "CSRF In JSF 2.0: Predicting CSRF Tokens For Apache MyFaces",
                  "Link": "https://certitude.consulting/blog/en/csrf-myfaces-2/"
               }
            ],
            "Authors": ["Wolfgang Ettlinger"],
            "Programs": ["Apache"],
            "Bugs": ["CSRF", "ViewState"],
            "Bounty": "-",
            "PublicationDate": "2021-02-19",
            "AddedDate": "2022-12-09"
         },
           {
              "Links": [
                 {
                    "Title": "Build Pipeline Security",
                    "Link": "https://sprocketfox.io/xssfox/2021/02/18/pipeline/"
                 }
              ],
              "Authors": ["xssfox (@xssfox)"],
              "Programs": ["AWS"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Take Over by Response Manipulation",
                    "Link": "https://thevillagehacker.medium.com/account-take-over-by-response-manipulation-e1293ee51e9a"
                 }
              ],
              "Authors": ["Naveen J (@thevillagehackr)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Expose information about Partner accounts in Partner portal",
                    "Link": "https://ysamm.com/?p=640"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "GraphQL"],
              "Bounty": "3,600",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Expose Facebook object type (including private objects)",
                    "Link": "https://ysamm.com/?p=642"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Ability to find Facebook employee’s test accounts which lead to the disclosure of internal information.",
                    "Link": "https://ysamm.com/?p=638"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "GraphQL"],
              "Bounty": "500",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose internal CMS objects content",
                    "Link": "https://ysamm.com/?p=636"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Confirm if an invitation is sent to a specific email in Partners Portal / Possibility to resend the invitation",
                    "Link": "https://ysamm.com/?p=634"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "GraphQL"],
              "Bounty": "500",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Facebook CDN due to improper filtering of uploaded files extensions",
                    "Link": "https://ysamm.com/?p=632"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS"],
              "Bounty": "500",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Enumerate internal cached URLs which lead to data exposure",
                    "Link": "https://ysamm.com/?p=629"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Caching issue"],
              "Bounty": "4,800",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Make recruiting referrals on behalf of employees",
                    "Link": "https://ysamm.com/?p=620"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "GraphQL"],
              "Bounty": "3,000",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaking Facebook user information to external websites / Setting some cookies values",
                    "Link": "https://ysamm.com/?p=627"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["GraphQL", "Logic flaw", "Information disclosure"],
              "Bounty": "2,000",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Access private information about SparkAR effect owners who has a publicly viewable portfolio",
                    "Link": "https://ysamm.com/?p=621"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Information disclosure", "GraphQL"],
              "Bounty": "1,500",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open redirect in Instagram.com",
                    "Link": "https://ysamm.com/?p=625"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "500",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of a very lethal IDOR.",
                    "Link": "https://vedanttekale20.medium.com/idor-that-allowed-me-to-takeover-any-users-account-129e55871d8"
                 }
              ],
              "Authors": ["Vedant Tekale (@_justYnot)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From AWS S3 Misconfiguration to Sensitive Data Exposure",
                    "Link": "https://infosecwriteups.com/from-aws-s3-misconfiguration-to-sensitive-data-exposure-784f37a30bf9"
                 }
              ],
              "Authors": ["Jadek Mark (@mase289)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2021-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dropping a shell in Google’s Cloud SQL (the speckle-umbrella story)",
                    "Link": "https://irsl.medium.com/dropping-a-shell-in-googles-cloud-sql-the-speckle-umbrella-story-f9375bd4960d"
                 }
              ],
              "Authors": ["Imre Rad (@ImreRad)"],
              "Programs": ["Google"],
              "Bugs": ["Configuration file injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting for bugs in Telegram's animated stickers remote attack surface",
                    "Link": "https://www.shielder.it/blog/2021/02/hunting-for-bugs-in-telegrams-animated-stickers-remote-attack-surface/"
                 }
              ],
              "Authors": ["polict (@polict_)"],
              "Programs": ["Telegram"],
              "Bugs": ["Memory corruption", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2021-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sub-domain Takeover on api.techprep.fb.com (AWS Elastic Beanstalk)!",
                    "Link": "https://publish.whoisbinit.me/subdomain-takeover-on-api-techprep-fb-com-through-aws-elastic-beanstalk"
                 }
              ],
              "Authors": ["Binit Ghimire (@WHOISbinit)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "500",
              "PublicationDate": "2021-02-16",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "SHAREit Flaw Could Lead to Remote Code Execution",
                  "Link": "https://www.trendmicro.com/en_us/research/21/b/shareit-flaw-could-lead-to-remote-code-execution.html"
               }
            ],
            "Authors": ["Echo Duan", "Jesse Chang"],
            "Programs": ["SHAREit"],
            "Bugs": ["Android", "RCE", "MiTM", "Man-in-the-Disk attack", "Insecure intent", "Vulnerable Android content provider"],
            "Bounty": "-",
            "PublicationDate": "2021-02-15",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "I Own your Cloud Shell: Taking over “Azure Cloud Shell” Kubernetes Cluster Through Unsecured Kubelet API 30,000$ Bounty",
                    "Link": "https://hencohen10.medium.com/i-own-your-cloud-shell-taking-over-azure-cloud-shell-kubernetes-cluster-through-unsecured-558621519cf9"
                 }
              ],
              "Authors": ["Chen Cohen (@chencococococo)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Privilege escalation", "RCE"],
              "Bounty": "30,000",
              "PublicationDate": "2021-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Access files uploaded by employees to internal CDNs / Regenerate URL signature of user uploaded content.",
                    "Link": "https://ysamm.com/?p=606"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "12,500",
              "PublicationDate": "2021-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full account takeover worth $1000 Think out of the box",
                    "Link": "https://mokhansec.medium.com/full-account-takeover-worth-1000-think-out-of-the-box-808f0bdd8ac7"
                 }
              ],
              "Authors": ["Mohsin Khan (@tabaahi_)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "CSRF", "IDOR"],
              "Bounty": "1,000",
              "PublicationDate": "2021-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Delete linked payments accounts of a Facebook page (or user)",
                    "Link": "https://ysamm.com/?p=609"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2021-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "URLs in img tag aren’t passed through safe_image.php which lead to exposure of Facebook users IPs.",
                    "Link": "https://ysamm.com/?p=603"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2021-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leak of internal categorySets names and employees test accounts.",
                    "Link": "https://ysamm.com/?p=613"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2021-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "View orders and financial reports lists for any page shop",
                    "Link": "https://ysamm.com/?p=597"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2021-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in icloud.com — $5000",
                    "Link": "https://vbharad.medium.com/stored-xss-in-icloud-com-5000-998b8c4b2075"
                 }
              ],
              "Authors": ["Vishal Bharad"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2021-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first bounty (stored-xss)",
                    "Link": "https://karansh491.medium.com/my-first-bounty-stored-xss-96dea41fd9cf"
                 }
              ],
              "Authors": ["Karan sharma (@karansh491)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2021-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR via Websockets allow me to takeover any users account",
                    "Link": "https://mokhansec.medium.com/idor-via-websockets-allow-me-to-takeover-any-users-account-23460dacdeab"
                 }
              ],
              "Authors": ["Mohsin Khan (@tabaahi_)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "450",
              "PublicationDate": "2021-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked Everyone’s Resume/CV’s and Got €€€",
                    "Link": "https://vbharad.medium.com/how-i-hacked-everyones-resume-cv-s-and-got-851aaa4d75d9"
                 }
              ],
              "Authors": ["Vishal Bharad"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Broken authorization", "Information disclosure"],
              "Bounty": "250",
              "PublicationDate": "2021-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Changing other users Episode title & description - IDOR Vulnerability in [REDACTED] (Write Up)",
                    "Link": "https://blog.evanricafort.com/2021/02/idor-in-redacted.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "1,150",
              "PublicationDate": "2021-02-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[GITLAB] — Server Side Request Forgery in “Project Import” page.",
                    "Link": "https://ltsirkov.medium.com/gitlab-server-side-request-forgery-in-project-import-page-6fdb9ef423e4"
                 }
              ],
              "Authors": ["Lyubomir Tsirkov (@lyubo_tsirkov)"],
              "Programs": ["GitLab"],
              "Bugs": ["SSRF"],
              "Bounty": "1,500",
              "PublicationDate": "2021-02-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[GITLAB] — Just another SSRF issue.",
                    "Link": "https://ltsirkov.medium.com/gitlab-just-another-ssrf-issue-483bc040392b"
                 }
              ],
              "Authors": ["Lyubomir Tsirkov (@lyubo_tsirkov)"],
              "Programs": ["GitLab"],
              "Bugs": ["SSRF"],
              "Bounty": "1,000",
              "PublicationDate": "2021-02-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OAuth Misconfiguration Leads to Full Account takeover",
                    "Link": "https://neroli.medium.com/oauth-misconfiguration-leads-to-full-account-takeover-22b032cb6732"
                 }
              ],
              "Authors": ["Yasser Mohammed (@boomneroli)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "Clickjacking", "CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-02-13",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "[GITLAB] — Denial of service via “Login Panel” functionality.",
                  "Link": "https://ltsirkov.medium.com/gitlab-denial-of-service-via-login-panel-functionality-684c8583706c"
               }
            ],
            "Authors": ["Lyubomir Tsirkov (@lyubo_tsirkov)"],
            "Programs": ["GitLab"],
            "Bugs": ["Application-level DoS"],
            "Bounty": "-",
            "PublicationDate": "2021-02-12",
            "AddedDate": "2023-05-04"
         },
           {
              "Links": [
                 {
                    "Title": "How I was able to get extra coins",
                    "Link": "https://web.archive.org/web/20220519231807/https://wisdomfreak.com/how-i-was-able-to-get-extra-coins/"
                 }
              ],
              "Authors": ["Saddam Hussain (@wisdomfreak1)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-02-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaked Credentials gives access to internalfb.com",
                    "Link": "https://philippeharewood.com/leaked-credentials-gives-access-to-internalfb-com/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "6,000",
              "PublicationDate": "2021-02-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Chess.com and Accessing 50 Million Customer Records",
                    "Link": "https://samcurry.net/hacking-chesscom/"
                 }
              ],
              "Authors": ["Sam Curry (@samwcyo)"],
              "Programs": ["Chess.com"],
              "Bugs": ["Reflected XSS", "Information disclosure", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-02-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The \"P\" in Telegram stands for Privacy",
                    "Link": "https://www.inputzero.io/2020/12/telegram-privacy-fails-again.html"
                 }
              ],
              "Authors": ["Dhiraj (@RandomDhiraj)"],
              "Programs": ["Telegram"],
              "Bugs": ["Privacy issue"],
              "Bounty": "3,000",
              "PublicationDate": "2021-02-11",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "An Accidental XSS on uu.nl",
                  "Link": "https://santoshdbobade.blogspot.com/"
               }
            ],
            "Authors": ["Santosh Bobade (@Santosh88267387)"],
            "Programs": ["Utrecht University"],
            "Bugs": ["XSS"],
            "Bounty": "-",
            "PublicationDate": "2021-02-11",
            "AddedDate": "2022-11-08"
         },
           {
              "Links": [
                 {
                    "Title": "Fastest Subdomain Take Over & DNS Misconfiguration Hunt.",
                    "Link": "https://web.archive.org/web/20210213062858/https://www.cysek.org/post/subdomain-dnsmiscon"
                 }
              ],
              "Authors": ["Kabeer (@iTheKabeer)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover", "DNS zone transfer"],
              "Bounty": "-",
              "PublicationDate": "2021-02-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sending ephemeral message to any Facebook user",
                    "Link": "https://servicenger.com/blog/mobile/sending-ephemeral-message-to-any-facebook-user/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-02-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Tale of 2nd $xxx Bounty from Facebook",
                    "Link": "https://medium.com/bugbountywriteup/a-tale-of-2nd-xxx-bounty-ability-to-gain-persistence-on-facebook-events-as-an-unremovable-9408338ccf8f"
                 }
              ],
              "Authors": ["Kunjan Nayak"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2021-02-10",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "How I Got An Appreciation Letter From Harvard University",
                  "Link": "https://santoshdbobade.medium.com/how-i-got-an-appreciation-letter-from-harvard-university-a3d19de69701"
               }
            ],
            "Authors": ["Santosh Bobade (@Santosh88267387)"],
            "Programs": ["Harvard University"],
            "Bugs": ["Subdomain takeover"],
            "Bounty": "-",
            "PublicationDate": "2021-02-10",
            "AddedDate": "2022-11-08"
         },
           {
              "Links": [
                 {
                    "Title": "Self-XSS to rXSS via Uploaded File Name",
                    "Link": "https://enfinlay.github.io//xss/selfxss/upload/bugbounty/2021/02/09/selfxss-to-rxss-via-file-name.html"
                 }
              ],
              "Authors": ["P4nda (@InfoSecP4nda)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-02-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies",
                    "Link": "https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610"
                 }
              ],
              "Authors": ["Alex Birsan (@alxbrsn)"],
              "Programs": ["Paypal", "Shopify", "Apple", "Netflix", "Yelp", "Uber", "Microsoft"],
              "Bugs": ["Dependency confusion"],
              "Bounty": "130,000",
              "PublicationDate": "2021-02-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing URI Parsers for fun and profit",
                    "Link": "https://huntingreads.com/abusing-uri-parsers-for-fun-and-profit/"
                 }
              ],
              "Authors": ["Mohammad Owais (@_mohammadowais)"],
              "Programs": ["-"],
              "Bugs": ["URL validation bypass"],
              "Bounty": "500",
              "PublicationDate": "2021-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Duplicate Registration - The Twinning Twins",
                    "Link": "https://shahjerry33.medium.com/duplicate-registration-the-twinning-twins-883dfee59eaf"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2021-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bigbasket Bug Bounty Writeup",
                    "Link": "https://infosecwriteups.com/bigbasket-bug-bounty-writeup-9fedc490b814"
                 }
              ],
              "Authors": ["Lohith Gowda M (@lohi_gowda_)"],
              "Programs": ["-"],
              "Bugs": ["Insecure data storage", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS on a Public Program",
                    "Link": "https://thevillagehacker.medium.com/reflected-xss-on-a-public-program-e8c0416daca1"
                 }
              ],
              "Authors": ["Naveen J (@thevillagehackr)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Gain Access to the Server Administration of a Million-Dollar Company",
                    "Link": "https://marxchryz.medium.com/how-i-gain-access-to-the-server-administration-of-a-million-dollar-company-14da68c7a9dd"
                 }
              ],
              "Authors": ["Marx Chryz Del Mundo"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Mass assignment"],
              "Bounty": "5,000",
              "PublicationDate": "2021-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating SSRF to RCE",
                    "Link": "https://sanderwind.medium.com/escalating-ssrf-to-rce-7c0147371c40"
                 }
              ],
              "Authors": ["Sander Wind (@SanderWind)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XXE To AWS Metadata Disclosure",
                    "Link": "http://almadj.us/infosec/xxe-to-aws-metadata-disclosure/"
                 }
              ],
              "Authors": ["Al-Madjus (@AlMadjus)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "2,000",
              "PublicationDate": "2021-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Messenger Desktop App Arbitrary File Read",
                    "Link": "https://medium.com/@renwa/facebook-messenger-desktop-app-arbitrary-file-read-db2374550f6d"
                 }
              ],
              "Authors": ["Renwa (@RenwaX23)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Arbitrary file read"],
              "Bounty": "2,000",
              "PublicationDate": "2021-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Page Admin Disclosed In Groups Due To Improper Session Handling In Facebook Web",
                    "Link": "https://medium.com/bugbountywriteup/page-admin-disclosed-in-groups-due-to-bad-session-handling-in-facebook-web-184514fafff9"
                 }
              ],
              "Authors": ["Samip Aryal (@samiparyal_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Redwood Report2Web XSS and Frame injection",
                    "Link": "https://vict0ni.me/redwood-report2web-xss-and-frame-injection/"
                 }
              ],
              "Authors": ["vict0ni (@vict0ni)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "Frame injection"],
              "Bounty": "-",
              "PublicationDate": "2021-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug bounty failure stories to learn from: how we ended up to hack a bank with no reward",
                    "Link": "https://www.redtimmy.com/bug-bounty-failure-stories-to-learn-from-how-we-ended-up-to-hack-a-bank-with-no-reward/"
                 }
              ],
              "Authors": ["Red Timmy Security (@redtimmysec)"],
              "Programs": ["-"],
              "Bugs": ["DoS", "Default credentials"],
              "Bounty": "-",
              "PublicationDate": "2021-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open Redirect vulnerability found using link parameter",
                    "Link": "https://muhammad-aamir.medium.com/open-redirect-vulnerability-found-using-link-parameter-5fc43e2ea8fd"
                 }
              ],
              "Authors": ["Muhammad Aamir (@Muhammad__Aamir)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "100",
              "PublicationDate": "2021-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Remote Desktop Web Access Authentication Timing Attack",
                    "Link": "https://raxis.com/blog/rd-web-access-vulnerability"
                 }
              ],
              "Authors": ["Matt Dunn"],
              "Programs": ["Microsoft"],
              "Bugs": ["Timing attack", "Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2021-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to Turn a XSS into a Account Takeover",
                    "Link": "https://pullerjsecu.medium.com/how-i-was-able-to-turn-a-xss-into-a-account-takeover-ae0c478640e7"
                 }
              ],
              "Authors": ["Josh Fam (@Pullerze)"],
              "Programs": ["-"],
              "Bugs": ["Web cache poisoning", "Stored XSS", "Account takeover", "OAuth", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020-9759 - Getting root on webOS",
                    "Link": "https://blog.recurity-labs.com/2021-02-03/webOS_Pt1.html"
                 }
              ],
              "Authors": ["Andreas Lindh (@addelindh)"],
              "Programs": ["LG"],
              "Bugs": ["Local Privilege Escalation", "Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2021-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing Chat session ID with CORS and execute CSRF attack",
                    "Link": "https://sunilyedla.medium.com/stealing-chat-session-id-with-cors-and-execute-csrf-attack-f9f7ea229db1"
                 }
              ],
              "Authors": ["Sunil Yedla (@sunilyedla2)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2021-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Applying Offensive Reverse Engineering to Facebook Gameroom",
                    "Link": "https://spaceraccoon.dev/applying-offensive-reverse-engineering-to-facebook-gameroom"
                 }
              ],
              "Authors": ["Eugene Lim (@spaceraccoonsec)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2021-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "1st Facebook Bug Bounty | Disclose page’s admin to mod/admin of group",
                    "Link": "https://web.archive.org/web/20210204093332/https://nhiephon1337.medium.com/1st-facebook-bug-bounty-disclose-pages-admin-to-mod-admin-of-group-c3161c22c858"
                 }
              ],
              "Authors": ["nhiephon (@_nhiephon)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spoofing and Attacking With Skype",
                    "Link": "https://mrd0x.com/spoofing-and-attacking-with-skype/"
                 }
              ],
              "Authors": ["mr.d0x (@mrd0x)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Spoofing"],
              "Bounty": "-",
              "PublicationDate": "2021-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Access developer tasks list of any Facebook Application (GraphQL IDOR)",
                    "Link": "https://amineaboud.medium.com/access-developer-tasks-list-of-any-of-facebook-application-graphql-idor-62307c5e5b34"
                 }
              ],
              "Authors": ["Amine Aboud (@amineaboud)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-02-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose the FB profile of Facebook employees who create official announcement messages (Bug Bounty)",
                    "Link": "https://amineaboud.medium.com/disclose-the-fb-profile-of-facebook-employees-who-create-official-announcement-messages-bug-76554068caf7"
                 }
              ],
              "Authors": ["Amine Aboud (@amineaboud)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-02-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An Account Takeover Vulnerability Due to Response Manipulation.",
                    "Link": "https://avanishpathak46.medium.com/an-account-takeover-vulnerability-due-to-response-manipulation-e23fe629bd1"
                 }
              ],
              "Authors": ["Avanish Pathak (@avanish46)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "Account takeover"],
              "Bounty": "4,100",
              "PublicationDate": "2021-01-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An unexpected bug",
                    "Link": "https://cyberhacks200.medium.com/an-unexpected-bug-9cab5072e009"
                 }
              ],
              "Authors": ["Nitin yadav (@Nitinydv14)"],
              "Programs": ["-"],
              "Bugs": ["Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2021-01-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An Interesting Account Takeover Vulnerability",
                    "Link": "https://avanishpathak46.medium.com/an-interesting-account-takeover-vulnerability-a1fbec0e01a"
                 }
              ],
              "Authors": ["Avanish Pathak (@avanish46)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Android apk leaks access token to takeover the whole infrastructure",
                    "Link": "https://notifybugme.medium.com/android-apk-leaks-access-token-to-takeover-the-whole-infrastructure-c979187f8fc8"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Hardcoded credentials", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I chained P4 To P2 [Open Redirection To Full Account Takeover]",
                    "Link": "https://medium.com/bugbountywriteup/how-i-chained-p4-to-p2-open-redirection-to-full-account-takeover-a28b09a94bf7"
                 }
              ],
              "Authors": ["Bishal Shrestha (@bishal0x01)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Access Control & Stored XSS - Easy Hunt",
                    "Link": "https://web.archive.org/web/20210201180254/https://www.cysek.org/post/bac-sxss"
                 }
              ],
              "Authors": ["Kabeer (@iTheKabeer)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-01-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Destroying Armies and Villages through Cross-Site Scripting - Bug Bounty Write-up",
                    "Link": "https://0xfabiof.github.io/stored-xss-tw/"
                 }
              ],
              "Authors": ["Fábio Freitas (@0xfabiof)"],
              "Programs": ["InnoGames"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2021-01-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Launching Internal & Non-Exported Deeplinks On Facebook",
                    "Link": "https://ash-king.co.uk/blog/Launching-internal-non-exported-deeplinks-on-Facebook"
                 }
              ],
              "Authors": ["Ashley King (@AshleyKingUK)", "Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "4,000",
              "PublicationDate": "2021-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Analysing Crash Messages To Achieve Blind Root Command Injection",
                    "Link": "https://www.shawarkhan.com/2021/01/analysing-crash-messages-to-achieve.html"
                 }
              ],
              "Authors": ["Shawar Khan (@ShawarkOFFICIAL)"],
              "Programs": ["-"],
              "Bugs": ["OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2021-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Code Execution – LimeSurvey (CVE-2018-7556)",
                    "Link": "https://yeuchimse.com/remote-code-execution-limesurvey-cve-2018-7556/"
                 }
              ],
              "Authors": ["yeuchimse (@yeuchimse)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OTP Bypass Account Takeover to Admin Panel — Ft. Header Injection",
                    "Link": "https://logicbomb.medium.com/otp-bypass-account-takeover-to-admin-panel-ft-header-injection-16f2982a0136"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business Logic Error Methodology (easy way) + PoC-s",
                    "Link": "https://medium.com/bugbountywriteup/business-logic-error-methodology-easy-way-poc-s-8195d8dee95b"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How We Escaped Docker in Azure Functions",
                    "Link": "https://www.intezer.com/blog/research/how-we-escaped-docker-in-azure-functions/"
                 }
              ],
              "Authors": ["Intezer"],
              "Programs": ["Microsoft"],
              "Bugs": ["Privilege escalation", "Cloud"],
              "Bounty": "-",
              "PublicationDate": "2021-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weird functionality leads to Account Takeover (Millions of Users affected)",
                    "Link": "https://nullr3x.medium.com/weird-functionality-leads-to-account-takeover-millions-of-users-affected-3fdf06be45"
                 }
              ],
              "Authors": ["Sahil Mehra (@nullr3x)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Broken authentication"],
              "Bounty": "4,000",
              "PublicationDate": "2021-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bragging Rights(Part 1): Short story of a bug wave",
                    "Link": "https://medium.com/bugbountywriteup/bragging-rights-part-1-short-story-of-a-bug-wave-dbb88f48b604"
                 }
              ],
              "Authors": ["Manas Harsh (@ManasH4rsh)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Stored XSS", "SSRF", "Subdomain takeover", "Hardcoded credentials"],
              "Bounty": "1,550",
              "PublicationDate": "2021-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hijacking Google Drive Files (Documents, Photo & Video) Through Google Docs Sharing",
                    "Link": "https://santuysec.com/2021/01/27/hijacking-google-drive-files-documents-photo-video-through-google-docs-sharing/"
                 }
              ],
              "Authors": ["santuySec (@santuySec)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2021-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$500 For No Rate Limit On Forgot Password Page",
                    "Link": "https://bugbountyhunter.medium.com/500-for-no-rate-limit-on-forgot-password-page-d534d1d750db"
                 }
              ],
              "Authors": ["BBHC (@community_bug)"],
              "Programs": ["-"],
              "Bugs": ["Lack of rate limiting", "Password reset"],
              "Bounty": "500",
              "PublicationDate": "2021-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding SSRF BY Full Automation",
                    "Link": "https://notifybugme.medium.com/finding-ssrf-by-full-automation-7d2680091d68"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BMW Bug Bounty – Account Verification Bypass writeup",
                    "Link": "https://www.pethuraj.com/blog/bmw-bugbounty-writeup/"
                 }
              ],
              "Authors": ["Pethuraj (@Pethuraj)"],
              "Programs": ["BMW"],
              "Bugs": ["OTP bypass", "Bruteforce", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2021-01-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaking issues from linked Jira – Atlassian Confluence Server",
                    "Link": "https://yeuchimse.com/leaking-issues-from-linked-jira-atlassian-confluence-server/"
                 }
              ],
              "Authors": ["yeuchimse (@yeuchimse)"],
              "Programs": ["Atlassian"],
              "Bugs": ["XS-Search"],
              "Bounty": "600",
              "PublicationDate": "2021-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Get paid by smuggling, the legal way",
                    "Link": "https://medium.com/bugbountywriteup/get-paid-by-smuggling-the-legal-way-c31805de3c59"
                 }
              ],
              "Authors": ["James Ling (@James_puppykok)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "-",
              "PublicationDate": "2021-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining a self XSS to Account Takeover",
                    "Link": "https://github.com/tess-ss/writeups/blob/main/bug.md"
                 }
              ],
              "Authors": ["Arman Sameer (@ArmanSameer95)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "Reflected XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR Revealing Images CDN Links",
                    "Link": "https://susanwagle123.medium.com/idor-revealing-images-cdn-links-6589e19bdbaf"
                 }
              ],
              "Authors": ["susan wagle"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing WAF with incorrect proxy settings for Hunting Bugs.",
                    "Link": "https://shaurya-sharma.medium.com/bypassing-waf-with-incorrect-proxy-settings-for-hunting-bugs-3449b7716f59"
                 }
              ],
              "Authors": ["Shaurya Sharma (@ShauryaSharma05)"],
              "Programs": ["-"],
              "Bugs": ["URL validation bypass"],
              "Bounty": "-",
              "PublicationDate": "2021-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sql Injection via hidden parameter",
                    "Link": "https://hajarerutik9.medium.com/sql-injection-via-hidden-parameter-6da7699248fc"
                 }
              ],
              "Authors": ["Rutvik Hajare (@HajareRutvik)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2021-01-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$10,000 for automatic email confirmation bug in Microsoft’s Edge browser",
                    "Link": "https://kingkaran977.medium.com/10-000-for-automatic-email-confirmation-bug-in-microsofts-edge-browser-22f15ceccb4a"
                 }
              ],
              "Authors": ["Karan Chaudhary (@0xKaran)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Logic flaw"],
              "Bounty": "10,000",
              "PublicationDate": "2021-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Secret Parameter, LFR, and Potential RCE in NodeJS Apps",
                    "Link": "https://blog.shoebpatel.com/2021/01/23/The-Secret-Parameter-LFR-and-Potential-RCE-in-NodeJS-Apps/"
                 }
              ],
              "Authors": ["CaptainFreak (@0xCaptainFreak)"],
              "Programs": ["-"],
              "Bugs": ["Local File Read", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF Protection Bypass in Atlassian Confluence Server",
                    "Link": "https://yeuchimse.com/csrf-protection-bypass-in-atlassian-confluence-server/"
                 }
              ],
              "Authors": ["yeuchimse (@yeuchimse)"],
              "Programs": ["Atlassian"],
              "Bugs": ["CSRF"],
              "Bounty": "3,600",
              "PublicationDate": "2021-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Page Admin Disclosure When Replying Comments",
                    "Link": "https://www.pantaprakash.com.np/posts/categories/bugbounty-writeup/4.html"
                 }
              ],
              "Authors": ["Prakash Panta (@prakashpanta268)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2021-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Staff Information Disclosure on Support Ticketing System ($x,xxx)",
                    "Link": "https://ph-hitachi.medium.com/staff-information-disclosure-on-support-ticketing-system-p2-x-xxx-a08960aea7b1"
                 }
              ],
              "Authors": ["Ph.Hitachi"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "KindleDrip — From Your Kindle’s Email Address to Using Your Credit Card",
                    "Link": "https://medium.com/realmodelabs/kindledrip-from-your-kindles-email-address-to-using-your-credit-card-bb93dbfb2a08"
                 }
              ],
              "Authors": ["Yogev Bar-On"],
              "Programs": ["Amazon"],
              "Bugs": ["RCE"],
              "Bounty": "18,000",
              "PublicationDate": "2021-01-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story Behind Sweet SSRF.",
                    "Link": "https://systemweakness.com/story-behind-sweet-ssrf-40c705f13053"
                 }
              ],
              "Authors": ["Rohit Soni (@streetofhacker)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-01-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF Exploitation in Libreoffice Spreadsheet File Converter",
                    "Link": "https://r4id3n.medium.com/ssrf-exploitation-in-spreedsheet-to-pdf-converter-2c7eacdac781"
                 }
              ],
              "Authors": ["R4id3n (@R4id3n__)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-01-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Bug Bounty] 600$ Info Disclosure: obtain any user’s backup data",
                    "Link": "https://medium.com/bugbountywriteup/bug-bounty-600-info-disclosure-a-token-is-not-the-same-on-all-endpoints-febf5b7ea745"
                 }
              ],
              "Authors": ["Tommaso De Ponti"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-01-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open-redirect [in email]",
                    "Link": "https://inakcf.medium.com/open-redirect-in-email-c658c248eec1"
                 }
              ],
              "Authors": ["Akhil"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2021-01-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Simple & Sweet: Bypass email update restriction to change emails of team members",
                    "Link": "https://sunilyedla.medium.com/simple-sweet-bypassing-email-update-restriction-to-change-emails-of-team-members-6ce5770e7929"
                 }
              ],
              "Authors": ["Sunil Yedla (@sunilyedla2)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-01-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Embedded YouTube Player Told Me What You Were Watching (and more)",
                    "Link": "https://bugs.xdavidhu.me/google/2021/01/18/the-embedded-youtube-player-told-me-what-you-were-watching-and-more/"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,337",
              "PublicationDate": "2021-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was rewarded a $1000 bounty after abusing File Upload functionality to Stored XSS Vulnerability leading to credential theft of a vistor in a website.",
                    "Link": "https://kunalkhubchandani.medium.com/how-i-was-rewarded-a-1000-bounty-after-abusing-file-upload-functionality-to-stored-xss-945a40ac6f94"
                 }
              ],
              "Authors": ["Kunal Khubchandani (@iamkun4l)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2021-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Let’s know How I have explored the buried secrets in React Native application",
                    "Link": "https://secureitmania.medium.com/lets-know-how-i-have-explored-the-buried-secrets-in-react-native-application-6236728198f7"
                 }
              ],
              "Authors": ["secureITmania (@secureitmania)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Hardcoded credentials"],
              "Bounty": "-",
              "PublicationDate": "2021-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ShazLocate! Abusing CVE-2019-8791 & CVE-2019-8792",
                    "Link": "https://www.ash-king.co.uk/blog/Shazlocate-abusing-CVE-2019-8791-CVE-2019-8792"
                 }
              ],
              "Authors": ["Ashley King (@AshleyKingUK)"],
              "Programs": ["Google", "Apple"],
              "Bugs": ["Insecure deeplink", "Information disclosure", "Android"],
              "Bounty": "-",
              "PublicationDate": "2021-01-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Strange Admin Panel Bypass Story | | Bug Bounty",
                    "Link": "https://geekboyranjeet.medium.com/strange-admin-panel-bypass-story-bug-bounty-5e618099baaf"
                 }
              ],
              "Authors": ["Ranjeet Kumar Singh (@geekboyranjeet)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-01-17",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "How we exploited a remote code execution vulnerability in math.js",
                  "Link": "https://jwlss.pw/mathjs/"
               }
            ],
            "Authors": ["Giulio Muscarello (@CapacitorSet)", "Denys Vitali (@denysvitali)"],
            "Programs": ["math.js"],
            "Bugs": ["RCE", "Code injection"],
            "Bounty": "-",
            "PublicationDate": "2021-01-16",
            "AddedDate": "2023-06-27"
         },
           {
              "Links": [
                 {
                    "Title": "My first and last crit of 2020 on Hackerone",
                    "Link": "https://takester.medium.com/my-first-and-last-crit-of-2020-on-hackerone-702a694781b0"
                 }
              ],
              "Authors": ["Takester (@dhiraj_ramteke)"],
              "Programs": ["-"],
              "Bugs": ["Lack of rate limiting", "Bruteforce", "IDOR", "Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-01-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding 0day to hack Apple",
                    "Link": "https://httpvoid.com/Apple-RCE.md"
                 }
              ],
              "Authors": ["Harsh Jaiswal (@rootxharsh)", "Rahul Maini (@iamnoooob)"],
              "Programs": ["Apple", "Lucee"],
              "Bugs": ["RCE", "ColdFusion"],
              "Bounty": "50,000",
              "PublicationDate": "2021-01-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weaponizing Apify for mass bug bounty $$$",
                    "Link": "https://warandcode.com/post/apify-mass-bug-bounty/"
                 }
              ],
              "Authors": ["Randy Gingeleski (@gingeleski)"],
              "Programs": ["-"],
              "Bugs": ["Akamai ARL attack"],
              "Bounty": "-",
              "PublicationDate": "2021-01-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking naked Akamai ARL at scale",
                    "Link": "https://warandcode.com/post/akamai-arl-hack/"
                 }
              ],
              "Authors": ["Randy Gingeleski (@gingeleski)"],
              "Programs": ["-"],
              "Bugs": ["Akamai ARL attack"],
              "Bounty": "-",
              "PublicationDate": "2021-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BitLocker Lockscreen bypass",
                    "Link": "https://secret.club/2021/01/15/bitlocker-bypass.html"
                 }
              ],
              "Authors": ["Jonas L (@jonasLyk)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Lock screen bypass", "Local Privilege Escalation", "Windows"],
              "Bounty": "-",
              "PublicationDate": "2021-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Attack of the clones 2: Git CLI remote code execution strikes back",
                    "Link": "https://blog.blazeinfosec.com/attack-of-the-clones-2-git-command-client-remote-code-execution-strikes-back/"
                 }
              ],
              "Authors": ["Vitor Fernandes (@Rapt00rVF)"],
              "Programs": ["GitHub"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hijacked the top-level domain of a sovereign state",
                    "Link": "https://labs.detectify.com/2021/01/15/how-i-hijacked-the-top-level-domain-of-a-sovereign-state/"
                 }
              ],
              "Authors": ["Fredrik N. Almroth (@Almroot)"],
              "Programs": ["Internet Bug Bounty"],
              "Bugs": ["Domain takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Insertion Of Malicious Links For Execution In Profile Picture - Unvalidated User Input In MS Sharepoint 2019 (CVE-2020-1456)",
                    "Link": "https://slashcrypto.org/2021/01/15/CVE-2020-1456/"
                 }
              ],
              "Authors": ["David (@slashcrypto)", "user_x73x76x6E"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Irremovable Facebook group album photos and entire album under certain circumstances (Bounty: 1000 USD)",
                    "Link": "https://theshubh77.medium.com/irremovable-facebook-group-album-photos-and-entire-album-under-certain-circumstances-bounty-1000-b1b2a870b8e0"
                 }
              ],
              "Authors": ["Shubham Bhamare (@theshubh77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2021-01-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tale of 2 TOOTB Bugs: Google and WhatsApp",
                    "Link": "https://medium.com/bug-bounty-hunting/tale-of-2-tootb-bugs-google-and-whatsapp-3c0ad40d604c"
                 }
              ],
              "Authors": ["Circle Ninja (@circleninja)"],
              "Programs": ["Google", "Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2021-01-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I managed to trigger a Stored-XSS in an online store with the help of Cache Poisoning",
                    "Link": "https://web.archive.org/web/20210730144815/https://www.cysek.org/post/sxss-by-cache-poison-attack"
                 }
              ],
              "Authors": ["Schizo!"],
              "Programs": ["-"],
              "Bugs": ["Web cache poisoning", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2021-01-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of a really cool SSRF bug.",
                    "Link": "https://vedanttekale20.medium.com/story-of-a-really-cool-ssrf-bug-cf88a3800efc"
                 }
              ],
              "Authors": ["Vedant Tekale (@_justYnot)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2021-01-13",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "GoCD Multiple Vulnerabilities",
                  "Link": "https://pulsesecurity.co.nz/advisories/GOCD-Multiple-Vulnerabilities"
               }
            ],
            "Authors": ["Denis Andzakovic"],
            "Programs": ["GoCD"],
            "Bugs": ["RCE", "Information disclosure", "Insecure deserialization", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2021-01-12",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Making Clouds Rain :: Remote Code Execution in Microsoft Office 365",
                    "Link": "https://srcincite.io/blog/2021/01/12/making-clouds-rain-rce-in-office-365.html"
                 }
              ],
              "Authors": ["Steven Seeley (@steventseeley)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-01-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing User Information Via XSS Via Parameter Pollution",
                    "Link": "https://levelup.gitconnected.com/stealing-user-information-via-xss-via-parameter-pollution-7d99b3379e7d"
                 }
              ],
              "Authors": ["Hamza Avvan (@hamzaavvan)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "XSS"],
              "Bounty": "1,250",
              "PublicationDate": "2021-01-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF with IDOR - A Deadly Combo",
                    "Link": "https://shahjerry33.medium.com/csrf-with-idor-a-deadly-combo-203e93967702"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-01-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unrestricted File Upload",
                    "Link": "https://binamrapandey.medium.com/unrestricted-file-upload-e95e1c6fb80"
                 }
              ],
              "Authors": ["Binamra Pandey"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2021-01-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Guest Blog Post: Leaking silhouettes of cross-origin images",
                    "Link": "https://blog.mozilla.org/attack-and-defense/2021/01/11/leaking-silhouettes-of-cross-origin-images/"
                 }
              ],
              "Authors": ["Aleksejs Popovs (@aleksejspopovs)"],
              "Programs": ["Mozilla", "Google (Chrome)"],
              "Bugs": ["Side-channel information leakage", "Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2021-01-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing Your Private YouTube Videos, One Frame at a Time",
                    "Link": "https://bugs.xdavidhu.me/google/2021/01/11/stealing-your-private-videos-one-frame-at-a-time/"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "5,000",
              "PublicationDate": "2021-01-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "UNEP Breached, 100K+ Employee Records Accessed",
                    "Link": "https://johnjhacking.com/blog/unep-breach/"
                 }
              ],
              "Authors": ["Jackson Henry (@JacksonHHax)", "John Jackson (@johnjhacking)", "Nick Sahler (@nicksahler)", "Aubrey Cottle"],
              "Programs": ["United Nations"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-01-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weblogic Remote Code Execution (Exploiting CVE-2019-2725)",
                    "Link": "https://blog.cybercastle.io/weblogic-remote-code-execution-exploiting-cve-2019-2725/"
                 }
              ],
              "Authors": ["Mahmoud Gamal (@Zombiehelp54)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-01-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthorized Access to OData Entities + $2K Bounty From Microsoft",
                    "Link": "https://medium.com/bugbountywriteup/unauthorized-access-to-odata-entities-2k-bounty-from-microsoft-e070b2ef88c2"
                 }
              ],
              "Authors": ["Borna Nematzadeh (@LogicalHunter)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Broken authorization", "Information disclosure"],
              "Bounty": "2,000",
              "PublicationDate": "2021-01-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to Regain access to account deleted by Admin leading to $$$",
                    "Link": "https://rajeshranjan457.medium.com/how-i-was-able-to-regain-access-to-account-deleted-by-admin-leading-to-a2c29025f8cd"
                 }
              ],
              "Authors": ["Rajesh Ranjan (@_rajesh_ranjan_)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2021-01-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A 'Novel' Way to Bypass Executable Signature Checks with Electron",
                    "Link": "https://parsiya.net/blog/2021-01-08-a-novel-way-to-bypass-executable-signature-checks-with-electron/"
                 }
              ],
              "Authors": ["Parsia Hackerman (@cryptogangsta)"],
              "Programs": ["-"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2021-01-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Create post on any Facebook page",
                    "Link": "https://www.darabi.me/2020/12/create-invisible-post-on-any-facebook.html"
                 }
              ],
              "Authors": ["Pouya Darabi (@Pouyadarabi)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "30,000",
              "PublicationDate": "2021-01-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Application-Level Profile Semantics (APLS)",
                    "Link": "https://niemand.com.ar/2021/01/08/exploiting-application-level-profile-semantics-apls-from-spring-data-rest/"
                 }
              ],
              "Authors": ["Niemand (@niemand_sec)"],
              "Programs": ["-"],
              "Bugs": ["APLS misconfiguration", "API misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2021-01-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind XSS in Google Analytics Admin Panel — $3133.70",
                    "Link": "https://ashketchum.medium.com/blind-xss-in-google-analytics-admin-panel-3133-70-2185d1cce82a"
                 }
              ],
              "Authors": ["Ashish Dhone (@ashketchum_16)"],
              "Programs": ["Google"],
              "Bugs": ["Blind XSS"],
              "Bounty": "3,133.70",
              "PublicationDate": "2021-01-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Information Disclosure through Signup Endpoint",
                    "Link": "https://orthonviper.medium.com/information-disclosure-through-signup-endpoint-86d2d66dfef1"
                 }
              ],
              "Authors": ["Sunil Yedla (@sunilyedla2)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2021-01-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook: Linkshim protection bypass using fb://webview",
                    "Link": "https://servicenger.com/blog/mobile/facebook-linkshim-protection-bypass-using-fb-webview/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2021-01-08",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Universal Deserialisation Gadget for Ruby 2.x-3.x",
                  "Link": "https://devcraft.io/2021/01/07/universal-deserialisation-gadget-for-ruby-2-x-3-x.html"
               }
            ],
            "Authors": ["William Bowling / vakzz (@wcbowling)"],
            "Programs": ["Ruby"],
            "Bugs": ["Insecure deserialization", "Security code review", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2021-01-07",
            "AddedDate": "2023-08-08"
         },
           {
              "Links": [
                 {
                    "Title": "$10,000 for a vulnerability that doesn’t exist",
                    "Link": "https://krevetk0.medium.com/10-000-for-a-vulnerability-that-doesnt-exist-9dbc63684e94"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "10,500",
              "PublicationDate": "2021-01-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Github Organization Takeover By Claiming Owner Invitation",
                    "Link": "https://abss.me/posts/github-org-takeover/"
                 }
              ],
              "Authors": ["Abss (@absshax)"],
              "Programs": ["GitHub"],
              "Bugs": ["Account takeover", "Logic flaw"],
              "Bounty": "5,000",
              "PublicationDate": "2021-01-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on Product Description [HIGH] — $400",
                    "Link": "https://emanuel-beni.medium.com/stored-xss-on-product-description-high-400-2f078fd70fd2"
                 }
              ],
              "Authors": ["Emanuel Beni Harijanto"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "400",
              "PublicationDate": "2021-01-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Take Over Worth 100£",
                    "Link": "https://web.archive.org/web/20210106234354/https://medium.com/bugbountywriteup/subdomain-take-over-worth-100-ce822ed85ba0"
                 }
              ],
              "Authors": ["c0d3x27 (@c0d3x27)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "100",
              "PublicationDate": "2021-01-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding bugs on Chess.com",
                    "Link": "https://medium.com/bugbountywriteup/finding-bugs-on-chess-com-739a71fbdb31"
                 }
              ],
              "Authors": ["Seqrity (@seqrity9)"],
              "Programs": ["Chess.com"],
              "Bugs": ["Lack of rate limiting", "Bruteforce", "CSRF"],
              "Bounty": "180",
              "PublicationDate": "2021-01-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Nick's infrequently updated blog",
                    "Link": "https://njbooher.github.io/blog/cloudflare-workers-ip-spoofing"
                 }
              ],
              "Authors": ["Nick Booher"],
              "Programs": ["Cloudflare"],
              "Bugs": ["WAF bypass", "IP spoofing"],
              "Bounty": "-",
              "PublicationDate": "2021-01-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Achieving Remote Code Execution By Exploiting Variable Check Feature",
                    "Link": "https://www.shawarkhan.com/2021/01/achieve-remote-code-execution-by.html"
                 }
              ],
              "Authors": ["Shawar Khan (@ShawarkOFFICIAL)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2021-01-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Incident Response during Christmas",
                    "Link": "https://tmosh.medium.com/incident-response-during-christmas-33c7fabb1429"
                 }
              ],
              "Authors": ["TMO"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2021-01-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Each and every request make sense…",
                    "Link": "https://akshartank.medium.com/each-and-every-request-make-sense-4572b3205382"
                 }
              ],
              "Authors": ["Akshar Tank"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Exposed JWT generation endpoint", "JWT"],
              "Bounty": "-",
              "PublicationDate": "2021-01-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation: From being a normal user to admin",
                    "Link": "https://parasarora06.medium.com/privilege-escalation-from-being-a-normal-user-to-admin-3f86896f1c93"
                 }
              ],
              "Authors": ["Akshar Tank"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2021-01-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Max. Character Limitation",
                    "Link": "https://orthonviper.medium.com/exploiting-max-character-limitation-cde982545019"
                 }
              ],
              "Authors": ["Sunil Yedla (@sunilyedla2)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "DoS"],
              "Bounty": "400",
              "PublicationDate": "2021-01-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Patch. Bypass. Repeat: Story of a FaceBook Page Admin Disclosure bug worth $5000",
                    "Link": "https://savebreach.com/facebook-page-admin-identity-disclosure-through-document-edit-history/"
                 }
              ],
              "Authors": ["Shubham Bhamare (@theshubh77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "5,000",
              "PublicationDate": "2021-01-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Expose the email address of Workplace users",
                    "Link": "https://ysamm.com/?p=588"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "5,000",
              "PublicationDate": "2021-01-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS on forums.oculusvr.com leads to Oculus and Facebook account takeovers",
                    "Link": "https://ysamm.com/?p=525"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS", "Account takeover"],
              "Bounty": "30,000",
              "PublicationDate": "2021-01-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "API based IDOR to leaking Private IP address of 6000 businesses",
                    "Link": "https://rafi-ahamed.medium.com/api-based-idor-to-leaking-private-ip-address-of-6000-businesses-6bc085ac6a6f"
                 }
              ],
              "Authors": ["Rafi Ahamed (Leonidas D. Ace)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2021-01-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bad regex used in Facebook Javascript SDK leads to account takeovers in websites that included it",
                    "Link": "https://ysamm.com/?p=510"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Account takeover", "HTTP parameter pollution", "postMessage"],
              "Bounty": "21,000",
              "PublicationDate": "2020-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook bug bounty (500 USD) : A blocked fundraiser organizer would be unable to view or remove themselves from the fundraiser.",
                    "Link": "https://medium.com/bugbountywriteup/facebook-bug-bounty-500-usd-a-blocked-fundraiser-organizer-would-be-unable-to-view-or-remove-5da9f86d2fa0"
                 }
              ],
              "Authors": ["Vivek ps (@vivekps143)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS", "Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2020-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cross Domain Referrer Leakage",
                    "Link": "https://mohsinalibukc.medium.com/cross-domain-referrer-leakage-7873ada102ad"
                 }
              ],
              "Authors": ["Mohsinalibukc"],
              "Programs": ["-"],
              "Bugs": ["Cross-Domain Referrer Leakage"],
              "Bounty": "300",
              "PublicationDate": "2020-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Replying Comments On Someone’s Livestream From Page Is Posted As Personal Identity",
                    "Link": "https://www.pantaprakash.com.np/posts/categories/bugbounty-writeup/1.html"
                 }
              ],
              "Authors": ["Prakash Panta (@prakashpanta268)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2020-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Group Admin Can’t Able To Moderate Comments When Posted Through Page : Facebook Bug Bounty 2020",
                    "Link": "https://www.pantaprakash.com.np/posts/categories/bugbounty-writeup/2.html"
                 }
              ],
              "Authors": ["Prakash Panta (@prakashpanta268)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Event Creator Is Not Able To Block The Attacker During Event Livestream",
                    "Link": "https://www.pantaprakash.com.np/posts/categories/bugbounty-writeup/3.html"
                 }
              ],
              "Authors": ["Prakash Panta (@prakashpanta268)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cache-Key Normalization - What could go wrong?",
                    "Link": "https://iustin24.github.io/Cache-Key-Normalization-Denial-of-Service/"
                 }
              ],
              "Authors": ["Youstin (@iustinBB)"],
              "Programs": ["-"],
              "Bugs": ["Web cache poisoning", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-12-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sensitive data leak using IDOR in integration service",
                    "Link": "https://ronak-9889.medium.com/sensitive-data-leak-using-idor-in-integration-service-d9301be9c91e"
                 }
              ],
              "Authors": ["Ronak Patel (@ronak_9889)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-12-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook page admin disclosure by \"Create doc\" button (Bounty: 5000 USD)",
                    "Link": "https://theshubh77.medium.com/facebook-page-admin-disclosure-by-create-doc-button-bounty-5000-usd-2fd1ff615bf8"
                 }
              ],
              "Authors": ["Shubham Bhamare (@theshubh77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "5,000",
              "PublicationDate": "2020-12-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Got My First Bounty & Hof From Google (CSRF Lead To Account Delete)",
                    "Link": "https://bhupendra1238.medium.com/how-i-got-my-first-bounty-hof-from-google-csrf-lead-to-account-delete-85f9906ba9ec"
                 }
              ],
              "Authors": ["Bhupendra Rajbhar (@bhupendra1238)"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-12-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Google VRP] Hijacking Google Docs Screenshots",
                    "Link": "https://blog.geekycat.in/google-vrp-hijacking-your-screenshots/"
                 }
              ],
              "Authors": ["Sreeram KL (@kl_sree)"],
              "Programs": ["Google"],
              "Bugs": ["postMessage", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Regular expression injection, a code review low hanging fruit",
                    "Link": "https://blog.deesee.xyz/regex/security/2020/12/27/regular-expression-injection.html"
                 }
              ],
              "Authors": ["Dominic (@dee__see)"],
              "Programs": ["-"],
              "Bugs": ["ReDoS"],
              "Bounty": "-",
              "PublicationDate": "2020-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining CORS by Reflected xss to Account takeover #My first Blog",
                    "Link": "https://notifybugme.medium.com/chaining-cors-by-reflected-xss-to-account-takeover-my-first-blog-5b4f12b43c70"
                 }
              ],
              "Authors": ["Santosh Kumar Sha (@killmongar1996)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration", "Reflected XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-12-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook page admin disclosure by \"Message Seller\" button (Bounty: 1500 USD)",
                    "Link": "https://theshubh77.medium.com/facebook-page-admin-disclosure-by-message-seller-button-bounty-1500-usd-caaa2eac4121"
                 }
              ],
              "Authors": ["Shubham Bhamare (@theshubh77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,500",
              "PublicationDate": "2020-12-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full Address Bar Spoofing On Opera Mini Android",
                    "Link": "https://0x48piraj.medium.com/full-address-bar-spoofing-on-opera-mini-android-597fafa60627"
                 }
              ],
              "Authors": ["Piyush Raj ~ Rex (@0x48piraj)"],
              "Programs": ["Opera", "Google"],
              "Bugs": ["Address Bar Spoofing"],
              "Bounty": "-",
              "PublicationDate": "2020-12-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "EN | Account Takeover via Web Cache Poisoning based Reflected XSS",
                    "Link": "https://lutfumertceylan.com.tr/posts/acc-takeover-web-cache-xss/"
                 }
              ],
              "Authors": ["Lütfü Mert Ceylan (@lutfumertceylan)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "Web cache poisoning", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-12-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hiding from custom story privacy list is possible in FBlite making the victim unable to remove you from the list.",
                    "Link": "https://baibhavjha.com.np/blogs/hidingfromcustomlistfblite/"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2020-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Supply Chain Pollution: Hunting a 16 Million Download/Week npm Package Vulnerability for a CTF Challenge",
                    "Link": "https://spaceraccoon.dev/supply-chain-pollution-hunting-a-16-million-download-week-npm-package"
                 }
              ],
              "Authors": ["Eugene Lim (@spaceraccoonsec)"],
              "Programs": ["Node.js third-party modules"],
              "Bugs": ["Prototype pollution"],
              "Bounty": "-",
              "PublicationDate": "2020-12-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cookie Tossing to RCE on Google Cloud JupyterLab",
                    "Link": "https://blog.s1r1us.ninja/research/cookie-tossing-to-rce-on-google-cloud-jupyter-notebooks"
                 }
              ],
              "Authors": ["s1r1us (@s1r1u5_)"],
              "Programs": ["Google"],
              "Bugs": ["Self-XSS", "DoS", "CSRF", "RCE"],
              "Bounty": "3,133.70",
              "PublicationDate": "2020-12-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hack crypto secrets from heap memory to exploit Android application",
                    "Link": "https://secureitmania.medium.com/hack-crypto-secrets-from-heap-memory-to-exploit-android-application-728097fcda3"
                 }
              ],
              "Authors": ["secureITmania (@secureitmania)"],
              "Programs": ["-"],
              "Bugs": ["Cryptographic issues"],
              "Bounty": "-",
              "PublicationDate": "2020-12-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSTI in Google Maps",
                    "Link": "https://www.ehpus.com/post/ssti-in-google-maps"
                 }
              ],
              "Authors": ["s1r1us (@s1r1u5_)"],
              "Programs": ["Google"],
              "Bugs": ["SSTI"],
              "Bounty": "-",
              "PublicationDate": "2020-12-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This is how I was able to view anyone’s private email and birthday on Instagram",
                    "Link": "https://saugatpokharel.medium.com/this-is-how-i-was-able-to-view-anyones-private-email-and-birthday-on-instagram-1469f44b842b"
                 }
              ],
              "Authors": ["Saugat Pokharel (@saugatscript)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "13,125",
              "PublicationDate": "2020-12-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook bug Bounty -Finding the hidden members of the private events.",
                    "Link": "https://vivekps143.medium.com/facebook-bug-bounty-finding-the-hidden-members-of-the-private-events-977dc1784ff9"
                 }
              ],
              "Authors": ["Vivek ps (@vivekps143)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2020-12-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Worth $1,500 IDOR (Access Unauthorize Data)",
                    "Link": "https://web.archive.org/web/20210123173946/https://protector47.medium.com/worth-1-500-idor-access-unauthorize-data-52604aec99"
                 }
              ],
              "Authors": ["Muhammad Asim Shahzad (@protector47)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "1,500",
              "PublicationDate": "2020-12-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up: Google VRP N/A – Sandboxed Rce As Root On Apigee API Proxies",
                    "Link": "https://omespino.com/write-up-google-vrp-n-a-sandboxed-rce-as-root-on-apigee-api-proxies/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Google"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-12-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Access Control on samsung.com subdomain leads to Mass Account Takeover of Samsung employees application accounts",
                    "Link": "https://web.archive.org/web/20221001135501/https://galnagli.com/Samsung_Exposure/"
                 }
              ],
              "Authors": ["Gal Nagli (@naglinagli)"],
              "Programs": ["Samsung"],
              "Bugs": ["Information disclosure", "Account takeover", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-12-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Misconfigured s3 bucket leads to Sensitive Data exposure(No super controls )",
                    "Link": "https://virdoexhunter.medium.com/misconfigured-s3-bucket-leads-to-sensitive-data-exposure-no-super-controls-f47e26b586c6"
                 }
              ],
              "Authors": ["Virdoexhunter"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "400",
              "PublicationDate": "2020-12-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Bug Bounty Journey and My First Critical Bug — Time Based Blind SQL Injection",
                    "Link": "https://marxchryz.medium.com/my-bug-bounty-journey-and-my-first-critical-bug-time-based-blind-sql-injection-aa91d8276e41"
                 }
              ],
              "Authors": ["Marx Chryz"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "3,500",
              "PublicationDate": "2020-12-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Github Secrets exposed due to RCE in Formatter Action from pull_request_target event",
                    "Link": "https://lf.lc/vrp/175896812/"
                 }
              ],
              "Authors": ["Anthony Weems"],
              "Programs": ["Google"],
              "Bugs": ["RCE"],
              "Bounty": "500",
              "PublicationDate": "2020-12-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "D-Link: Multiple Security Vulnerabilities Leading to RCE",
                    "Link": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/d-link-multiple-security-vulnerabilities-leading-to-rce/"
                 }
              ],
              "Authors": ["Harold Zang"],
              "Programs": ["D-Link"],
              "Bugs": ["RCE", "Authentication bypass", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-12-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked IBM and got full access on many services?",
                    "Link": "https://medium.com/@3bodymo/how-i-hacked-ibm-and-got-full-access-on-many-services-ecf1dab4a054"
                 }
              ],
              "Authors": ["Abdullah Mohamed (@3bodymo_)"],
              "Programs": ["IBM"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-12-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "JavaScript analysis leading to Admin portal access",
                    "Link": "https://rikeshbaniyaaa.medium.com/javascript-analysis-leading-to-admin-portal-access-ea30f8328c8e"
                 }
              ],
              "Authors": ["Rikesh Baniya (@rikeshbaniya)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization", "Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2020-12-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "TikTok Careers Portal Account Takeover",
                    "Link": "https://security.lauritz-holtmann.de"
                 }
              ],
              "Authors": ["Lauritz Holtmann (@_lauritz_)"],
              "Programs": ["TikTok"],
              "Bugs": ["CSRF", "Open redirect", "Account takeover"],
              "Bounty": "2,373",
              "PublicationDate": "2020-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Download Filename Manipulation due to improper rendering of RTLO characters",
                    "Link": "https://jayateerthag.medium.com/download-filename-manipulation-due-to-improper-rendering-of-rtlo-characters-69e2751a8f28"
                 }
              ],
              "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
              "Programs": ["-"],
              "Bugs": ["RTLO"],
              "Bounty": "-",
              "PublicationDate": "2020-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclosing the members of private Facebook Group as a non-member.",
                    "Link": "https://baibhavjha.com.np/blogs/fblitegroupmemberdisclosure/"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "4,500",
              "PublicationDate": "2020-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Confirm an email address belonging to a specific user",
                    "Link": "https://medium.com/@yaala/confirm-an-email-address-belonging-to-a-specific-user-fe9c305e0af"
                 }
              ],
              "Authors": ["abdellah yaala (@yaalaab)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "5,000",
              "PublicationDate": "2020-12-12",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Abusing AirWatch MDM Services to Bypass MFA",
                  "Link": "https://emptynebuli.github.io/tooling/2020/12/11/aircross.html"
               }
            ],
            "Authors": ["Matt Burch (@emptynebuli)"],
            "Programs": ["VMware (AirWatch)"],
            "Bugs": ["Android", "2FA / MFA bypass", "Username enumeration"],
            "Bounty": "-",
            "PublicationDate": "2020-12-11",
            "AddedDate": "2024-05-11"
         },
           {
            "Links": [
               {
                  "Title": "Security Study of Service Worker Cross-Site Scripting.",
                  "Link": "https://dl.acm.org/doi/fullHtml/10.1145/3427228.3427290"
               }
            ],
            "Authors": ["Phakpoom Chinprutthiwong", "Raj Vardhan", "GuangLiang Yang", "Guofei Gu"],
            "Programs": ["-"],
            "Bugs": ["XSS", "Service worker based XSS"],
            "Bounty": "-",
            "PublicationDate": "2020-12-11",
            "AddedDate": "2022-11-30"
         },
           {
              "Links": [
                 {
                    "Title": "How I hacked Facebook: Part One",
                    "Link": "https://infosecwriteups.com/how-i-hacked-facebook-part-one-282bbb125a5d"
                 }
              ],
              "Authors": ["Alaa Abdulridha (@alaa0x2)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Missing authentication", "Authentication bypass", "Account takeover"],
              "Bounty": "7,500",
              "PublicationDate": "2020-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i got my First Bug Bounty in Intersting Target (LFI to SXSS)",
                    "Link": "https://ph-hitachi.medium.com/how-i-got-my-first-bug-bounty-in-intersting-target-lfi-to-sxss-58fa5c4f5882"
                 }
              ],
              "Authors": ["Ph.Hitachi"],
              "Programs": ["-"],
              "Bugs": ["LFI", "Stored XSS"],
              "Bounty": "250",
              "PublicationDate": "2020-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I dumped PII information of customers in an ecommerce site?",
                    "Link": "https://rikeshbaniyaaa.medium.com/how-i-dumped-pii-information-of-customers-in-an-ecommerce-site-237761f813cf"
                 }
              ],
              "Authors": ["Rikesh Baniya (@rikeshbaniya)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2020-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting new-era of Request forgery on mobile applications",
                    "Link": "https://web.archive.org/web/20210508050717/http://dphoeniixx.com/2020/12/13-2/"
                 },
                 {
                  "Title": "Alternative link",
                  "Link": "https://dphoeniixx.medium.com/exploiting-request-forgery-on-mobile-applications-e1d196d187b3"
               }
               ],
              "Authors": ["Sayed Abdelhafiz (@dPhoeniixx)"],
              "Programs": ["Pinterest"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hiding from a custom list is possible on who sees our post is possible making victim not remove them from the list.",
                    "Link": "https://baibhavjha.com.np/blogs/hidingcustomlist/"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2020-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Game On – Finding vulnerabilities in Valve’s “Steam Sockets”",
                    "Link": "https://research.checkpoint.com/2020/game-on-finding-vulnerabilities-in-valves-steam-sockets/"
                 }
              ],
              "Authors": ["Eyal Itkin (@EyalItkin)"],
              "Programs": ["Valve"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2020-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Content-Security-Policy Bypass to perform XSS using MIME sniffing",
                    "Link": "https://kurtikleiton.medium.com/content-security-policy-bypass-to-perform-xss-3c8dd0d40c2e"
                 }
              ],
              "Authors": ["Kleiton Kurti (@kleiton0x7e)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking — Tamper with the URL Parameters, especially if they modify the page",
                    "Link": "https://medium.com/the-volatile-triad/hacking-tamper-with-the-url-parameters-especially-if-they-modify-the-page-7edf158c8db9"
                 }
              ],
              "Authors": ["Jack"],
              "Programs": ["-"],
              "Bugs": ["HTTP parameter pollution"],
              "Bounty": "-",
              "PublicationDate": "2020-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook leak referrer data",
                    "Link": "https://nmochea.medium.com/facebook-leak-referrer-data-in-every-sub-domain-48da5e505cf6"
                 }
              ],
              "Authors": ["Neil Mark Ochea (@nmochea)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-12-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Was Able To Take Over One Of Dell’s Subdomains",
                    "Link": "https://pyrrhon.medium.com/how-i-was-able-to-take-over-one-of-dells-subdomains-7e06b8516e41"
                 }
              ],
              "Authors": ["Taha Bıyıklı (@tahabykl)"],
              "Programs": ["Dell"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-12-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook push notification linkshim bypassed",
                    "Link": "https://infosecwriteups.com/facebook-push-notification-linkshim-bypassed-385fe471516"
                 }
              ],
              "Authors": ["Neil Mark Ochea (@nmochea)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "\"Important, Spoofing\" - zero-click, wormable, cross-platform remote code execution in Microsoft Teams",
                    "Link": "https://github.com/oskarsve/ms-teams-rce"
                 }
              ],
              "Authors": ["Oskars Vegeris"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE", "Stored XSS", "CSP bypass", "CSTI"],
              "Bounty": "-",
              "PublicationDate": "2020-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of the best vulnerability I’ve found so far…",
                    "Link": "https://medium.com/@vedanttekale20/story-of-the-best-vulnerability-ive-found-so-far-5e3b0e02b47e"
                 }
              ],
              "Authors": ["Vedant Tekale (@_justYnot)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "Blind XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[CVE-2019-17674 & CVE-2020-11025] Stored XSS through navigation menu item edited in Customizer in Wordpress (Write Up)",
                    "Link": "https://blog.evanricafort.com/2020/12/cve-2019-17674-wordpress-stored-xss.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["WordPress"],
              "Bugs": ["Stored XSS"],
              "Bounty": "600",
              "PublicationDate": "2020-12-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE via LFI Log Poisoning - The Death Potion",
                    "Link": "https://shahjerry33.medium.com/rce-via-lfi-log-poisoning-the-death-potion-c0831cebc16d"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "LFI", "Log poisoning"],
              "Bounty": "-",
              "PublicationDate": "2020-12-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Redirects work on Facebook? Technical breakdown",
                    "Link": "https://abhisek3122.medium.com/how-redirects-work-on-facebook-technical-breakdown-6699de52996c"
                 }
              ],
              "Authors": ["Abhisek R (@abh1sek_r)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-12-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Opera Browser Cross Site Scripting (XSS)",
                    "Link": "https://nmochea.medium.com/this-post-is-about-an-reflected-xss-that-i-found-on-opera-browser-application-which-could-have-been-39823a22045d"
                 }
              ],
              "Authors": ["Neil Mark Ochea (@nmochea)"],
              "Programs": ["Opera"],
              "Bugs": ["XSS", "Android"],
              "Bounty": "-",
              "PublicationDate": "2020-12-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$10000 Facebook SSRF (Bug Bounty)",
                    "Link": "https://amineaboud.medium.com/10000-facebook-ssrf-bug-bounty-402bd21e58e5"
                 }
              ],
              "Authors": ["Amine Aboud (@amineaboud)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["SSRF"],
              "Bounty": "10,000",
              "PublicationDate": "2020-12-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaking Credit card Activity in logs? Yes Sir!",
                    "Link": "https://komradz86.medium.com/leaking-credit-card-activity-in-logs-yes-sir-b988bb6c0c2"
                 }
              ],
              "Authors": ["Rody Shahnazarian (@Komradz86)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "800",
              "PublicationDate": "2020-12-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cross Site Scripting (XSS) Reflected in one of the subdomains of “General Motors”(Bugbounty)",
                    "Link": "https://securitytrooper.com/en/cross-site-scripting-xss-reflected-in-one-of-the-subdomains-of-general-motorsbugbounty"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["General Motors"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-12-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Site Wide CSRF On Glassdoor",
                    "Link": "https://blog.witcoat.com/2020/12/03/site-wide-csrf-on-glassdoor/"
                 }
              ],
              "Authors": ["Tabahi (@_tabahi)"],
              "Programs": ["Glassdoor"],
              "Bugs": ["CSRF"],
              "Bounty": "3,000",
              "PublicationDate": "2020-12-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaking Browser URL/Protocol Handlers",
                    "Link": "https://www.fortinet.com/blog/threat-research/leaking-browser-url-protocol-handlers"
                 }
              ],
              "Authors": ["Tabahi (@_tabahi)"],
              "Programs": ["Google", "Microsoft", "Mozilla"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-12-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSTI to Local File Read",
                    "Link": "https://www.r29k.com/articles/bb/ssti"
                 }
              ],
              "Authors": ["Demon (@R29k_)"],
              "Programs": ["-"],
              "Bugs": ["SSTI", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2020-12-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking — Always check out the Images",
                    "Link": "https://medium.com/the-volatile-triad/hacking-always-check-out-the-images-99217e6cea"
                 }
              ],
              "Authors": ["Jack"],
              "Programs": ["GitLab"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2020-12-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An iOS zero-click radio proximity exploit odyssey",
                    "Link": "https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-click-radio-proximity.html"
                 }
              ],
              "Authors": ["Ian Beer (@i41nbeer)"],
              "Programs": ["Apple"],
              "Bugs": ["iOS", "Memory corruption", "Buffer Overflow"],
              "Bounty": "-",
              "PublicationDate": "2020-12-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining vulnerabilities lead to account takeover",
                    "Link": "https://medium.com/bugbountywriteup/chaining-vulnerabilities-lead-to-account-takeover-b583f0c10591"
                 }
              ],
              "Authors": ["Ahmed (@ahzsec)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset", "Open redirect", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2020-12-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Blind Postgresql Injection And Exfiltrating Data In Psycopg2",
                    "Link": "https://www.shawarkhan.com/2020/11/exploiting-blind-postgresql-injection.html"
                 }
              ],
              "Authors": ["Shawar Khan (@ShawarkOFFICIAL)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "3,000",
              "PublicationDate": "2020-11-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AliExpress Captcha Reuse",
                    "Link": "https://therealunicornsecurity.github.io/Aliexpress/"
                 }
              ],
              "Authors": ["Unicorn Security"],
              "Programs": ["Aliexpress"],
              "Bugs": ["Captcha bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-11-30",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "WonderCMS 3.1.3 - Authenticated RCE & Blind SSRF Vulnerability",
                  "Link": "https://zetc0de.github.io/post/authenticated-rce-ssrf-wondercms/"
               }
            ],
            "Authors": ["Mas Zet (@zetc0de)"],
            "Programs": ["WonderCMS"],
            "Bugs": ["Blind SSRF", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2020-11-29",
            "AddedDate": "2022-11-17"
         },
           {
              "Links": [
                 {
                    "Title": "Chaining Multiple Requests to Achieve Rate Limiting Vulnerabilities",
                    "Link": "https://ahmdhalabi.medium.com/chaining-multiple-requests-to-achieve-rate-limiting-vulnerabilities-96c1e8365c06"
                 }
              ],
              "Authors": ["Ahmad Halabi (@Ahmad_Halabi_)"],
              "Programs": ["-"],
              "Bugs": ["Rate limiting bypass"],
              "Bounty": "1,000",
              "PublicationDate": "2020-11-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bcrypt — Account TakeOver Due To Weak Encryption — #HR51KDB",
                    "Link": "https://medium.com/bugbountywriteup/bcrypt-account-takeover-due-to-weak-encryption-hr51kdb-4418f6e65907"
                 }
              ],
              "Authors": ["DarkLotus (@darklotuskdb)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-11-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Story of my first critical bug",
                    "Link": "https://shellbr3ak.medium.com/the-story-of-my-first-critical-bug-93a5920d6c43"
                 }
              ],
              "Authors": ["Shellbr3ak (@0xShellbr3ak)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-11-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i got easy $$$ for SQL Injection Bug",
                    "Link": "https://rafipiun.medium.com/how-i-got-easy-for-sql-injection-bug-7ff622236e4c"
                 }
              ],
              "Authors": ["Rafi Andhika Galuh"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-11-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pre-Account Takeover using OAuth Misconfiguration",
                    "Link": "https://vijetareigns.medium.com/pre-account-takeover-using-oauth-misconfiguration-ebd32b80f3d3"
                 }
              ],
              "Authors": ["the_unluck_guy (@7he_unlucky_guy)"],
              "Programs": ["-"],
              "Bugs": ["OAuth"],
              "Bounty": "800",
              "PublicationDate": "2020-11-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SD-PWN Part 4 — VMware VeloCloud — The Last Takeover",
                    "Link": "https://medium.com/realmodelabs/sd-pwn-part-4-vmware-velocloud-the-last-takeover-a7016f9a9175"
                 }
              ],
              "Authors": ["Realmode Labs (@RealmodeLabs)"],
              "Programs": ["VMware"],
              "Bugs": ["RCE", "Authentication bypass", "Default credentials", "SQL injection", "Path traversal", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2020-11-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How images on Github will leak your private information",
                    "Link": "https://fuomag9.medium.com/how-images-on-github-will-leak-your-private-information-88f3b563e7d9"
                 }
              ],
              "Authors": ["fuomag9 (@fuomag9)"],
              "Programs": ["GitHub"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-11-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected Cross Site Scripting on REDACTED Program (Bounty: 750$)",
                    "Link": "https://medium.com/bugbountywriteup/reflected-cross-site-scripting-on-private-program-bounty-750-34cc67a931f1"
                 }
              ],
              "Authors": ["can1337 (@canmustdie)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "750",
              "PublicationDate": "2020-11-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SD-PWN — Part 3 — Cisco vManage — Another Day, Another Network Takeover",
                    "Link": "https://medium.com/realmodelabs/sd-pwn-part-3-cisco-vmanage-another-day-another-network-takeover-15731a4d75b7"
                 }
              ],
              "Authors": ["Realmode Labs (@RealmodeLabs)"],
              "Programs": ["Cisco"],
              "Bugs": ["RCE", "SSRF", "Arbitrary file write", "Path traversal", "OS command injection", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-11-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fixing a Google Vulnerability",
                    "Link": "https://security.love/blog/gcp/2020/11/22/lateral-movement-and-privesc-in-GCP.html"
                 }
              ],
              "Authors": ["I (@InsecureNature)", "Allison Donovan (@matter_of_cat)"],
              "Programs": ["Google"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-11-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating XSS to Account Takeover",
                    "Link": "https://cirius.medium.com/escalating-xss-to-account-takeover-ffde08624937"
                 }
              ],
              "Authors": ["Aditya Verma (@0cirius0)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-11-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weird (im)possible XSS on error page",
                    "Link": "https://komradz86.medium.com/weird-im-possible-xss-on-error-page-a0b943ead41"
                 }
              ],
              "Authors": ["Rody Shahnazarian (@Komradz86)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-11-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2 Reflected XSS In Razer",
                    "Link": "https://mostafa-mano.medium.com/2-reflected-xss-in-razer-74783ae5ee53"
                 }
              ],
              "Authors": ["Mostafa"],
              "Programs": ["Razer"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-11-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Turning Blind Error Based SQL Injection into Exploitable Boolean One",
                    "Link": "https://ozguralp.medium.com/turning-blind-error-based-sql-injection-into-an-exploitable-boolean-one-85d6be3ca23b"
                 }
              ],
              "Authors": ["Ozgur Alp (@ozgur_bbh)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-11-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting dynamic rendering engines to take control of web apps",
                    "Link": "https://r2c.dev/blog/2020/exploiting-dynamic-rendering-engines-to-take-control-of-web-apps/"
                 }
              ],
              "Authors": ["Vasilii Ermilov (@ermil0v)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "Open redirect"],
              "Bounty": "5,000",
              "PublicationDate": "2020-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing the Redirect filters with 7 ways",
                    "Link": "https://elmahdi.tistory.com/m/4"
                 }
              ],
              "Authors": ["ElMahdi Mrhassel (@ElMrhassel)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "OAuth"],
              "Bounty": "-",
              "PublicationDate": "2020-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Arbitrary File Write On Client By ADB Pull",
                    "Link": "https://daeken.svbtle.com/arbitrary-file-write-by-adb-pull"
                 }
              ],
              "Authors": ["Serafina (Sera) Tonin Brocious (@daeken)"],
              "Programs": ["Google"],
              "Bugs": ["Arbitrary file write"],
              "Bounty": "-",
              "PublicationDate": "2020-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Out of Band XXE in an E-commerce IOS app",
                    "Link": "https://0xgaurang.medium.com/out-of-band-xxe-in-an-e-commerce-ios-app-e22981f7b59b"
                 }
              ],
              "Authors": ["Gaurang Bhatnagar (@0xgaurang)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2020-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GraphQL IDOR in Facebook streamer dashboard.",
                    "Link": "https://kailashbohara.com.np/blog/2020/11/18/GraphQL-IDOR-in-Facebook-streamer-dashboard/"
                 }
              ],
              "Authors": ["Kailash (@Corrupted_brain)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "GraphQL"],
              "Bounty": "2,000",
              "PublicationDate": "2020-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Server Side Misconfigurartion - A Funny Fix",
                    "Link": "https://shahjerry33.medium.com/server-side-misconfigurartion-a-funny-fix-63cc12b4c7fc"
                 }
              ],
              "Authors": ["Jerry Shah (@Jerry)"],
              "Programs": ["Basecamp"],
              "Bugs": ["Information disclosure"],
              "Bounty": "100",
              "PublicationDate": "2020-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tale of 3 vulnerabilities to account takeover!",
                    "Link": "https://medium.com/@logicbomb_1/tale-of-3-vulnerabilities-to-account-takeover-44ba631a0304"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-11-17",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "OpenEMR 5.0.1.3 Arbitrary File Actions",
                  "Link": "https://jsecu.github.io/2020/11/17/openemr/"
               }
            ],
            "Authors": ["Josh Fam (@Pullerze)"],
            "Programs": ["OpenEMR"],
            "Bugs": ["Arbitrary file write", "Arbitrary file read", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2020-11-17",
            "AddedDate": "2022-09-15"
         },
           {
            "Links": [
               {
                  "Title": "Hacking into (RCE) Government Server operated for the US Department of Energy’s National Nuclear Security Administration.",
                  "Link": "https://medium.com/@shaheenfazim/hacking-into-rce-government-server-operated-for-the-us-department-of-energys-national-nuclear-8aadc2e7e491"
               }
            ],
            "Authors": ["Shaheen Fazim"],
            "Programs": ["US Department of Energy"],
            "Bugs": ["RCE", "OS command injection"],
            "Bounty": "-",
            "PublicationDate": "2020-11-16",
            "AddedDate": "2022-10-18"
         },
           {
              "Links": [
                 {
                    "Title": "Firefox: How a website could steal all your cookies",
                    "Link": "https://medium.com/@kanytu/firefox-and-how-a-website-could-steal-all-of-your-cookies-581fe4648e8d"
                 }
              ],
              "Authors": ["Pedro Oliveira (@kanytu)"],
              "Programs": ["Mozilla"],
              "Bugs": ["Arbitrary file read"],
              "Bounty": "5,000",
              "PublicationDate": "2020-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing User’s PII info by visiting API endpoint directly",
                    "Link": "https://web.archive.org/web/20201116060315/https://medium.com/@kunal94/stealing-users-pii-info-by-visiting-api-endpoint-directly-5062e0147f67"
                 }
              ],
              "Authors": ["Kunal pandey (@kunalp94)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2020-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pentest-Story: Empirum password decryption",
                    "Link": "https://evait.medium.com/pentest-story-empirum-password-decryption-3a9e2530aba7"
                 }
              ],
              "Authors": ["evait security GmbH (@evait_security)"],
              "Programs": ["Matrix42"],
              "Bugs": ["Weak crypto", "Reverse engineering"],
              "Bounty": "-",
              "PublicationDate": "2020-11-16",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                 {
                    "Title": "RCE via Server-Side Template Injection",
                    "Link": "https://cyc10n3.medium.com/rce-via-server-side-template-injection-ad46f8e0c2ae"
                 }
              ],
              "Authors": ["Gaurav Mishra (@gmishra010)"],
              "Programs": ["-"],
              "Bugs": ["SSTI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Optimizing Hunting Results in VDP for use in Bug Bounty Programs - From Sensitive Information Disclosure to Accessing Hidden APIs which can be used to Retrieve Customer Data",
                    "Link": "http://www.firstsight.me/2020/11/optimizing-hunting-results-in-vdp-for-use-in-bug-bounty-programs-from-sensitive-information-disclosure-to-accessing-hidden-apis-which-can-be-used-to-retrieve-customer-data/"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Broken Access Control", "IDOR", "SQL injection"],
              "Bounty": "4,750",
              "PublicationDate": "2020-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Bug Bounty Writeup – Stored XSS Vulnerability",
                    "Link": "https://www.pethuraj.com/blog/microsoft-bug-bounty-writeup-stored-xss-vulnerability/"
                 }
              ],
              "Authors": ["Pethuraj (@Pethuraj)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weak Cryptography to Account Takeover’s",
                    "Link": "https://medium.com/@vasuyadav0786/weak-cryptography-to-account-takeovers-87782224ed0d"
                 }
              ],
              "Authors": ["letmeslidein (@VasuYadaav)"],
              "Programs": ["-"],
              "Bugs": ["Cryptographic issues", "Account takeover", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting API with AuthToken",
                    "Link": "https://rafi-ahamed.medium.com/exploiting-api-with-authtoken-3bea7b1fb6a9"
                 }
              ],
              "Authors": ["Rafi Ahamed (Leonidas D. Ace)"],
              "Programs": ["-"],
              "Bugs": ["Token leak", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SD-PWN Part 2 — Citrix SD-WAN Center — Another Network Takeover",
                    "Link": "https://medium.com/realmodelabs/sd-pwn-part-2-citrix-sd-wan-center-another-network-takeover-a9c950a1a27c"
                 }
              ],
              "Authors": ["Realmode Labs (@RealmodeLabs)"],
              "Programs": ["Citrix Systems"],
              "Bugs": ["RCE", "Authentication bypass", "Path traversal", "OS command injection", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account takeover through password reset",
                    "Link": "https://medium.com/@seaman00o/account-takeover-through-password-reset-82adc0c19248"
                 }
              ],
              "Authors": ["Omar Hamdy (@seaman00o)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset"],
              "Bounty": "2,000",
              "PublicationDate": "2020-11-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Theoretically Possible To Practical Account Takeover",
                    "Link": "https://ironfisto.medium.com/theoretically-possible-to-practical-account-takeover-c9383ab03f76"
                 }
              ],
              "Authors": ["Mukul Lohar (@ironfisto)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-11-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Replying Comments On Someone’s LiveStream From Page is Posted as Personal Identity",
                    "Link": "https://medium.com/@prakashpanta1999/replying-comments-on-someones-livestream-from-page-is-posted-as-personal-identity-5fe79ef78b28"
                 }
              ],
              "Authors": ["Prakash Panta (@Prakashpanta268)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2020-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Smuggling an (Un)exploitable XSS",
                    "Link": "https://www.rcesecurity.com/2020/11/Smuggling-an-un-exploitable-xss/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found The Facebook Messenger Leaking Access Token Of Million Users",
                    "Link": "https://medium.com/@guhanraja/how-i-found-the-facebook-messenger-leaking-access-token-of-million-users-8ee4b3f1e5e3"
                 }
              ],
              "Authors": ["Guhan Raja (@havocgwen)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "16,125",
              "PublicationDate": "2020-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Interesting case of SQLi",
                    "Link": "https://medium.com/@mrnikhilsri/interesting-case-of-sqli-84cc3f4a5255"
                 }
              ],
              "Authors": ["Nikhil (niks) (@niksthehacker)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "3,000",
              "PublicationDate": "2020-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How a simple bug in Facebook Lite let me win my first bug bounty from Facebook",
                    "Link": "https://samiparyal.medium.com/commenting-on-a-post-by-opening-it-via-pages-news-feed-goes-from-a-wrong-actor-i-e-56fab4cf5a91"
                 }
              ],
              "Authors": ["Samip Aryal (@samiparyal_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2020-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "User’s private watched videos/saved videos exposed through a messenger call from a locked smartphone.",
                    "Link": "https://medium.com/@aryalsamipofficial59/users-private-watched-videos-list-saved-videos-etc-30faa8610b33"
                 }
              ],
              "Authors": ["Samip Aryal (@samiparyal_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2020-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Evading Filters to perform the Arbitrary URL Redirection Attack",
                    "Link": "https://medium.com/bugbountywriteup/evading-filters-to-perform-the-arbitrary-url-redirection-attack-cce628b9b6a0"
                 }
              ],
              "Authors": ["Harsh Bothra (@harshbothra_)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Evernote: Universal-XSS, theft of all cookies from all sites, and more",
                    "Link": "https://blog.oversecured.com/Evernote-Universal-XSS-theft-of-all-cookies-from-all-sites-and-more/"
                 }
              ],
              "Authors": ["Oversecured (@OversecuredInc)"],
              "Programs": ["Evernote"],
              "Bugs": ["Universal XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Local Privilege Escalation Vulnerability Discovered in VMware Fusion",
                    "Link": "https://www.cyberonesecurity.com/blog/local-privilege-escalation-vulnerability-discovered-in-vmware-fusion"
                 }
              ],
              "Authors": ["Rich Mirch (@0xm1rch)"],
              "Programs": ["VMware"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-11-11",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "id.atlassian.com Username enumeration",
                  "Link": "https://pulsesecurity.co.nz/advisories/Atlassian-ID-Username-Enumeration"
               }
            ],
            "Authors": ["Denis Andzakovic"],
            "Programs": ["Atlassian"],
            "Bugs": ["Username enumeration"],
            "Bounty": "-",
            "PublicationDate": "2020-11-11",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "31k$ SSRF in Google Cloud Monitoring led to metadata exposure",
                    "Link": "https://nechudav.blogspot.com/2020/11/31k-ssrf-in-google-cloud-monitoring.html"
                 }
              ],
              "Authors": ["David Nechuta (@david_nechuta)"],
              "Programs": ["Google"],
              "Bugs": ["SSRF"],
              "Bounty": "31,337",
              "PublicationDate": "2020-11-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF (Server Side Request Forgery) worth $4,913 | My Highest Bounty Ever !",
                    "Link": "https://medium.com/techfenix/ssrf-server-side-request-forgery-worth-4913-my-highest-bounty-ever-7d733bb368cb"
                 }
              ],
              "Authors": ["Sayaan Alam (@ehsayaan)"],
              "Programs": ["Dropbox"],
              "Bugs": ["SSRF"],
              "Bounty": "4,913",
              "PublicationDate": "2020-11-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining password reset link poisoning, IDOR, and information leakage to achieve account takeover at api.redacted.com",
                    "Link": "https://medium.com/bugbountywriteup/chaining-password-reset-link-poisoning-idor-account-information-leakage-to-achieve-account-bb5e0e400745"
                 }
              ],
              "Authors": ["Jadek Mark (@mase289)"],
              "Programs": ["-"],
              "Bugs": ["HTTP header injection"],
              "Bounty": "-",
              "PublicationDate": "2020-11-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Firefox for Android: LAN-Based Intent Triggering",
                    "Link": "https://blog.mozilla.org/attack-and-defense/2020/11/10/firefox-for-android-lan-based-intent-triggering/"
                 }
              ],
              "Authors": ["initstring (@init_string)"],
              "Programs": ["Mozilla"],
              "Bugs": ["Insecure intent", "Android"],
              "Bounty": "-",
              "PublicationDate": "2020-11-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook iOS address bar spoofing",
                    "Link": "https://servicenger.com/blog/mobile/facebook-ios-address-bar-spoofing/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Address Bar Spoofing", "iOS"],
              "Bounty": "1,500",
              "PublicationDate": "2020-11-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Silver Peak Unity Orchestrator RCE",
                    "Link": "https://medium.com/realmodelabs/silver-peak-unity-orchestrator-rce-2928d65ef749"
                 }
              ],
              "Authors": ["Realmode Labs (@RealmodeLabs)"],
              "Programs": ["Silver Peak"],
              "Bugs": ["RCE", "Authentication bypass", "Path traversal", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-11-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i could take over any Account on a USA Department of Defense Website due to a simple IDOR",
                    "Link": "https://web.archive.org/web/20221110072323/https://galnagli.com/DoD_IDOR/"
                 }
              ],
              "Authors": ["Gal Nagli (@naglinagli)"],
              "Programs": ["U.S. Dept Of Defense"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-11-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook DOM Based XSS using postMessage",
                    "Link": "https://ysamm.com/?p=493"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DOM XSS", "postMessage"],
              "Bounty": "25,000",
              "PublicationDate": "2020-11-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Attack of the clones: Git clients remote code execution",
                    "Link": "https://blog.blazeinfosec.com/attack-of-the-clones-github-desktop-remote-code-execution/"
                 }
              ],
              "Authors": ["Vitor Fernandes (@Rapt00rVF)", "Julio Fort"],
              "Programs": ["GitHub"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-11-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of a Pre-Account Takeover",
                    "Link": "https://dhakal0kushal.medium.com/story-of-a-pre-account-takeover-33e3d5b4c33f"
                 }
              ],
              "Authors": ["Kushal Dhakal (@dhakal0kushal)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "OAuth"],
              "Bounty": "-",
              "PublicationDate": "2020-11-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "1000$ for Open redirect via unknown technique [BugBounty writeup]",
                    "Link": "https://ruvlol.medium.com/1000-for-open-redirect-via-unknown-technique-675f5815e38a"
                 }
              ],
              "Authors": ["ruvlol"],
              "Programs": ["GitLab"],
              "Bugs": ["Open redirect"],
              "Bounty": "1,000",
              "PublicationDate": "2020-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found a Tor vulnerability in Brave Browser, reported it, watched it get patched, got a CVE (CVE-2020-8276) and a small bounty, all in one working day",
                    "Link": "https://community.disclose.io/t/how-i-found-a-tor-vulnerability-in-brave-browser-reported-it-watched-it-get-patched-got-a-cve-cve-2020-8276-and-a-small-bounty-all-in-one-working-day/65"
                 }
              ],
              "Authors": ["sickcodes (@sickcodes)"],
              "Programs": ["Brave Software"],
              "Bugs": ["Information disclosure"],
              "Bounty": "100",
              "PublicationDate": "2020-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Delete Any Photos In Facebook",
                    "Link": "https://lokeshdlk77.medium.com/delete-any-photos-in-facebook-832dbe81cdc4"
                 }
              ],
              "Authors": ["Lokesh Kumar (@lokeshdlk77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "10,750",
              "PublicationDate": "2020-11-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From a 500 error to Django admin takeover",
                    "Link": "https://blog.shashank.co/2020/11/from-500-error-to-django-admin-takeover.html"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["-"],
              "Bugs": ["Authorization bypass", "Account takeover"],
              "Bounty": "3,000",
              "PublicationDate": "2020-11-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Forcing for a bounty$$",
                    "Link": "https://rafi-ahamed.medium.com/forcing-for-a-bounty-b637c468d7bd"
                 }
              ],
              "Authors": ["Rafi Ahamed (Leonidas D. Ace)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2020-11-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reveal the page admin that uploaded a video on the page in comment section",
                    "Link": "https://lokeshdlk77.medium.com/reveal-the-page-admin-that-uploaded-a-video-on-the-page-in-comment-section-9760e4a31453"
                 }
              ],
              "Authors": ["Lokesh Kumar (@lokeshdlk77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "4,838",
              "PublicationDate": "2020-11-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020-13294",
                    "Link": "https://security.lauritz-holtmann.de/advisories/cve-2020-13294/"
                 }
              ],
              "Authors": ["Lauritz Holtmann (@_lauritz_)"],
              "Programs": ["GitLab"],
              "Bugs": ["Broken authentication", "OIDC", "OAuth"],
              "Bounty": "-",
              "PublicationDate": "2020-11-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover in Azure: making a PoC",
                    "Link": "https://godiego.co/posts/STO-Azure/"
                 }
              ],
              "Authors": ["Diego Bernal Adelantado (@secfaults)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-11-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaked .git folder leads to RCE",
                    "Link": "https://james-clee.com/2020/11/01/leaked-git-folder-leads-to-rce/"
                 }
              ],
              "Authors": ["James Clee (@jtcsec)"],
              "Programs": ["-"],
              "Bugs": [".git folder disclosure", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-11-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An often overlooked Oauth misconfiguration.",
                    "Link": "https://dragon-sec.medium.com/an-often-overlooked-oauth-misconfiguration-7d2d441eae1f"
                 },
                 {
                    "Title": "Payload",
                    "Link": "https://twitter.com/VipItHunter1/status/1322995744475852801"
                 }
              ],
              "Authors": ["VipItHunter (@VipItHunter1)"],
              "Programs": ["-"],
              "Bugs": ["OAuth"],
              "Bounty": "-",
              "PublicationDate": "2020-11-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i got 7000$ in Bug-Bounty for my Critical Finding.",
                    "Link": "https://medium.com/@noobieboy1337/how-i-got-7000-in-bug-bounty-for-my-critical-finding-99326d2cc1ce"
                 }
              ],
              "Authors": ["Kishan Kumar / Noobie BoY (@hst_kishan)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "7,000",
              "PublicationDate": "2020-10-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing 'Report Abuse'",
                    "Link": "https://aseemshrey.in/abusing-report-abuse/"
                 }
              ],
              "Authors": ["Aseem Shrey (@AseemShrey)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "200",
              "PublicationDate": "2020-10-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Beyond the wall: command injection still alive.",
                    "Link": "https://a-constant.medium.com/beyond-the-wall-command-injection-still-alive-577a898df0b5"
                 }
              ],
              "Authors": ["Ahmed Constant (@a_Constant_)"],
              "Programs": ["-"],
              "Bugs": ["OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2020-10-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Ability To Backdoor Facebook For Android",
                    "Link": "https://ash-king.co.uk/blog/backdoor-android-facebook"
                 }
              ],
              "Authors": ["Ashley King (@AshleyKingUK)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Insecure deeplink", "Android"],
              "Bounty": "-",
              "PublicationDate": "2020-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Wormable remote code execution in Alien Swarm",
                    "Link": "https://secret.club/2020/10/30/alien-swarm-rce.html"
                 }
              ],
              "Authors": ["mev"],
              "Programs": ["Valve"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Rate Limit Bypassing Allowing Identity Spoofing",
                    "Link": "https://0xt4144t.medium.com/rate-limit-bypassing-allowing-identity-spoofing-789b2fe2efa8"
                 }
              ],
              "Authors": ["Mohamed Talaat (@T4144t)"],
              "Programs": ["-"],
              "Bugs": ["Rate limiting bypass", "OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-10-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Manual broken link monitoring",
                    "Link": "https://grumpinout.medium.com/manual-broken-link-monitoring-bcc064f5f5f2"
                 }
              ],
              "Authors": ["GrumpinouT (@RVerwilghen)"],
              "Programs": ["-"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2020-10-29",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Weblogic RCE by only one GET request — CVE-2020–14882 Analysis",
                  "Link": "https://testbnull.medium.com/weblogic-rce-by-only-one-get-request-cve-2020-14882-analysis-6e4b09981dbf"
               }
            ],
            "Authors": ["Nguyễn Tiến Giang (@testanull)"],
            "Programs": ["Oracle (WebLogic)"],
            "Bugs": ["RCE", "Authentication bypass", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2020-10-28",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Story of an interesting bug.",
                    "Link": "https://medium.com/@vedanttekale20/story-of-an-interesting-bug-de07fbef4017"
                 }
              ],
              "Authors": ["Vedant Tekale (@_justYnot)"],
              "Programs": ["-"],
              "Bugs": ["Lack of rate limiting", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-10-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Error-Based SQL Injection on a WordPress website and extract more than 150k user details",
                    "Link": "https://ynoof.medium.com/error-based-sql-injection-on-a-wordpress-website-and-extract-more-than-150k-user-details-f65f987c2cc0"
                 }
              ],
              "Authors": ["Ynoof Alassiri"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-10-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Automating xss identification with Dalfox & Paramspider",
                    "Link": "https://medium.com/bugbountywriteup/automating-xss-identification-with-dalfox-paramspider-e14283bb7916"
                 }
              ],
              "Authors": ["Paras Arora (@parasarora06)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-10-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The YouTube bug that allowed unlisted uploads to any channel",
                    "Link": "https://medium.com/bugbountywriteup/the-youtube-bug-that-allowed-uploads-to-any-channel-3b41c7b7902a"
                 }
              ],
              "Authors": ["Ryan Kovatch"],
              "Programs": ["Google"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "6,337",
              "PublicationDate": "2020-10-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i got 250$ in 5 munites using my phone",
                    "Link": "https://hamzadzworm.medium.com/how-i-got-250-in-5-munites-using-my-phone-91c9b2258282"
                 }
              ],
              "Authors": ["Abdelkader Mouaz (@hamzadzworm)"],
              "Programs": ["Basecamp"],
              "Bugs": ["HTML injection"],
              "Bounty": "250",
              "PublicationDate": "2020-10-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "TikTok fixes privacy issue discovered by Check Point Research",
                    "Link": "https://research.checkpoint.com/2021/tiktok-fixes-privacy-issue-discovered-by-check-point-research/"
                 }
              ],
              "Authors": ["Eran Vaknin", "Alon Boxiner"],
              "Programs": ["TikTok"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-10-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Link Previews: How a Simple Feature Can Have Privacy and Security Risks",
                    "Link": "https://www.mysk.blog/2020/10/25/link-previews/"
                 }
              ],
              "Authors": ["Talal Haj Bakry (@parasarora06)", "Tommy Mysk"],
              "Programs": ["Discord", "Meta / Facebook", "Google", "LINE", "LinkedIn", "Slack", "Twitter", "Zoom"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-10-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Perform substring search for emails even if Workplace admin hides email profile field.",
                    "Link": "https://servicenger.com/blog/mobile/perform-substring-search-for-emails-even-if-workplace-admin-hides-email-profile-field/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken Access Control", "Broken authorization"],
              "Bounty": "1,000",
              "PublicationDate": "2020-10-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first bug on Google",
                    "Link": "https://medium.com/bugbountywriteup/my-first-bug-on-google-observation-wins-1a13d0ea54b0"
                 }
              ],
              "Authors": ["Manas Harsh (@ManasH4rsh)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-10-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accidental Observation to Critical IDOR",
                    "Link": "https://medium.com/bugbountywriteup/accidental-observation-to-critical-idor-d4d910a855bf"
                 }
              ],
              "Authors": ["Harsh Bothra (@harshbothra_)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-10-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Samsung S20 - RCE via Samsung Galaxy Store App",
                    "Link": "https://labs.f-secure.com/blog/samsung-s20-rce-via-samsung-galaxy-store-app/"
                 }
              ],
              "Authors": ["F-Secure"],
              "Programs": ["Samsung"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-10-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "300$ P3 Easy Bug in 30 Seconds",
                    "Link": "https://medium.com/@seaman00o/300-p3-easy-bug-in-30-seconds-de65ea3d8f50"
                 }
              ],
              "Authors": ["Omar Hamdy (@seaman00o)"],
              "Programs": ["-"],
              "Bugs": ["Missing authentication", "Broken Access Control"],
              "Bounty": "300",
              "PublicationDate": "2020-10-22",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "IBM Datapower Exploit CVE-2020-5014",
                  "Link": "https://tomcope.com/exploit/2020/10/21/ibm-datapower-exploit-cve-2020-5014.html"
               }
            ],
            "Authors": ["Thomas Cope"],
            "Programs": ["IBM"],
            "Bugs": ["SSRF", "HTTP request smuggling"],
            "Bounty": "-",
            "PublicationDate": "2020-10-21",
            "AddedDate": "2023-03-02"
         },
           {
              "Links": [
                 {
                    "Title": "Perform substring search for emails even if Workplace admin hides email profile field.",
                    "Link": "https://servicenger.com/blog/mobile/perform-substring-search-for-emails-even-if-workplace-admin-hides-email-profile-field/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "2,000",
              "PublicationDate": "2020-10-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Page Admin Disclosure",
                    "Link": "https://servicenger.com/blog/mobile/facebook-page-admin-disclosure/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "3,000",
              "PublicationDate": "2020-10-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GitHub Pages - Multiple RCEs via insecure Kramdown configuration - $25,000 Bounty",
                    "Link": "https://devcraft.io/2020/10/20/github-pages-multiple-rces-via-kramdown-config.html"
                 }
              ],
              "Authors": ["William Bowling / vakzz (@wcbowling)"],
              "Programs": ["GitHub"],
              "Bugs": ["RCE", "Path traversal"],
              "Bounty": "25,000",
              "PublicationDate": "2020-10-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Back to 2019: Disclosure Employers PII and Credentials",
                    "Link": "https://medium.com/@saneklarek22/back-to-2019-disclosure-employers-pii-and-credentials-bb7f344dcb08"
                 }
              ],
              "Authors": ["Wh11teW0lf (@wh11tew0lf)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,000",
              "PublicationDate": "2020-10-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Address Bar Spoofing Vulnerabilities In Mobile Browsers",
                    "Link": "https://www.rafaybaloch.com/2020/10/multiple-address-bar-spoofing-vulnerabilities.html"
                 }
              ],
              "Authors": ["Rafay Baloch (@rafaybaloch)"],
              "Programs": ["Yandex", "Apple", "Opera"],
              "Bugs": ["Address Bar Spoofing"],
              "Bounty": "-",
              "PublicationDate": "2020-10-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Address Bar Spoofing Vulnerabilities In Mobile Browsers",
                    "Link": "https://www.rafaybaloch.com/2020/10/multiple-address-bar-spoofing-vulnerabilities.html"
                 }
              ],
              "Authors": ["James Sanderson (@zofrex)"],
              "Programs": ["NHS COVID-19 App"],
              "Bugs": ["Authentication bypass", "JWT", "Android"],
              "Bounty": "-",
              "PublicationDate": "2020-10-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GitHub Gist - Account takeover via open redirect - $10,000 Bounty",
                    "Link": "https://devcraft.io/2020/10/19/github-gist-account-takeover.html"
                 }
              ],
              "Authors": ["William Bowling / vakzz (@wcbowling)"],
              "Programs": ["GitHub"],
              "Bugs": ["Open redirect", "Account takeover"],
              "Bounty": "10,000",
              "PublicationDate": "2020-10-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GitHub - RCE via git option injection (almost) - $20,000 Bounty",
                    "Link": "https://devcraft.io/2020/10/18/github-rce-git-inject.html"
                 }
              ],
              "Authors": ["William Bowling / vakzz (@wcbowling)"],
              "Programs": ["GitHub"],
              "Bugs": ["RCE"],
              "Bounty": "20,000",
              "PublicationDate": "2020-10-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Discord Desktop app RCE",
                    "Link": "https://mksben.l0.cm/2020/10/discord-desktop-rce.html"
                 }
              ],
              "Authors": ["Masato Kinugawa (@kinugawamasato)"],
              "Programs": ["Discord"],
              "Bugs": ["RCE"],
              "Bounty": "5,000",
              "PublicationDate": "2020-10-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weaponizing XSS For Fun & Profit",
                    "Link": "https://saadahmedx.medium.com/weaponizing-xss-for-fun-profit-a1414f3fcee9"
                 }
              ],
              "Authors": ["Saad Ahmed (@XSaadAhmedX)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "CSRF"],
              "Bounty": "2,200",
              "PublicationDate": "2020-10-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "MS Enterprise app management service RCE. CVE-2022-35841",
                    "Link": "https://www.pentestpartners.com/security-blog/ms-enterprise-app-management-service-rce-cve-2022-35841/"
                 }
              ],
              "Authors": ["Ceri Coburn (@_ethicalchaos_)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE", "Local Privilege Escalation", "Windows"],
              "Bounty": "-",
              "PublicationDate": "2020-10-13",
              "AddedDate": "2022-10-17"
           },
           {
              "Links": [
                 {
                    "Title": "I had fun with this XSS",
                    "Link": "https://blog.yappare.com/2020/10/i-had-fun-with-this-xss.html"
                 }
              ],
              "Authors": ["yappare (@yappare)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-10-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind SSRF - The Hide & Seek Game",
                    "Link": "https://medium.com/@shahjerry33/blind-ssrf-the-hide-seek-game-da9d0ecef2fb"
                 }
              ],
              "Authors": ["Shrey Shah (@ShreySh43332033)"],
              "Programs": ["-"],
              "Bugs": ["Blind SSRF"],
              "Bounty": "400",
              "PublicationDate": "2020-10-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I find my first P1 level Bug. $$$",
                    "Link": "https://medium.com/@merry6607/how-i-find-my-first-p1-level-bug-5a6dd9587203"
                 }
              ],
              "Authors": ["Harsh"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-10-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose Emails, phone numbers, more For Facebook users who tried to add funds to their account",
                    "Link": "https://medium.com/@mustafa0x2021/disclose-emails-phone-numbers-other-information-for-facebook-users-who-tried-to-add-funds-to-31aea5f973a5"
                 }
              ],
              "Authors": ["Mustafa Ahmed (@mustafa0x2021)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2020-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Guest Blog Post: Rollback Attack",
                    "Link": "https://blog.mozilla.org/attack-and-defense/2020/10/12/guest-blog-post-rollback-attack/"
                 }
              ],
              "Authors": ["Xiaoyin Liu (@general_nfs)"],
              "Programs": ["Mozilla"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthorized access to all the user’s account.",
                    "Link": "https://web.archive.org/web/20211020083928/https://medium.com/@rahulnaidu_92192/unauthorized-access-to-all-the-users-account-c087511fe42a"
                 }
              ],
              "Authors": ["Rahul Naidu"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Authentication bypass", "JWT"],
              "Bounty": "-",
              "PublicationDate": "2020-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leveraging XSS to Read Internal Files",
                    "Link": "https://blog.dixitaditya.com/leveraging-xss-to-read-internal-files/"
                 }
              ],
              "Authors": ["Aditya Dixit (@zombie007o)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2020-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "JS is l0ve ❤️.",
                    "Link": "https://medium.com/@sechunter/js-is-love-%EF%B8%8F-ca393a4849e9"
                 }
              ],
              "Authors": ["Shivam Kamboj Dattana (@sechunt3r)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "API key leakage"],
              "Bounty": "5,000",
              "PublicationDate": "2020-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weak Password Setting function on practo.com",
                    "Link": "https://medium.com/@aakashadhikari786/weak-password-setting-function-on-practo-com-79df78245b81"
                 }
              ],
              "Authors": ["dark-haxor"],
              "Programs": ["Practo"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2018–5230 | JIRA Cross Site Scripting",
                    "Link": "https://medium.com/@parasarora06/cve-2018-5230-jira-cross-site-scripting-59ec96b3d75f"
                 }
              ],
              "Authors": ["Paras Arora (@parasarora06)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Admin Panel Like a Boss",
                    "Link": "https://medium.com/@sechunter/exploiting-admin-panel-like-a-boss-fc2dd2499d31"
                 }
              ],
              "Authors": ["Shivam Kamboj Dattana (@sechunt3r)"],
              "Programs": ["-"],
              "Bugs": ["Authorization bypass", "Weak credentials"],
              "Bounty": "1,500",
              "PublicationDate": "2020-10-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ATO via Host Header Poisoning",
                    "Link": "https://medium.com/@sechunter/ato-via-host-header-poisoning-dc5c29d2fd0d"
                 }
              ],
              "Authors": ["Shivam Kamboj Dattana (@sechunt3r)"],
              "Programs": ["-"],
              "Bugs": ["Host header injection", "Account takeover", "Password reset"],
              "Bounty": "2,000",
              "PublicationDate": "2020-10-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Kud I Enter Your Server? New Vulnerabilities in Microsoft Azure",
                    "Link": "https://www.intezer.com/blog/cloud-security/kud-i-enter-your-server-new-vulnerabilities-in-microsoft-azure/"
                 }
              ],
              "Authors": ["Intezer"],
              "Programs": ["Microsoft"],
              "Bugs": ["Privilege escalation", "RCE", "Cloud"],
              "Bounty": "-",
              "PublicationDate": "2020-10-08",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "We Hacked Apple for 3 Months: Here’s What We Found",
                  "Link": "https://samcurry.net/hacking-apple/"
               }
            ],
            "Authors": ["Sam Curry (@samwcyo)"],
            "Programs": ["Apple"],
            "Bugs": ["RCE", "Authentication bypass", "Authorization bypass", "SSRF", "XXE", "Blind XSS", "IDOR", "OS command injection", "SQL injection"],
            "Bounty": "288,500",
            "PublicationDate": "2020-10-07",
            "AddedDate": "2022-11-30"
         },
           {
              "Links": [
                 {
                    "Title": "SVE-2020-18025: Unauthorised access to Samsung secure folder files",
                    "Link": "https://servicenger.com/blog/mobile/sve-2020-18025-unauthorised-access-to-samsung-secure-folder-files/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Samsung"],
              "Bugs": ["Broken authorization"],
              "Bounty": "3,750",
              "PublicationDate": "2020-10-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Research: The mass CSRFing of *.google.com/* products.",
                    "Link": "http://www.missoumsai.com/google-csrfs.html"
                 }
              ],
              "Authors": ["Missoum Said (@missoum1307)"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "30,000",
              "PublicationDate": "2020-10-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "6k$ Worth Account Takeover via IDOR in Starbucks Singapore",
                    "Link": "http://www.kamilonurozkaleli.com/posts/starbucks-singapore-account-takeover/"
                 }
              ],
              "Authors": ["Kamil Onur Özkaleli (@ko2sec)"],
              "Programs": ["Starbucks"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "6,000",
              "PublicationDate": "2020-10-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sensitive Info Leak in Curve App [Bug Bounty]",
                    "Link": "https://praseudo.com/sensitive-info-leak-in-curve-app-bug-bounty/"
                 }
              ],
              "Authors": ["ΡRΛSΞUDΟ ® (@praseudo)"],
              "Programs": ["Curve"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,500",
              "PublicationDate": "2020-10-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Our Experiences Participating in Microsoft’s Azure Sphere Bounty Program",
                    "Link": "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/our-experiences-participating-in-microsofts-azure-sphere-bounty-program/"
                 }
              ],
              "Authors": ["McAfee Advanced Threat Research (ATR)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation", "RCE", "Security Feature bypass"],
              "Bounty": "160,000",
              "PublicationDate": "2020-10-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "90 days, 16 bugs, and an Azure Sphere Challenge",
                    "Link": "https://blog.talosintelligence.com/2020/10/Azure-Sphere-Challenge.html"
                 }
              ],
              "Authors": ["Cisco Talos"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation", "RCE", "DoS", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-10-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Watch your requests! Open redirect to a complete account takeover",
                    "Link": "https://ninetyn1ne.github.io/2020-10-05-open-redir-to-ato/"
                 }
              ],
              "Authors": ["Suraj Disoja (@ninetyn1ne_)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal", "Open redirect", "SSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-10-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Easy wins : verbose error worth Facebook HOF",
                    "Link": "https://medium.com/@ironfisto/easy-wins-verbose-error-worth-facebook-hof-7d8a99dd920b"
                 }
              ],
              "Authors": ["Mukul Lohar (@ironfisto)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2020-10-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leveraging LFI to RCE in a website with +20000 users",
                    "Link": "https://medium.com/bugbountywriteup/leveraging-lfi-to-rce-in-a-website-with-20000-users-129050f9982b"
                 }
              ],
              "Authors": ["Kleiton Kurti (@kleiton0x7e)"],
              "Programs": ["-"],
              "Bugs": ["LFI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-10-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spend more time doing recon, you’ll find more BUGS.",
                    "Link": "https://medium.com/@vedanttekale20/spend-more-time-doing-recon-youll-get-more-bugs-e7ffd5bf9202"
                 }
              ],
              "Authors": ["Vedant Tekale (@_justYnot)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-10-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Payment Gateways",
                    "Link": "https://medium.com/@vasuyadav0786/exploiting-payment-gateways-97ce7af5a9cf"
                 }
              ],
              "Authors": ["letmeslidein (@VasuYadaav)"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2020-10-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Journey Of My First Bug Bounty (Nov 2018)",
                    "Link": "https://medium.com/@harshtya9i/journey-of-my-first-bug-bounty-nov-2018-af471c21efc0"
                 }
              ],
              "Authors": ["Harsh Tyagi (@harshtya9i)"],
              "Programs": ["Samsung"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "200",
              "PublicationDate": "2020-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Arbitrary code execution on Facebook for Android through download feature",
                    "Link": "https://medium.com/@dPhoeniixx/arbitrary-code-execution-on-facebook-for-android-through-download-feature-fb6826e33e0f"
                 }
              ],
              "Authors": ["Sayed Abdelhafiz (@dPhoeniixx)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Arbitrary code execution"],
              "Bounty": "10,000",
              "PublicationDate": "2020-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Powerful HTTP Request Smuggling 💪",
                    "Link": "https://medium.com/@ricardoiramar/the-powerful-http-request-smuggling-af208fafa142"
                 }
              ],
              "Authors": ["Ricardo Iramar dos Santos (@ricardo_iramar)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "17,050",
              "PublicationDate": "2020-10-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write Up – Google Bug Bounty: XSS To Cloud Shell Instance Takeover (Rce As Root) – $5,000 USD",
                    "Link": "https://omespino.com/write-up-google-bug-bounty-xss-to-cloud-shell-instance-takeover-rce-as-root-5000-usd/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Google"],
              "Bugs": ["XSS", "RCE"],
              "Bounty": "5,000",
              "PublicationDate": "2020-10-01",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Forcing Firefox to Execute XSS Payloads during 302 Redirects",
                  "Link": "https://www.gremwell.com/firefox-xss-302"
               }
            ],
            "Authors": ["Quentin Kaiser (@QKaiser)"],
            "Programs": ["-"],
            "Bugs": ["XSS"],
            "Bounty": "-",
            "PublicationDate": "2020-09-30",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Story of a weird vulnerability I found on Facebook",
                    "Link": "https://medium.com/@amineaboud/story-of-a-weird-vulnerability-i-found-on-facebook-fc0875eb5125"
                 }
              ],
              "Authors": ["Amine Aboud (@amineaboud)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Authentication bypass", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-09-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE on Spip and Root-Me",
                    "Link": "https://thinkloveshare.com/hacking/rce_on_spip_and_root_me/"
                 }
              ],
              "Authors": ["Laluka (@TheLaluka)"],
              "Programs": ["SPIP"],
              "Bugs": ["RCE", "SQL injection", "XSS", "Open redirect", "Reflected file download"],
              "Bounty": "-",
              "PublicationDate": "2020-09-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Art of IDOR: 7 IDORs in Edm0d0",
                    "Link": "https://medium.com/@pratyush1337/the-art-of-idor-7-idors-in-edm0d0-b86d683c8de9"
                 }
              ],
              "Authors": ["Pratyush Anjan Sarangi"],
              "Programs": ["Edmodo"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-09-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Public Bucket Allowed Access to Images on Upcoming Google Cloud Blog Posts",
                    "Link": "https://websecblog.com/vulns/public-google-cloud-blog-bucket/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Google"],
              "Bugs": ["GCP bucket misconfiguration", "Information disclosure", "Cloud"],
              "Bounty": "-",
              "PublicationDate": "2020-09-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Taking down the SSO, Account Takeover in the Websites of Kolesa due to Insecure JSONP Call",
                    "Link": "https://medium.com/bugbountywriteup/taking-down-the-sso-account-takeover-in-3-websites-of-kolesa-due-to-insecure-jsonp-call-facd79732e45"
                 }
              ],
              "Authors": ["Yashar Shahinzadeh (@YShahinzadeh)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-09-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "P1: Critical - Discovering and Foiling a Threat Actor",
                    "Link": "https://johnjhacking.com/blog/p1-critical-discovering-and-foiling-a-threat-actor/"
                 }
              ],
              "Authors": ["Jackson Henry (@JacksonHHax)", "John Jackson (@johnjhacking)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,550",
              "PublicationDate": "2020-09-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "5 Ways to do Account Takeover in a Single Website",
                    "Link": "https://medium.com/@vasuyadav0786/5-ways-to-do-ato-in-a-single-website-cfe7e5da987e"
                 }
              ],
              "Authors": ["letmeslidein (@VasuYadaav)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Lack of rate limiting", "OTP bypass", "IDOR", "OAuth", "JWT"],
              "Bounty": "-",
              "PublicationDate": "2020-09-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chains on Chains: Chaining multiple low-level vulns into a Critical.",
                    "Link": "https://medium.com/@masonhck357/chains-on-chains-chaining-multiple-low-level-vulns-into-a-critical-8b88db29738e"
                 }
              ],
              "Authors": ["Daniel Marte (@Masonhck3571)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS", "CSP bypass", "Lack of rate limiting", "Exposed JWT generation endpoint", "JWT"],
              "Bounty": "-",
              "PublicationDate": "2020-09-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking the Medium partner program",
                    "Link": "https://medium.com/bugbountywriteup/hacking-the-medium-partner-program-84c0e9fa340"
                 }
              ],
              "Authors": ["Mohammad-Ali Bandzar"],
              "Programs": ["Medium"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-09-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Parameter Tampering ₹→$",
                    "Link": "https://medium.com/@suneets1ngh/parameter-tampering-ddd9b3de0da8"
                 }
              ],
              "Authors": ["SuneetSingh"],
              "Programs": ["-"],
              "Bugs": ["Parameter tampering"],
              "Bounty": "-",
              "PublicationDate": "2020-09-26",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Attacks On GCM With Repeated Nonces",
                  "Link": "https://www.elttam.com/blog/key-recovery-attacks-on-gcm/"
               }
            ],
            "Authors": ["Sebastien Macke"],
            "Programs": ["-"],
            "Bugs": ["Cryptographic issues", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2020-09-25",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Advisory: security issues in AWS KMS and AWS Encryption SDKs",
                    "Link": "https://vnhacker.blogspot.com/2020/09/advisory-security-issues-in-aws-kms-and.html"
                 }
              ],
              "Authors": ["Thai Duong (@XorNinja)"],
              "Programs": ["AWS"],
              "Bugs": ["Cryptographic issues", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-09-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PII Leakage via IDOR + Weak PasswordReset = Full Account Takeover",
                    "Link": "https://medium.com/bugbountywriteup/pii-leakage-via-idor-weak-passwordreset-full-account-takeover-58d159f88d73"
                 }
              ],
              "Authors": ["Pradeep Kumar (@Killer007p)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-09-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dangling DNS: AWS EC2",
                    "Link": "https://medium.com/@mohamed.elbadry/dangling-dns-aws-ec2-e2d801701e8"
                 }
              ],
              "Authors": ["Mohamed Elbadry (@_melbadry9)"],
              "Programs": ["-"],
              "Bugs": ["Dangling DNS records", "Subdomain takeover"],
              "Bounty": "2,900",
              "PublicationDate": "2020-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "VMware Workstation: Attack surface through Virtual Printer",
                    "Link": "https://blog.khonggianmang.vn/vmware-workstation-attack-surface-through-virtual-printer/"
                 }
              ],
              "Authors": ["Lê Hữu Quang Linh (@linhlhq)"],
              "Programs": ["VMware"],
              "Bugs": ["Memory corruption", "Integer overflow"],
              "Bounty": "-",
              "PublicationDate": "2020-09-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#Bugbounty- “How I was able to see other users Payments in a travel application” — IDOR #800$",
                    "Link": "https://medium.com/@haxor8595/bugbounty-how-i-was-able-to-see-other-users-payments-in-a-travel-application-idor-800-2060db62cbbe"
                 }
              ],
              "Authors": ["ganiganesh (@ganiganeshss79)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "800",
              "PublicationDate": "2020-09-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fun with Header and Forget Password",
                    "Link": "https://medium.com/bugbountywriteup/fun-with-header-and-forget-password-without-that-nasty-twist-cbf45e5cc8db"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["HTTP header injection"],
              "Bounty": "-",
              "PublicationDate": "2020-09-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "suPHP - The vulnerable ghost in your shell🎯Business Logic Flaw in Google Acquisition! (Hall Of Fame)🎯",
                    "Link": "https://medium.com/bugbountywriteup/business-logic-flaw-in-google-acquisition-hall-of-fame-1a9af5d3ac04"
                 }
              ],
              "Authors": ["Ritesh Gohil (@RiteshG37659480)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "suPHP - The vulnerable ghost in your shell",
                    "Link": "https://vulnerable.af/posts/suphp-ghost-in-your-shell/"
                 }
              ],
              "Authors": ["Maxime (@punkeel)", "(@swapgs)"],
              "Programs": ["-"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated File upload Vulnerability on Synology Sub-domain",
                    "Link": "https://blog.securelayer7.net/unauthenticated-file-upload-vulnerability-on-synology-sub-domain/"
                 }
              ],
              "Authors": ["Touhid Shaikh"],
              "Programs": ["Synology"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "2,000",
              "PublicationDate": "2020-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned $500 from Google - Flaw in Authentication",
                    "Link": "https://medium.com/bugbountywriteup/how-i-earned-500-from-google-flaw-in-authentication-a40018c05616"
                 }
              ],
              "Authors": ["Hemant Patidar (@HemantSolo)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authentication"],
              "Bounty": "500",
              "PublicationDate": "2020-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$25K Instagram Almost XSS Filter Link — Facebook Bug Bounty",
                    "Link": "https://medium.com/@alonnsoandres/25k-instagram-almost-xss-filter-link-facebook-bug-bounty-798b10c13b83"
                 }
              ],
              "Authors": ["Andres Alonso (@al0nnso)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Stored XSS"],
              "Bounty": "25,000",
              "PublicationDate": "2020-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I By-pass the login page and 2FA authentication…..",
                    "Link": "https://medium.com/@merry6607/how-i-by-pass-the-login-page-and-2fa-authentication-3f33b06838c"
                 }
              ],
              "Authors": ["Harsh"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass", "OTP bypass", "2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cross-tenant Cloud Function compromise via storage bucket squatting",
                    "Link": "https://lf.lc/vrp/168991979/"
                 }
              ],
              "Authors": ["Anthony Weems"],
              "Programs": ["Google"],
              "Bugs": ["Cross-tenant vulnerability"],
              "Bounty": "3,133.70",
              "PublicationDate": "2020-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "You can’t stop me. MS Teams session hijacking and bypass",
                    "Link": "https://www.pentestpartners.com/security-blog/you-cant-stop-me-ms-teams-session-hijacking-and-bypass/"
                 }
              ],
              "Authors": ["Bandit Pingu (@FlyingPhishy)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Insecure storage of sensitive information"],
              "Bounty": "-",
              "PublicationDate": "2020-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote code execution in import image task via storage bucket squatting",
                    "Link": "https://lf.lc/vrp/168987557/"
                 }
              ],
              "Authors": ["Anthony Weems"],
              "Programs": ["Google"],
              "Bugs": ["RCE"],
              "Bounty": "3,133.70",
              "PublicationDate": "2020-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Emoji error handling",
                    "Link": "https://medium.com/@Sheshasai/emoji-error-handling-ba11f1bdb8a6"
                 }
              ],
              "Authors": ["shesha sai_c (@Cyb3r_4ss4s1n)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020-9964 - An iOS infoleak",
                    "Link": "https://muirey03.blogspot.com/2020/09/cve-2020-9964-ios-infoleak.html"
                 }
              ],
              "Authors": ["Muirey03 (@Muirey03)"],
              "Programs": ["Apple"],
              "Bugs": ["iOS", "Memory initialisation issue"],
              "Bounty": "-",
              "PublicationDate": "2020-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation via Account Takeover on NodeBB Forum Software — Bug Bounty (512$) — CVE-2020–15149",
                    "Link": "https://medium.com/bugbountywriteup/privilege-escalation-via-account-takeover-on-nodebb-forum-software-512-a593a7b1b4a4"
                 }
              ],
              "Authors": ["Muhammed Eren Uygun (@erenuyguun)"],
              "Programs": ["NodeBB"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "512",
              "PublicationDate": "2020-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS via a hidden parameter on Dutch Gov. website",
                    "Link": "https://supras.io/reflected-xss-via-a-hidden-parameter-on-dutch-gov-website/"
                 }
              ],
              "Authors": ["Supras (@LdrTom)"],
              "Programs": ["Dutch Government"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Bug Bounty From Bug Bounty Platform redstorm.io",
                    "Link": "https://medium.com/@novan.rmd/my-first-bug-bounty-from-bug-bounty-platform-redstorm-io-50958f6adc90"
                 }
              ],
              "Authors": ["Novan Aziz Ramadhan (@novan_rmd)"],
              "Programs": ["RedStorm"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-09-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dropbox Escalation of Privileges to SYSTEM on Windows",
                    "Link": "https://dreamlab.net/en/blog/post/dropbox-escalation-of-privileges-to-system-on-windows-1/"
                 }
              ],
              "Authors": ["Teresa Alberto"],
              "Programs": ["Dropbox"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-09-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Res-block: Extension Resources Block Attack on Chrome’s Incognito Mode",
                    "Link": "https://medium.com/@0x48piraj/res-block-extension-resources-block-attack-on-chromes-incognito-mode-3a5ae8131142"
                 }
              ],
              "Authors": ["Piyush Raj (@0x48piraj)"],
              "Programs": ["Google"],
              "Bugs": ["Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2020-09-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting a \"Useless\" Cookie-Based XSS and Making it Useful",
                    "Link": "https://blog.long.lat/2020/09/16/exploiting-a-useless-cookie-based-xss-and-making-it-useful/"
                 }
              ],
              "Authors": ["Daniel Thatcher (@_danielthatcher)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-09-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Accidentally Got My First Bounty From Facebook",
                    "Link": "https://medium.com/bugbountywriteup/how-i-accidentally-got-my-first-bounty-from-facebook-facebook-bug-bounty-2020-c12bd2ad8575"
                 }
              ],
              "Authors": ["Bishal Shrestha (@bishal0x01)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-09-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Firefox for Android: LAN Based Intent Triggering",
                    "Link": "https://initblog.com/2020/firefox-android/"
                 }
              ],
              "Authors": ["initstring (@init_string)"],
              "Programs": ["Mozilla"],
              "Bugs": ["Insecure intent", "Android"],
              "Bounty": "-",
              "PublicationDate": "2020-09-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account takeover by OTP bypass",
                    "Link": "https://medium.com/@bhavarth33/how-i-was-able-to-takeover-any-account-by-otp-bypass-bba698a725f"
                 }
              ],
              "Authors": ["Bhavarth Kandoria"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business logic vulnerabilities — Low-level logic flaw",
                    "Link": "https://medium.com/@d.harish008/business-logic-vulnerabilities-low-level-logic-flaw-f308a21a945d"
                 }
              ],
              "Authors": ["Harry D"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection & Remote Code Execution - Double P1",
                    "Link": "https://medium.com/@shahjerry33/sql-injection-remote-code-execution-double-p1-6038ca88a2ec"
                 }
              ],
              "Authors": ["Shrey Shah (@ShreySh43332033)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked redbus [An online bus-ticketing application]",
                    "Link": "https://medium.com/bugbountywriteup/how-i-hacked-redbus-an-online-bus-ticketing-application-24ef5bb083cd"
                 }
              ],
              "Authors": ["Sangeetha Rajesh S (@rajesh_sangi12)"],
              "Programs": ["redBus"],
              "Bugs": ["LFI", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-09-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked Facebook Again! Unauthenticated RCE on MobileIron MDM",
                    "Link": "https://blog.orange.tw/2020/09/how-i-hacked-facebook-again-mobileiron-mdm-rce.html"
                 }
              ],
              "Authors": ["Orange Tsai (@orange_8361)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["RCE", "JNDI Injection"],
              "Bounty": "-",
              "PublicationDate": "2020-09-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Universal XSS in Android WebView (CVE-2020-6506)",
                    "Link": "https://alesandroortiz.com/articles/uxss-android-webview-cve-2020-6506/"
                 }
              ],
              "Authors": ["Alesandro Ortiz (@AlesandroOrtizR)"],
              "Programs": ["Google", "Microsoft", "Twitter"],
              "Bugs": ["Universal XSS"],
              "Bounty": "15,560",
              "PublicationDate": "2020-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unintended Behaviour of domain got me P4",
                    "Link": "https://medium.com/@gaupaler/unintended-behaviour-of-domain-got-me-p4-d6af19b5dcdd"
                 }
              ],
              "Authors": ["Takester (@dhiraj_ramteke)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How often do we overlook vulnerabilities?",
                    "Link": "https://medium.com/infosec/how-often-do-we-overlook-vulnerabilities-960a7c45f59"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["HackerOne"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020-8150 – Remote Code Execution as SYSTEM/root via Backblaze",
                    "Link": "https://github.com/geffner/CVE-2020-8150"
                 }
              ],
              "Authors": ["Jason Geffner (@JasonGeffner)"],
              "Programs": ["Backblaze"],
              "Bugs": ["RCE", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS->Fix->Bypass: 10000$ bounty in Google Maps",
                    "Link": "https://www.ehpus.com/post/xss-fix-bypass-10000-bounty-in-google-maps"
                 }
              ],
              "Authors": ["Zohar Shachar"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "10,000",
              "PublicationDate": "2020-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Android Static Analysis to RCE on Prod",
                    "Link": "https://blog.dixitaditya.com/from-android-app-to-rce/"
                 }
              ],
              "Authors": ["Aditya Dixit (@zombie007o)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Directory listing", "Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2020-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first bug in google and how i got CSRF token for victim account rather than bypass it ($1337)!",
                    "Link": "https://medium.com/@odayalhalbe1/my-first-bug-in-google-and-how-i-got-csrf-token-for-victim-account-rather-than-bypass-it-1337-bf01261feb47"
                 }
              ],
              "Authors": ["Oday Alhalbe"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "1,337",
              "PublicationDate": "2020-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How response Manipulation got me a little, but sweet Bounty",
                    "Link": "https://infosecwriteups.com/how-response-manipulation-got-me-a-little-but-sweet-bounty-38b515ca0910"
                 }
              ],
              "Authors": ["Tommaso De Ponti (@heytdep)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Never Give Up, The Story Behind a Dupe-To-Triaged",
                    "Link": "https://medium.com/@soyelmago/never-give-up-the-story-behind-a-dupe-to-a-triaged-43b72debb6c9"
                 }
              ],
              "Authors": ["Alan Brian (@soyelmago)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "OAuth", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-09-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS that can pay your Bills :)",
                    "Link": "https://medium.com/@smilehackerofficial/xss-that-can-pay-your-bills-9377eff1fd0d"
                 }
              ],
              "Authors": ["Smile Hacker (@_smile_hacker_)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "500",
              "PublicationDate": "2020-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How_i_was_able_to_pawned_website_via_escilating_webcache deception to rce",
                    "Link": "https://web.archive.org/web/20201125190336/https://tox7cv3nom.github.io/2020-08-05-how_i_was_able_to_pawned_website_via_escilating_webcache-deception-to-rce/"
                 }
              ],
              "Authors": ["mohit (@mohit29295572)"],
              "Programs": ["-"],
              "Bugs": ["Web cache deception", "SSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover via IDOR",
                    "Link": "https://blog.deteact.com/account-takeover-via-idor/"
                 }
              ],
              "Authors": ["Roma Ramazanoff (@r0hack)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "25,000",
              "PublicationDate": "2020-09-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Story With XSS",
                    "Link": "https://medium.com/@soufianehabti/my-story-with-xss-ed017bdc44c4"
                 }
              ],
              "Authors": ["Soufiane Habti (@wld_basha)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-09-03",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "CVE-2020-6519 - Chromium 83 Zero Day Full CSP Bypass Cross Platforms",
                  "Link": "https://weizman.github.io/2020/09/02/csp-vuln/"
               }
            ],
            "Authors": ["Gal Weizman (@WeizmanGal)"],
            "Programs": ["Google (Chrome & Chromium)"],
            "Bugs": ["CSP bypass"],
            "Bounty": "3,000",
            "PublicationDate": "2022-09-02",
            "AddedDate": "2023-05-04"
         },
           {
              "Links": [
                 {
                    "Title": "Cloud firewall management API SNAFU put 500k SonicWall customers at risk",
                    "Link": "https://www.pentestpartners.com/security-blog/cloud-firewall-management-api-snafu-put-500k-sonicwall-customers-at-risk/"
                 }
              ],
              "Authors": ["Vangelis Stykas (@evstykas)"],
              "Programs": ["SonicWall"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Denial of Service in the protection service provided by Avast Security Premium.",
                    "Link": "https://medium.com/stolabs/denial-of-service-in-the-protection-service-provided-by-avast-security-premium-284dfd5ab40"
                 }
              ],
              "Authors": ["Silton Santos"],
              "Programs": ["Avast"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-09-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stop scratching the surface, and hack the dependencies",
                    "Link": "https://medium.com/@reiss.r/stop-scratching-the-surface-and-hack-the-dependencies-fe4c26cd8ea"
                 }
              ],
              "Authors": ["Rotem Reiss (@rotem_reiss)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Page shops with a hidden Product in “Featured product section” which could be controlled by attacker (Ex Editor).",
                    "Link": "https://medium.com/@rohitcoder/page-shops-with-a-hidden-product-in-featured-product-section-which-could-be-controlled-by-d0fd58c4cc8b"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unhiding the hidden",
                    "Link": "https://medium.com/bugbountywriteup/unhiding-the-hidden-2ef44192c10b"
                 }
              ],
              "Authors": ["I am Broot"],
              "Programs": ["-"],
              "Bugs": ["Client-side enforcement of server-side security", "Broken authorization", "CSRF"],
              "Bounty": "530",
              "PublicationDate": "2020-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Importance of keeping up to date, or how I found an interesting bug thanks to a tweet",
                    "Link": "https://medium.com/bugbountywriteup/the-importance-of-keeping-up-to-date-or-how-i-found-an-interesting-bug-thanks-to-a-tweet-2ec6ba9a5e1e"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Oversecured automatically discovers persistent code execution in the Google Play Core Library",
                    "Link": "https://blog.oversecured.com/Oversecured-automatically-discovers-persistent-code-execution-in-the-Google-Play-Core-Library/"
                 }
              ],
              "Authors": ["Oversecured (@OversecuredInc)"],
              "Programs": ["Google"],
              "Bugs": ["Arbitrary Code Execution", "Android"],
              "Bounty": "-",
              "PublicationDate": "2020-08-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Hacking Adventures With Safari Reader Mode",
                    "Link": "https://payatu.com/blog/nikhil-mittal/my-hacking-adventures-with-safari-reader-mode"
                 }
              ],
              "Authors": ["Nikhil Mittal (@c0d3G33k)"],
              "Programs": ["Apple"],
              "Bugs": ["CSP bypass", "SOP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-08-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accessing the website directly through its IP address, a case of a poorly hidden sql injection",
                    "Link": "https://medium.com/bugbountywriteup/accessing-the-website-directly-through-its-ip-address-a-case-of-a-poorly-hidden-sql-injection-82833defbbc3"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-08-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Delete IDOR on a Fashion eCommerce Website",
                    "Link": "https://techkranti.com/delete-idor-on-a-fashion-ecommerce-website/"
                 }
              ],
              "Authors": ["Amey Anekar (@ameyanekar)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-08-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Auth bypass: Leaking Google Cloud service accounts and projects",
                    "Link": "https://www.ezequiel.tech/2020/08/leaking-google-cloud-projects.html"
                 }
              ],
              "Authors": ["Ezequiel Pereira (@epereiralopez)"],
              "Programs": ["Google"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-08-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty Failsx101[4]",
                    "Link": "https://medium.com/@leviwof/bug-bounty-failsx101-4-b601616fbe9f"
                 }
              ],
              "Authors": ["ArcherL (@realArcherL)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-08-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Waze: How I Tracked Your Mother",
                    "Link": "https://www.malgregator.com/post/waze-how-i-tracked-your-mother/"
                 }
              ],
              "Authors": ["Peter Gasper (@malgregator)"],
              "Programs": ["Google (Waze)"],
              "Bugs": ["Logic flaw", "Information disclosure"],
              "Bounty": "1,337",
              "PublicationDate": "2020-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing local files using Safari Web Share API",
                    "Link": "https://blog.redteam.pl/2020/08/stealing-local-files-using-safari-web.html"
                 }
              ],
              "Authors": ["Pawel Wylecial (@h0wlu)"],
              "Programs": ["Apple"],
              "Bugs": ["Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2020-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover For The Win 🏆",
                    "Link": "https://medium.com/@ricardoiramar/account-takeover-for-the-win-e320ce83cdd9"
                 }
              ],
              "Authors": ["Ricardo Iramar dos Santos (@ricardo_iramar)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Broken authentication", "Password reset"],
              "Bounty": "2,225",
              "PublicationDate": "2020-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$$ Bounties for Unauthenticated file read in Cisco ASA CVE-2020–3452",
                    "Link": "https://infosecwriteups.com/bounties-for-unauthenticated-file-read-in-cisco-asa-cve-2020-3452-9a0b9143370e"
                 }
              ],
              "Authors": ["Supun Halangoda (@halangoda_supun)"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2020-08-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to find easy P1 just by doing Recon",
                    "Link": "https://medium.com/@kirtanpatel9111998/how-i-was-able-to-find-easy-p1-just-by-doing-recon-fdef0c689362"
                 }
              ],
              "Authors": ["Kirtan Patel (@kirtanpatel9111)"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2020-08-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Upload to the future",
                    "Link": "https://medium.com/bugbountywriteup/upload-to-the-future-1fd38fd502bd"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-08-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found My First Bug Stored Xss and Earned My First Bounty 1000$",
                    "Link": "https://medium.com/@0xnazmul/how-i-found-my-first-bug-stored-xss-and-earned-my-first-bounty-1000-33556678d1ed"
                 }
              ],
              "Authors": ["Nazmul Haque (@0xnazmul)"],
              "Programs": ["Badoo"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2020-08-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "(Shopify.com) Blind Stored XSS Via Staff Name $$$$",
                    "Link": "https://apapedulimu.click/shopify-com-blind-stored-xss-via-staff-name/"
                 }
              ],
              "Authors": ["Rio Mulyadi (@riomulyadi_)"],
              "Programs": ["Shopify"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-08-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Confused Mailman: Sending SPF and DMARC passing mail as any Gmail or G Suite customer",
                    "Link": "https://ezh.es/blog/2020/08/the-confused-mailman-sending-spf-and-dmarc-passing-mail-as-any-gmail-or-g-suite-customer/"
                 }
              ],
              "Authors": ["Allison Husain (@ezhes_)"],
              "Programs": ["Google"],
              "Bugs": ["Email spoofing"],
              "Bounty": "-",
              "PublicationDate": "2020-08-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A perfect duplicate or how to send an email with a spoofed invoice’s content",
                    "Link": "https://medium.com/@mateusz.olejarka/a-perfect-duplicate-or-how-to-send-an-email-with-a-spoofed-invoices-content-66cf369bbaa3"
                 }
              ],
              "Authors": ["Mateusz Olejarka (@molejarka)"],
              "Programs": ["-"],
              "Bugs": ["Email spoofing", "Open mail relay", "Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2020-08-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Django debug mode to RCE in Microsoft acquisition",
                    "Link": "https://medium.com/@syedabuthahir/django-debug-mode-to-rce-in-microsoft-acquisition-189d27d08971"
                 }
              ],
              "Authors": ["Syed Abuthahir (@writerabu)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-08-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating a GitHub leak to takeover entire organization",
                    "Link": "https://blog.shashank.co/2020/08/escalating-github-leak-to-takeover.html"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "4,000",
              "PublicationDate": "2020-08-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fun with header and forget password, with a twist:",
                    "Link": "https://medium.com/bugbountywriteup/fun-with-header-and-forget-password-with-a-twist-af095b426fb2"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Host header injection"],
              "Bounty": "-",
              "PublicationDate": "2020-08-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to contact Google SRE: Dropping a shell in cloud SQL",
                    "Link": "https://offensi.com/2020/08/18/how-to-contact-google-sre-dropping-a-shell-in-cloud-sql/"
                 }
              ],
              "Authors": ["wtm@offensi.com (@wtm_offensi)", "Ezequiel Pereira (@epereiralopez)"],
              "Programs": ["Google"],
              "Bugs": ["SQL injection", "Privilege escalation", "Parameter injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-08-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How could I Tag Photo to any user’s Scrapbook on Facebook",
                    "Link": "https://medium.com/bugbountywriteup/how-could-i-tag-photo-to-any-users-scrapbook-on-facebook-23ab15e6e4b4"
                 }
              ],
              "Authors": ["Raja Sudhakar (@Rajasudhakar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-08-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From SQL Injection to Hall Of Fame",
                    "Link": "https://medium.com/bugbountywriteup/from-sql-injection-to-hall-of-fame-96a08c869acd"
                 }
              ],
              "Authors": ["Jadek Mark (@mase289)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-08-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Windows AppX Deployment Service Local Privilege Escalation (CVE-2020-1488",
                    "Link": "https://www.activecyber.us/activelabs/windows-appx-deployment-service-local-privilege-escalation-cve-2020-1488"
                 }
              ],
              "Authors": ["ACTIVELabs"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-08-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Firebase Cloud Messaging Service Takeover: A small research that led to 30k$+ in bounties",
                    "Link": "https://abss.me/posts/fcm-takeover/"
                 }
              ],
              "Authors": ["Abss (@absshax)"],
              "Programs": ["Google"],
              "Bugs": ["Hardcoded API keys", "Information disclosure"],
              "Bounty": "30,000",
              "PublicationDate": "2020-08-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover Using Re-Register [ Bug Bounty ]",
                    "Link": "https://web.archive.org/web/20200819113116/https://medium.com/@godofdarkness.msf/account-takeover-using-re-register-bug-bounty-bda8bb2106e6"
                 }
              ],
              "Authors": ["Myo Min Thu (@myominthu1337)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "2,048",
              "PublicationDate": "2020-08-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing your data using XSS",
                    "Link": "https://medium.com/bugbountywriteup/stealing-your-data-using-xss-bf7e4a31e6ee"
                 }
              ],
              "Authors": ["Viren Pawar (@VirenPawar_)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-08-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Witnet Network Bug Bounty: DOS Bug from Harsh Jain",
                    "Link": "https://medium.com/witnet/witnet-network-acknowledged-dos-bug-f7d55b709051"
                 }
              ],
              "Authors": ["Harsh Jain"],
              "Programs": ["Witnet"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-08-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "InfluxDB Access at redact.8x8.com",
                    "Link": "https://web.archive.org/web/20200816192659/https://medium.com/@godofdarkness.msf/influxdb-access-at-redact-8x8-com-1b54976b137"
                 }
              ],
              "Authors": ["Myo Min Thu (@myominthu1337)"],
              "Programs": ["8x8"],
              "Bugs": ["Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2020-08-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got 450$ just in one Google search (SQLi + RXSS)?",
                    "Link": "https://medium.com/@z.x/how-i-got-450-just-in-one-google-search-sqli-rxss-8c7c28ceba79"
                 }
              ],
              "Authors": ["Zhenwar Hawlery"],
              "Programs": ["-"],
              "Bugs": ["XSS", "SQL injection"],
              "Bounty": "450",
              "PublicationDate": "2020-08-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclosing wifi password via content provider injection in Xiaomi",
                    "Link": "https://vishwarajbhattrai.wordpress.com/2020/08/16/disclosing-wifi-password-via-content-provider-injection-in-xiaomi/"
                 }
              ],
              "Authors": ["Vishwaraj Bhattrai (@vishwaraj101)"],
              "Programs": ["Xiaomi"],
              "Bugs": ["Content provider injection", "Vulnerable Android content provider", "Android"],
              "Bounty": "-",
              "PublicationDate": "2020-08-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to send Authentic Emails as others — Google VRP [Resolved]",
                    "Link": "https://medium.com/bugbountywriteup/how-i-was-able-to-send-authentic-emails-as-others-google-vrp-resolved-2af94295f326"
                 }
              ],
              "Authors": ["Sriram Kesavan (@sriramoffcl)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw", "HTML injection", "Email spoofing", "Open mail relay"],
              "Bounty": "-",
              "PublicationDate": "2020-08-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How recon helped me to find an interesting bug…",
                    "Link": "https://medium.com/@vedanttekale20/how-recon-helped-me-to-find-an-interesting-bug-17a2d8cf1778"
                 }
              ],
              "Authors": ["Vedant Tekale (@_justYnot)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-08-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open Sesame: Escalating Open Redirect to RCE with Electron Code Review",
                    "Link": "https://spaceraccoon.dev/open-sesame-escalating-open-redirect-to-rce-with-electron-code-review"
                 }
              ],
              "Authors": ["Eugene Lim (@spaceraccoonsec)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "RCE", "Security code review"],
              "Bounty": "-",
              "PublicationDate": "2020-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Crowdsource Success Story: From an Out-of-Scope Open Redirect to CVE-2020-1323",
                    "Link": "https://blog.detectify.com/2020/08/14/crowdsource-success-story-from-an-out-of-scope-open-redirect-to-cve-2020-1323/"
                 }
              ],
              "Authors": ["Ozgur Alp (@ozgur_bbh)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Deleted data stored permanently on Instagram? Facebook Bug Bounty 2020",
                    "Link": "https://medium.com/nassec-cybersecurity-writeups/deleted-data-stored-permanently-on-instagram-facebook-bug-bounty-2020-26074c229955"
                 }
              ],
              "Authors": ["Saugat Pokharel (@saugatscript)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Privacy issue"],
              "Bounty": "6,000",
              "PublicationDate": "2020-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Improper Implementation of My Status video time limit in WhatsApp",
                    "Link": "https://medium.com/@vishalranjan00012/hi-folks-2f28dd8fdfe9"
                 }
              ],
              "Authors": ["Vishal Ranjan"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Privacy issue", "Android"],
              "Bounty": "-",
              "PublicationDate": "2020-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "False2True, Match and Replace bug hunting — A cautionary tale",
                    "Link": "https://medium.com/bugbountywriteup/false2true-match-and-replace-bug-hunting-a-cautionary-tale-fbe7020f02ad"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaking AWS Metadata - The Unusual Way",
                    "Link": "https://medium.com/bugbountywriteup/leaking-aws-metadata-f5bc8de03284"
                 }
              ],
              "Authors": ["Shubham Garg (@nullb0t)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-08-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Journey to my First Bug Hunt$$$$",
                    "Link": "https://medium.com/@balapraneeth98/journey-to-my-first-bug-hunt-6dc5e4552128"
                 }
              ],
              "Authors": ["Bala Praneeth (@Begin_hunt)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "900",
              "PublicationDate": "2020-08-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind OS Command Injection",
                    "Link": "https://medium.com/@ashikbhaskar94/blind-os-command-injection-87910f0d2276"
                 }
              ],
              "Authors": ["Ashik B"],
              "Programs": ["-"],
              "Bugs": ["OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2020-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cache poisoning of wget",
                    "Link": "https://medium.com/bugbountywriteup/cache-poisoning-of-wget-94a4d70104b1"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["Web cache poisoning"],
              "Bounty": "-",
              "PublicationDate": "2020-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cracking the 2FA",
                    "Link": "https://medium.com/@rushikesh12gaikwad/cracking-the-2fa-215d24ccb29b"
                 }
              ],
              "Authors": ["Rushikesh Gaikwad (@rsg_1212)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made $2000 with URL REDIRECTION?",
                    "Link": "https://medium.com/@singh.simran7838/how-i-made-2000-with-url-redirection-b1b5f4e7a678"
                 }
              ],
              "Authors": ["Simran Singh"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "SQL injection"],
              "Bounty": "2,000",
              "PublicationDate": "2020-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020-1337 – PrintDemon is dead, long live PrintDemon!",
                    "Link": "https://voidsec.com/cve-2020-1337-printdemon-is-dead-long-live-printdemon/"
                 }
              ],
              "Authors": ["Paolo Stagno (@Void_Sec)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation", "Windows"],
              "Bounty": "-",
              "PublicationDate": "2020-08-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to find page/personal account disclosure on Instagram",
                    "Link": "https://medium.com/nassec-cybersecurity-writeups/how-i-was-able-to-find-page-personal-account-disclosure-on-instagram-d9607de4883f"
                 }
              ],
              "Authors": ["Ajay Gautam (@evilboyajay)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "2,000",
              "PublicationDate": "2020-08-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Group Admin Can’t Able to Moderate Comments When Posted Through Page : Facebook Bug Bounty 2020",
                    "Link": "https://medium.com/@prakashpanta1999/group-admin-cant-able-to-moderate-comments-when-posted-through-page-facebook-bug-bounty-2020-16c2d04a27cb"
                 }
              ],
              "Authors": ["Prakash Panta (@Prakashpanta268)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-08-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020-11518: how I bruteforced my way into your Active Directory",
                    "Link": "https://honoki.net/2020/08/10/cve-2020-11518-how-i-bruteforced-my-way-into-your-active-directory/"
                 }
              ],
              "Authors": ["Pieter Hiele (@honoki)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Insecure deserialization", "Arbitrary file upload", "Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2020-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSP Bypass Vulnerability in Google Chrome Discovered - Almost Every Website In The World Was At Risk",
                    "Link": "https://www.perimeterx.com/tech-blog/2020/csp-bypass-vuln-disclosure/"
                 }
              ],
              "Authors": ["Gal Weizman (@WeizmanGal)"],
              "Programs": ["Google"],
              "Bugs": ["CSP bypass"],
              "Bounty": "3,000",
              "PublicationDate": "2020-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My 2nd 4digit Bug Bounty From Facebook",
                    "Link": "https://medium.com/@sudipshah_66336/my-2nd-4digit-bug-bounty-from-facebook-99baa727ed02"
                 }
              ],
              "Authors": ["Sudip Shah"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing 403",
                    "Link": "https://observationsinsecurity.com/2020/08/09/bypassing-403-to-get-access-to-an-admin-console-endpoints/"
                 }
              ],
              "Authors": ["Michael Hyndman (@michaelhyndman)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Zoom: Uncovering Tales of Security Vulnerabilities in Zoom",
                    "Link": "https://mazinahmed.net/blog/hacking-zoom/"
                 }
              ],
              "Authors": ["Mazin Ahmed (@mazen160)"],
              "Programs": ["Zoom"],
              "Bugs": ["Information disclosure", "RCE", "Memory leak"],
              "Bounty": "-",
              "PublicationDate": "2020-08-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Google Maps API Key Restrictions",
                    "Link": "https://blog.dixitaditya.com/bypassing-google-maps-api-key-restrictions/"
                 }
              ],
              "Authors": ["Aditya Dixit (@zombie007o)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-08-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Hunting with Param Miner: Cache poisoning with XSS, a peculiar case",
                    "Link": "https://medium.com/bugbountywriteup/cache-poisoning-with-xss-a-peculiar-case-eb5973850814"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Web cache poisoning"],
              "Bounty": "-",
              "PublicationDate": "2020-08-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS in Facebook’s mirror websites",
                    "Link": "https://medium.com/bugbountywriteup/reflected-xss-in-facebooks-mirror-websites-4384b4eb3e11"
                 }
              ],
              "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "500",
              "PublicationDate": "2020-08-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The feature works as intended, but what’s in the source?",
                    "Link": "https://medium.com/@zseano/the-feature-works-as-intended-but-whats-in-the-source-d29f9401bcf6"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-08-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting JWT - Lack of Signature Verification",
                    "Link": "https://blog.dixitaditya.com/exploiting-jwt-lack-of-signature-verification"
                 }
              ],
              "Authors": ["Aditya Dixit (@zombie007o)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Smear phishing: a new Android vulnerability",
                    "Link": "https://jameshfisher.com/2020/08/06/smear-phishing-how-to-scam-an-android-user/"
                 }
              ],
              "Authors": ["Jim Fisher (@MrJamesFisher)"],
              "Programs": ["Google"],
              "Bugs": ["Phishing", "Android"],
              "Bounty": "-",
              "PublicationDate": "2020-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS at fotoservice.hema.nl",
                    "Link": "https://medium.com/@jonathanbouman/reflected-xss-at-fotoservice-hema-nl-af344ef63433"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Hema"],
              "Bugs": ["Reflected XSS", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind SQL Injection at fasteditor.hema.com",
                    "Link": "https://medium.com/@jonathanbouman/blind-sql-injection-at-fasteditor-hema-com-6ac140c0d1a3"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Hema"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on Slack, Bug Bounty",
                    "Link": "https://medium.com/@tommysuriel/stored-xss-on-slack-bug-bounty-88fe167d75df"
                 }
              ],
              "Authors": ["Tommysuriel"],
              "Programs": ["Slack"],
              "Bugs": ["Stored XSS"],
              "Bounty": "4,875",
              "PublicationDate": "2020-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Apache Example Servlet leads to $$$$",
                    "Link": "https://medium.com/@DK999/apache-example-servlet-leads-to-61a2720cac20"
                 }
              ],
              "Authors": ["Debangshu Kundu (@debangshu_kundu)"],
              "Programs": ["-"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2020-08-06",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "The Case of the Missing Cache Keys",
                  "Link": "https://enumerated.wordpress.com/2020/08/05/the-case-of-the-missing-cache-keys/"
               }
            ],
            "Authors": ["Aaron Costello (@ConspiracyProof)"],
            "Programs": ["-"],
            "Bugs": ["Web cache poisoning"],
            "Bounty": "-",
            "PublicationDate": "2020-08-05",
            "AddedDate": "2023-02-13"
         },
           {
              "Links": [
                 {
                    "Title": "CSRF PoC mistake that broke crucial functions for the end user/victim",
                    "Link": "https://medium.com/bugbountywriteup/csrf-poc-mistake-that-broke-crucial-functions-for-the-end-user-victim-ef4fa4584ca8"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I want all these features",
                    "Link": "https://medium.com/@mohamedayad_72488/i-want-all-these-features-bb41e8252020"
                 }
              ],
              "Authors": ["Mohamed Ayad"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2020-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to do Mass Account Takeover[Bug Bounty]",
                    "Link": "https://medium.com/@rikeshbaniyaaa/how-i-was-able-to-do-mass-account-takeover-bug-bounty-b279af1ce62b"
                 }
              ],
              "Authors": ["Not Rickyy (@RickyyNot)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2020-08-05",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Amazon AWS Bastion - Logger Bypass",
                  "Link": "https://pulsesecurity.co.nz/advisories/AWS-Bastion-Logger-Bypass"
               }
            ],
            "Authors": ["Denis Andzakovic"],
            "Programs": ["AWS"],
            "Bugs": ["Logging bypass", "Local Privilege Escalation"],
            "Bounty": "-",
            "PublicationDate": "2020-08-03",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Vulnerability in new TouchID feature put iCloud accounts at risk of being breached",
                    "Link": "https://www.computest.nl/en/knowledge-platform/blog/vulnerability-new-touchid-feature-iCloud-accounts-at-risk-breached/"
                 }
              ],
              "Authors": ["Thijs Alkemade (@xnyhps)"],
              "Programs": ["Apple"],
              "Bugs": ["OAuth", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account takeover in cups.mail.ru",
                    "Link": "https://medium.com/kminthein/account-takeover-in-cups-mail-ru-bdab1483f92c"
                 }
              ],
              "Authors": ["kminthein / weev3 (@kyawminthein99)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["Logic flaw", "Password reset", "Account takeover"],
              "Bounty": "1,500",
              "PublicationDate": "2020-08-03",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Look at what i found in Comodo",
                  "Link": "https://maordayanofficial.medium.com/look-at-what-i-found-in-comodo-57d62af2f263"
               }
            ],
            "Authors": ["Maor Dayan (@mord1234)"],
            "Programs": ["Comodo"],
            "Bugs": ["Stored XSS", "Reflected XSS"],
            "Bounty": "-",
            "PublicationDate": "2020-08-03",
            "AddedDate": "2022-11-11"
         },
           {
              "Links": [
                 {
                    "Title": "Banning users Race condition",
                    "Link": "https://web.archive.org/web/20200920134643/http://wisdomfreak.com/2020/08/banning-users-race-condition/"
                 }
              ],
              "Authors": ["Saddam Hussain (@wisdomfreak1)"],
              "Programs": ["-"],
              "Bugs": ["Race condition"],
              "Bounty": "-",
              "PublicationDate": "2020-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multi-factor Auth Bypass with Password Reset Function",
                    "Link": "https://vj0shii.github.io/multi-factor-auth-bypass-with-password-reset-function/"
                 }
              ],
              "Authors": ["Vaibhav Joshi (@vj0shii)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass", "Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-08-02",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "CVE-2020–9854: \"Unauthd\"",
                  "Link": "https://objective-see.org/blog/blog_0x4D.html"
               }
            ],
            "Authors": ["Ilias Morad (@A2nkF_)"],
            "Programs": ["Apple (macOS)"],
            "Bugs": ["MacOS", "Local Privilege Escalation", "SIP bypass"],
            "Bounty": "-",
            "PublicationDate": "2020-08-01",
            "AddedDate": "2023-01-06"
         },
           {
              "Links": [
                 {
                    "Title": "Refocusing in bug hunting, Bonus: An interestingly simple to test CSRF bypass",
                    "Link": "https://medium.com/bugbountywriteup/refocusing-in-bug-hunting-bonus-an-interestingly-simple-to-test-csrf-bypass-8595b3312147"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020-13379 Unauthenticated Full-Read SSRF in Grafana",
                    "Link": "https://rhynorater.github.io/CVE-2020-13379-Write-Up"
                 }
              ],
              "Authors": ["Justin Gardner (@Rhynorater)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020–9854: \"Unauthd\" - (three) logic bugs ftw!",
                    "Link": "https://objective-see.com/blog/blog_0x4D.html"
                 }
              ],
              "Authors": ["Ilias Morad (@A2nkF_)"],
              "Programs": ["Apple"],
              "Bugs": ["Local Privilege Escalation", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthd - Logic bugs FTW",
                    "Link": "https://a2nkf.github.io/unauthd_Logic_bugs_FTW/"
                 }
              ],
              "Authors": ["Ilias Morad (@A2nkF_)"],
              "Programs": ["Apple"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing OTP via reset password",
                    "Link": "https://medium.com/bugbountywriteup/bypassing-otp-via-reset-password-f004a29020c"
                 }
              ],
              "Authors": ["Ahmed Cj (@0x0Cj)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Using XAMPP and Burp Intruder when scanning for subdomains to look for interesting behaviour & code",
                    "Link": "https://medium.com/@zseano/using-xampp-and-burp-intruder-when-scanning-for-subdomains-to-look-for-interesting-behaviour-code-f24c511d15ed"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "New features means new bugs",
                    "Link": "https://medium.com/@zseano/new-features-means-new-bugs-ece4d10cdf9d"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Broken authorization", "Payment bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weird Behavior of Facebook Page FAQ Leading to Bounty from Facebook",
                    "Link": "https://medium.com/@ashokcpg/weird-behavior-of-facebook-page-faq-leading-to-bounty-from-facebook-b4984e623b38"
                 }
              ],
              "Authors": ["Ashok Chapagai (@ashokcpg)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Business Logic — Wallet Money",
                    "Link": "https://medium.com/bugbountywriteup/exploiting-business-logic-wallet-money-6a7654f4e147"
                 }
              ],
              "Authors": ["Keshav Malik (@g0t_rOoT_)"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One Click to Compromise -- Fun With ClickOnce Deployment Manifests",
                    "Link": "http://blog.redxorblue.com/2020/07/one-click-to-compromise-fun-with.html"
                 }
              ],
              "Authors": ["Dave Cossa (@G0ldenGunSec)"],
              "Programs": ["Microsoft"],
              "Bugs": ["NTLMv2 hash disclosure", "One-click execution of arbitrary .Net assemblies", "Windows"],
              "Bounty": "-",
              "PublicationDate": "2020-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zoom Security Exploit – Cracking private meeting passwords",
                    "Link": "https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/"
                 }
              ],
              "Authors": ["Tom Anthony (@TomAnthonySEO)"],
              "Programs": ["Zoom"],
              "Bugs": ["CSRF", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2020-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Noob Way Of Taking Over Accounts",
                    "Link": "https://medium.com/@mudassirsharief58/the-noob-way-of-taking-over-accounts-81aee783c064"
                 }
              ],
              "Authors": ["Mudassir Sharief"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization", "Account takeover", "Homograph attack"],
              "Bounty": "955",
              "PublicationDate": "2020-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS, RCE & HTML File Upload in same endpoint",
                    "Link": "https://sa1tama0.medium.com/xss-rce-html-file-upload-in-same-endpoint-4a03348445f4"
                 }
              ],
              "Authors": ["Tarikul Islam (@sa1tama0)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "RCE", "Unrestricted file upload"],
              "Bounty": "1,200",
              "PublicationDate": "2020-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "FFUF and my first bounty",
                    "Link": "https://medium.com/bugbountywriteup/my-first-bug-bounty-21d3203ffdb0"
                 }
              ],
              "Authors": ["Suryansh Mansharamani"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "300",
              "PublicationDate": "2020-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authorization bypass in Google’s ticketing system (Google-GUTS)",
                    "Link": "https://www.ehpus.com/post/authorization-bypass-in-google-s-ticketing-system"
                 }
              ],
              "Authors": ["Zohar Shachar"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "1,337",
              "PublicationDate": "2020-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Company’s zendesk subdomain lead to hidden access.",
                    "Link": "https://hunter-55.medium.com/introduction-fae7c8b3d16c"
                 }
              ],
              "Authors": ["himanshu pdy (@himanshu_pdy)"],
              "Programs": ["-"],
              "Bugs": ["Exposed registration page"],
              "Bounty": "-",
              "PublicationDate": "2020-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authentication Token Leads To IDOR",
                    "Link": "https://tox7cv3nom.github.io/2020/07/28/authentication-token-bypass-leads-too-idor.html"
                 }
              ],
              "Authors": ["mohit (@mohit29295572)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pre-Access to Victim’s Account via Facebook Signup",
                    "Link": "https://medium.com/@akshanshjaiswal/pre-access-to-victims-account-via-facebook-signup-60219e9e381d"
                 }
              ],
              "Authors": ["Akshansh Jaiswal (@Akshanshjaiswl)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "Account takeover"],
              "Bounty": "500",
              "PublicationDate": "2020-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug HTML Injection On Tokopedia !",
                    "Link": "https://medium.com/@jjowi/bug-html-injection-on-tokopedia-9a9b0534ceaa"
                 }
              ],
              "Authors": ["jowi"],
              "Programs": ["Tokopedia"],
              "Bugs": ["HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2020-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF + Open Redirect To Account Takeover",
                    "Link": "https://www.r29k.com/articles/bb/csrf"
                 }
              ],
              "Authors": ["R29k (@R29k_)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Open redirect", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020–9934: Bypassing the macOS Transparency, Consent, and Control (TCC) Framework for unauthorized access to sensitive user data",
                    "Link": "https://medium.com/@mattshockl/cve-2020-9934-bypassing-the-os-x-transparency-consent-and-control-tcc-framework-for-4e14806f1de8"
                 }
              ],
              "Authors": ["Matt Shockley (@mattshockl)"],
              "Programs": ["Apple"],
              "Bugs": ["MacOS", "Local Privilege Escalation", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting popular macOS apps with a single “.terminal” file.",
                    "Link": "https://medium.com/@metnew/exploiting-popular-macos-apps-with-a-single-terminal-file-f6c2efdfedaa"
                 }
              ],
              "Authors": ["Vladimir Metnew (@vladimir_metnew)"],
              "Programs": ["Internet Bug Bounty", "Slack", "Keybase", "Telegram"],
              "Bugs": ["MacOS", "File Quarantine bypass"],
              "Bounty": "750",
              "PublicationDate": "2020-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An unreproducable bug due to the load balancer, an unusual Open Redirect bug",
                    "Link": "https://tolo7010note.blogspot.com/2020/07/an-unreproducable-bug-due-to-load.html"
                 }
              ],
              "Authors": ["tololovejoi (@tolo7010)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I bypassed 2fa in a 3 years old private program!",
                    "Link": "https://shivangx01b.github.io/2fa_bypass/"
                 }
              ],
              "Authors": ["Shivangx01b (@shivangx01b)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass", "Bruteforce", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2020-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Obtained a bunch of sensitive data in just few steps — Hacking",
                    "Link": "https://medium.com/@airlanggamurthi/obtained-a-bunch-of-sensitive-data-in-just-few-steps-hacking-1a474200a8c2"
                 }
              ],
              "Authors": ["Airlangga Visnhu Murthi"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration", "Information disclosure"],
              "Bounty": "550",
              "PublicationDate": "2020-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Simple IDOR which should not be missed on dating site ;)",
                    "Link": "https://medium.com/@vneelam609/a-simple-idor-which-should-not-be-missed-on-dating-site-c500cba8e6c3"
                 }
              ],
              "Authors": ["neelam"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DNS Rebinding, The treacherous attack it can be",
                    "Link": "https://medium.com/bugbountywriteup/dns-rebinding-the-treacherous-attack-it-can-be-b367c61b4372"
                 }
              ],
              "Authors": ["Vuk Ivanovic"],
              "Programs": ["-"],
              "Bugs": ["DNS rebinding"],
              "Bounty": "-",
              "PublicationDate": "2020-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A $5000 Account Takeover",
                    "Link": "https://medium.com/@vneelam609/5000-account-takeover-bf7749746981"
                 }
              ],
              "Authors": ["neelam"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset"],
              "Bounty": "5,000",
              "PublicationDate": "2020-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting Android Application Bugs Using Android Studio.",
                    "Link": "https://co0nan.gitbook.io/wirteups/"
                 }
              ],
              "Authors": ["Tarek Mohammed (@Conan0x3)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization", "Client-side enforcement of server-side security", "Information disclosure"],
              "Bounty": "3,000",
              "PublicationDate": "2020-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HTTP Parameter Pollution - It’s Contaminated",
                    "Link": "https://medium.com/@shahjerry33/http-parameter-pollution-its-contaminated-85edc0805654"
                 }
              ],
              "Authors": ["Shrey Shah (@ShreySh43332033)"],
              "Programs": ["-"],
              "Bugs": ["HTTP parameter pollution"],
              "Bounty": "-",
              "PublicationDate": "2020-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose content of internal Facebook javascript modules ( Revisited )",
                    "Link": "https://ysamm.com/?p=487"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hack Till Your Last Breath",
                    "Link": "https://medium.com/@totmukesh/hack-till-your-last-breath-3e58f4fb1738"
                 }
              ],
              "Authors": ["mechboy / _m.u.h.e_ (@Muhe76355002)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "200",
              "PublicationDate": "2020-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Increasing reward points N number of time",
                    "Link": "https://web.archive.org/web/20220519224811/http://wisdomfreak.com/increasing-reward-points-n-number-of-time/"
                 }
              ],
              "Authors": ["Saddam Hussain (@wisdomfreak1)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Denial of Service(DoS) By Regex",
                    "Link": "https://medium.com/@ashikbhaskar94/denial-of-service-dos-by-regex-205536c8dcd0"
                 }
              ],
              "Authors": ["Ashik B"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The $1,000 worth cookie",
                    "Link": "https://medium.com/bugbountywriteup/the-1-000-worth-cookie-6cf48af08e08"
                 }
              ],
              "Authors": ["Jadek Mark (@mase289)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2020-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOS over wep application",
                    "Link": "https://medium.com/@mohamedayad_72488/dos-over-wep-application-c5176dc29035"
                 }
              ],
              "Authors": ["Mohamed Ayad"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining rate limiting for account lockout",
                    "Link": "https://web.archive.org/web/20201123204526/https://medium.com/@olisandip99/chaining-rate-limiting-for-account-lockout-6a2a7828dd24"
                 }
              ],
              "Authors": ["Sandip Oli"],
              "Programs": ["-"],
              "Bugs": ["Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2020-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "bypass user-restriction registration",
                    "Link": "https://medium.com/@mohamedayad_72488/bypass-user-restriction-registration-cbfc4eb855"
                 }
              ],
              "Authors": ["Mohamed Ayad"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2020-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I landed on my first bounty : No SPF / DMARC Record Found leading to Social Engineering Attack",
                    "Link": "https://medium.com/@fardeenahmed410/how-i-landed-on-my-first-bounty-no-spf-dmarc-record-found-2fdfea64cf52"
                 }
              ],
              "Authors": ["Fardeen Ahmed"],
              "Programs": ["Lululemon"],
              "Bugs": ["No valid SPF records", "No DMARC records"],
              "Bounty": "250",
              "PublicationDate": "2020-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unique Case for Price Manipulation | BugBounty | VAPT",
                    "Link": "https://medium.com/bugbountywriteup/unique-case-for-price-manipulation-bugbounty-vapt-df57637769cd"
                 }
              ],
              "Authors": ["Harshit Sengar (@sengarharshit1)"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2020-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Creative Android pin bypass with Race conditon",
                    "Link": "https://medium.com/@balook/creative-android-pin-bypass-with-race-conditon-63a8bc3f0e31"
                 }
              ],
              "Authors": ["Baluz (@t3chman)"],
              "Programs": ["-"],
              "Bugs": ["Race condition", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Android pin bypass with rate limiting",
                    "Link": "https://medium.com/@balook/android-pin-bypass-with-rate-limiting-a3f5dd811715"
                 }
              ],
              "Authors": ["Baluz (@t3chman)"],
              "Programs": ["-"],
              "Bugs": ["Lack of rate limiting", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Idor in google product",
                    "Link": "https://medium.com/@balook/idor-in-google-datastudio-google-com-f2fa51b763de"
                 }
              ],
              "Authors": ["Baluz (@t3chman)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "5,000",
              "PublicationDate": "2020-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I lost my followers on Medium",
                    "Link": "https://medium.com/bugbountywriteup/how-i-lost-my-followers-on-medium-9fe10e9862aa"
                 }
              ],
              "Authors": ["Florian (@fh4ntke)"],
              "Programs": ["Medium"],
              "Bugs": ["GraphQL", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Story of My first 4 digit bounty from Facebook",
                    "Link": "https://medium.com/@sudipshah_66336/the-story-of-my-first-4-digit-bounty-from-facebook-3a29830e03cd"
                 }
              ],
              "Authors": ["Sudip Shah"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I am able to see user’s sensitive data through JSON file.",
                    "Link": "https://medium.com/@saurabhsanmane06/i-am-able-to-see-users-sensitive-data-from-json-file-905e330278df"
                 }
              ],
              "Authors": ["Saurabh siddharam sanmane (@saurabhsanmane2)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Broken authorization"],
              "Bounty": "150",
              "PublicationDate": "2020-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The 3 Day Account Takeover",
                    "Link": "https://medium.com/@__mr_beast__/the-3-day-account-takeover-269b0075d526"
                 }
              ],
              "Authors": ["Mr. Beast (@__mr_beast__)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Password reset", "Account takeover", "Bruteforce", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2020-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Admin ,Editor can disclose personnel email of other editor, admin on page(who created shop)",
                    "Link": "https://medium.com/@yaala/admin-editor-can-disclose-personnel-email-of-other-editor-admin-on-page-who-created-shop-57c35ed9f9b7"
                 }
              ],
              "Authors": ["The 3 Day Account Takeover"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,000",
              "PublicationDate": "2020-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting postMessage Vulnerabilities ",
                    "Link": "https://web.archive.org/web/20211016075506/https://insight.claranet.co.uk/technical-blogs/hunting-postmessage-vulnerabilities"
                 }
              ],
              "Authors": ["Gary O'Leary-Steele (@garyoleary)", "Graham Bacon"],
              "Programs": ["Apple", "Google (Youtube)", "Adobe"],
              "Bugs": ["postMessage", "DOM XSS"],
              "Bounty": "6,267.40",
              "PublicationDate": "2020-07-14",
              "AddedDate": "2023-01-06"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Imported Libraries to Bypass WAF",
                    "Link": "https://medium.com/bugbountywriteup/exploiting-imported-libraries-to-bypass-cloudflare-waf-7aed99186c5a"
                 }
              ],
              "Authors": ["Greg Gibson"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF in import file function",
                    "Link": "https://medium.com/@rafaelrodripaz/ssrf-in-import-file-function-d0f1c6397262"
                 }
              ],
              "Authors": ["Rafael Silva"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How An API Misconfiguration Can Lead To Your Internal Company Data",
                    "Link": "https://www.secjuice.com/api-misconfiguration-data-breach/"
                 }
              ],
              "Authors": ["Me9187 (@Me9187)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Self stored xss to full account takeover",
                    "Link": "https://medium.com/@nandwanajatin25/self-stored-xss-to-full-account-takeover-fe8e71471795"
                 }
              ],
              "Authors": ["Jatin Aesthetic (@techyfreakk)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty Experience: Unvalidated Redirection Vulnerability",
                    "Link": "https://medium.com/@letssimplysecure/bug-bounty-experience-unvalidated-redirection-vulnerability-eed40d91da27"
                 }
              ],
              "Authors": ["Simply Secure"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to change victim’s password using IDN Homograph Attack",
                    "Link": "https://medium.com/bugbountywriteup/how-i-was-able-to-change-victims-password-using-idn-homograph-attack-587111843aff"
                 }
              ],
              "Authors": ["Abhishek Karle (@AbhishekKarle3)"],
              "Programs": ["-"],
              "Bugs": ["IDN homograph attack"],
              "Bounty": "600",
              "PublicationDate": "2020-07-11",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "How I hacked into a Telecom Network",
                  "Link": "https://infosecwriteups.com/how-i-hacked-into-a-telecom-network-part-1-getting-the-rce-167c2bb320e6"
               }
            ],
            "Authors": ["Harpreet Singh"],
            "Programs": ["-"],
            "Bugs": ["RCE", "Security misconfiguration", "JBoss"],
            "Bounty": "-",
            "PublicationDate": "2020-07-11",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "A tale of critical account take over",
                    "Link": "https://medium.com/@sp2417487/a-tale-of-critical-account-take-over-e1b7c180917c"
                 }
              ],
              "Authors": ["Shivam Pandey (@shivam31200)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Exposed JWT generation endpoint", "JWT"],
              "Bounty": "-",
              "PublicationDate": "2020-07-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Phone number validation bypass through url path manipulation .",
                    "Link": "https://medium.com/@ben.aymen.182/phone-number-validation-bypass-through-url-path-manipulation-c03721cf3676"
                 }
              ],
              "Authors": ["ben aymen (@ben_aymen_182)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-07-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Don’t stop at one bug $$$$",
                    "Link": "https://medium.com/bugbountywriteup/dont-stop-at-one-bug-d3c56806b5"
                 }
              ],
              "Authors": ["Dheeraj Madhukar (@Dheerajmadhukar)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "XSS", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2020-07-10",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
              {
                 "Title": "Tenda AC15 AC1900 Vulnerabilities Discovered and Exploited",
                 "Link": "https://blog.securityevaluators.com/tenda-ac1900-vulnerabilities-discovered-and-exploited-e8e26aa0bc68"
              }
             ],
            "Authors": ["Sanjana Sarda"],
            "Programs": ["Tenda"],
            "Bugs": ["CSRF", "XSS", "Hardcoded credentials", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2020-07-10",
            "AddedDate": "2022-10-21"
         },
           {
              "Links": [
                 {
                    "Title": "See whether a Hackercup Facebook participant allows recruitment contact",
                    "Link": "https://philippeharewood.com/see-whether-a-hackercup-facebook-participant-allows-recruitment-contact/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Denial-of-Service with Chrome",
                    "Link": "https://medium.com/@danlyt74/remote-denial-of-service-with-chrome-82638507a87f"
                 }
              ],
              "Authors": ["Dan Lyton"],
              "Programs": ["Google"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Application Logic to Referral Code Disclosure",
                    "Link": "https://vj0shii.github.io/exploiting-application-logic-to-referral-code-disclosure/"
                 }
              ],
              "Authors": ["Vaibhav Joshi (@vj0shii)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Global grant uri in Android 8.0-9.0 (2018 year)",
                    "Link": "https://www.vulnano.com/2020/07/global-grant-uri-in-android-80-90-2018.html"
                 }
              ],
              "Authors": ["Dzmitry Lukyanenka (@vulnano)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From N/A to Resolved For BackBlaze Android App[Hackerone Platform] Bucket Takeover",
                    "Link": "https://medium.com/@pig.wig45/from-n-a-to-resolved-for-backblaze-android-app-hackerone-platform-bucket-takeover-f817692a590"
                 }
              ],
              "Authors": ["Sahil Tikoo (@viperbluff)"],
              "Programs": ["BackBlaze"],
              "Bugs": ["Hardcoded credentials", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Journey from low to critical bug $$$",
                    "Link": "https://medium.com/@dheerajkmadhukar/journey-from-low-to-critical-bug-2ab98db2eec1"
                 }
              ],
              "Authors": ["Dheeraj Madhukar (@Dheerajmadhukar)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found 10 Remote Code Execution in 10 minutes CVE-2020–5902",
                    "Link": "https://medium.com/@b3twise/how-i-found-10-remote-code-execution-in-10-minutes-cve-2020-5902-3def1aa29e9b"
                 }
              ],
              "Authors": ["Saransh Srivastav (@malfuncti0n_)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Zoom.us Signup Flow",
                    "Link": "https://github.com/google/security-research/security/advisories/GHSA-fpgp-vrmv-v8f2"
                 }
              ],
              "Authors": ["Eduardo Vela (@sirdarckcat)"],
              "Programs": ["Zoom"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Free blockchain storage – Tale of a bug in Substrate’s FRAME runtime",
                    "Link": "https://mudit.blog/free-blockchain-storage-bug-substrate/"
                 }
              ],
              "Authors": ["Mudit Gupta (@Mudit__Gupta)"],
              "Programs": ["Parity Technologies"],
              "Bugs": ["Blockchain"],
              "Bounty": "250",
              "PublicationDate": "2020-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From . in regex to SSRF — part 3",
                    "Link": "https://xvnpw.github.io/posts/from-dot-in-regex-to-ssrf-part-3/"
                 }
              ],
              "Authors": ["Niemiec Marcin (@xvnpw)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "CRLF injection"],
              "Bounty": "400",
              "PublicationDate": "2020-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to bypass Email Confirm — P4",
                    "Link": "https://web.archive.org/web/20200821010435/https://medium.com/@Alone_Wwolf/how-i-was-able-to-bypass-email-confirm-p4-e17af66a4eb0"
                 }
              ],
              "Authors": ["Mohammed Ehssan (@alone_Wwolf)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-07-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Issue 1040755: Security: Another \"universal\" XSS via copy&paste",
                    "Link": "https://bugs.chromium.org/p/chromium/issues/detail?id=1040755"
                 }
              ],
              "Authors": ["Michał Bentkowski (@SecurityMB)"],
              "Programs": ["Google (Chromium)"],
              "Bugs": ["Universal XSS", "Browser hacking"],
              "Bounty": "2,000",
              "PublicationDate": "2020-07-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Make Featured Product in any video",
                    "Link": "https://medium.com/@yaala/make-featured-product-in-any-video-ec2bd4816ae4"
                 }
              ],
              "Authors": ["abdellah yaala (@yaalaab)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-07-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Bug: Blind SSRF Through Profile Picture Upload",
                    "Link": "https://medium.com/@swaysthinking/my-first-bug-blind-ssrf-through-profile-picture-upload-72f00fd27bc6"
                 }
              ],
              "Authors": ["swaysthinking (@swaysThinking)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-07-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE via image upload functionality",
                    "Link": "https://medium.com/@escapesequence89/rce-via-image-upload-functionality-925c902943b8"
                 }
              ],
              "Authors": ["Adwaith KS"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-07-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Case Study I - Browser Anomaly with Facebook Apps -1500$",
                    "Link": "https://blog.easysiem.com/application-security/case-study-i-browser-anomaly-with-facebook-apps-1500usd"
                 }
              ],
              "Authors": ["easySIEM (@easySIEM)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "1,500",
              "PublicationDate": "2020-07-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Taking Over Files in a chat —IDOR in Microsoft Teams",
                    "Link": "https://medium.com/@alyanwar/taking-over-files-in-a-chat-idor-in-microsoft-teams-e5289c2efd0"
                 }
              ],
              "Authors": ["Aly Anwar (@alyanwarr)"],
              "Programs": ["Microsoft"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-07-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Host Header injection to SQL injection",
                    "Link": "https://medium.com/@daoud_youssef/from-host-header-injection-to-sql-injection-e7c61a61b575"
                 }
              ],
              "Authors": ["Daoud Youssef (@daoud_youssef)"],
              "Programs": ["-"],
              "Bugs": ["Host header injection", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-07-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Why I paid 3.5K to become a TLD registrar reseller when doing bug bounty",
                    "Link": "https://medium.com/@hgreal/why-i-paid-3-5k-to-become-a-tld-registrar-reseller-when-doing-bug-bounty-d9d407911dce"
                 }
              ],
              "Authors": ["hg_real (@hgreal1)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "7,500",
              "PublicationDate": "2020-07-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BBC Bug Bounty Write-up | XSS Vulnerability",
                    "Link": "https://pethuraj.com/blog/bbc-bug-bounty-write-up-xss-vulnerability/"
                 }
              ],
              "Authors": ["Pethuraj (@Pethuraj)"],
              "Programs": ["BBC"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-07-05",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Hinge Hackerone Writeup",
                  "Link": "https://tbutler0x90.medium.com/hinge-hackerone-writeup-dd81fd410e0d"
                },
                {
                   "Title": "PDF report",
                   "Link": "https://web.archive.org/web/20210827070751/https://tbutler.org/assets/pdf/Butler,Tyler-MAID-Hinge-BBR.pdf"
                 }      
            ],
            "Authors": ["Tyle Butler (@tbutler0x90)"],
            "Programs": ["Hinge"],
            "Bugs": ["Broken Access Control"],
            "Bounty": "-",
            "PublicationDate": "2020-07-04",
            "AddedDate": "2022-09-15"
         },
           {
            "Links": [
               {
                  "Title": "Copy Drag — Paste Drop",
                  "Link": "https://medium.com/@renwa/copy-drag-paste-drop-2fd4613ad1d1"
               }
            ],
            "Authors": ["Renwa (@RenwaX23)"],
            "Programs": ["-"],
            "Bugs": ["XSS"],
            "Bounty": "-",
            "PublicationDate": "2020-07-04",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "How I got hall of fame in Microsoft",
                    "Link": "https://medium.com/@noneofyou/how-i-got-hall-of-fame-in-microsoft-9b507dec3860"
                 }
              ],
              "Authors": ["Akash basnet (@noneofyou007)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-07-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "EN | Account Takeover and Sensitive Data Leakage via CORS Misconfiguration",
                    "Link": "https://lutfumertceylan.com.tr/posts/ato-and-data-leakage-via-cors-misc/"
                 }
              ],
              "Authors": ["Lütfü Mert Ceylan (@lutfumertceylan)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration", "CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-07-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF Attack!!!",
                    "Link": "https://balapraneeth.medium.com/csrf-attack-e7bb9f3f36e1"
                 }
              ],
              "Authors": ["Bala Praneeth (@Begin_hunt)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "500",
              "PublicationDate": "2020-07-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug bounty write-up: From SSRF to $4000",
                    "Link": "https://thehackerish.com/bug-bounty-write-up-from-ssrf-to-4000/"
                 },
                 {
                    "Title": "Video",
                    "Link": "https://www.youtube.com/watch?v=apzJiaQ6a3k"
                 }
              ],
              "Authors": ["thehackerish (@thehackerish)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "RCE"],
              "Bounty": "4,000",
              "PublicationDate": "2020-07-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Writeup][Bug Bounty][Tokopedia] Manipulate Other User’s Cart and Wishlist on Tokopedia [EN]",
                    "Link": "https://fadhilthomas.github.io/post/bug-bounty-tokopedia-03/"
                 }
              ],
              "Authors": ["Muhammad Thomas Fadhila Yahya (@fadhilthomas)"],
              "Programs": ["Tokopedia"],
              "Bugs": ["IDOR"],
              "Bounty": "135",
              "PublicationDate": "2020-07-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Breaking Business Logic via Coupons — The Story of my 1st Valid Bug Bounty",
                    "Link": "https://medium.com/@ifediri/breaking-business-logic-via-coupons-the-story-of-my-1st-valid-bug-bounty-89c30ff214dc"
                 }
              ],
              "Authors": ["Dominic Ifediri (@Edi4all)"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-07-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i got 200$ with an out of the box open redirect vulnerability",
                    "Link": "https://medium.com/@tarek.tix/how-i-got-200-with-an-out-of-the-box-open-redirect-vulnerability-809e91270"
                 }
              ],
              "Authors": ["Tarek Galleze"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Token leak"],
              "Bounty": "200",
              "PublicationDate": "2020-07-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Price Tampering due to Improper checks on applying Coupon",
                    "Link": "https://vj0shii.github.io/improper-bakend-checks-food-order-site/"
                 }
              ],
              "Authors": ["Vaibhav Joshi (@vj0shii)"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-07-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Admin disclosure of Facebook verified pages/ Disclose Facebook employee assigned to help a verified page.",
                    "Link": "https://ysamm.com/?p=479"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "5,500",
              "PublicationDate": "2020-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of a 2.5k Bounty — SSRF on Zimbra Led to Dump All Credentials in Clear Text",
                    "Link": "https://infosecwriteups.com/story-of-a-2-5k-bounty-ssrf-on-zimbra-led-to-dump-all-credentials-in-clear-text-6fe826005ccc"
                 }
              ],
              "Authors": ["Yashar Shahinzadeh (@YShahinzadeh)"],
              "Programs": ["Cafebazaar"],
              "Bugs": ["SSRF"],
              "Bounty": "2,500",
              "PublicationDate": "2020-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made $1500 dollars using base64 decoder :)",
                    "Link": "https://medium.com/@sprtndilip99/how-i-made-1500-dollars-using-base64-decoder-8da1a7672b"
                 }
              ],
              "Authors": ["Dilip (@dilip_spartn)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,500",
              "PublicationDate": "2020-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Misconfigured S3 Bucket Access Controls to Critical Vulnerability",
                    "Link": "https://medium.com/bugbountywriteup/s3-bucket-misconfigured-access-controls-to-critical-vulnerability-6b535e3df9a5"
                 }
              ],
              "Authors": ["Harsh Bothra (@harshbothra_)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2020-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blast from the past: Cross Site Scripting on the AWS Console",
                    "Link": "https://embracethered.com/blog/posts/2020/aws-xss-cross-site-scripting-vulnerability/"
                 }
              ],
              "Authors": ["Johann Rehberger (wunderwuzzi23)"],
              "Programs": ["Amazon"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-07-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Art of bug bounty: a way from JS file analysis to XSS",
                    "Link": "https://research.securitum.com/art-of-bug-bounty-a-way-from-js-file-analysis-to-xss/"
                 }
              ],
              "Authors": ["Jakub Żoczek (@zoczus)"],
              "Programs": ["Verizon Media", "Tumblr"],
              "Bugs": ["XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2020-07-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ZombieVPN, Breaking That Internet Security",
                    "Link": "https://0xsha.io/posts/zombievpn-breaking-that-internet-security"
                 }
              ],
              "Authors": ["0xSha (@0xsha)"],
              "Programs": ["Bitdefender", "AnchorFree"],
              "Bugs": ["RCE", "Insecure deserialization"],
              "Bounty": "-",
              "PublicationDate": "2020-07-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS with Password Recovery Page",
                    "Link": "https://lutfumertceylan.com.tr/posts/stored-xss-with-password-recovery-page/"
                 }
              ],
              "Authors": ["Lütfü Mert Ceylan (@lutfumertceylan)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-07-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerability in Electron-based Application: Unintentionally Giving Malicious Code Room to Run",
                    "Link": "https://certik.io/blog/technology/vulnerability-electron-based-application-malicious-code-execution"
                 }
              ],
              "Authors": ["CertiK (@certik_io)"],
              "Programs": ["Symbol"],
              "Bugs": ["XSS", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-07-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of stealing mail conversation, contacts in mail.ru and myMail iOS applications via XSS",
                    "Link": "https://medium.com/kminthein/story-of-stealing-mail-conversation-contacts-in-mail-ru-and-mymail-ios-applications-via-xss-1e49c4ed560"
                 }
              ],
              "Authors": ["kminthein / weev3 (@kyawminthein99)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2020-06-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Using Inspect Element to Bypass Security restrictions | Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2020/06/30/using-inspect-element-to-bypass-security-restrictions-bug-bounty-poc/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["-"],
              "Bugs": ["Client-side enforcement of server-side security"],
              "Bounty": "-",
              "PublicationDate": "2020-06-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Patched Zoom Exploit: Altering Camera Settings via Remote SQL Injection",
                    "Link": "https://medium.com/@keegan.ryan/patched-zoom-exploit-altering-camera-settings-via-remote-sql-injection-4fdf3de8a0d"
                 }
              ],
              "Authors": ["Keegan Ryan (@inf_0_)"],
              "Programs": ["Zoom"],
              "Bugs": ["SQL injection"],
              "Bounty": "2,000",
              "PublicationDate": "2020-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "API Endpoint leads to Account Takeover In Android Application",
                    "Link": "https://web.archive.org/web/20200629033551/https://blogs.ad3sh.com/2020/06/api-endpoint-leads-to-account-takeover.html"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["-"],
              "Bugs": ["Exposed token generation endpoint", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Taking over Azure DevOps Accounts with 1 Click",
                    "Link": "https://blog.assetnote.io/2020/06/29/subdomain-takeover-to-account-takeover/"
                 }
              ],
              "Authors": ["Sean Yeoh (@seanyeoh)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Subdomain takeover", "Account takeover"],
              "Bounty": "3,000",
              "PublicationDate": "2020-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked a bank their application using it for hacking another bank company — 10K XSS",
                    "Link": "https://medium.com/@hgreal/how-i-hacked-a-bank-their-application-using-it-for-hacking-another-bank-company-10-k-xss-b9cc801a675"
                 }
              ],
              "Authors": ["hg_real (@hgreal1)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "10,000",
              "PublicationDate": "2020-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to take over any account via the Password Reset Functionality.",
                    "Link": "https://medium.com/@fatnassifiras45/how-i-was-able-to-take-over-any-account-via-the-password-reset-functionality-ef1659f8b481"
                 }
              ],
              "Authors": ["Firas Fatnassi (@Fatnass1F1ras)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An attempt to escalate a low-impact hidden input XSS",
                    "Link": "https://officialaimm.medium.com/an-attempt-to-escalate-a-low-impact-hidden-input-xss-9f4b9c88f19c"
                 }
              ],
              "Authors": ["Ayush Ojha (@officialaimm)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-06-28",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Bypassing file upload filter by source code review in Bolt CMS",
                  "Link": "https://blog.stazot.com/boltcms-file-upload-bypass/"
               }
            ],
            "Authors": ["Sivanesh Ashok (@sivaneshashok)"],
            "Programs": ["Bolt CMS"],
            "Bugs": ["RCE", "Unrestricted file upload", "Path traversal", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2020-06-27",
            "AddedDate": "2023-02-26"
         },
           {
              "Links": [
                 {
                    "Title": "How I Bypassed open redirect and i have get reward from yandex",
                    "Link": "https://medium.com/@minometidji/how-i-bypassed-open-redirect-and-i-have-get-reward-from-yandex-5df5de836718"
                 }
              ],
              "Authors": ["Mohamed Lakhdar Metidji (@minometidjii)"],
              "Programs": ["Yandex"],
              "Bugs": ["Open redirect"],
              "Bounty": "100",
              "PublicationDate": "2020-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i hacked worldwide ZOOM users",
                    "Link": "https://web.archive.org/web/20200627125016/https://medium.com/@s3c/hacked-worldwide-zoom-users-fceb31868c2d"
                 }
              ],
              "Authors": ["s3c (@s3c_krd)"],
              "Programs": ["Zoom"],
              "Bugs": ["OAuth", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Create hidden comment by blocking an Admin: Facebook Bug Bounty 2020",
                    "Link": "https://web.archive.org/web/20200626065913/https://medium.com/@saugatpokharel/able-to-create-hidden-comment-by-blocking-an-admin-facebook-bug-bounty-2020-c62bd10712f"
                 }
              ],
              "Authors": ["Saugat Pokharel (@saugatscript)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-06-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty in Lockdown (SQLi and Business Logic)",
                    "Link": "https://medium.com/@abhishake100/bug-bounty-in-lockdown-sqli-and-business-logic-98ab8cb5f661"
                 }
              ],
              "Authors": ["Abhishek Yadav (@abhishake100)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "All About Getting First Bounty with IDOR",
                    "Link": "https://medium.com/bugbountywriteup/all-about-getting-first-bounty-with-idor-849db2828c8"
                 }
              ],
              "Authors": ["Mukul Trivedi (@M0hn1sh)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-06-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Bitdefender Antivirus: RCE from any website",
                    "Link": "https://palant.info/2020/06/22/exploiting-bitdefender-antivirus-rce-from-any-website/"
                 }
              ],
              "Authors": ["Wladimir Palant (@WPalant)"],
              "Programs": ["Bitdefender"],
              "Bugs": ["RCE", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A tale of my first ever full SSRF bug",
                    "Link": "https://medium.com/@mase289/a-tale-of-my-first-ever-full-ssrf-bug-4fe71a76e9c4"
                 }
              ],
              "Authors": ["Jadek Mark (@mase289)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "1,000",
              "PublicationDate": "2020-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leveraging an SSRF to leak a secret API key",
                    "Link": "https://jub0bs.com/posts/2020-06-23-ssrf/"
                 }
              ],
              "Authors": ["Julien Cretel (@jub0bs)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "1,000",
              "PublicationDate": "2020-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "API Token Hijacking Through Clickjacking",
                    "Link": "https://medium.com/bugbountywriteup/api-token-hijacking-through-clickjacking-2e36c02e6c48"
                 }
              ],
              "Authors": ["DarkLotus (@darklotuskdb)"],
              "Programs": ["-"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2020-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to chain bugs and gain access to internal okta instance",
                    "Link": "https://medium.com/@eldeebxboy/how-i-was-able-to-chain-bugs-and-gain-access-to-internal-okta-instance-f2da9ab71367"
                 }
              ],
              "Authors": ["Mmohammed Eldeeb (@malcolmx0x)"],
              "Programs": ["-"],
              "Bugs": ["Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2020-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "It took me only 5 minutes to find an RCE on Bentley",
                    "Link": "https://medium.com/@divyanshsharma2401/it-took-me-only-5-minutes-to-find-an-rce-on-bentley-38265da15788"
                 }
              ],
              "Authors": ["Divyansh Sharma"],
              "Programs": ["Bentley"],
              "Bugs": ["RCE", "Weak credentials"],
              "Bounty": "300",
              "PublicationDate": "2020-06-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Simple story of some complicated XSS on Facebook",
                    "Link": "https://medium.com/@win3zz/simple-story-of-some-complicated-xss-on-facebook-8a9c0d80969d"
                 }
              ],
              "Authors": ["Bipin Jitiya (@win3zz)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-06-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass 2FA like a Boss",
                    "Link": "https://medium.com/bugbountywriteup/bypass-2fa-like-a-boss-378787707ba"
                 }
              ],
              "Authors": ["Seqrity (@seQrity)"],
              "Programs": ["-"],
              "Bugs": ["Lack of rate limiting", "Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2020-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How did i find information Disclosure on Facebook-Writeup",
                    "Link": "https://alaa.blog/2020/06/how-did-i-found-information-disclosure-on-facebook-writeup/"
                 }
              ],
              "Authors": ["Alaa Abdulridha (@Madrid89001310)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,500",
              "PublicationDate": "2020-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Starbucks and Accessing Nearly 100 Million Customer Records",
                    "Link": "https://samcurry.net/hacking-starbucks/"
                 }
              ],
              "Authors": ["Sam Curry (@samwcyo)"],
              "Programs": ["Starbucks"],
              "Bugs": ["Path traversal"],
              "Bounty": "4,000",
              "PublicationDate": "2020-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Recon to Bypassing MFA Implementation in OWA by Using EWS Misconfiguration",
                    "Link": "http://www.firstsight.me/2020/06/from-recon-to-bypassing-mfa-implementation-in-owa-by-using-ews-misconfiguration/"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "2FA / MFA bypass"],
              "Bounty": "500",
              "PublicationDate": "2020-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One Token to leak them all : The story of a $8000 NPM_TOKEN",
                    "Link": "https://medium.com/@aseem.shrey/one-token-to-leak-them-all-the-story-of-a-8000-npm-token-79b13af182a3"
                 }
              ],
              "Authors": ["Aseem Shrey (@AseemShrey)"],
              "Programs": ["Google"],
              "Bugs": ["Information disclosure"],
              "Bounty": "8,000",
              "PublicationDate": "2020-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Replying on LiveStream leading to Page Admin Disclosure: Facebook Bug Bounty",
                    "Link": "https://web.archive.org/web/20200814031536/https://medium.com/@saugatpokharel/replying-on-livestream-leading-to-page-admin-disclosure-facebook-bug-bounty-b24792a19638"
                 }
              ],
              "Authors": ["Saugat Pokharel (@saugatscript)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-06-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hackerone Bug Bounty Report: Hinge",
                    "Link": "https://tylerbutler.io/hackerone-hinge/"
                 }
              ],
              "Authors": ["Tyle Butler (@tbutler0x90)"],
              "Programs": ["Hinge"],
              "Bugs": ["Information disclosure"],
              "Bounty": "250",
              "PublicationDate": "2020-06-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A subtle stored-XSS in WordPress core",
                    "Link": "https://pentest.co.uk/labs/research/subtle-stored-xss-wordpress-core/"
                 }
              ],
              "Authors": ["Sam Thomas (@_s_n_t)"],
              "Programs": ["WordPress"],
              "Bugs": ["Stored XSS", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug bounty bout report 0x01 - WebRTC edition",
                    "Link": "https://www.rtcsec.com/post/2020/06/03-bug-bounty-bout-0x01-webrtc-edition/"
                 }
              ],
              "Authors": ["Enable Security (@enablesecurity)"],
              "Programs": ["-"],
              "Bugs": ["WebRTC", "TURN", "Outdated component with a known vulnerability", "DoS", "RCE", "Default credentials", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made more than $30K with Jolokia CVEs",
                    "Link": "https://wss.sh/en/blog/how-i-made-more-than-30k-with-jolokia-cves/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "RCE", "Information disclosure"],
              "Bounty": "33,500",
              "PublicationDate": "2020-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I managed to Escalate privilege as admin",
                    "Link": "https://medium.com/@abireena2002/how-i-managed-to-escalate-privilege-as-admin-94b8dc910d14"
                 }
              ],
              "Authors": ["Abisheik Magesh (@AbisheikMagesh)"],
              "Programs": ["-"],
              "Bugs": ["Lack of rate limiting", "Bruteforce", "Weak credentials"],
              "Bounty": "-",
              "PublicationDate": "2020-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to buy t-shirt for €1 — Payment Price Manipulation",
                    "Link": "https://medium.com/@muztahidultanim/how-i-was-able-to-buy-t-shirt-for-1-payment-price-manipulation-36b4d6a30034"
                 }
              ],
              "Authors": ["Muztahidul Tanim (@TheMuztahidul)"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering"],
              "Bounty": "2,000",
              "PublicationDate": "2020-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "All *.intercom.help subdomains vulnerable to Subdomain Takeover from intercom Service",
                    "Link": "https://web.archive.org/web/20201123204430/https://www.mohamedharon.com/2020/06/all-intercomhelp-subdomains-vulnerable.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Intercom"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SMTP Injection in Gsuite",
                    "Link": "https://www.ehpus.com/post/smtp-injection-in-gsuite"
                 }
              ],
              "Authors": ["Zohar Shachar"],
              "Programs": ["Google"],
              "Bugs": ["SMTP injection"],
              "Bounty": "3,133.7",
              "PublicationDate": "2020-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected User Input == XSS!",
                    "Link": "https://medium.com/bugbountywriteup/reflected-user-input-xss-c3e681710e74"
                 }
              ],
              "Authors": ["Silent Bronco (@silentbronco)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "50",
              "PublicationDate": "2020-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business logic flaw in the invitation system allows to Takeover any account at a private company",
                    "Link": "https://medium.com/bugbountywriteup/business-logic-flaw-in-invitation-system-allows-to-takeover-any-account-at-private-company-daaf898966b0"
                 }
              ],
              "Authors": ["Daniel V. (@d4niel_v)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Another \"Fappening\" on the Horizon?",
                    "Link": "https://www.sociosploit.com/2020/06/another-fappening-on-horizon.html"
                 }
              ],
              "Authors": ["Sociosploit"],
              "Programs": ["Apple"],
              "Bugs": ["Account takeover", "Phishing"],
              "Bounty": "-",
              "PublicationDate": "2020-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to Secure AWS ServerLess Lambda from ReDoS(Regular Expression Denial-of-Service) & Resultant Financial Impact",
                    "Link": "https://medium.com/@ddigvijay29/how-to-secure-aws-serverless-lambda-from-redos-regular-expression-denial-of-service-resultant-12f0401118cd"
                 }
              ],
              "Authors": ["Ddigvijay (@itsdig)"],
              "Programs": ["-"],
              "Bugs": ["ReDoS"],
              "Bounty": "-",
              "PublicationDate": "2020-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege escalation in Partners Portal to Admin access",
                    "Link": "https://ysamm.com/?p=460"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose internal files related to testing of some Facebook tools",
                    "Link": "https://ysamm.com/?p=450"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose the Instagram account linked to a Facebook user account or page",
                    "Link": "https://ysamm.com/?p=455"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Internal directories enumeration in www",
                    "Link": "https://ysamm.com/?p=458"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Internal directories enumeration"],
              "Bounty": "-",
              "PublicationDate": "2020-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RACE Condition vulnerability found in bug-bounty program",
                    "Link": "https://medium.com/@pravinponnusamy/race-condition-vulnerability-found-in-bug-bounty-program-573260454c43"
                 }
              ],
              "Authors": ["Pravinrp"],
              "Programs": ["-"],
              "Bugs": ["Race condition"],
              "Bounty": "-",
              "PublicationDate": "2020-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover via OTP Bruteforce (Apigee API)",
                    "Link": "https://medium.com/@vishnu0002/account-takeover-via-otp-bruteforce-apigee-api-9b5481c642df"
                 }
              ],
              "Authors": ["Vishnuraj"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass", "Bruteforce", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2020-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DoS and BugBounties :A series of DoS attacks on HackerOne",
                    "Link": "https://medium.com/@NinadMishra/dos-and-bugbounties-a-series-of-dos-attacks-on-hackerone-9c8316e192c9"
                 }
              ],
              "Authors": ["Ninad Mishra (@iamr000t)"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "500",
              "PublicationDate": "2020-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Let’s Bypass CSRF Protection & Password Confirmation to Takeover Victim Accounts :D",
                    "Link": "https://medium.com/bugbountywriteup/lets-bypass-csrf-protection-password-confirmation-to-takeover-victim-accounts-d-4a21297847ff"
                 }
              ],
              "Authors": ["Harsh Bothra (@harshbothra_)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Race Conditions - Exploring the Possibilities",
                    "Link": "https://pandaonair.com/2020/06/11/race-conditions-exploring-the-possibilities.html"
                 }
              ],
              "Authors": ["Milind Purswani (@MilindPurswani)"],
              "Programs": ["Reddit"],
              "Bugs": ["Race condition"],
              "Bounty": "-",
              "PublicationDate": "2020-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HUNT for SQL Injection- The Smart Way!",
                    "Link": "https://medium.com/@mudassirsharief58/hunt-for-sql-injection-the-smart-way-db85243a4e90"
                 }
              ],
              "Authors": ["Mudassir Sharief"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Frustrating XSS",
                    "Link": "https://medium.com/@__mr_beast__/the-frustrating-xss-33607894a071"
                 }
              ],
              "Authors": ["Mr. Beast (@__mr_beast__)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Guest Blog: From File Upload to RCE",
                    "Link": "https://www.synack.com/blog/guest-blog-from-file-upload-to-rce/"
                 }
              ],
              "Authors": ["Lukasz Wierzbicki (@v13rs8a)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation by Changing HTTP Response (Admin Access)",
                    "Link": "https://medium.com/@bachrudinashari/privilege-escalation-by-changing-http-response-admin-access-5e67c44713f6"
                 }
              ],
              "Authors": ["Bachrudin Ashari Pujakusuma (@Bachrudinashari)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "563",
              "PublicationDate": "2020-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Utilizing Lockdown: Blind Sqli leads to Account Takeover & Data Extraction",
                    "Link": "https://medium.com/@shakti.gtp/utilizing-lockdown-blind-sqli-leads-to-account-takeover-data-extraction-3705ce8bdb62"
                 }
              ],
              "Authors": ["Shakti Mohanty (@3ncryptSaan)"],
              "Programs": ["-"],
              "Bugs": ["Blind SQL injection", "Account takeover"],
              "Bounty": "1,400",
              "PublicationDate": "2020-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The “P5” Link Injection Story",
                    "Link": "https://medium.com/@silentbronco/the-p5-link-injection-story-2632e61f62b7"
                 }
              ],
              "Authors": ["Silent Bronco (@silentbronco)"],
              "Programs": ["-"],
              "Bugs": ["Hyperlink injection"],
              "Bounty": "-",
              "PublicationDate": "2020-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing Microsoft Teams rate limiting for DDoS",
                    "Link": "https://medium.com/swlh/abusing-microsoft-teams-rate-limiting-for-ddos-a8238958376a"
                 }
              ],
              "Authors": ["Omayr Zanata (@omayrzanata)"],
              "Programs": ["Microsoft"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cmd Hijack - a command/argument confusion with path traversal in cmd.exe",
                    "Link": "https://hackingiscool.pl/cmdhijack-command-argument-confusion-with-path-traversal-in-cmd-exe/"
                 }
              ],
              "Authors": ["Julian Horoszkiewicz"],
              "Programs": ["Microsoft"],
              "Bugs": ["OS command injection", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2020-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Accidental RCE",
                    "Link": "https://medium.com/@__mr_beast__/the-accidental-rce-7ceef9cee179"
                 }
              ],
              "Authors": ["Mr. Beast (@__mr_beast__)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "4,800",
              "PublicationDate": "2020-06-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Local Privilege Escalation Discovered in VMware Fusion",
                    "Link": "https://www.cyberonesecurity.com/blog/local-privilege-escalation-discovered-in-vmware-fusion"
                 }
              ],
              "Authors": ["Rich Mirch (@0xm1rch)", "Jeff Ball (@jeffball55)"],
              "Programs": ["VMware"],
              "Bugs": ["Local Privilege Escalation", "MacOS"],
              "Bounty": "-",
              "PublicationDate": "2020-06-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This is fine 🐶",
                    "Link": "https://medium.com/@ricardoiramar/this-is-fine-6e032f497b8f"
                 }
              ],
              "Authors": ["Ricardo Iramar dos Santos (@ricardo_iramar)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-06-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Different host header injection worth 2k",
                    "Link": "https://medium.com/@imunissar786/awesome-host-header-injection-worth-2k-a7e5be1dbb1d"
                 }
              ],
              "Authors": ["Imran Nissar (@Imrannissar3)"],
              "Programs": ["-"],
              "Bugs": ["Host header injection"],
              "Bounty": "2,000",
              "PublicationDate": "2020-06-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i earned $500 from google by change one character .",
                    "Link": "https://medium.com/@odayalhalbe1/how-i-earned-500-from-google-by-change-one-character-8350d2b618e5"
                 }
              ],
              "Authors": ["Oday Alhalbe"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "500",
              "PublicationDate": "2020-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS to Database Credential Leakage & Database Access — Story of total luck!",
                    "Link": "https://medium.com/bugbountywriteup/xss-to-database-credential-leakage-database-access-story-of-total-luck-77c990be8ab2"
                 }
              ],
              "Authors": ["Harsh Bothra (@harshbothra_)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From 3,99 to 1,650 USD (Part I) – Simple Vertical Privilege Escalation by Changing HTTP Response",
                    "Link": "http://www.firstsight.me/2020/06/from-399-to-1650-usd-part-i-simple-vertical-privilege-escalation-by-changing-http-response/"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "1,000",
              "PublicationDate": "2020-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Information exposed due to misconfigured Service-now ITSM instances",
                    "Link": "https://medium.com/@th3g3nt3l/multiple-information-exposed-due-to-misconfigured-service-now-itsm-instances-de7a303ebd56"
                 }
              ],
              "Authors": ["Th3G3nt3lman (@Th3G3nt3lman)"],
              "Programs": ["-"],
              "Bugs": ["Missing authentication", "Information disclosure"],
              "Bounty": "30,000",
              "PublicationDate": "2020-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account takeover via postMessage",
                    "Link": "https://yxw21.github.io/2020/06/05/Account-Takeover-Via-PostMessage/"
                 }
              ],
              "Authors": ["socket (@yxw21)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "postMessage"],
              "Bounty": "1,500",
              "PublicationDate": "2020-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Local file read via XSS using PDF generate functionality",
                    "Link": "https://echopwn.com/local-file-read-via-xss-using-pdf-generate-functionality/"
                 }
              ],
              "Authors": ["Sanjay Singh Jhala (@lordjerry0x01)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2020-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of Blind SQL with a typo error.",
                    "Link": "https://medium.com/@amyrahm786/story-of-blind-sql-with-a-typo-error-43a21913c8d"
                 }
              ],
              "Authors": ["Amyrahm (@Amyrahm11)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[IDOR] Delete saved credit cards from any Business Manager Account — Facebook Bug Bounty",
                    "Link": "https://medium.com/@rohitcoder/idor-delete-saved-credit-cards-from-any-business-manager-account-f28c773982eb"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Three Privilege Escalation Bugs in Google Cloud Platform’s OS Login",
                    "Link": "https://initblog.com/2020/oslogin-privesc/"
                 }
              ],
              "Authors": ["initstring (@init_string)"],
              "Programs": ["Google"],
              "Bugs": ["Local Privilege Escalation", "Cloud"],
              "Bounty": "-",
              "PublicationDate": "2020-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Another image removal vulnerability on Facebook",
                    "Link": "https://blog.darabi.me/2020/06/image-removal-vulnerability-on-facebook.html"
                 }
              ],
              "Authors": ["Pouya Darabi (@Pouyadarabi)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "10,000",
              "PublicationDate": "2020-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation in Google Cloud Platform's OS Login",
                    "Link": "https://gitlab.com/gitlab-com/gl-security/gl-redteam/red-team-tech-notes/-/tree/master/oslogin-privesc-june-2020"
                 }
              ],
              "Authors": ["Chris Moberly (@init_string)"],
              "Programs": ["Google"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got my first big bounty payout with Tesla",
                    "Link": "https://medium.com/heck-the-packet/how-i-got-my-first-big-bounty-payout-with-tesla-8d28b520162d"
                 }
              ],
              "Authors": ["CJ Fairhead (@xyantix)"],
              "Programs": ["Tesla"],
              "Bugs": ["Information disclosure"],
              "Bounty": "5,000",
              "PublicationDate": "2020-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From CRLF to Account Takeover",
                    "Link": "https://medium.com/@valeriyshevchenko/from-crlf-to-account-takeover-a94d7aa0d74e"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["-"],
              "Bugs": ["CRLF injection", "HTTP response splitting", "Reflected XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-06-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IP-in-IP protocol routes arbitrary traffic by default",
                    "Link": "https://kb.cert.org/vuls/id/636397"
                 },
                 {
                    "Title": "HackerOne report",
                    "Link": "https://hackerone.com/reports/893922"
                 }
              ],
              "Authors": ["yannayl (@Yannayli)"],
              "Programs": ["Internet Bug Bounty"],
              "Bugs": ["DoS", "Spoofing"],
              "Bounty": "750",
              "PublicationDate": "2020-06-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Curious Case of Copy & Paste – on risks of pasting arbitrary content in browsers",
                    "Link": "https://research.securitum.com/the-curious-case-of-copy-paste/"
                 }
              ],
              "Authors": ["Michał Bentkowski (@SecurityMB)"],
              "Programs": ["Google", "Mozilla"],
              "Bugs": ["XSS"],
              "Bounty": "30,000",
              "PublicationDate": "2020-06-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Double URL-encoded XSS",
                    "Link": "https://web.archive.org/web/20200807155244/https://vict0ni.me/double-url-encoding-xss/"
                 }
              ],
              "Authors": ["vict0ni (@vict0ni)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-06-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "When it’s not only about a Kubernetes CVE…",
                    "Link": "https://medium.com/@BreizhZeroDayHunters/when-its-not-only-about-a-kubernetes-cve-8f6b448eafa8"
                 }
              ],
              "Authors": ["Reever Zax (@ReeverZax)", "Hach (@__hach_)"],
              "Programs": ["Microsoft"],
              "Bugs": ["SSRF"],
              "Bounty": "40,000",
              "PublicationDate": "2020-06-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Information disclosure and reflected XSS on Tokopedia",
                    "Link": "https://medium.com/bugbountywriteup/information-disclosure-and-reflected-xss-on-tokopedia-1b3a00ec64c6"
                 }
              ],
              "Authors": ["wis4nggeni"],
              "Programs": ["Tokopedia"],
              "Bugs": ["Reflected XSS", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I leveraged an interesting CSRF vulnerability to turn self XSS into a persistent attack?",
                    "Link": "https://medium.com/bugbountywriteup/how-i-leveraged-an-interesting-csrf-vulnerability-to-turn-self-xss-into-a-persistent-attack-b780824042d2"
                 }
              ],
              "Authors": ["Akash Methani (@0xAkash)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made $31500 by submitting a bug to Facebook",
                    "Link": "https://medium.com/@win3zz/how-i-made-31500-by-submitting-a-bug-to-facebook-d31bb046e204"
                 }
              ],
              "Authors": ["Bipin Jitiya (@win3zz)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["SSRF"],
              "Bounty": "31,500",
              "PublicationDate": "2020-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "h1{Error based XXE - bug bounty writeup}",
                    "Link": "https://f4d3.io/xxe_wild/"
                 }
              ],
              "Authors": ["f4d3 (@f4d3_cl)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2020-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting on ASPX Application For P1's [Unauthenticated SOAP,RCE, Info Disclosure]",
                    "Link": "https://elmahdi.tistory.com/3"
                 }
              ],
              "Authors": ["ElMahdi Mrhassel (@ElMrhassel)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Information disclosure", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weird “Subdomain Take Over” pattern of Amazon S3",
                    "Link": "https://medium.com/@secureITmania/weird-subdomain-take-over-pattern-of-amazon-s3-75165ab2e883"
                 }
              ],
              "Authors": ["Simgamsetti Manikanta (@zaheckmania)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The story of My First $xxx Bug Bounty From Facebook",
                    "Link": "https://medium.com/@sudipshah_66336/the-story-of-my-first-xxx-bug-bounty-from-facebook-565a212c94ad"
                 }
              ],
              "Authors": ["Sudip Shah"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cross-site scripting: The power of the hidden parameters.",
                    "Link": "https://medium.com/@kassihmouhssine/cross-site-scripting-the-power-of-the-hidden-parameters-259a4d2c4c09"
                 }
              ],
              "Authors": ["Kassih Mouhssine (@KassihMouhssine)"],
              "Programs": ["Sony"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zero-day in Sign in with Apple",
                    "Link": "https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-apple/"
                 }
              ],
              "Authors": ["Bhavuk Jain (@bhavukjain1)"],
              "Programs": ["Apple"],
              "Bugs": ["Account takeover"],
              "Bounty": "100,000",
              "PublicationDate": "2020-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft's first bug",
                    "Link": "https://ezqelusia.blogspot.com/2020/05/microsofts-first-bug.html"
                 }
              ],
              "Authors": ["Lê Hữu Quang Linh (@linhlhq)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Memory corruption", "File format vulnerability"],
              "Bounty": "-",
              "PublicationDate": "2020-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weak Cryptography Leads To Open Redirect",
                    "Link": "https://medium.com/bugbountywriteup/weak-cryptography-leads-to-open-redirect-3fe052c12995"
                 }
              ],
              "Authors": ["DarkLotus (@darklotuskdb)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Analysis and Discovery of CVE-2020-13693",
                    "Link": "https://blog.raphael.karger.is/articles/2020-05/CVE-2020-13693"
                 }
              ],
              "Authors": ["Raphael Karger (@pwnszn)"],
              "Programs": ["BBPress"],
              "Bugs": ["Privilege escalation", "Security code review"],
              "Bounty": "-",
              "PublicationDate": "2020-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Expense Report resulted in a Server-Side Request Forgery (SSRF) on Lyft",
                    "Link": "https://www.nahamsec.com/posts/my-expense-report-resulted-in-a-server-side-request-forgery-ssrf-on-lyft"
                 }
              ],
              "Authors": ["Ben Sadeghipour (@nahamsec)", "Serafina (Sera) Tonin Brocious (@daeken)"],
              "Programs": ["Lyft"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR in session cookie leading to Mass Account Takeover",
                    "Link": "https://zonduu.medium.com/idor-in-session-cookie-leading-to-mass-account-takeover-d815ff3732d5"
                 }
              ],
              "Authors": ["Zonduhackerone (@zonduu1)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "2,000",
              "PublicationDate": "2020-05-29",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Exploring macOS Calendar Alerts: Part 1 – Attempting to execute code",
                  "Link": "https://research.nccgroup.com/2020/05/05/exploring-macos-calendar-alerts-part-1-attempting-to-execute-code/"
               },
               {
                  "Title": "Part 2 – Exfiltrating data (CVE-2020-3882)",
                  "Link": "https://research.nccgroup.com/2020/05/28/exploring-macos-calendar-alerts-part-2-exfiltrating-data-cve-2020-3882/"
               }
            ],
            "Authors": ["Andy Grant"],
            "Programs": ["Apple"],
            "Bugs": ["Information disclosure"],
            "Bounty": "-",
            "PublicationDate": "2020-05-28",
            "AddedDate": "2022-12-12"
         },
           {
              "Links": [
                 {
                    "Title": "XSS Stored On Messages In [ Outlook Web — Outlook Android App ]",
                    "Link": "https://elmahdi.tistory.com/m/2"
                 }
              ],
              "Authors": ["ElMahdi Mrhassel (@ElMrhassel)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing WAF to perform XSS",
                    "Link": "https://medium.com/bugbountywriteup/bypassing-waf-to-perform-xss-2d2f5a4367f3"
                 }
              ],
              "Authors": ["Kleiton Kurti (@kleiton0x7e)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to see Private Video Uploader Via Facebook Rights Manager.[Responsible Disclosure]",
                    "Link": "https://medium.com/@kishoretk/how-i-was-able-to-see-identity-of-a-private-video-up-loader-via-rights-manager-responsible-39d996517b6e"
                 }
              ],
              "Authors": ["Kishore TK (@kishoretk_off)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Long Overdue Write-up: How I got into the Oppo Hall of Fame",
                    "Link": "https://shibinbshaji.space/bug-bounty/oppo-bugbounty-writeup/"
                 }
              ],
              "Authors": ["Shibin B. Shaji (@shibinbshaji06)"],
              "Programs": ["oppo"],
              "Bugs": ["Login screen bypass", "Authentication bypass"],
              "Bounty": "133",
              "PublicationDate": "2020-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Clickjacking to Account Takeover",
                    "Link": "https://medium.com/@abhishake100/clickjacking-to-account-takeover-97e286f26b95"
                 }
              ],
              "Authors": ["Abhishek Yadav (@abhishake100)"],
              "Programs": ["-"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2020-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "iOS Outlook Stored XSS Write-Up($3000)",
                    "Link": "https://medium.com/@kminthein/ios-outlook-stored-xss-write-up-ce34d7da192b"
                 }
              ],
              "Authors": ["kminthein / weev3 (@kyawminthein99)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "3,000",
              "PublicationDate": "2020-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in Microsoft outlook",
                    "Link": "https://medium.com/@kminthein/stored-xss-in-microsoft-outlook-ebce9ff9e45b"
                 }
              ],
              "Authors": ["kminthein / weev3 (@kyawminthein99)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in Yahoo mail IOS app($3500)",
                    "Link": "https://medium.com/@kminthein/stored-xss-in-yahoo-mail-ios-app-3500-6b40e86358b9"
                 }
              ],
              "Authors": ["kminthein / weev3 (@kyawminthein99)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Stored XSS"],
              "Bounty": "3,500",
              "PublicationDate": "2020-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Android : SOP Bypass to steal system files.",
                    "Link": "https://servicenger.com/blog/mobile/android-sop-bypass-to-steal-system-files/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["-"],
              "Bugs": ["SOP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Hunting Stories: Schneider Electric & The Andover Continuum Web.Client",
                    "Link": "https://www.cyberark.com/resources/threat-research-blog/bug-hunting-stories-schneider-electric-the-andover-continuum-web-client"
                 }
              ],
              "Authors": ["Niv Levy (@restr1ct3d)"],
              "Programs": ["Uber"],
              "Bugs": ["XXE", "Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining an IDOR with a business-logic error to achieve critical impact",
                    "Link": "https://jub0bs.com/posts/2020-05-26-idor/"
                 }
              ],
              "Authors": ["Julien Cretel (@jub0bs)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-05-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber",
                    "Link": "https://andrei-abakumov.medium.com/how-dangerous-is-request-splitting-a-vulnerability-in-golang-or-how-we-found-the-rce-in-portainer-7339ba24c871"
                 }
              ],
              "Authors": ["Andrey Abakumov (@andrewaeva)"],
              "Programs": ["Uber"],
              "Bugs": ["HTTP request splitting", "SSRF", "CRLF injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-05-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story About OTP Bypass To Stored XSS",
                    "Link": "https://medium.com/@pallabjyoti218/story-about-otp-bypass-to-stored-xss-81bfd735c709"
                 }
              ],
              "Authors": ["PJ Borah (@PJBorah1)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Source code reading helped me find an IDOR",
                    "Link": "http://hack4bounty.com/how-source-code-reading-helped-me-find-an-idor/"
                 }
              ],
              "Authors": ["Sanjay Verdu (@codersanjay)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Bug Bounty — 2 Factor Authentication Bypass",
                    "Link": "https://medium.com/@talatmehmood1995/my-first-bug-bounty-2-factor-authentication-bypass-b034812c8243"
                 }
              ],
              "Authors": ["Talatmehmood"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass"],
              "Bounty": "100",
              "PublicationDate": "2020-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Parsing the DOM elements of Other pages via XSS: A Bug Bounty Story",
                    "Link": "https://medium.com/@ciph3r7r0ll/parsing-the-dom-elements-of-other-pages-via-xss-bug-bounty-story-46d517e6711d"
                 }
              ],
              "Authors": ["Mandeep Jadon (@1337tr0lls)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE in Google Cloud Deployment Manager",
                    "Link": "https://www.ezequiel.tech/2020/05/rce-in-cloud-dm.html"
                 }
              ],
              "Authors": ["Ezequiel Pereira (@epereiralopez)"],
              "Programs": ["Google"],
              "Bugs": ["SSRF", "RCE"],
              "Bounty": "31,337",
              "PublicationDate": "2020-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Message Request inbox",
                    "Link": "https://medium.com/@yaala/bypassing-message-request-inbox-cf54f859dd25"
                 }
              ],
              "Authors": ["abdellah yaala (@yaalaab)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Change any link at https://fbwat.ch/",
                    "Link": "https://philippeharewood.com/change-any-link-at-https-fbwat-ch/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2020-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Become member of close & public group",
                    "Link": "https://medium.com/@yaala/become-member-of-close-public-group-9564c359c050"
                 }
              ],
              "Authors": ["abdellah yaala (@yaalaab)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "7,500",
              "PublicationDate": "2020-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Easy bounties with subdomain discovery - Using Project Sonar for bug bounty",
                    "Link": "https://torbencapiau.be/?p=106"
                 }
              ],
              "Authors": ["Torben Capiau (@TorbenCapiau)"],
              "Programs": ["Bpost"],
              "Bugs": ["Broken Access Control", "Broken authorization"],
              "Bounty": "100",
              "PublicationDate": "2020-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got 200$ in 5 minutes – Sensitive data leak",
                    "Link": "http://hack4bounty.com/how-i-got-200-in-5-minutes-%f0%9f%98%9c-sensitive-data-leak-%f0%9f%98%9c/"
                 }
              ],
              "Authors": ["Sanjay Verdu (@codersanjay)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "200",
              "PublicationDate": "2020-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Teradici and CVE-2020-10965: An issue of routing.",
                    "Link": "https://healdb.tech/blog/teradici.html"
                 }
              ],
              "Authors": ["Benjamin Heald (@heald_ben)"],
              "Programs": ["Teradici"],
              "Bugs": ["Missing authentication"],
              "Bounty": "1,350",
              "PublicationDate": "2020-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "FB & Messenger for iOS : Address Bar spoofing using data uri",
                    "Link": "https://servicenger.com/blog/mobile/facebook-for-ios-address-bar-spoofing/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Address Bar Spoofing", "URL spoofing"],
              "Bounty": "3,000",
              "PublicationDate": "2020-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2020–1088 — Yet another arbitrary delete EoP",
                    "Link": "https://medium.com/csis-techblog/cve-2020-1088-yet-another-arbitrary-delete-eop-a00b97d8c3e2"
                 }
              ],
              "Authors": ["Søren Fritzbøger (@fritzboger)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Local Privilege Escalation", "Windows"],
              "Bounty": "-",
              "PublicationDate": "2020-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple flaws leads to Account Takeover within an Application",
                    "Link": "https://medium.com/hackcura/multiple-flaws-leads-to-account-takeover-within-an-application-9f64abfb1073"
                 }
              ],
              "Authors": ["Harshit Sengar (@sengarharshit1)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2020-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first 10k bdt bounty from an e-commerce site",
                    "Link": "https://medium.com/@0xh7ml.py/my-first-10k-bdt-bounty-from-an-e-commerce-site-cec9d58e1f55"
                 }
              ],
              "Authors": ["Md Saikat"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "117",
              "PublicationDate": "2020-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Netgear meshed(*) up WiFi for Business",
                    "Link": "https://www.modzero.com/modlog/archives/2020/05/18/how_netgear_meshed_up_wifi_for_business/index.html"
                 }
              ],
              "Authors": ["Thorsten Schröder"],
              "Programs": ["Netgear"],
              "Bugs": ["Weak crypto", "Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2020-05-18",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Cors Blimey: The power of chaining CORS",
                  "Link": "https://web.archive.org/web/20200616051351/https://hazana.xyz/posts/cors-blimey/"
               },
               {
                  "Title": "Alternative link",
                  "Link": "https://hazanasec.github.io/2021-01-28-CORS-Blimey/"
               }
            ],
            "Authors": ["Hazana (@hazanasec)"],
            "Programs": ["-"],
            "Bugs": ["CORS misconfiguration", "Stored XSS", "CSRF"],
            "Bounty": "-",
            "PublicationDate": "2020-05-17",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Tale of Account Takeovers (Part-2)",
                    "Link": "https://medium.com/@bathinivijaysimhareddy/tale-of-account-takeovers-part-2-9abf62de4ca3"
                 }
              ],
              "Authors": ["Vijaysimha Reddy Bathini (@fatratfatrat)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS Leads to Plaintext Password Disclosure",
                    "Link": "https://www.bad5ect0r.sh/posts/stored-xss-leads-to-plaintext-password-disclosure/"
                 }
              ],
              "Authors": ["bad5ect0r (@bad5ect0r)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "Information disclosure", "Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2020-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One Param => $10k",
                    "Link": "https://medium.com/@bilalmerokhel/one-param-10k-9d80a33f5eb5"
                 }
              ],
              "Authors": ["Bilal Khan (@bilalmerokhel)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "XSS", "Account takeover"],
              "Bounty": "10,000",
              "PublicationDate": "2020-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Logical Bug which let me stop Users from Creating Ads at a Website",
                    "Link": "https://bugwriteups.tech/logical-bug-which-let-me-stop-users-from-creating-ads-at-a-website"
                 }
              ],
              "Authors": ["Merbin Russel (e_23_e)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to make users loss of money on Google Pay",
                    "Link": "https://santuysec.com/2020/05/16/how-i-was-able-to-make-users-loss-of-money-on-google-pay/"
                 }
              ],
              "Authors": ["santuySec (@santuySec)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2020-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chained Bugs [ Account TakeOver ]",
                    "Link": "https://medium.com/@bilalmerokhel/chained-bugs-account-takeover-ceff67d1d55a"
                 }
              ],
              "Authors": ["Bilal Khan (@bilalmerokhel)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "XSS", "Account takeover"],
              "Bounty": "1,050",
              "PublicationDate": "2020-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Password Reset Poisoning leading to Account Takeover",
                    "Link": "https://medium.com/@swapmaurya20/password-reset-poisoning-leading-to-account-takeover-f178f5f1de87"
                 }
              ],
              "Authors": ["Swapnil Maurya (@swapmaurya20)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got my first swag on Edmodo with a simple XSS.",
                    "Link": "http://hack4bounty.com/how-i-got-my-first-swag-on-edmodo-with-a-simple-xss/"
                 }
              ],
              "Authors": ["Sanjay Verdu (@codersanjay)"],
              "Programs": ["Edmodo"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weak Cryptography in Password Reset to Full Account Takeover",
                    "Link": "https://medium.com/bugbountywriteup/weak-cryptography-in-password-reset-to-full-account-takeover-fc61c75b36b9"
                 }
              ],
              "Authors": ["Harsh Bothra (@harshbothra_)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset", "Cryptographic issues"],
              "Bounty": "-",
              "PublicationDate": "2020-05-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty — Advanced Manual Penetration Testing Leading to Price Manipulation Vulnerability",
                    "Link": "https://medium.com/@talatmehmood1995/bug-bounty-advanced-manual-penetration-testing-leading-to-price-manipulation-vulnerability-d935a3a5ddf6"
                 }
              ],
              "Authors": ["Talatmehmood"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2020-05-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$3000 Bug Bounty Award from Mozilla for a successful targeted Credential Hunt",
                    "Link": "https://embracethered.com/blog/posts/2020/mozilla-bug-bounty-credential-hunt-phabricator-token/"
                 }
              ],
              "Authors": ["Johann Rehberger (wunderwuzzi23)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "3,000",
              "PublicationDate": "2020-05-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Lucky Bug Which Let Me Change Name of Every Accounts at a Single Click",
                    "Link": "https://bugwriteups.tech/bug-bounty-write-up-lucky-vulnerability"
                 }
              ],
              "Authors": ["Merbin Russel (e_23_e)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-05-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Change the profanity filter for any Facebook page",
                    "Link": "https://philippeharewood.com/change-the-profanity-filter-for-any-facebook-page/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "750",
              "PublicationDate": "2020-05-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Magic of the Back Slash",
                    "Link": "https://medium.com/@aniltom/magic-of-the-back-slash-d868e66b532a"
                 }
              ],
              "Authors": ["Anil Tom (mr_4nk)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "2,100",
              "PublicationDate": "2020-05-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Another Zoho ManageEngine Story",
                    "Link": "https://medium.com/@frycos/another-zoho-manageengine-story-7b472f1515f5"
                 }
              ],
              "Authors": ["Florian Hauser (@frycos)"],
              "Programs": ["Zoho"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-05-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made $10K in bug bounties from GitHub secret leaks",
                    "Link": "https://tillsongalloway.com/finding-sensitive-information-on-github/index.html"
                 }
              ],
              "Authors": ["Tillson Galloway (tillson_)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "10,000",
              "PublicationDate": "2020-05-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass XSS filter using HTML Escape",
                    "Link": "https://medium.com/@adonkidz7/bypass-xss-filter-using-html-escape-f2e06bebc8c3"
                 }
              ],
              "Authors": ["Syahri Ramadan (@adonkidz7)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "4,133.70",
              "PublicationDate": "2020-05-08",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Pentesting Cisco SD-WAN Part 2: Breaking Routers",
                  "Link": "https://www.synacktiv.com/en/publications/pentesting-cisco-sd-wan-part-2-breaking-routers.html"
               }
            ],
            "Authors": ["Julien Legras (@Julien_Legras)" , "Thomas Etrillard"],
            "Programs": ["Cisco"],
            "Bugs": ["OS command injection", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2020-05-07",
            "AddedDate": "2022-12-26"
         },
           {
              "Links": [
                 {
                    "Title": "$20000 Facebook DOM XSS",
                    "Link": "https://vinothkumar.me/20000-facebook-dom-xss/"
                 }
              ],
              "Authors": ["Vinoth Kumar (@vinodsparrow)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DOM XSS"],
              "Bounty": "20,000",
              "PublicationDate": "2020-05-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I Found XSS Security Flaws in Rails – Here's What Happened.",
                    "Link": "https://chefsecure.com/blog/i-found-xss-security-flaws-in-rails-heres-what-happened"
                 }
              ],
              "Authors": ["Jesse Campos"],
              "Programs": ["Ruby on Rails"],
              "Bugs": ["XSS"],
              "Bounty": "500",
              "PublicationDate": "2020-05-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM-Based XSS at accounts.google.com by Google Voice Extension.",
                    "Link": "https://twitter.com/missoum1307/status/1258472717453582336"
                 }
              ],
              "Authors": ["missoum1307 (@missoum1307)"],
              "Programs": ["Google"],
              "Bugs": ["DOM XSS"],
              "Bounty": "3,133.7",
              "PublicationDate": "2020-05-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How we Hijacked 26+ Subdomains",
                    "Link": "https://medium.com/@aishwaryakendle/how-we-hijacked-26-subdomains-9c05c94c7049"
                 }
              ],
              "Authors": ["Aishwarya Kendle (@aish_kendle)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-05-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM XSS Walkthrough",
                    "Link": "https://medium.com/@youssefla/dom-xss-walkthrough-4d60c45ffb21"
                 }
              ],
              "Authors": ["Youssef Lahouifi (@YLahouifi)"],
              "Programs": ["-"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Acquisition XSS (Apigee)",
                    "Link": "https://medium.com/@TnMch/google-acquisition-xss-apigee-5479d7b5dc4"
                 }
              ],
              "Authors": ["TnMch (@TnMch_)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A tale of verbose error message and a JWT token",
                    "Link": "https://geleta.eu/2020/a-tale-of-verbose-error-message-and-jwt-token/"
                 }
              ],
              "Authors": ["Marek Geleta (@marek_geleta)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on biz.waze.com",
                    "Link": "https://sites.google.com/securifyinc.com/vrp-writeups/waze/waze-xss"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Google (Waze)"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple XSS",
                    "Link": "https://sites.google.com/securifyinc.com/vrp-writeups/hire-with-google/xsses"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "G Suite - Device Management XSS",
                    "Link": "https://sites.google.com/securifyinc.com/vrp-writeups/gsuite/bookmark-xss-device-management"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cool paste jacking attack earned me $$$",
                    "Link": "https://gyanihackers.com/blog/cool-paste-jacking-attack/"
                 }
              ],
              "Authors": ["Aman Rawat (@theamanrawat)"],
              "Programs": ["-"],
              "Bugs": ["Paste jacking"],
              "Bounty": "-",
              "PublicationDate": "2020-05-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM XSS in Gmail with a little help from Chrome",
                    "Link": "https://opnsec.com/2020/05/dom-xss-in-gmail-with-a-little-help-from-chrome"
                 }
              ],
              "Authors": ["Enguerran Gillier (@opnsec)"],
              "Programs": ["Google"],
              "Bugs": ["DOM XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2020-05-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — Adding Money Using Response Modification",
                    "Link": "https://medium.com/@sandeepkumarsingh1902/bugbounty-adding-money-using-response-modification-334448d34251"
                 }
              ],
              "Authors": ["Line_no 6"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-05-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Private Dashboards were accessible by other Admins in Analytics Dashboard",
                    "Link": "https://medium.com/@rohitcoder/private-dashboards-were-accessible-by-other-admins-in-analytics-dashboard-558010a379ab"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS on Microsoft.com via Angular Js template injection",
                    "Link": "https://medium.com/@impratikdabhi/reflected-xss-on-microsoft-com-via-angular-template-injection-2e26d80a7fd8"
                 }
              ],
              "Authors": ["Pratik Dabhi (@impratikdabhi)"],
              "Programs": ["Microsoft"],
              "Bugs": ["CSTI", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind SSRF on coda.io",
                    "Link": "https://web.archive.org/web/20210117211634/https://kurtikleiton.medium.com/blind-ssrf-on-coda-io-c7063f304455"
                 }
              ],
              "Authors": ["Kleiton Kurti (@kleiton0x7e)"],
              "Programs": ["Coda"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exposure of Facebook object type by knowing the object ID",
                    "Link": "https://ysamm.com/?p=444"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Add draft subtitles to any Facebook video and Full Path Disclosure",
                    "Link": "https://ysamm.com/?p=437"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Ok Google! bypass ‘flag_secure’",
                    "Link": "https://pankajupadhyay.in/2020/05/01/ok-google-bypass-flag-secure/"
                 }
              ],
              "Authors": ["Pankaj Upadhyay (@_pupadhyay)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-05-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Story of Blind SSRF leads to internal Host discovery.",
                    "Link": "https://medium.com/@rooterkaustubh/the-story-of-blind-ssrf-leads-to-internal-host-discovery-ee65b9b91e23"
                 }
              ],
              "Authors": ["kaustubh padwad (@s3curityb3ast)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-05-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Razer Pay Ewallet App",
                    "Link": "https://blog.sambal0x.com/2020/04/30/Hacking-razer-pay-ewallet-app.html"
                 }
              ],
              "Authors": ["Richard Tan (@sambal0x)"],
              "Programs": ["Razer"],
              "Bugs": ["IDOR"],
              "Bounty": "6,000",
              "PublicationDate": "2020-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Researching Polymorphic Images for XSS on Google Scholar",
                    "Link": "https://blog.doyensec.com/2020/04/30/polymorphic-images-for-xss.html"
                 }
              ],
              "Authors": ["Lorenzo Stella (@lorenzostella)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS"],
              "Bounty": "9,401.1",
              "PublicationDate": "2020-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Bug Bounty Writeups] Exploiting SQL Injection Vulnerability",
                    "Link": "https://medium.com/sud0root/bug-bounty-writeups-exploiting-sql-injection-vulnerability-20b019553716"
                 }
              ],
              "Authors": ["Ahmed ElTijani"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "2,000",
              "PublicationDate": "2020-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account taken over in style !!!",
                    "Link": "https://medium.com/@kishorehariram/account-taken-over-in-style-8a547342a5ad"
                 }
              ],
              "Authors": ["kishore hariram (@kishorehariram)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing the Trello token by abusing a cross-iframe XSS on the Butler Plugin",
                    "Link": "https://hethical.io/stealing-the-trello-token-by-abusing-a-cross-iframe-xss-on-the-butler-plugin/"
                 }
              ],
              "Authors": ["Florian Courtial (@theflofly)"],
              "Programs": ["Trello"],
              "Bugs": ["XSS"],
              "Bounty": "3,600",
              "PublicationDate": "2020-04-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Indirect UXSS issue on a private Android target app",
                    "Link": "https://medium.com/@kunal94/indirect-uxss-issues-on-a-private-integrated-browser-219f6b809b6c"
                 }
              ],
              "Authors": ["Kunal pandey (@kunalp94)"],
              "Programs": ["-"],
              "Bugs": ["Universal XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2020-04-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Recon to Sensitive Information Disclosure in Minutes",
                    "Link": "https://medium.com/@hbothra22/recon-to-sensitive-information-disclosure-in-minutes-503fc7ccdf0b"
                 }
              ],
              "Authors": ["Harsh Bothra (@harshbothra_)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Outdated component with a known vulnerability"],
              "Bounty": "-",
              "PublicationDate": "2020-04-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Private giant chat app – Send message to victim while sender blocked",
                    "Link": "https://servicenger.com/blog/mobile/private-bounty-sendmsg/"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-04-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Piercing the Veal: Short Stories to Read with Friends",
                    "Link": "https://medium.com/@d0nut/piercing-the-veal-short-stories-to-read-with-friends-4aa86d606fc5"
                 }
              ],
              "Authors": ["d0nut (@d0nutptr)"],
              "Programs": ["DuckDuckGo"],
              "Bugs": ["SSRF"],
              "Bounty": "4,800",
              "PublicationDate": "2020-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Beware of the GIF: Account Takeover Vulnerability in Microsoft Teams",
                    "Link": "https://www.cyberark.com/threat-research-blog/beware-of-the-gif-account-takeover-vulnerability-in-microsoft-teams/"
                 }
              ],
              "Authors": ["Omer Tsarfati (@OmerTsarfati)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Account takeover", "Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bitrix WAF bypass",
                    "Link": "https://blog.deteact.com/bitrix-waf-bypass/"
                 }
              ],
              "Authors": ["Roma Ramazanoff (@r0hack)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "300",
              "PublicationDate": "2020-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "1-click RCE on Keybase",
                    "Link": "https://www.shielder.it/blog/1-click-rce-on-keybase/"
                 }
              ],
              "Authors": ["smaury (@smaury92)"],
              "Programs": ["Keybase"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fun With CORS Misconfiguration — II",
                    "Link": "https://medium.com/@amangupta566/fun-with-cors-misconfiguration-ii-927caccfe932"
                 }
              ],
              "Authors": ["Aman Gupta (@gupt4j1)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Peerio 2 Windows Application (Write Up)",
                    "Link": "https://blog.evanricafort.com/2020/04/xss-in-peerio-2-windows-application.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Peerio"],
              "Bugs": ["XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2020-04-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Web Cache Poisoning in Postmates [$1500]",
                    "Link": "https://web.archive.org/web/20200426140225/https://medium.com/@aungpyaehackeronetester/web-cache-poisoning-in-postmates-1500-a67eee4fc118"
                 }
              ],
              "Authors": ["Aung Pyae Ko Ko (@BlcKVRtuL1)"],
              "Programs": ["Postmates"],
              "Bugs": ["Web cache poisoning"],
              "Bounty": "1,500",
              "PublicationDate": "2020-04-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Recon to P1 (Critical) — An Easy Win",
                    "Link": "https://medium.com/@hbothra22/from-recon-to-p1-critical-an-easy-win-6ca93d5b6e6d"
                 }
              ],
              "Authors": ["Harsh Bothra (@harshbothra_)"],
              "Programs": ["-"],
              "Bugs": ["Exposed registration page"],
              "Bounty": "-",
              "PublicationDate": "2020-04-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Two Factor Authentication Bypass [ $50 ]",
                    "Link": "https://medium.com/@aungpyaehackeronetester/two-factor-authentication-bypass-50-5b397e68cfed"
                 }
              ],
              "Authors": ["Aung Pyae Ko Ko (@BlcKVRtuL1)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "50",
              "PublicationDate": "2020-04-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Messenger Rooms Bug Bounty Write-up",
                    "Link": "https://wongmjane.com/blog/messenger-rooms-writeup"
                 }
              ],
              "Authors": ["Jane Manchun Wong (@wongmjane)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Privilege escalation", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-04-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hiding ourself in close friend’s list and avoiding victim to remove us from his close friend’s list.",
                    "Link": "https://baibhavjha.com.np/blogs/hidinginclosefriendlist/"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2020-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Misconfigured WordPress takeover to Remote Code Execution",
                    "Link": "https://smaranchand.com.np/2020/04/misconfigured-wordpress-takeover-to-remote-code-execution/"
                 }
              ],
              "Authors": ["Smaran Chand (@smaranchand)"],
              "Programs": ["-"],
              "Bugs": ["Wordpress takeover", "RCE", "Security misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2020-04-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From P5 to P2, from nothing to 1000+$",
                    "Link": "https://medium.com/@mohameddaher/from-p5-to-p5-to-p2-from-nothing-to-1000-bxss-4dd26bc30a82"
                 }
              ],
              "Authors": ["Mohamed Daher (@DaherMohamed4)"],
              "Programs": ["-"],
              "Bugs": ["Race condition", "Self-XSS", "Blind XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2020-04-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Secret sauce of bug bounty",
                    "Link": "https://web.archive.org/web/20200513210337/https://medium.com/bugbountywriteup/the-secret-sauce-of-bug-bounty-bdcc2e2d45af"
                 }
              ],
              "Authors": ["Mohamed Slamat (@oxxy37)"],
              "Programs": ["-"],
              "Bugs": ["CSTI", "Stored XSS", "CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2020-04-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting a Race Condition Vulnerability",
                    "Link": "https://medium.com/@vincenz/exploiting-a-race-condition-vulnerability-3f2cb387a72"
                 }
              ],
              "Authors": ["Vivek Kumar Singh (@v7nc3nz)"],
              "Programs": ["-"],
              "Bugs": ["Race condition"],
              "Bounty": "-",
              "PublicationDate": "2020-04-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CORS bug on GOOGLE’s 404 page REWARDED!!!",
                    "Link": "https://medium.com/@jayateerthag/cors-bug-on-googles-404-page-rewarded-2163d58d3c8b"
                 }
              ],
              "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
              "Programs": ["Google"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2020-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM based open redirect to the leak of a JWT token",
                    "Link": "https://medium.com/@adam.adreleve/dom-based-open-redirect-to-the-leak-of-a-jwt-token-1b1dd2ced9a1"
                 }
              ],
              "Authors": ["Adolphoramirez"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "DOM-based open redirect", "Token leak"],
              "Bounty": "-",
              "PublicationDate": "2020-04-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Maps API (Not the Key) Bugs That I Found Over the Years",
                    "Link": "https://medium.com/bugbountywriteup/google-maps-api-not-the-key-bugs-that-i-found-over-the-years-781840fc82aa"
                 }
              ],
              "Authors": ["Ozgur Alp (@ozgur_bbh)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-04-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing HTTP Path Normalization and Cache Poisoning to steal Rocket League accounts",
                    "Link": "https://samcurry.net/abusing-http-path-normalization-and-cache-poisoning-to-steal-rocket-league-accounts/"
                 }
              ],
              "Authors": ["Sam Curry (@samwcyo)"],
              "Programs": ["Rocket League"],
              "Bugs": ["HTTP cache poisoning", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-04-19",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "CSRF to RCE bug chain in Prestashop v1.7.6.4 and below",
                  "Link": "https://blog.stazot.com/prestashop-csrf-to-rce-article/"
               }
            ],
            "Authors": ["Sivanesh Ashok (@sivaneshashok)"],
            "Programs": ["PrestaShop"],
            "Bugs": ["RCE", "CSRF", "Stored XSS", "Unrestricted file upload"],
            "Bounty": "-",
            "PublicationDate": "2020-04-18",
            "AddedDate": "2023-02-26"
         },
           {
              "Links": [
                 {
                    "Title": "How was i able to find privilege escalation.",
                    "Link": "https://medium.com/@np20121996/how-was-i-able-to-find-privilege-escalation-b13366b97706"
                 }
              ],
              "Authors": ["Akshar Tank (@Akshar__tank)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Here is the Non Technical write-up on Technical Bug for My Second Bounty of $xxxx From Facebook",
                    "Link": "https://medium.com/@ashokcpg/non-technical-write-up-on-my-second-bounty-of-1-000-from-facebook-74daecd6879b"
                 }
              ],
              "Authors": ["Ashok Chapagai (@ashokcpg)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2020-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Strange Redirect (Fixed but no bounty)",
                    "Link": "https://medium.com/@abhishake100/strange-redirect-fixed-but-no-bounty-54425aea7f19"
                 }
              ],
              "Authors": ["Abhishek Yadav (@abhishake100)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2020-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OTP Verification Bypass",
                    "Link": "https://medium.com/@rat010/otp-verification-bypass-ee17d68f8425"
                 }
              ],
              "Authors": ["Kanhaiya Kumar Singh"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Writeup][Bug Bounty][Instagram] Instagram Still Send New DMs and Video Calls to Device After Logout [ID][EN]",
                    "Link": "https://fadhilthomas.github.io/post/facebook-white-hat-01/"
                 }
              ],
              "Authors": ["Muhammad Thomas Fadhila Yahya (@fadhilthomas)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Session management issue"],
              "Bounty": "750",
              "PublicationDate": "2020-04-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tricky Oracle SQL Injection Situation",
                    "Link": "https://blog.yappare.com/2020/04/tricky-oracle-sql-injection-situation.html"
                 }
              ],
              "Authors": ["yappare (@yappare)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-04-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Kernel Vulnerabilities Affecting All Qualcomm Devices",
                    "Link": "https://blog.zimperium.com/multiple-kernel-vulnerabilities-affecting-all-qualcomm-devices/"
                 }
              ],
              "Authors": ["Tamir Zahavi-Brunner (@tamir_zb)"],
              "Programs": ["Qalcomm", "Samsung"],
              "Bugs": ["Memory corruption", "Race condition"],
              "Bounty": "-",
              "PublicationDate": "2020-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Netflix Party — XSS Vulnerabilities",
                    "Link": "https://medium.com/@kristian.balog/netflix-party-simple-xss-ec92ed1d7e18"
                 }
              ],
              "Authors": ["kr-b (@pirxcy)"],
              "Programs": ["Netflix"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business Logic Errors - A New Look",
                    "Link": "https://medium.com/@shahjerry33/business-logic-errors-a-new-look-3b18d9c2a12f"
                 }
              ],
              "Authors": ["Shrey Shah (@ShreySh43332033)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bounty Tip !! Easiest way to bypass API’s Rate Limit.",
                    "Link": "https://medium.com/bugbountywriteup/bounty-tip-easiest-way-to-bypass-apis-rate-limit-f984fad40093"
                 }
              ],
              "Authors": ["Shaurya Sharma (@ShauryaSharma05)"],
              "Programs": ["-"],
              "Bugs": ["Rate limiting bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking a Telecommunication company(MTN)",
                    "Link": "https://medium.com/@afolicdaralee/hacking-a-telecommunication-company-mtn-c46696451fed"
                 }
              ],
              "Authors": ["Afolic"],
              "Programs": ["MTN Group"],
              "Bugs": ["OTP bypass", "Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2020-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i Unlocked the blocked accounts?",
                    "Link": "https://medium.com/bugbountywriteup/how-i-unlocked-the-blocked-accounts-545e9b7d7be1"
                 }
              ],
              "Authors": ["Maria Zulfiqar"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "HTTP parameter pollution", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-04-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The story of a fuzzing integration reward",
                    "Link": "https://blog.doyensec.com/2020/04/08/libressl-fuzzer.html"
                 }
              ],
              "Authors": ["Andrea Brancaleoni (@nJoyneer)"],
              "Programs": ["Google"],
              "Bugs": ["Memory corruption"],
              "Bounty": "10,000",
              "PublicationDate": "2020-04-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Listing all registered email addresses on Google’s Crisis Map thanks to IDOR and incremental IDs",
                    "Link": "https://websecblog.com/vulns/listing-email-addresses-on-google-crisis-map/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unrestricted CV File Upload",
                    "Link": "https://web.archive.org/web/20200601005729/https://vict0ni.me/unrestricted-file-upload-on-pdf/"
                 }
              ],
              "Authors": ["vict0ni (@vict0ni)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2020-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in Google Nest",
                    "Link": "https://medium.com/bugbountywriteup/stored-xss-in-google-nest-a82373bbda68"
                 }
              ],
              "Authors": ["Harikrishnan Chandraganesan (@hari_cybex)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$3K Bounty For Elastic-Search Takeover",
                    "Link": "https://medium.com/@D0rkerDevil/3k-bounty-for-elastic-search-takeover-70c0847d2e40"
                 }
              ],
              "Authors": ["Ashish Kunwar (@D0rkerDevil)"],
              "Programs": ["-"],
              "Bugs": ["Elasticsearch Takeover", "Information disclosure"],
              "Bounty": "3,000",
              "PublicationDate": "2020-04-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How we abused Slack's TURN servers to gain access to internal services",
                    "Link": "https://www.rtcsec.com/article/slack-webrtc-turn-compromise-and-bug-bounty/"
                 }
              ],
              "Authors": ["Sandro Gauci (@sandrogauci)"],
              "Programs": ["Slack"],
              "Bugs": ["SSRF", "TURN", "WebRTC"],
              "Bounty": "3,500",
              "PublicationDate": "2020-04-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How a Simple CSRF Attack Turned into a P1 Level Bug",
                    "Link": "https://ladysecspeare.wordpress.com/2020/04/05/how-a-simple-csrf-attack-turned-into-a-p1-level-bug/"
                 }
              ],
              "Authors": ["Lady Secspeare (@bejuveria_)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Page Admin Disclosure: Facebook Bug Bounty 2020",
                    "Link": "https://web.archive.org/web/20200407121700/https://medium.com/nassec-cybersecurity-writeups/page-admin-disclosure-facebook-bug-bounty-2020-8a45cf911e24"
                 }
              ],
              "Authors": ["Saugat Pokharel (@saugatscript)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cannot Delete Post on Facebook Group: Facebook Bug Bounty",
                    "Link": "https://web.archive.org/web/20200405123820/https://medium.com/@saugatpokharel/cannot-delete-post-on-facebook-group-facebook-bug-bounty-4f2661655c3a"
                 }
              ],
              "Authors": ["Saugat Pokharel (@saugatscript)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Playing with JSON Web Tokens for Fun and Profit",
                    "Link": "https://blog.securitybreached.org/2020/04/04/playing-with-json-web-tokens-for-fun-and-profit/"
                 }
              ],
              "Authors": ["Muhammad Qasim Munir (@MeetAn0nym0us)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Email verification bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Touch ID Authentication Bypass on Evernote and Dropbox IOS Apps",
                    "Link": "https://medium.com/@pig.wig45/touch-id-authentication-bypass-on-evernote-and-dropbox-ios-apps-7985219767b2"
                 }
              ],
              "Authors": ["Sahil Tikoo (@viperbluff)"],
              "Programs": ["Evernote", "Dropbox"],
              "Bugs": ["Authentication bypass", "iOS"],
              "Bounty": "-",
              "PublicationDate": "2020-04-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "iPhone Camera Hack",
                    "Link": "https://www.ryanpickren.com/webcam-hacking-overview"
                 }
              ],
              "Authors": ["Ryan Pickren"],
              "Programs": ["Apple"],
              "Bugs": ["Zero-Click Unauthorized Access to Sensitive Data"],
              "Bounty": "75,000",
              "PublicationDate": "2020-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hundreds of internal servicedesks exposed due to COVID-19",
                    "Link": "https://medium.com/@intideceukelaire/hundreds-of-internal-servicedesks-exposed-due-to-covid-19-ecd0baec87bd"
                 }
              ],
              "Authors": ["Inti De Ceukelaire (@securinti)"],
              "Programs": ["-"],
              "Bugs": ["Security misconfiguration"],
              "Bounty": "10,000",
              "PublicationDate": "2020-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Always escalate! From Self-XSS to Persistent XSS on Login Portal",
                    "Link": "https://medium.com/@nnez/always-escalate-from-self-xss-to-persistent-xss-on-login-portal-54265b0adfd0"
                 }
              ],
              "Authors": ["Phuriphat Boontanon (@zanezenzane)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "CSRF"],
              "Bounty": "650",
              "PublicationDate": "2020-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Take Over without user Interaction",
                    "Link": "https://medium.com/@ravillabharath123/account-take-over-without-user-interaction-f4ed2bf977de"
                 }
              ],
              "Authors": ["Ravilla Bharath"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Information disclosure", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation - Hello Admin",
                    "Link": "https://medium.com/@shahjerry33/privilege-escalation-hello-admin-a53ac14fd388"
                 }
              ],
              "Authors": ["Shrey Shah (@ShreySh43332033)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The story of my first ever, 1500$, bounty from Facebook.",
                    "Link": "https://medium.com/@ashokcpg/the-story-of-my-first-ever-1500-bounty-from-facebook-49eb64d26160"
                 }
              ],
              "Authors": ["Ashok Chapagai (@ashokcpg)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,500",
              "PublicationDate": "2020-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$3133.7 Google Bug Bounty Writeup- XSS Vulnerability!",
                    "Link": "https://pethuraj.com/blog/google-bug-bounty-writeup/"
                 }
              ],
              "Authors": ["Pethuraj (@Pethuraj)"],
              "Programs": ["Google"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "3,133.7",
              "PublicationDate": "2020-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Apache Solr RCE Velocity Template | Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2020/03/31/microsoft-rce-bugbounty/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Akamai Web Application Firewall Bypass Journey: Exploiting “Google BigQuery” SQL Injection Vulnerability",
                    "Link": "https://hackemall.live/index.php/2020/03/31/akamai-web-application-firewall-bypass-journey-exploiting-google-bigquery-sql-injection-vulnerability/"
                 }
              ],
              "Authors": ["Duc Nguyen (@ducnt_)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking makes me forget my pain",
                    "Link": "https://medium.com/@abidafahd/hacking-makes-me-forget-my-pain-b04bf51d0407"
                 }
              ],
              "Authors": ["Abida Fahd"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Limited freemarker ssti to arbitrary liql query and manage lithium cms",
                    "Link": "https://blog.mert.ninja/freemarker-ssti-on-lithium-cms/"
                 }
              ],
              "Authors": ["Mert (@mertistaken)", "F. Celal Erdik (@celalerdik)"],
              "Programs": ["-"],
              "Bugs": ["SSTI"],
              "Bounty": "-",
              "PublicationDate": "2020-03-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Restriction is not a promise : Privilege escalation on Google.",
                    "Link": "https://medium.com/@hariharan21/restriction-is-not-a-promise-privilege-escalation-on-google-2a35104ded5a"
                 }
              ],
              "Authors": ["Hariharan.s (@DJHARIZ1)"],
              "Programs": ["Google"],
              "Bugs": ["Privilege escalation", "Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2020-03-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2019-17004—Semi Universal XSS affecting Firefox for iOS",
                    "Link": "https://0x65.dev/blog/2020-03-30/cve-2019-17004-semi-universal-xss-affecting-firefox-for-ios.html"
                 }
              ],
              "Authors": ["cliqz (@cliqz)"],
              "Programs": ["Mozilla", "Brave Software"],
              "Bugs": ["Universal XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-03-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OTP Bruteforce- Account Takeover",
                    "Link": "https://medium.com/@ranjitsinghnit/otp-bruteforce-account-takeover-faaac3d712a8"
                 }
              ],
              "Authors": ["Ranjit Kumar"],
              "Programs": ["-"],
              "Bugs": ["OTP bruteforce", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-03-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Attacking HelpDesks Part 1: RCE Chain on DeskPro, with Bitdefender as a Case Study",
                    "Link": "https://blog.redforce.io/attacking-helpdesks-part-1-rce-chain-on-deskpro-with-bitdefender-as-case-study/"
                 }
              ],
              "Authors": ["Abdulrahman Nour (@aboodnour)"],
              "Programs": ["Bitdefender"],
              "Bugs": ["RCE"],
              "Bounty": "5,000",
              "PublicationDate": "2020-03-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Executing scripts in Safari Reader Mode to CSP Bypass",
                    "Link": "https://payatu.com/blog/nikhil-mittal/executing-scripts-in-safari-reader-mode--to-csp-bypass"
                 }
              ],
              "Authors": ["Nikhil Mittal (@c0d3G33k)"],
              "Programs": ["Apple"],
              "Bugs": ["XSS", "CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-03-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I Want that Cookie !!!",
                    "Link": "https://medium.com/@adnanmalikinfo110/i-want-that-cookie-8d2daab242ac"
                 }
              ],
              "Authors": ["Adnan Malik (@infoadnanmalik)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-03-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting magic links, critical bugs are one line away",
                    "Link": "https://0xsha.io/posts/exploiting-magic-links-critical-bugs-are-one-line-away"
                 }
              ],
              "Authors": ["0xSha (@0xsha)"],
              "Programs": ["Razer"],
              "Bugs": ["Information disclosure", "Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2020-03-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "1st Bug Bounty Write-Up — Open Redirect Vulnerability on Login Page",
                    "Link": "https://medium.com/@nnez/1st-bug-bounty-write-up-open-redirect-vulnerability-on-login-page-5e0dd9a6eb69"
                 }
              ],
              "Authors": ["Phuriphat Boontanon (@zanezenzane)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "250",
              "PublicationDate": "2020-03-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover Flow In Mail.ru ‘s Ext.A Domain [ $150 ]",
                    "Link": "https://web.archive.org/web/20200511145923/https://medium.com/@godofdarkness.msf/account-takeover-flow-in-mail-ru-s-ext-a-domain-150-8952e8078211"
                 }
              ],
              "Authors": ["Myo Min Thu (@myominthu1337)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Account takeover"],
              "Bounty": "150",
              "PublicationDate": "2020-03-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploitation of the CVE-2018-15961 – Unrestricted File Upload in Adobe ColdFusion",
                    "Link": "https://supras.io/exploitation-of-the-cve-2018-15961-unrestricted-file-upload-in-adobe-coldfusion/"
                 }
              ],
              "Authors": ["Supras (@LdrTom)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2020-03-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing Videos From VLC",
                    "Link": "https://www.inputzero.io/2020/03/idor-in-vlc-ios.html"
                 }
              ],
              "Authors": ["Dhiraj (@RandomDhiraj)"],
              "Programs": ["Internet Bug Bounty"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-03-26",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Pentesting Cisco SD-WAN Part 1: Attacking vManage",
                  "Link": "https://www.synacktiv.com/publications/pentesting-cisco-sd-wan-part-1-attacking-vmanage.html"
               }
            ],
            "Authors": ["Julien Legras (@Julien_Legras)" , "Thomas Etrillard"],
            "Programs": ["Cisco"],
            "Bugs": ["Cypher injection", "Stored XSS"],
            "Bounty": "-",
            "PublicationDate": "2020-03-25",
            "AddedDate": "2022-12-26"
         },
           {
              "Links": [
                 {
                    "Title": "XSS WAF & Character limitation bypass like a boss",
                    "Link": "https://medium.com/bugbountywriteup/xss-waf-character-limitation-bypass-like-a-boss-2c788647c229"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "VPN bypass vulnerability in Apple iOS",
                    "Link": "https://protonvpn.com/blog/apple-ios-vulnerability-disclosure/"
                 }
              ],
              "Authors": ["Proton Team"],
              "Programs": ["Apple"],
              "Bugs": ["Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2020-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Self XSS to Account Takeover",
                    "Link": "https://medium.com/@ch3ckm4te/self-xss-to-account-takeover-72c89775cf8f"
                 }
              ],
              "Authors": ["Ch3ckM4te"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-03-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Ticklish XSS",
                    "Link": "https://adnanmalik.info/blog/the-ticklish-xss%EF%BF%BC/"
                 }
              ],
              "Authors": ["Adnan Malik (@adnanmalikinfo)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-03-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Image Upload Leads to RCE (Inject Malicious Code to PHP-GD Image)",
                    "Link": "https://asdqw3.medium.com/remote-image-upload-leads-to-rce-inject-malicious-code-to-php-gd-image-90e1e8b2aada"
                 }
              ],
              "Authors": ["asdqw3"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "API DOCS takeover on Readme.io",
                    "Link": "https://telegra.ph/API-DOCS-takeover-on-Readmeio-03-19"
                 }
              ],
              "Authors": ["Oktavandi (@0ktavandi)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "EN | Administrator level Privilege Escalation story",
                    "Link": "https://web.archive.org/web/20201004092711/https://sametsahin.net/posts/administrator-level-privilege-escalation-story/"
                 }
              ],
              "Authors": ["Samet Sahin (@sametsahinnet)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS on microsoft.com subdomains",
                    "Link": "https://medium.com/bugbountywriteup/reflected-xss-on-microsoft-com-subdomains-4bdfc2c716df"
                 }
              ],
              "Authors": ["Raimonds Liepins (@lv_linkers)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking — Always Check the Cross-domain Policy",
                    "Link": "https://medium.com/the-volatile-triad/hacking-always-check-the-cross-domain-policy-369940372de3"
                 }
              ],
              "Authors": ["Jack"],
              "Programs": ["Starbucks"],
              "Bugs": ["SOP bypass", "CSRF"],
              "Bounty": "750",
              "PublicationDate": "2020-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XXE-scape through the front door: circumventing the firewall with HTTP request smuggling",
                    "Link": "https://honoki.net/2020/03/18/xxe-scape-through-the-front-door-circumventing-the-firewall-with-http-request-smuggling/"
                 }
              ],
              "Authors": ["Pieter Hiele (@honoki)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2020-03-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Where is my Train : Tracking to Hacking !",
                    "Link": "https://medium.com/@aniltom/where-is-my-train-tracking-to-hacking-d388e4b97225"
                 }
              ],
              "Authors": ["Anil Tom (mr_4nk)"],
              "Programs": ["Google"],
              "Bugs": ["Reflected XSS", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2020-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to verify any contact number for my account?",
                    "Link": "https://medium.com/@parasarora06/how-i-was-able-to-verify-any-contact-number-for-my-account-57c939dab202"
                 }
              ],
              "Authors": ["Paras Arora (@parasarora06)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass", "2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Razer mobile PIN verification bypass $1k Bug",
                    "Link": "https://web.archive.org/web/20200317103909/https://medium.com/sourav-sahana/razer-mobile-pin-verification-bypass-1k-bug-2eb1485796b3"
                 }
              ],
              "Authors": ["Sourav Sahana (@kernel_rider)"],
              "Programs": ["Razer"],
              "Bugs": ["OTP bypass", "2FA / MFA bypass"],
              "Bounty": "1,000",
              "PublicationDate": "2020-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Earned $1750 at Shopify Bug Bounty Program",
                    "Link": "https://medium.com/@ashketchum/how-i-earned-1750-at-shopify-bug-bounty-program-ca7821990d08"
                 }
              ],
              "Authors": ["Ashish Dhone (@ashketchum_16)"],
              "Programs": ["Shopify"],
              "Bugs": ["XSS", "Open redirect"],
              "Bounty": "1,750",
              "PublicationDate": "2020-03-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weak session validation bug let you login even after changing the session IDs and logging out from the accounts",
                    "Link": "https://medium.com/@manasjha7965/weak-session-validation-bug-let-you-login-even-after-changing-the-session-ids-and-logging-out-from-4bb3ee29a598"
                 }
              ],
              "Authors": ["Manasjha (@manas_hunter)"],
              "Programs": ["viator.com"],
              "Bugs": ["Logic flaw", "Session management issue"],
              "Bounty": "-",
              "PublicationDate": "2020-03-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Using Vulnerability Analytics Feature Like a Boss",
                    "Link": "https://medium.com/@ozguralp/using-vulnerability-analytics-feature-like-a-boss-655fc1f1543b"
                 }
              ],
              "Authors": ["Ozgur Alp (@ozgur_bbh)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "Reflected XSS", "Authentication bypass"],
              "Bounty": "8,600",
              "PublicationDate": "2020-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned $800 for Host Header Injection Vulnerability",
                    "Link": "https://www.pethuraj.com/blog/how-i-earned-800-for-host-header-injection-vulnerability/"
                 }
              ],
              "Authors": ["Pethuraj (@Pethuraj)"],
              "Programs": ["-"],
              "Bugs": ["Host header injection", "Password reset"],
              "Bounty": "800",
              "PublicationDate": "2020-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Weirdest Bug Bounty — Getting PII from O365.",
                    "Link": "https://medium.com/@omaidfaizyar/my-weirdest-bug-bounty-getting-pii-from-o365-b4477f4739e"
                 }
              ],
              "Authors": ["Omaid Faizyar (@rulesofthetrade)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "1,000",
              "PublicationDate": "2020-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blocked User Can Send Notification Due to Logical Bug in Instagram | First Instagram Bug",
                    "Link": "https://medium.com/bugbountywriteup/blocked-user-can-send-notification-due-to-logical-bug-in-instagram-first-instagram-bug-2bd09aa52f14"
                 }
              ],
              "Authors": ["Divyanshu Shukla (@justm0rph3u5)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "What is your GCP infra worth?...about ~$700 [Bugbounty]",
                    "Link": "http://carnal0wnage.attackresearch.com/2020/03/what-is-your-gcp-infra-worthabout-700.html"
                 }
              ],
              "Authors": ["Chris Gates (@carnal0wnage)"],
              "Programs": ["Tokopedia"],
              "Bugs": ["Information disclosure"],
              "Bounty": "700",
              "PublicationDate": "2020-03-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "User's email disclosure via invalid password reset link [$250]",
                    "Link": "https://web.archive.org/web/20200511115634/https://medium.com/@godofdarkness.msf/users-email-disclosure-via-invalid-password-reset-link-250-c431ed46680e"
                 }
              ],
              "Authors": ["Myo Min Thu (@myominthu1337)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Information disclosure"],
              "Bounty": "250",
              "PublicationDate": "2020-03-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "API secret key Leakage leads to disclosure of Employee’s Information",
                    "Link": "https://medium.com/@spade.com/api-secret-key-leakage-leads-to-disclosure-of-employees-information-5ca4ce17e1ce"
                 }
              ],
              "Authors": ["Ace Candelario (@phspades)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "2,000",
              "PublicationDate": "2020-03-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Generate valid signatures for FBCDN urls",
                    "Link": "https://philippeharewood.com/generate-valid-signatures-for-fbcdn-urls/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-03-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got access to critical data of a Company in no time ?",
                    "Link": "https://medium.com/@kaustubhk80/how-i-got-access-to-critical-data-of-a-company-in-no-time-6c396aee21c0"
                 }
              ],
              "Authors": ["Kaustubh Kale"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Lack of rate limiting", "Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2020-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Bug Bounty] Email Content Injection",
                    "Link": "https://medium.com/@navne3t/bug-bounty-email-content-injection-544196d59e91"
                 }
              ],
              "Authors": ["Navneet (@na5n33t)"],
              "Programs": ["-"],
              "Bugs": ["Email content injection"],
              "Bounty": "25",
              "PublicationDate": "2020-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Reported a DoS Vulnerability to AWS",
                    "Link": "https://techkranti.com/how-i-reported-a-dos-vulnerability-to-aws/"
                 }
              ],
              "Authors": ["Amey Anekar (@ameyanekar)"],
              "Programs": ["AWS"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Generate valid signatures for files hosted in Facebook CDNs",
                    "Link": "https://ysamm.com/?p=404"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Ability to bruteforce Instagram account’s password due to lack of rate limitation protection",
                    "Link": "https://ysamm.com/?p=396"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Lack of rate limiting", "Bruteforce"],
              "Bounty": "3,000",
              "PublicationDate": "2020-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to bypass the current password?",
                    "Link": "https://ninadmathpati.com/how-i-was-able-to-bypass-the-current-password/"
                 }
              ],
              "Authors": ["Ninad Mathpati (@ninad_mathpati)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OTP Bypass - Developer’s Check",
                    "Link": "https://medium.com/@shahjerry33/otp-bypass-developers-check-5786885d55c6"
                 }
              ],
              "Authors": ["Shrey Shah (@ShreySh43332033)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding a P1 in one minute with Shodan.io (RCE)",
                    "Link": "https://medium.com/@sw33tlie/finding-a-p1-in-one-minute-with-shodan-io-rce-735e08123f52"
                 }
              ],
              "Authors": ["Paolo Arnolfo (@sw33tLie)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Got Easiest Bounty with HTML injection via email confirmation!",
                    "Link": "https://medium.com/cyberverse/got-easiest-bounty-with-html-injection-via-email-confirmation-b1b10575a105"
                 }
              ],
              "Authors": ["Shaurya Sharma (@ShauryaSharma05)"],
              "Programs": ["-"],
              "Bugs": ["HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2020-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerable design leads to personal data leakage- yet another case of an inter-application vulnerability…",
                    "Link": "https://medium.com/bugbountywriteup/vulnerable-design-leads-to-personal-data-leakage-yet-another-case-of-an-inter-application-8a9d7e2d0f1a"
                 }
              ],
              "Authors": ["Marcin Szydlowski (@SecurityKsl)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broke limited scope with a chain of bugs (tips for every rider CORS)",
                    "Link": "https://medium.com/bugbountywriteup/broke-limited-scope-with-a-chain-of-bugs-ef734ac430f5"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The unexpected Google wide domain check bypass",
                    "Link": "https://bugs.xdavidhu.me/google/2020/03/08/the-unexpected-google-wide-domain-check-bypass/"
                 }
              ],
              "Authors": ["David Schütz (@xdavidhu)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "6,000",
              "PublicationDate": "2020-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Breaking the Competition (Bug Bounty Write-up)",
                    "Link": "https://medium.com/ctf-writeups/breaking-the-competition-bug-bounty-write-up-ca7cb7bc53f5"
                 }
              ],
              "Authors": ["George O (@georgeomnet)"],
              "Programs": ["-"],
              "Bugs": ["Race condition", "DoS", "Logic flaw", "Session management issue"],
              "Bounty": "-",
              "PublicationDate": "2020-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$5,005 worth vulnerability Duplicated, How I loose $5,005 in a day? Denial of Service - Billion LAUGH Attack (XXE)",
                    "Link": "https://web.archive.org/web/20200820030054/https://medium.com/@protector47/5-005-worth-vulnerability-duplicated-how-i-loose-5-005-in-a-day-831f5a064713"
                 }
              ],
              "Authors": ["Muhammad Asim Shahzad (@protector47)"],
              "Programs": ["-"],
              "Bugs": ["DoS", "XXE"],
              "Bounty": "-",
              "PublicationDate": "2020-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Ads Self-XSS & Html Injection $5000",
                    "Link": "https://medium.com/@adonkidz7/google-ads-self-xss-html-injection-5000-52280da76c80"
                 }
              ],
              "Authors": ["Syahri Ramadan (@adonkidz7)"],
              "Programs": ["Google"],
              "Bugs": ["Self-XSS", "HTML injection"],
              "Bounty": "5,000",
              "PublicationDate": "2020-03-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I exploit the JSON CSRF with method override technique",
                    "Link": "https://medium.com/@secureITmania/how-i-exploit-the-json-csrf-with-method-override-technique-71c0a9a7f3b0"
                 }
              ],
              "Authors": ["Simgamsetti Manikanta (@zaheckmania)"],
              "Programs": ["-"],
              "Bugs": ["JSON CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-03-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Bug Bounty: Clickjacking on Google Payment (1337$)",
                    "Link": "https://santuysec.com/2020/03/06/google-bug-bounty-clickjacking-on-google-payment-1337/"
                 }
              ],
              "Authors": ["santuySec (@santuySec)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "1,337",
              "PublicationDate": "2020-03-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Got *Bounty* with Account takeover (ATO ) Unicode-Case Mapping Collision !",
                    "Link": "https://medium.com/cyberverse/got-bounty-with-account-takeover-ato-unicode-case-mapping-collision-d23a7785e1be"
                 }
              ],
              "Authors": ["Shaurya Sharma (@ShauryaSharma05)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-03-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing Slack for Offensive Operations",
                    "Link": "https://posts.specterops.io/abusing-slack-for-offensive-operations-2343237b9282"
                 }
              ],
              "Authors": ["Cody Thomas (@its_a_feature_)"],
              "Programs": ["Slack"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-03-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF vulnerability in Uppy, Detected by Shieldfy",
                    "Link": "https://eslam.io/posts/uppy-js-ssrf-vulnerability/"
                 }
              ],
              "Authors": ["Eslam Salem (@net_code)"],
              "Programs": ["Node.js third-party modules"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-03-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SOP Bypass",
                    "Link": "https://web.archive.org/web/20200304074843/https://medium.com/@kenanistaken/sop-bypass-ecae7f4a5c00"
                 }
              ],
              "Authors": ["Kenan (@kenanistaken)"],
              "Programs": ["-"],
              "Bugs": ["SOP bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-03-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting an SSRF: Trials and Tribulations",
                    "Link": "https://medium.com/a-bugz-life/exploiting-an-ssrf-trials-and-tribulations-14c5d8dbd69a"
                 }
              ],
              "Authors": ["A Bug’z Life (@abugzlife1)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-03-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ManageEngine ServiceDesk Plus: Arbitrary File Upload",
                    "Link": "https://medium.com/@ducanhbui/manageengine-servicedesk-plus-arbitrary-file-upload-4bab0bd00425"
                 }
              ],
              "Authors": ["Duc Anh Bui"],
              "Programs": ["-"],
              "Bugs": ["Arbitrary file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-03-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I CSRF’d My First Bounty!",
                    "Link": "https://medium.com/@rajeshranjan457/how-i-csrfd-my-first-bounty-a62b593d3f4d"
                 }
              ],
              "Authors": ["Rajesh Ranjan (@rajesh_ranjan4)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "500",
              "PublicationDate": "2020-03-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection Via Stopping the redirection to a login page",
                    "Link": "https://medium.com/@St00rm/sql-injection-via-stopping-the-redirection-to-a-login-page-52b0792d5592"
                 }
              ],
              "Authors": ["Abde Ouabala (@4mgh0z)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-03-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF on PDF generator.",
                    "Link": "https://medium.com/@michan001/ssrf-on-pdf-generator-36b81e16d67b"
                 }
              ],
              "Authors": ["John Michael (@michan2514)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-03-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Discord embed spoofing",
                    "Link": "https://medium.com/@DarkMatterMatt/discord-embed-spoofing-c6d07ab1decc"
                 }
              ],
              "Authors": ["DarkMatterMatt"],
              "Programs": ["Discord"],
              "Bugs": ["Phishing"],
              "Bounty": "-",
              "PublicationDate": "2020-03-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook OAuth Framework Vulnerability",
                    "Link": "https://www.amolbaikar.com/facebook-oauth-framework-vulnerability/"
                 }
              ],
              "Authors": ["Amol Baikar (@AmolBaikar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["OAuth"],
              "Bounty": "55,000",
              "PublicationDate": "2020-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A mysterious bug in the firmware of Google's Titan M chip (CVE-2019-9465)",
                    "Link": "https://alexbakker.me/post/mysterious-google-titan-m-bug-cve-2019-9465.html"
                 }
              ],
              "Authors": ["Alexander Bakker"],
              "Programs": ["Google"],
              "Bugs": ["Cryptographic issues"],
              "Bounty": "-",
              "PublicationDate": "2020-02-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Hijack using Authorization bypass $$$$",
                    "Link": "https://medium.com/@bhaveshthakur2015/account-hijack-using-authorization-bypass-which-made-me-richer-by-ba9dace72682"
                 }
              ],
              "Authors": ["Bhavesh Thakur (@Bhavesh_Thakur_)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Page Admin Disclosure via an Upgraded Page Post",
                    "Link": "https://medium.com/@timpaxerror/page-admin-disclosure-via-an-upgraded-page-post-57863fb02c50"
                 }
              ],
              "Authors": ["Dan Fabro (@0x61_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Information disclosure"],
              "Bounty": "3,000",
              "PublicationDate": "2020-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Tricky XSS",
                    "Link": "https://smaranchand.com.np/2020/02/the-tricky-xss/"
                 }
              ],
              "Authors": ["Smaran Chand (@smaranchand)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook CSRF bug which lead to Instagram Partial account takeover.",
                    "Link": "https://ysamm.com/?p=379"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF", "OAuth"],
              "Bounty": "12,500",
              "PublicationDate": "2020-02-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE via Apache Struts2 - Still out there.",
                    "Link": "https://medium.com/@abhishake100/rce-via-apache-struts2-still-out-there-b15ce205aa21"
                 }
              ],
              "Authors": ["Abhishek (@abhishake100)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-02-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write-up: AWS Document Signing Security Control Bypass",
                    "Link": "https://medium.com/@ozguralp/write-up-aws-document-signing-security-control-bypass-2b13a9c22a4d"
                 }
              ],
              "Authors": ["Ozgur Alp (@ozgur_bbh)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "1,000",
              "PublicationDate": "2020-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Long String DoS",
                    "Link": "https://medium.com/@shahjerry33/long-string-dos-6ba8ceab3aa0"
                 }
              ],
              "Authors": ["Shrey Shah (@ShreySh43332033)"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "100",
              "PublicationDate": "2020-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Get my first P1 (Sensitive Information Disclosure) using WPScan",
                    "Link": "https://medium.com/@harrmahar/how-i-get-my-first-p1-sensitive-information-disclosure-using-wpscan-c2fba00ac361"
                 }
              ],
              "Authors": ["Harrmahar (@harrmahar)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i found 3 SSRF in one day on different bug bounty targets",
                    "Link": "https://medium.com/@Mr.Daman.Singh/how-i-found-3-ssrf-in-one-day-on-different-bug-bounty-targets-62e91b4268f8"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Mail.Ru Ext.B Scope Account Takeover [ $1500 ]",
                    "Link": "https://web.archive.org/web/20200511064630/https://medium.com/@godofdarkness.msf/mail-ru-ext-b-scope-account-takeover-1500-abdb1560e5f9"
                 }
              ],
              "Authors": ["Myo Min Thu (@myominthu1337)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["Account takeover", "OAuth"],
              "Bounty": "1,500",
              "PublicationDate": "2020-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored-XSS-on-groups-google-com",
                    "Link": "https://web.archive.org/web/20200513211717/https://mrss4nd0x.000webhostapp.com/Stored-XSS-on-groups-google-com.php"
                 }
              ],
              "Authors": ["Alessandro Rumampuk (@Rando02355205)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Discord DoS with a single message",
                    "Link": "https://medium.com/@DarkMatterMatt/breaking-a-discord-channel-with-a-single-message-5095eb7604f1"
                 }
              ],
              "Authors": ["DarkMatterMatt"],
              "Programs": ["Discord"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2020-02-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind XSS against a Googler",
                    "Link": "https://sites.google.com/securifyinc.com/vrp-writeups/hire-with-google/blind-xss"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Google"],
              "Bugs": ["Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-02-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS In AT&T",
                    "Link": "https://web.archive.org/web/20200505142429/https://medium.com/@godofdarkness.msf/reflected-xss-in-at-t-7f1bdd10d8f7"
                 }
              ],
              "Authors": ["Myo Min Thu (@myominthu1337)"],
              "Programs": ["AT&T"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-02-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tale of Account Takeovers (Part-1)",
                    "Link": "https://medium.com/@bathinivijaysimhareddy/tale-of-account-takeovers-part-1-b24e1f3c3187"
                 }
              ],
              "Authors": ["Vijaysimha Reddy Bathini (@fatratfatrat)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "HTTP parameter pollution", "Password reset", "OTP bypass"],
              "Bounty": "5,000",
              "PublicationDate": "2020-02-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting Tesla Model Y Secrets in the Parts Catalog",
                    "Link": "https://medium.com/@evan.connelly/hunting-tesla-model-y-secrets-in-the-parts-catalog-2f453f853dd8"
                 }
              ],
              "Authors": ["Evan Connelly (@Evan_Connelly)"],
              "Programs": ["Tesla"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-02-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Jira for Host Discovery",
                    "Link": "https://medium.com/tenable-techblog/exploiting-jira-for-host-discovery-43be3cddf023"
                 }
              ],
              "Authors": ["Alex Peña"],
              "Programs": ["Atlassian"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking SMS API Service Provider of a Company |Android App Static Security Analysis | Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2020/02/19/hacking-sms-api-service-provider-of-a-company-android-app-static-security-analysis-bug-bounty-poc/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Hardcoded credentials"],
              "Bounty": "-",
              "PublicationDate": "2020-02-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Tale of Two Formats: Exploiting Insecure XML and ZIP File Parsers to Create a Web Shell",
                    "Link": "https://spaceraccoon.dev/a-tale-of-two-formats-exploiting-insecure-xml-and-zip-file-parsers-to-create-a"
                 }
              ],
              "Authors": ["Eugene Lim (@spaceraccoonsec)"],
              "Programs": ["-"],
              "Bugs": ["XXE", "RCE", "Directory Traversal"],
              "Bounty": "-",
              "PublicationDate": "2020-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Recon to Optimizing RCE Results – Simple Story with One of the Biggest ICT Company in the World",
                    "Link": "http://www.firstsight.me/2020/02/from-recon-to-optimizing-rce-results-simple-story-with-one-of-the-biggest-ict-company-in-the-world/"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Bounty From Google.",
                    "Link": "https://medium.com/@adonkidz7/my-first-bounty-from-google-d9f1f3f5787a"
                 }
              ],
              "Authors": ["Syahri Ramadan (@adonkidz7)"],
              "Programs": ["Google"],
              "Bugs": ["Self-XSS", "HTML injection"],
              "Bounty": "5,000",
              "PublicationDate": "2020-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How We Found Another XSS in Google with Acunetix",
                    "Link": "https://www.acunetix.com/blog/web-security-zone/xss-google-acunetix/"
                 }
              ],
              "Authors": ["Andrey Leonov (@4lemon)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2020-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Plan Change Logic in Google Fiber (Webpass)",
                    "Link": "https://s1gnalcha0s.github.io/logic/2020/02/17/Google-Fiber.html"
                 }
              ],
              "Authors": ["Craig Arendt (@signalchaos)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw", "Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2020-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting WebSocket [Application Wide XSS / CSRF]",
                    "Link": "https://medium.com/@osamaavvan/exploiting-websocket-application-wide-xss-csrf-66e9e2ac8dfa"
                 }
              ],
              "Authors": ["Osama Avvan (@osamaavvan)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Gain Unrestricted File Upload Remote Code Execution Bug Bounty",
                    "Link": "https://medium.com/@shayboy123/how-i-gain-unrestricted-file-upload-remote-code-execution-bug-bounty-381d0aab0dad"
                 }
              ],
              "Authors": ["Shay Grant (@kidshay)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2020-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Uploading Backdoor For Fun And Profit.",
                    "Link": "https://medium.com/@mohdaltaf163/uploading-backdoor-for-fun-and-profit-rce-db-cred-p1-2cdaa00e2125"
                 }
              ],
              "Authors": ["Mohammed Abdul Raheem (@mohdaltaf163)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to hack a company by circumventing its WAF through the abuse of a different security appliance and win bug bounties",
                    "Link": "https://www.redtimmy.com/web-application-hacking/how-to-hack-a-company-by-circumventing-its-waf-through-the-abuse-of-a-different-security-appliance-and-win-bug-bounties/"
                 }
              ],
              "Authors": ["Red Timmy Security (@redtimmysec)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open-redirect Vulnerability on Facebook",
                    "Link": "https://medium.com/@dwi.siswanto98/open-redirect-on-facebook-bypass-linkshim-4050f680d45c"
                 }
              ],
              "Authors": ["dw1"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "500",
              "PublicationDate": "2020-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind IDOR in LinkedIn iOS application",
                    "Link": "https://hailstorm1422.com/linkedin-blind-idor/"
                 }
              ],
              "Authors": ["Hailstorm (@hailstorm1422)"],
              "Programs": ["LinkedIn"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-02-16",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "CVE-2019-18426 - WhatsApp Vulnerabilities Disclosure - Open Redirect + CSP Bypass + Persistent XSS + FS read permissions + potential for RCE",
                  "Link": "https://weizman.github.io/2020/02/14/whatsapp-vuln/"
               }
            ],
            "Authors": ["Gal Weizman (@WeizmanGal)"],
            "Programs": ["Meta / Facebook (WhatsApp)"],
            "Bugs": ["RCE", "Stored XSS", "CSP bypass", "Arbitrary file read", "Open redirect", "Security code review"],
            "Bounty": "12,500",
            "PublicationDate": "2020-02-14",
            "AddedDate": "2023-05-04"
         },
           {
              "Links": [
                 {
                    "Title": "A Simple IDOR to Account Takeover",
                    "Link": "https://medium.com/@swapmaurya20/a-simple-idor-to-account-takeover-88b8a1d2ec24"
                 }
              ],
              "Authors": ["Swapnil Maurya (@swapmaurya20)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "4,500",
              "PublicationDate": "2020-02-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weird Vulnerabilities Happening on Load Balancers, Shallow Copies and Caches",
                    "Link": "https://medium.com/@ozguralp/weird-vulnerabilities-happening-on-load-balancers-shallow-copies-and-caches-9194d4f72322"
                 }
              ],
              "Authors": ["Ozgur Alp (@ozgur_bbh)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,500",
              "PublicationDate": "2020-02-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I discovered an SSRF leading to AWS Metadata Leakage",
                    "Link": "https://techkranti.com/ssrf-aws-metadata-leakage"
                 }
              ],
              "Authors": ["Amey Anekar (@ameyanekar)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-02-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A step-by-step walk-through of an Invalid Endpoint",
                    "Link": "https://medium.com/@mdisrail2468/a-step-by-step-walk-through-of-an-invalid-endpoint-acfbdc84b209"
                 }
              ],
              "Authors": ["Mohammed Israil (@mdisrail2468)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-02-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "External XML Entity via File Upload (SVG)",
                    "Link": "https://web.archive.org/web/20200305081812/https://0xatul.github.io/posts/2020/02/external-xml-entity-via-file-upload-svg/"
                 }
              ],
              "Authors": ["Atul (@atul_hax)"],
              "Programs": ["-"],
              "Bugs": ["XXE", "Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2020-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Determine users with detailed role model on behalf of any Facebook Application",
                    "Link": "https://www.amolbaikar.com/determine-users-with-detailed-role-model-on-behalf-of-any-facebook-application/"
                 }
              ],
              "Authors": ["Amol Baikar (@AmolBaikar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-02-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR leads to Data leakage and Profile Update",
                    "Link": "https://web.archive.org/web/20200223073527/https://victoni.github.io/changing-userID-leads-to-data-leak/"
                 },
                 {
                  "Title": "Alternative link",
                  "Link": "https://0x00sec.org/t/idor-leads-to-data-leakage-and-profile-update/19025"
               }
               ],
              "Authors": ["vict0ni (@vict0ni)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2020-02-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Inspect Element Got me a Bounty",
                    "Link": "https://medium.com/@hetroublemakr/how-inspect-element-got-me-a-bounty-58d3a9946225"
                 }
              ],
              "Authors": ["Aditya Soni (@hetroublemakr)"],
              "Programs": ["-"],
              "Bugs": ["Client-side enforcement of server-side security"],
              "Bounty": "-",
              "PublicationDate": "2020-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Popping Alerts in Mixmax Chrome Extension (Write Up)",
                    "Link": "https://blog.evanricafort.com/2020/02/popping-alerts-in-mixmax-chrome.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Mixmax"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Simple Remote Code Execution Vulnerability Examples for Beginners",
                    "Link": "https://ozguralp.medium.com/simple-remote-code-execution-vulnerability-examples-for-beginners-985867878311"
                 }
              ],
              "Authors": ["Ozgur Alp (@ozgur_bbh)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Unrestricted file upload"],
              "Bounty": "15,000",
              "PublicationDate": "2020-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google APIS ClickJacking ( $1337)",
                    "Link": "https://web.archive.org/web/20200225040957/https://medium.com/@godofdarkness.msf/google-apis-clickjacking-1337-7a3a9f3eb8df"
                 }
              ],
              "Authors": ["Myo Min Thu (@myominthu1337)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "1,337",
              "PublicationDate": "2020-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Site wide CSRF on a popular program",
                    "Link": "https://fellchase.blogspot.com/2020/02/site-wide-csrf-on-popular-program.html"
                 }
              ],
              "Authors": ["Ajinkya Pathare (@fellchase)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Made $600 in Bug Bounty in 15 Minutes with Contrast CE – CVE- 2019-8442",
                    "Link": "https://www.contrastsecurity.com/security-influencers/i-made-600-with-contrast-ce-cve-2019-8442"
                 }
              ],
              "Authors": ["David Lindner (@golfhackerdave)"],
              "Programs": ["Atlassian"],
              "Bugs": ["Information disclosure"],
              "Bounty": "600",
              "PublicationDate": "2020-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Using CSRF I Got Weird Account Takeover",
                    "Link": "https://flex0geek.blogspot.com/2020/02/using-csrf-i-got-weird-account-takeover.html"
                 }
              ],
              "Authors": ["Mohamed Sayed (@FlEx0Geek)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An Unexpected Bounty — Email Bounce Issues",
                    "Link": "https://medium.com/@keshavaarav22/an-unexpected-bounty-email-bounce-issues-b9f24a35eb68"
                 }
              ],
              "Authors": ["Keshav Malik (@g0t_rOoT_)"],
              "Programs": ["-"],
              "Bugs": ["DoS", "Email Bounce Issue"],
              "Bounty": "-",
              "PublicationDate": "2020-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hijacking shared report links in Google Data Studio",
                    "Link": "https://medium.com/@sushiwushi2/hijacking-shared-report-links-in-google-data-studio-75eab320c391"
                 }
              ],
              "Authors": ["sushiwushi (@sushiwushi2)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How, I dumped crypto data by chaining directory listing to open S3 Bucket",
                    "Link": "https://medium.com/@ddigvijay29/how-i-dumped-millions-of-crypto-currencies-accounts-28d388053713"
                 }
              ],
              "Authors": ["Ddigvijay"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration", "Directory listing", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Arbitary File Upload too Stored XSS - Bug Bounty",
                    "Link": "https://web.archive.org/web/20200515015005/https://m0chan.github.io/2020/02/04/Arbitary-File-Upload-Too-Stored-XSS.html"
                 }
              ],
              "Authors": ["m0chan (@m0chan98)"],
              "Programs": ["-"],
              "Bugs": ["Arbitrary file upload", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Critical Security Flaw Found in WhatsApp Desktop Platform Allowing Cybercriminals Read From The File System Access",
                    "Link": "https://www.perimeterx.com/tech-blog/2020/whatsapp-fs-read-vuln-disclosure/"
                 }
              ],
              "Authors": ["Gal Weizman (@WeizmanGal)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Stored XSS", "CSP bypass", "Open redirect", "RCE"],
              "Bounty": "12,500",
              "PublicationDate": "2020-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Responsible Disclosure: Breaking out of a Sandboxed Editor to perform RCE",
                    "Link": "https://jatindhankhar.in/blog/responsible-disclosure-breaking-out-of-a-sandboxed-editor-to-perform-rce/"
                 }
              ],
              "Authors": ["Jatin Dhankhar (@jatindhankhar_)"],
              "Programs": ["HackerEarth"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2020-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Insecure Firebase Database!",
                    "Link": "https://blog.securitybreached.org/2020/02/04/exploiting-insecure-firebase-database-bugbounty/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["-"],
              "Bugs": ["Insecure Firebase database", "Android"],
              "Bounty": "-",
              "PublicationDate": "2020-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Easily leaking passenger information on an Airline",
                    "Link": "https://medium.com/@zseano/easily-leaking-passenger-information-on-an-airline-18f99b22cf95"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://blog.bugbountyhunter.com/leaking-airline-passenger-info/"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF CSRF CSRF…",
                    "Link": "https://medium.com/@navne3t/csrf-csrf-csrf-f203e6452a9c"
                 }
              ],
              "Authors": ["Navneet (@na5n33t)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "50",
              "PublicationDate": "2020-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tumblr Bug Bounty ( $200)",
                    "Link": "https://web.archive.org/web/20200328011551/https://medium.com/@godofdarkness.msf/tumblr-bug-bounty-200-2051ba54e981"
                 }
              ],
              "Authors": ["Myo Min Thu (@myominthu1337)"],
              "Programs": ["Automattic"],
              "Bugs": ["Unrestricted file upload", "XSS", "Broken authorization"],
              "Bounty": "200",
              "PublicationDate": "2020-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose Full Admin List of any Facebook Applications",
                    "Link": "https://www.amolbaikar.com/disclose-full-admin-list-of-any-facebook-applications/"
                 }
              ],
              "Authors": ["Amol Baikar (@AmolBaikar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OK Google: bypass the authentication!",
                    "Link": "https://techblog.mediaservice.net/2020/01/ok-google-bypass-the-authentication/"
                 }
              ],
              "Authors": ["Mattia Vinci"],
              "Programs": ["Google"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-01-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2FA Bypass via Logical Rate Limiting Bypass",
                    "Link": "https://web.archive.org/web/20200506144651/https://medium.com/@jeppe.b.weikop/2fa-bypass-via-logical-rate-limiting-bypass-25ae2a4e1835"
                 }
              ],
              "Authors": ["Jeppe Bonde Weikop"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass", "Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2020-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to takeover the company’s LinkedIn Page",
                    "Link": "https://medium.com/@bathinivijaysimhareddy/how-i-takeover-the-companys-linkedin-page-790c9ed2b04d"
                 }
              ],
              "Authors": ["Vijaysimha Reddy Bathini (@fatratfatrat)"],
              "Programs": ["-"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "500",
              "PublicationDate": "2020-01-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I get my first SWAG from SIDN (Sensitive Data Expose)",
                    "Link": "https://medium.com/@mehedi1194/how-i-get-my-first-swag-from-sidn-sensitive-data-expose-fc8e202fef85"
                 }
              ],
              "Authors": ["Mehedi Hasan Remon (@mehedi1194)"],
              "Programs": ["SIDN"],
              "Bugs": ["Broken Access Control", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-01-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hyperlink Injection - Easy Money (sometimes)",
                    "Link": "https://medium.com/@abhishake100/hyperlink-injection-easy-money-sometimes-cc1104655300"
                 }
              ],
              "Authors": ["Abhishek Yadav (@abhishake100)"],
              "Programs": ["-"],
              "Bugs": ["Hyperlink injection"],
              "Bounty": "450",
              "PublicationDate": "2020-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Adding anyone including non-friend and blocked people as co-host in personal event!",
                    "Link": "https://publish.whoisbinit.me/adding-anyone-including-non-friend-and-blocked-people-as-co-host-in-personal-event"
                 }
              ],
              "Authors": ["Binit Ghimire (@WHOISbinit)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "750",
              "PublicationDate": "2020-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tale of a Misconfiguration in Password Reset",
                    "Link": "https://medium.com/@naveenroy008/tale-of-a-misconfiguration-in-password-reset-e8fb484a4661"
                 }
              ],
              "Authors": ["Naveenroy"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating reflected XSS with HTTP Smuggling",
                    "Link": "https://web.archive.org/web/20200825001615/https://hazana.xyz/posts/escalating-reflected-xss-with-http-smuggling/"
                 },
                 {
                  "Title": "Alternative link",
                  "Link": "https://hazanasec.github.io/2021-02-11-Escalating-reflected-XSS-with-HTTP-Smuggling/"
               }
               ],
              "Authors": ["Hazana (@HazanaSec)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "HTTP request smuggling"],
              "Bounty": "-",
              "PublicationDate": "2020-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS on Facebook-Instagram CDN Server bypassing signature protection",
                    "Link": "https://www.amolbaikar.com/xss-on-facebook-instagram-cdn-server-bypassing-signature-protection/"
                 }
              ],
              "Authors": ["Amol Baikar (@AmolBaikar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-01-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose Facebook Business Account ID",
                    "Link": "https://www.amolbaikar.com/disclose-facebook-business-account-id/"
                 }
              ],
              "Authors": ["Amol Baikar (@AmolBaikar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,500",
              "PublicationDate": "2020-01-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS on Facebook’s acquisition Oculus CDN Server",
                    "Link": "https://www.amolbaikar.com/xss-on-facebooks-acquisition-oculus-cdn-server/"
                 }
              ],
              "Authors": ["Amol Baikar (@AmolBaikar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-01-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Improper Input Validation | Add Custom Text and URLs In SMS send by Snapchat | Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2020/01/26/improper-input-validation-add-custom-text-and-urls-in-sms-send-by-snapchat-bug-bounty-poc/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Parameter tampering"],
              "Bounty": "1,000",
              "PublicationDate": "2020-01-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accidental IDOR that Deleted Admin Account.",
                    "Link": "https://medium.com/bugbountywriteup/accidental-idor-that-deleted-admin-account-d51264292b66"
                 }
              ],
              "Authors": ["Sayaan Alam (@ehsayaan)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "325",
              "PublicationDate": "2020-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The unexpected bounty: A story of Zendesk takeover on REDACTED.com",
                    "Link": "https://medium.com/bugbountywriteup/the-unexpected-bounty-a-story-of-zendesk-takeover-on-redacted-com-f2aa96ce2026"
                 }
              ],
              "Authors": ["wis4nggeni"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cross-Site Websocket Hijacking bug in Facebook that leads to account takeover",
                    "Link": "https://ysamm.com/?p=363"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Cross-Site Websocket Hijacking (CSWH)", "Account takeover"],
              "Bounty": "12,500",
              "PublicationDate": "2020-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to take over any users account with host header injection",
                    "Link": "https://medium.com/nassec-cybersecurity-writeups/how-i-was-able-to-take-over-any-users-account-with-host-header-injection-546fff6d0f2"
                 }
              ],
              "Authors": ["Ajay Gautam (@evilboyajay)"],
              "Programs": ["-"],
              "Bugs": ["Host header injection"],
              "Bounty": "900",
              "PublicationDate": "2020-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CORS Misconfiguration leading to Private Information Disclosure",
                    "Link": "https://medium.com/@sasaxxx777/cors-misconfiguration-leading-to-private-information-disclosure-3034cfcb4b93"
                 }
              ],
              "Authors": ["Virus0X01 (@Virus0X01)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2020-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Less Known Attack Vector, Second Order IDOR Attacks",
                    "Link": "https://medium.com/@ozguralp/a-less-known-attack-vector-second-order-idor-attacks-14468009781a"
                 }
              ],
              "Authors": ["Ozgur Alp (@ozgur_bbh)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2020-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Password Reset Token Leak Via Referrer",
                    "Link": "https://medium.com/@shahjerry33/password-reset-token-leak-via-referrer-2e622500c2c1"
                 }
              ],
              "Authors": ["Shrey Shah (@ShreySh43332033)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Vulnerability: Hidden “Community Manager” in Pages due to “Invitation Accept” logic",
                    "Link": "https://medium.com/@ritishkumarsingh/facebook-vulnerability-hidden-community-manager-in-pages-due-to-invitation-accept-logic-61ddbe229c97"
                 }
              ],
              "Authors": ["Ritish Kumar Singh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2020-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "User Account Takeover via Signup Feature | Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2020/01/22/user-account-takeover-via-signup-feature-bug-bounty-poc/"
                 }
              ],
              "Authors": ["Muzammil Kayani (@muzammilabbas2)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2020-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Bug Bounty: CSRF in learndigital.withgoogle.com",
                    "Link": "https://santuysec.com/2020/01/21/google-bug-bounty-csrf-in-learndigital-withgoogle-com/"
                 }
              ],
              "Authors": ["santuySec (@santuySec)"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-01-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cross Site Request Forgery vulnerability Leads to User Profile Change in Microsoft Express Logic",
                    "Link": "https://web.archive.org/web/20200819163234/https://medium.com/@adeshkolte/cross-site-request-forgery-vulnerability-leads-to-user-profile-change-in-microsoft-express-logic-dc3481ab47ba"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["Microsoft"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-01-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i bought my way to subdomain takeover on Tokopedia",
                    "Link": "https://medium.com/bugbountywriteup/how-i-bought-my-way-to-subdomain-takeover-on-tokopedia-8c6697c85b4d"
                 }
              ],
              "Authors": ["wis4nggeni"],
              "Programs": ["Tokopedia"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2020-01-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GGvulnz — How I hacked hundreds of companies through Google Groups",
                    "Link": "https://medium.com/@milanmagyar/ggvulnz-how-i-hacked-hundreds-of-companies-through-google-groups-b69c658c8924"
                 }
              ],
              "Authors": ["Milan Magyar"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2020-01-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I accidentally found Bug in Google Search Console",
                    "Link": "https://noobe.io/articles/2020-01/how-i-found-bug-google-search-console"
                 }
              ],
              "Authors": ["Tomi (@noobe_io)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "1,337",
              "PublicationDate": "2020-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Adding a malicious notebook to be treated like a trusted notebook in Google Colab — 1337$",
                    "Link": "https://medium.com/@raushanraj_65039/adding-a-malicious-notebook-to-be-treated-like-a-trusted-notebook-in-google-colab-1337-b84353a9f77"
                 }
              ],
              "Authors": ["Raushan Raj (@raushan_rajj)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "1,337",
              "PublicationDate": "2020-01-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The trouble with Microsoft’s Troubleshooters",
                    "Link": "https://irsl.medium.com/the-trouble-with-microsofts-troubleshooters-6e32fc80b8bd"
                 }
              ],
              "Authors": ["Imre Rad (@ImreRad)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE", "MiTM"],
              "Bounty": "-",
              "PublicationDate": "2020-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From . in regex to SSRF — part 2",
                    "Link": "https://xvnpw.github.io/posts/from-dot-in-regex-to-ssrf-part-2/"
                 }
              ],
              "Authors": ["Niemiec Marcin (@xvnpw)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-01-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I discovered an interesting account takeover flaw?",
                    "Link": "https://medium.com/bugbountywriteup/how-i-discovered-an-interesting-account-takeover-flaw-18a7fb1e5359"
                 }
              ],
              "Authors": ["Akash Methani (@0xAkash)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2020-01-14",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Pwning Avast Secure Browser for fun and profit",
                  "Link": "https://palant.info/2020/01/13/pwning-avast-secure-browser-for-fun-and-profit"
               }
            ],
            "Authors": ["Wladimir Palant (@WPalant)"],
            "Programs": ["Avast"],
            "Bugs": ["RCE", "Command injection"],
            "Bounty": "-",
            "PublicationDate": "2020-01-13",
            "AddedDate": "2022-12-09"
         },
           {
              "Links": [
                 {
                    "Title": "In Cloud we “Trust”: Wrong Kubernetes implementation by Google Cloud Platform & Microsoft Azure affecting customers",
                    "Link": "https://faun.pub/in-cloud-we-trust-wrong-kubernetes-implementation-by-google-cloud-platform-microsoft-azure-a60f50ba943f"
                 }
              ],
              "Authors": ["Chen Cohen (@chencococococo)"],
              "Programs": ["Microsoft", "Google"],
              "Bugs": ["Old components with known vulnerabilities"],
              "Bounty": "-",
              "PublicationDate": "2020-01-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "No Rate Limit - 2K Bounty",
                    "Link": "https://medium.com/@shahjerry33/no-rate-limit-2k-bounty-642720ffba99"
                 }
              ],
              "Authors": ["Shrey Shah (@ShreySh43332033)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Lack of rate limiting"],
              "Bounty": "2,000",
              "PublicationDate": "2020-01-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earn $500 from Razer open S3 bucket",
                    "Link": "https://medium.com/sourav-sahana/how-i-earn-500-from-razer-open-s3-bucket-fe314e4bbab8"
                 }
              ],
              "Authors": ["Sourav Sahana (@kernel_rider)"],
              "Programs": ["Razer"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "500",
              "PublicationDate": "2020-01-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First RCE (Stressed Employee gets me 2x bounty)",
                    "Link": "https://medium.com/@abhishake100/my-first-rce-stressed-employee-gets-me-2x-bounty-c4879c277e37"
                 }
              ],
              "Authors": ["Abhishek Yadav (@abhishake100)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "900",
              "PublicationDate": "2020-01-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting Good Bugs with only <HTML>",
                    "Link": "https://medium.com/@know.0nix/hunting-good-bugs-with-only-html-d8fd40d17b38"
                 }
              ],
              "Authors": ["Ak1T4 (@akita_zen)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "HTML injection", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-01-10",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Bypass SameSite Cookies Default to Lax and get CSRF",
                  "Link": "https://medium.com/@renwa/bypass-samesite-cookies-default-to-lax-and-get-csrf-343ba09b9f2b"
               }
            ],
            "Authors": ["Renwa (@RenwaX23)"],
            "Programs": ["-"],
            "Bugs": ["CSRF", "Samesite cookie bypass"],
            "Bounty": "-",
            "PublicationDate": "2020-01-08",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Google Chrome display locking fuzzing",
                    "Link": "https://blog.redteam.pl/2020/04/google-chrome-display-locking-fuzzing.html"
                 }
              ],
              "Authors": ["Pawel Wylecial (@h0wlu)"],
              "Programs": ["Google"],
              "Bugs": ["Use-After-Free", "Memory corruption"],
              "Bounty": "5,000",
              "PublicationDate": "2020-01-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Bug That Exposed Your PayPal Password",
                    "Link": "https://medium.com/@alex.birsan/the-bug-that-exposed-your-paypal-password-539fc2896da9"
                 }
              ],
              "Authors": ["Alex Birsan (@alxbrsn)"],
              "Programs": ["Paypal"],
              "Bugs": ["XSSI"],
              "Bounty": "15,300",
              "PublicationDate": "2020-01-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Update: Want to take over the Java ecosystem? All you need is a MITM!",
                    "Link": "https://medium.com/@jonathan.leitschuh/update-want-to-take-over-the-java-ecosystem-all-you-need-is-a-mitm-d069d253fe23"
                 }
              ],
              "Authors": ["Jonathan Leitschuh (@jlleitschuh)"],
              "Programs": ["Github"],
              "Bugs": ["MiTM", "Insecure communications"],
              "Bounty": "2,300",
              "PublicationDate": "2020-01-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HTML Injection(Unique Exploitation)",
                    "Link": "https://medium.com/@pratiky054/html-injection-unique-exploitation-a5c3d4e6fed8"
                 }
              ],
              "Authors": ["Pratik Yadav (@PratikY9967)"],
              "Programs": ["-"],
              "Bugs": ["HTML injection"],
              "Bounty": "250",
              "PublicationDate": "2020-01-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Saying Goodbye to my Favorite 5 Minute P1",
                    "Link": "https://www.allysonomalley.com/2020/01/06/saying-goodbye-to-my-favorite-5-minute-p1/"
                 }
              ],
              "Authors": ["Allyson O'Malley (@ally_o_malley)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-01-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found a Privilege Escalation Bug in a private Ecommerce?",
                    "Link": "https://medium.com/nassec-cybersecurity-writeups/an-interesting-story-of-privilege-escalation-1da021e7fd0"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2020-01-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS on Sony subdomain",
                    "Link": "https://medium.com/@gguzelkokar.mdbf15/xss-on-sony-subdomain-feddaea8f5ac"
                 }
              ],
              "Authors": ["Gökhan Güzelkokar (@gkhck_)"],
              "Programs": ["Sony"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2020-01-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From . in regex to SSRF — part 1",
                    "Link": "https://xvnpw.github.io/posts/from-dot-in-regex-to-ssrf-part-1/"
                 }
              ],
              "Authors": ["Niemiec Marcin (@xvnpw)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2020-01-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account takeover via HTTP Request Smuggling",
                    "Link": "https://hipotermia.pw/bb/http-desync-account-takeover"
                 }
              ],
              "Authors": ["hipotermia (@_hipotermia_)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling", "Account takeover", "Open redirect", "Internal header disclosure"],
              "Bounty": "-",
              "PublicationDate": "2020-01-03",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Exploiting Wi-Fi Stack on Tesla Model S",
                  "Link": "https://keenlab.tencent.com/en/2020/01/02/exploiting-wifi-stack-on-tesla-model-s/"
               }
            ],
            "Authors": ["Tencent Keen Security Lab"],
            "Programs": ["Tesla"],
            "Bugs": ["Wifi hacking", "Driver hacking", "RCE", "Memory corruption"],
            "Bounty": "-",
            "PublicationDate": "2020-01-02",
            "AddedDate": "2022-11-21"
         },
           {
            "Links": [
               {
                  "Title": "Admin capabilities around your ears",
                  "Link": "https://markus-krell.de/admin-capabilities-around-your-ears/"
               }
            ],
            "Authors": ["Markus Krell (@MarkusKrell)"],
            "Programs": ["Poly (Plantronics)"],
            "Bugs": ["Local Privilege Escalation"],
            "Bounty": "-",
            "PublicationDate": "2020-01-02",
            "AddedDate": "2022-10-24"
         },
           {
              "Links": [
                 {
                    "Title": "Bypass 2FA in a website",
                    "Link": "https://medium.com/sourav-sahana/bypass-2fa-in-a-website-d616eaead1e3"
                 }
              ],
              "Authors": ["Sourav Sahana (@kernel_rider)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2020-01-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass Mobile PIN Verification",
                    "Link": "https://medium.com/sourav-sahana/bypass-mobile-pin-verification-d2c571afa3aa"
                 }
              ],
              "Authors": ["Sourav Sahana (@kernel_rider)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "100",
              "PublicationDate": "2020-01-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of an IDOR via HTTP",
                    "Link": "https://footstep.ninja/posts/idor-via-http/"
                 }
              ],
              "Authors": ["Shuaib Oladigbolu (@_sawzeeyy)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting HTML Injection in Email",
                    "Link": "https://footstep.ninja/posts/html-injection-in-email/"
                 }
              ],
              "Authors": ["Shuaib Oladigbolu (@_sawzeeyy)"],
              "Programs": ["-"],
              "Bugs": ["HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2019-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From POST to GET Open redirect",
                    "Link": "https://medium.com/sourav-sahana/from-post-to-get-open-redirect-e91f4f4206a"
                 }
              ],
              "Authors": ["Sourav Sahana (@kernel_rider)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "450",
              "PublicationDate": "2019-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Hunting Journey of 2019",
                    "Link": "https://medium.com/@sudhanshur705/bug-hunting-journey-of-2019-95e5190aca7c"
                 }
              ],
              "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
              "Programs": ["Alibaba", "Yahoo! / Verizon Media"],
              "Bugs": ["XSS", "Privilege escalation", "Information disclosure"],
              "Bounty": "2,500",
              "PublicationDate": "2019-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting a Self Stored XSS with an IDOR",
                    "Link": "https://footstep.ninja/posts/exploiting-self-xss/"
                 }
              ],
              "Authors": ["Shuaib Oladigbolu (@_sawzeeyy)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "Stored XSS", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How did I earn $3133.70 from Google Translator?",
                    "Link": "https://medium.com/monetary/how-did-i-earn-3133-70-from-google-translator-9becf942dbdc"
                 }
              ],
              "Authors": ["Beri Bey (@uppmen)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "3,133.70",
              "PublicationDate": "2019-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Bug bounty Story: $X000 for an Information Disclosure Bug",
                    "Link": "https://medium.com/bug-bounty-hunting/facebook-bug-bounty-story-x000-for-an-information-disclosure-bug-f0c0d19d7815"
                 }
              ],
              "Authors": ["Circle Ninja (@circleninja)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-12-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made $7500 from My First Bug Bounty Found on Google Cloud Platform",
                    "Link": "https://medium.com/@jbgrunewald/how-i-made-7500-from-my-first-bug-bounty-found-on-google-cloud-platform-1a5415d7569b"
                 }
              ],
              "Authors": ["James Grunewald"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "7,500",
              "PublicationDate": "2019-12-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Drop the mic?! no! Drop the connection ;)",
                    "Link": "https://sasi2103.blogspot.com/2019/12/drop-mic-no-drop-connection.html"
                 }
              ],
              "Authors": ["Sasi Levi (@sasi2103)"],
              "Programs": ["Google"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-12-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Effortlessly finding Cross Site Script Inclusion (XSSI) & JSONP for bug bounty",
                    "Link": "https://medium.com/bugbountywriteup/effortlessly-finding-cross-site-script-inclusion-xssi-jsonp-for-bug-bounty-38ae0b9e5c8a"
                 }
              ],
              "Authors": ["Omkar Bhagwat (@th3_hidd3n_mist)"],
              "Programs": ["-"],
              "Bugs": ["XSSI"],
              "Bounty": "-",
              "PublicationDate": "2019-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Brand Collabs Manager Eligibility on Facebook",
                    "Link": "https://medium.com/nassec-cybersecurity-writeups/bypassing-brand-collabs-manager-eligibility-7d26523da816"
                 }
              ],
              "Authors": ["Ajay Gautam (@evilboyajay)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-12-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain takeover via pantheon",
                    "Link": "https://smaranchand.com.np/2019/12/subdomain-takeover-via-pantheon/"
                 }
              ],
              "Authors": ["Smaran Chand (@smaranchand)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-12-26",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "XSS Is Love <3 !",
                  "Link": "https://nirmaldahal.com.np/posts/2019/12/xss-is-love/"
               }
            ],
            "Authors": ["Nirmal Dahal (@TheNittam)"],
            "Programs": ["-"],
            "Bugs": ["XSS"],
            "Bounty": "-",
            "PublicationDate": "2019-12-26",
            "AddedDate": "2022-09-15"
         },
         {
            "Links": [
               {
                  "Title": "BugBounty | A Dom Xss",
                  "Link": "https://jinone.github.io/bugbounty-a-dom-xss/"
               }
            ],
            "Authors": ["Jinone (@jinonehk)"],
            "Programs": ["-"],
            "Bugs": ["DOM XSS"],
            "Bounty": "500",
            "PublicationDate": "2019-12-24",
            "AddedDate": "2022-09-26"
         },
         {
              "Links": [
                 {
                    "Title": "Microsoft Edge (Chromium) - EoP via XSS to Potential RCE",
                    "Link": "https://leucosite.com/Edge-Chromium-EoP-RCE/"
                 }
              ],
              "Authors": ["Abdulrahman Alqabandi (@Qab)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS", "RCE"],
              "Bounty": "40,000",
              "PublicationDate": "2019-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SOP Bypass via browser-cache",
                    "Link": "https://enumerated.wordpress.com/2019/12/24/sop-bypass-via-browser-cache"
                 }
              ],
              "Authors": ["Aaron Costello (@ConspiracyProof)"],
              "Programs": ["Keybase"],
              "Bugs": ["SOP bypass"],
              "Bounty": "1,500",
              "PublicationDate": "2019-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing ImageMagick to obtain RCE",
                    "Link": "https://web.archive.org/web/20210116171139/https://strynx.org/imagemagick-rce/"
                 }
              ],
              "Authors": ["Strynx (@Strynx_Security)"],
              "Programs": ["-"],
              "Bugs": ["ImageTragick", "RCE"],
              "Bounty": "5,000",
              "PublicationDate": "2019-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How we hacked one of the worlds largest Cryptocurrency Website",
                    "Link": "https://web.archive.org/web/20210116173906/https://strynx.org/insecure-crypto-code-execution/"
                 }
              ],
              "Authors": ["Strynx (@Strynx_Security)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Airbnb : Steal Earning of Airbnb hosts by Adding Bank Account/Payment Method (IDOR)",
                    "Link": "https://www.indoappsec.in/2019/12/airbnb-steal-earning-of-airbnb-hosts-by.html"
                 }
              ],
              "Authors": ["Vijay Kumar (@IndoAppSec)"],
              "Programs": ["Airbnb"],
              "Bugs": ["IDOR"],
              "Bounty": "3,000",
              "PublicationDate": "2019-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bugbounty | A DOM XSS",
                    "Link": "https://jinone.github.io/bugbounty-a-dom-xss/"
                 }
              ],
              "Authors": ["Jinone (@jinonehk)"],
              "Programs": ["-"],
              "Bugs": ["DOM XSS"],
              "Bounty": "500",
              "PublicationDate": "2019-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GraphQL IDOR leads to information disclosure",
                    "Link": "https://medium.com/bugbountywriteup/graphql-idor-leads-to-information-disclosure-175eb560170d"
                 }
              ],
              "Authors": ["Eshan Singh (@R0X4R)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF Token Bypasss — A Tale of my $2k bug",
                    "Link": "https://web.archive.org/web/20200320111950/https://medium.com/@sainttobs/csrf-token-bypasss-a-tale-of-my-2k-bug-ff7f51166ea1"
                 }
              ],
              "Authors": ["Adeyefa Oluwatoba (@adeyefa_codes)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "2,000",
              "PublicationDate": "2019-12-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "reCAPTCHA Exploits",
                    "Link": "https://www.hackerfactor.com/blog/index.php?/archives/862-reCAPTCHA-Exploits.html"
                 }
              ],
              "Authors": ["Dr. Neal Krawetz (@hackerfactor)"],
              "Programs": ["Google"],
              "Bugs": ["Captcha bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-12-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From broken link to subfolder takeover on Bukalapak",
                    "Link": "https://medium.com/bugbountywriteup/from-broken-link-to-sub-folder-takeover-on-bukalapak-3aa985e622c4"
                 }
              ],
              "Authors": ["wis4nggeni"],
              "Programs": ["Bukalapak"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2019-12-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2 FA Bypass via CSRF Attack",
                    "Link": "https://medium.com/@vbharad/2-fa-bypass-via-csrf-attack-8f2f6a6e3871"
                 }
              ],
              "Authors": ["Vishal Bharad"],
              "Programs": ["Mail.ru"],
              "Bugs": ["2FA / MFA bypass", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-12-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full Account Takeover (Android Application)",
                    "Link": "https://medium.com/@vbharad/full-account-takeover-android-application-78fa922f78c5"
                 }
              ],
              "Authors": ["Vishal Bharad"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Captcha !",
                    "Link": "https://medium.com/@abhishake100/bypassing-captcha-17c59d37f459"
                 }
              ],
              "Authors": ["Abhishek Yadav (@abhishake100)"],
              "Programs": ["-"],
              "Bugs": ["Captcha bypass"],
              "Bounty": "200",
              "PublicationDate": "2019-12-20",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "An experience with Daimler’s vulnerability reporting program",
                  "Link": "https://eaton-works.com/2019/12/19/an-experience-with-daimlers-vulnerability-reporting-program/"
               }
            ],
            "Authors": ["Eaton Z. (@XeEaton)"],
            "Programs": ["Daimler"],
            "Bugs": ["Information disclosure"],
            "Bounty": "-",
            "PublicationDate": "2019-12-19",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Account Takeover Through Password Reset Poisoning",
                    "Link": "https://medium.com/@vbharad/account-takeover-through-password-reset-poisoning-72989a8bb8ea"
                 }
              ],
              "Authors": ["Vishal Bharad"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-12-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — How Snapdeal (India’s Popular E-commerce Website) Kept their Users Data at Risk!",
                    "Link": "https://medium.com/@nanda_kumar/bugbounty-how-snapdeal-indias-popular-e-commerce-website-kept-their-user-data-at-risk-3d02b4092d9c"
                 }
              ],
              "Authors": ["Nanda Kumar (@nk00_nk)"],
              "Programs": ["Snapdeal"],
              "Bugs": ["Insecure storage of sensitive information"],
              "Bounty": "-",
              "PublicationDate": "2019-12-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Google VRP] SSRF in Google Cloud Platform StackDriver",
                    "Link": "https://ngailong.wordpress.com/2019/12/19/google-vrp-ssrf-in-google-cloud-platform-stackdriver/"
                 }
              ],
              "Authors": ["Ron Chan (@ngalongc)"],
              "Programs": ["Google"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-12-19",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Javascript Anti Debugging - Abusing SourceMappingURL",
                  "Link": "https://weizman.github.io/2019/12/18/js-anti-debug-1/"
               }
            ],
            "Authors": ["Gal Weizman (@WeizmanGal)"],
            "Programs": ["Google (Chromium)"],
            "Bugs": ["Browser hacking"],
            "Bounty": "-",
            "PublicationDate": "2019-12-17",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Abusing feature to steal your tokens",
                    "Link": "https://medium.com/@rootxharsh_90844/abusing-feature-to-steal-your-tokens-f15f78cebf74"
                 }
              ],
              "Authors": ["Harsh Jaiswal (@rootxharsh)"],
              "Programs": ["-"],
              "Bugs": ["OAuth"],
              "Bounty": "3,750",
              "PublicationDate": "2019-12-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BreakingApp – WhatsApp Crash & Data Loss Bug",
                    "Link": "https://research.checkpoint.com/2019/breakingapp-whatsapp-crash-data-loss-bug/"
                 }
              ],
              "Authors": ["Dikla Barda", "Roman Zaikin", "Yaara Shriki"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2019-12-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Inf0rM@tion Disclosure via IDOR",
                    "Link": "https://medium.com/@pratyush1337/inf0rm-tion-disclosure-via-idor-cff5541a9232"
                 }
              ],
              "Authors": ["Pratyush Anjan Sarangi"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "750",
              "PublicationDate": "2019-12-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored Iframe Injection + CSRF = Account Takeover 😎😎",
                    "Link": "https://medium.com/@irounakdhadiwal999/stored-iframe-injection-csrf-account-takeover-42c93ad13f5d"
                 }
              ],
              "Authors": ["Rounak Dhadiwal (@XploiteR_D)"],
              "Programs": ["-"],
              "Bugs": ["HTML injection", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-12-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Took Over 2 Subdomains with Azure CDN Profiles",
                    "Link": "https://m0chan.github.io/2019/12/16/Subdomain-Takeover-Azure-CDN.html"
                 }
              ],
              "Authors": ["m0chan (@m0chan98)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-12-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "4 Google Cloud Shell bugs explained",
                    "Link": "https://offensi.com/2019/12/16/4-google-cloud-shell-bugs-explained-introduction/"
                 }
              ],
              "Authors": ["wtm@offensi.com (@wtm_offensi)"],
              "Programs": ["Google"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-12-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authorization bug that every bug hunter missed on a popular program",
                    "Link": "https://fellchase.blogspot.com/2019/12/authorization-bug-that-every-bug-hunter-missed-on-a-popular-program.html"
                 }
              ],
              "Authors": ["Ajinkya Pathare (@fellchase)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vimeo upload function SSRF",
                    "Link": "https://medium.com/@dPhoeniixx/vimeo-upload-function-ssrf-7466d8630437"
                 }
              ],
              "Authors": ["Sayed Abdelhafiz (@dPhoeniixx)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "5,000",
              "PublicationDate": "2019-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to find a logical bug on Instagram?",
                    "Link": "https://medium.com/nassec-cybersecurity-writeups/this-is-how-i-got-xxxx-from-facebook-for-instagram-bug-aaff50342246"
                 }
              ],
              "Authors": ["Jabir Khan (@Jabirkhan0x0)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-12-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook New Account Verification Bypass",
                    "Link": "https://medium.com/@santoshbrl5/facebook-new-account-verification-bypass-c589017f2faf"
                 }
              ],
              "Authors": ["Santosh Baral (@santoshbrl5)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-12-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Host Header Attacks after bypassing protection with… a Header Attack",
                    "Link": "https://web.archive.org/web/20200530191901/https://vict0ni.me/multiple-header-injections-bug-hunting/"
                 }
               ],
              "Authors": ["vict0ni (@vict0ni)"],
              "Programs": ["-"],
              "Bugs": ["Host header injection"],
              "Bounty": "-",
              "PublicationDate": "2019-12-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$500 getClass",
                    "Link": "https://www.ezequiel.tech/p/500-getclass.html"
                 }
              ],
              "Authors": ["Ezequiel Pereira (@epereiralopez)"],
              "Programs": ["Google"],
              "Bugs": ["Sandbox bypass"],
              "Bounty": "500",
              "PublicationDate": "2019-12-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A $25 Easy Bug.",
                    "Link": "https://medium.com/@navne3t/a-25-easy-bug-bdfcde4d1370"
                 }
              ],
              "Authors": ["Navneet (@na5n33t)"],
              "Programs": ["-"],
              "Bugs": ["Session management issue"],
              "Bounty": "25",
              "PublicationDate": "2019-12-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF via FFmpeg HLS processing",
                    "Link": "https://medium.com/@pflash0x0punk/ssrf-via-ffmpeg-hls-processing-a04e0288a8c5"
                 }
              ],
              "Authors": ["Pflash Punk (@PflashPunk)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind XSS (A mind game to win the battle)",
                    "Link": "https://medium.com/@dirtycoder0124/blind-xss-a-mind-game-to-win-the-battle-4fc67c524678?"
                 }
              ],
              "Authors": ["Dirtycoder (@dirtycoder0124)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2019-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AirDoS: Remotely render any nearby iPhone or iPad unusable",
                    "Link": "https://kishanbagaria.com/airdos/"
                 }
              ],
              "Authors": ["Kishan Bagaria (@KishanBagaria)"],
              "Programs": ["Apple"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2019-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Get pwned by scanning QR Code",
                    "Link": "https://payatu.com/blog/nikhil-mittal/firefox-ios-qr-code-reader-xss-(cve-2019-17003)"
                 }
              ],
              "Authors": ["Nikhil Mittal (@c0d3G33k)"],
              "Programs": ["Mozilla"],
              "Bugs": ["XSS", "CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authentication Bypass",
                    "Link": "https://medium.com/@ultranoob/weird-and-simple-2fa-bypass-without-any-test-b869e09ac261"
                 }
              ],
              "Authors": ["Rushiikesh (@u1tran00b)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "700",
              "PublicationDate": "2019-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Media deletion CSRF vulnerability on Instagram",
                    "Link": "https://blog.darabi.me/2019/12/instagram-delete-media-csrf.html"
                 }
              ],
              "Authors": ["Pouya Darabi (@Pouyadarabi)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "3,000",
              "PublicationDate": "2019-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Telegram (v4.9.155353) was rendering file:// links + opening them via NSWorkspace.open -> code execution.",
                    "Link": "https://github.com/Metnew/telegram-links-nsworkspace-open"
                 }
              ],
              "Authors": ["Vladimir Metnew (@vladimir_metnew)"],
              "Programs": ["Telegram"],
              "Bugs": ["RCE"],
              "Bounty": "500",
              "PublicationDate": "2019-12-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spilling Local Files via XXE when HTTP OOB fails",
                    "Link": "https://blog.noob.ninja/spilling-local-files-via-xxe-when/"
                 }
              ],
              "Authors": ["Rahul Maini (@iamnoooob)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2019-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reusing Cookies",
                    "Link": "https://medium.com/swlh/reusing-cookies-23ed4691122b"
                 }
              ],
              "Authors": ["Ricardo Iramar dos Santos"],
              "Programs": ["-"],
              "Bugs": ["Session management issue"],
              "Bounty": "400",
              "PublicationDate": "2019-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HTML Injection to XSS bypass in [REDACTED.com]",
                    "Link": "https://blog.evanricafort.com/2019/12/html-injection-to-xss-bypass-in.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "600",
              "PublicationDate": "2019-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$150 XSS at Error Page of Respository Code",
                    "Link": "https://medium.com/@navne3t/150-xss-at-error-page-of-respository-code-4fc628892742"
                 }
              ],
              "Authors": ["Navneet (@na5n33t)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "150",
              "PublicationDate": "2019-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Chrome portal element fuzzing",
                    "Link": "https://blog.redteam.pl/2019/12/chrome-portal-element-fuzzing.html"
                 }
              ],
              "Authors": ["Pawel Wylecial (@h0wlu)"],
              "Programs": ["Google"],
              "Bugs": ["RCE", "Memory corruption", "Buffer Overflow", "Use-After-Free"],
              "Bounty": "8,000",
              "PublicationDate": "2019-12-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HTTP Request Smuggling + IDOR",
                    "Link": "https://hipotermia.pw/bb/http-desync-idor"
                 }
              ],
              "Authors": ["hipotermia (@_hipotermia_)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-12-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS like a Pro",
                    "Link": "https://www.hackerinside.me/2019/12/xss-like-pro.html"
                 }
              ],
              "Authors": ["Anas Mahmood (@AnasIsHere)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "450",
              "PublicationDate": "2019-12-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dank Writeup On Broken Access Control On An Indian Startup",
                    "Link": "https://medium.com/bugbountywriteup/dank-writeup-on-broken-access-control-on-an-indian-startup-d29132a1ecd"
                 }
              ],
              "Authors": ["Divyanshu Shukla (@justm0rph3u5)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-11-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first RCE: a tale of good ideas and good friends",
                    "Link": "https://rez0.blog/hacking/2019/11/29/rce-via-imagetragick.html"
                 }
              ],
              "Authors": ["rez0 (@rez0__)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "ImageTragick"],
              "Bounty": "-",
              "PublicationDate": "2019-11-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I turned Self XSS to Stored via CSRF",
                    "Link": "https://medium.com/@abhishake100/how-i-turned-self-xss-to-stored-via-csrf-d12eaaf59f2e"
                 }
              ],
              "Authors": ["Abhishek Yadav (@abhishake100)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "CSRF"],
              "Bounty": "550",
              "PublicationDate": "2019-11-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking GitHub with Unicode's dotless 'i'",
                    "Link": "https://web.archive.org/web/20211106053748/https://eng.getwisdom.io/hacking-github-with-unicode-dotless-i/"
                 }
              ],
              "Authors": ["John Gracey (@jagracey)"],
              "Programs": ["GitHub"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-11-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Stored On [ Outlook Web — Outlook Android App ]",
                    "Link": "https://medium.com/@elmrhassel/xss-stored-on-outlook-web-outlook-android-app-ad4bd46b8823"
                 }
              ],
              "Authors": ["ElMahdi Mrhassel (@ElMrhassel)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Stored XSS"],
              "Bounty": "2,400",
              "PublicationDate": "2019-11-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS in graph.facebook.com leads to account takeover in IE/Edge",
                    "Link": "https://ysamm.com/?p=343"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Reflected XSS", "Account takeover"],
              "Bounty": "5,000",
              "PublicationDate": "2019-11-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Site Isolation bypass via Chrome extension",
                    "Link": "https://lf.lc/vrp/145304705/"
                 }
              ],
              "Authors": ["Anthony Weems"],
              "Programs": ["Google"],
              "Bugs": ["Site Isolation bypass", "Browser hacking"],
              "Bounty": "3,133.70",
              "PublicationDate": "2019-11-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Getting access to disabled/hidden features with the help of Burpsuite Match and Replace settings",
                    "Link": "https://medium.com/@johnssimon_6607/getting-access-to-disabled-hidden-features-with-the-help-of-burp-match-and-replace-e1d7b70d131e"
                 }
              ],
              "Authors": ["Johns Simon (@Johnssimon22)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-11-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Did Tons of People Like Me on Tinder?",
                    "Link": "https://pastebin.com/E6LMFm2w"
                 }
              ],
              "Authors": ["Mustafa iran (@Mustafaran)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "2,500",
              "PublicationDate": "2019-11-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding a security bug in Discord and what it taught me",
                    "Link": "https://medium.com/@tristanfarkas/finding-a-security-bug-in-discord-and-what-it-taught-me-516cda561295"
                 }
              ],
              "Authors": ["Tristan Farkas (@TristanAtFarkas)"],
              "Programs": ["Discord"],
              "Bugs": ["OAuth"],
              "Bounty": "-",
              "PublicationDate": "2019-11-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CORS Misconfiguration to Account TakeOver [Out of scope to grab items In-Scope]",
                    "Link": "https://medium.com/@mashoud1122/cors-misconfiguration-account-takeover-out-of-scope-to-grab-items-in-scope-66d9d18c7a46"
                 }
              ],
              "Authors": ["Mashoud1122 (@mashoud1122)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration", "Open redirect", "Reflected XSS", "Session management issue"],
              "Bounty": "1,500",
              "PublicationDate": "2019-11-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The AccountTakeOver Killing Chain",
                    "Link": "https://web.archive.org/web/20200511012319/https://medium.com/@xhzeem/the-accounttakeover-killing-chain-6ba23f4c9d4"
                 }
              ],
              "Authors": ["أنس روبي (@xhzeem)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "CSRF", "Self-XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-11-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting padding oracles with fixed IVs",
                    "Link": "https://blog.teddykatz.com/2019/11/23/json-padding-oracles.html"
                 }
              ],
              "Authors": ["Teddy Katz (@not_aardvark)"],
              "Programs": ["-"],
              "Bugs": ["Padding oracle attack", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-11-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR via Websockets",
                    "Link": "https://footstep.ninja/posts/idor-via-websockets/"
                 }
              ],
              "Authors": ["Shuaib Oladigbolu (@_sawzeeyy)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-11-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stories Of IDOR-Part 2",
                    "Link": "https://medium.com/bugbountywriteup/stories-of-idor-part-2-29d313a39e55"
                 }
              ],
              "Authors": ["Shivbihari Pandey (@ninja_pandit_)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "3,650",
              "PublicationDate": "2019-11-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disable Any Unconfirmed Account in Facebook",
                    "Link": "https://medium.com/@lokeshdlk77/disable-any-unconfirmed-account-in-facebook-123aeba19426"
                 }
              ],
              "Authors": ["Lokesh Kumar (@lokeshdlk77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Bruteforce"],
              "Bounty": "1,000",
              "PublicationDate": "2019-11-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "700$ Denial of Service(DoS) vulnerability in script-loader.php (CVE-2018-6389)",
                    "Link": "https://www.pankajinfosec.com/post/700-denial-of-service-dos-vulnerability-in-script-loader-php-cve-2018-6389"
                 }
              ],
              "Authors": ["Pankaj Thakur (@Nep_1337_1998)"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "700",
              "PublicationDate": "2019-11-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reply To Instagram Stories where privacy of who can reply is set to ‘Nobody’. (Part 2)",
                    "Link": "https://baibhavjha.com.np/blogs/instagramstory2/"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "1,000",
              "PublicationDate": "2019-11-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cracking reCAPTCHA, Turbo Intruder style",
                    "Link": "https://portswigger.net/research/cracking-recaptcha-turbo-intruder-style"
                 }
              ],
              "Authors": ["James Kettle (@albinowax)"],
              "Programs": ["Google"],
              "Bugs": ["Captcha bypass", "Race condition"],
              "Bounty": "-",
              "PublicationDate": "2019-11-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I paid 2$ for a 1054$ XSS bug + 20 chars blind XSS payloads",
                    "Link": "https://medium.com/@mohameddaher/how-i-paid-2-for-1054-xss-bug-20-chars-blind-xss-payloads-12d32760897b"
                 }
              ],
              "Authors": ["Mohamed Daher (@DaherMohamed4)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "1,054",
              "PublicationDate": "2019-11-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover via Campaignmonitor.com",
                    "Link": "https://web.archive.org/web/20200929013918/https://www.mohamedharon.com/2019/11/subdomain-takeover-via.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "900",
              "PublicationDate": "2019-11-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could delete Facebook Ask for Recommendations post’s place objects in comments",
                    "Link": "https://medium.com/@rajasudhakar/how-i-could-delete-facebook-ask-for-recommendations-posts-place-objects-in-comments-b7c9bcdf1c92"
                 }
              ],
              "Authors": ["Raja Sudhakar (@Rajasudhakar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-11-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken session management leads to bypass 2FA and Permanent access to Facebook user’s",
                    "Link": "https://medium.com/@0xBarakat/broken-session-permanent-access-to-facebook-users-cfed68684113"
                 }
              ],
              "Authors": ["Mahmoud Barakat (@0xBarakat)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose the owner of a recruiting manager in Jobs Beta",
                    "Link": "https://philippeharewood.com/disclose-the-owner-of-a-recruiting-manager-in-jobs-beta/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Million Users PII Leak Data Leak",
                    "Link": "https://medium.com/bugbountywriteup/million-users-pii-leak-attack-288c5e37b283"
                 }
              ],
              "Authors": ["Shivbihari Pandey (@ninja_pandit_)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Blind XSS"],
              "Bounty": "3,250",
              "PublicationDate": "2019-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in GMail’s AMP4Email via DOM Clobbering",
                    "Link": "https://research.securitum.com/xss-in-amp4email-dom-clobbering/"
                 }
              ],
              "Authors": ["Michał Bentkowski (@SecurityMB)"],
              "Programs": ["Google"],
              "Bugs": ["XSS", "DOM Clobbering"],
              "Bounty": "-",
              "PublicationDate": "2019-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This is How I was able to hunt a rare bug in a private program",
                    "Link": "https://medium.com/@abidafahd/how-i-was-able-to-hunt-a-rare-bug-in-a-private-program-caec0ebaef7f"
                 }
              ],
              "Authors": ["Abida Fahd"],
              "Programs": ["-"],
              "Bugs": ["Missing authentication", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2019-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Bug ($500)",
                    "Link": "https://medium.com/@abhishake100/my-first-bug-500-9222998e6249"
                 }
              ],
              "Authors": ["Abhishek Yadav (@abhishake100)"],
              "Programs": ["-"],
              "Bugs": ["No valid SPF records"],
              "Bounty": "500",
              "PublicationDate": "2019-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing the patch for my previous Instagram bug.",
                    "Link": "https://medium.com/bugbountywriteup/bypassing-the-fix-of-my-previous-instagram-bug-49ece4ea7e1d"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation with simple recon",
                    "Link": "https://medium.com/@Rising_Hunter/privilege-escalation-with-simple-recon-da4e50fea9e5"
                 }
              ],
              "Authors": ["Mayur Gupta (@RisingHunter_)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "LDAP Admin Account Bypassed :)",
                    "Link": "https://medium.com/@himanshu_pdy/ldap-admin-account-bypassed-2cc8b264d66e"
                 }
              ],
              "Authors": ["Himanshu Pdy (@himanshu_pdy)"],
              "Programs": ["-"],
              "Bugs": ["LDAP injection", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "View the ranked messenger users for any page",
                    "Link": "https://philippeharewood.com/view-the-ranked-messenger-users-for-any-page/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Writeup][Bug Bounty][Tokopedia] Manipulation of Likes in Product Reviews [EN]",
                    "Link": "https://fadhilthomas.github.io/post/bug-bounty-tokopedia-01-en/"
                 }
              ],
              "Authors": ["Muhammad Thomas Fadhila Yahya (@fadhilthomas)"],
              "Programs": ["Tokopedia"],
              "Bugs": ["IDOR"],
              "Bounty": "135",
              "PublicationDate": "2019-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authenticated CORS with Access-Control-Allow-Origin: *",
                    "Link": "https://web.archive.org/web/20220826045457/https://blog.bi.tk/chrome-cors/"
                 }
              ],
              "Authors": ["BitK (@BitK_)"],
              "Programs": ["Google (Chromium)"],
              "Bugs": ["Caching issue", "Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2019-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chains on Chains!! Chaining several IDOR’s into Account Takeover(PART ONE)",
                    "Link": "https://medium.com/@masonhck357/chains-on-chains-chaining-several-idors-into-account-takeover-part-one-373627f2910f"
                 }
              ],
              "Authors": ["Daniel Marte (@DanielM59720745)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Taking over Facebook Page Tabs",
                    "Link": "https://blog.sagarvd.me/2019/11/taking-over-facebook-page-tabs.html"
                 }
              ],
              "Authors": ["Taking over Facebook Page Tabs"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2019-11-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Server Side Request Forgery] Blind SSRF due to Sentry Misconfiguration",
                    "Link": "https://web.archive.org/web/20200908050502/https://kntx.xyz/Blind-SSRF-due-to-Sentry-Misconfiguration/"
                 }
              ],
              "Authors": ["Kent Bayron (@bayronkentoy)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "300",
              "PublicationDate": "2019-11-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Command Injection Through BLH",
                    "Link": "https://medium.com/@trapp3rhat/command-injection-through-blh-3c32614bb395"
                 }
              ],
              "Authors": ["Shankar R (@trapp3r_hat)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2019-11-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Mass XS-Search using Cache Attack",
                    "Link": "https://terjanq.github.io/Bug-Bounty/Google/cache-attack-06jd2d2mz2r0/index.html"
                 }
              ],
              "Authors": ["Terjanq (@terjanq)"],
              "Programs": ["Google"],
              "Bugs": ["XS-Search"],
              "Bounty": "-",
              "PublicationDate": "2019-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I accidentally took down GitHub Actions",
                    "Link": "https://blog.teddykatz.com/2019/11/12/github-actions-dos.html"
                 }
              ],
              "Authors": ["Teddy Katz (@not_aardvark)"],
              "Programs": ["GitHub"],
              "Bugs": ["DoS", "Commit Hash Collisions"],
              "Bounty": "5,000",
              "PublicationDate": "2019-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty: Broken API Authorization",
                    "Link": "https://medium.com/@th3hidd3nmist/bug-bounty-broken-api-authorization-d30c940ccb42"
                 }
              ],
              "Authors": ["Th3hidd3nmist (@th3_hidd3n_mist)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "440",
              "PublicationDate": "2019-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i Bought VPS, Hosting, Domain only $0.01",
                    "Link": "https://medium.com/@androgaming1912/got-vps-hosting-domain-only-0-01-bug-bounty-edeea1a7d5e6"
                 }
              ],
              "Authors": ["Zerb0a"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering"],
              "Bounty": "500",
              "PublicationDate": "2019-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Keylogging users via Slack themes",
                    "Link": "https://fletchto99.dev/2019/november/slack-vulnerability/"
                 }
              ],
              "Authors": ["Matt Langlois (@fletchto99)"],
              "Programs": ["Slack"],
              "Bugs": ["CSS injection"],
              "Bounty": "500",
              "PublicationDate": "2019-11-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First SSRF Using DNS Rebinding",
                    "Link": "https://geleta.eu/2019/my-first-ssrf-using-dns-rebinfing/"
                 }
              ],
              "Authors": ["Marek Geleta (@marek_geleta)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "DNS rebinding"],
              "Bounty": "-",
              "PublicationDate": "2019-11-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM-Based XSS | Bug Bounty Writeup",
                    "Link": "https://hacknpentest.com/dom-based-xss-bug-bounty-writeup/"
                 }
              ],
              "Authors": ["HacknPentest (@HacknPentest)"],
              "Programs": ["-"],
              "Bugs": ["DOM XSS"],
              "Bounty": "100",
              "PublicationDate": "2019-11-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BugBounty: How I Cracked 2FA (Two-Factor Authentication) with Simple Factor Brute-force !!! 😎",
                    "Link": "https://medium.com/clouddevops/bugbounty-how-i-cracked-2fa-two-factor-authentication-with-simple-factor-brute-force-a1c0f3a2f1b4"
                 }
              ],
              "Authors": ["Akash Agrawal (@akashmagrawal)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2019-11-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A simple post auth bypass leads to unauthorized web server access",
                    "Link": "https://medium.com/@heinthantzin/a-simple-post-auth-bypass-leads-to-unauthorized-web-server-access-483c053c110e"
                 }
              ],
              "Authors": ["Hein Thant Zin (@H3Lowr)"],
              "Programs": ["-"],
              "Bugs": ["Default credentials"],
              "Bounty": "750",
              "PublicationDate": "2019-11-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked Dutch Government in 5 Minutes? Twitter Account Takeover",
                    "Link": "https://web.archive.org/web/20200604001225/https://hackking.net/threads/how-i-hacked-dutch-government-in-5-minutes-twitter-account-takeover.20/"
                 }
              ],
              "Authors": ["Numan ÖZDEMİR (@numanozdemircom)"],
              "Programs": ["Dutch Government"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2019-11-06",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "BugBounty | A Simple SSRF",
                  "Link": "https://jinone.github.io/bugbounty-a-simple-ssrf/"
               }
            ],
            "Authors": ["Jinone (@jinonehk)"],
            "Programs": ["-"],
            "Bugs": ["SSRF", "DNS rebinding"],
            "Bounty": "1,500",
            "PublicationDate": "2019-11-05",
            "AddedDate": "2022-12-26"
         },
           {
              "Links": [
                 {
                    "Title": "Bypassing GitHub's OAuth flow",
                    "Link": "https://blog.teddykatz.com/2019/11/05/github-oauth-bypass.html"
                 }
              ],
              "Authors": ["Teddy Katz (@not_aardvark)"],
              "Programs": ["GitHub"],
              "Bugs": ["OAuth", "Authorization bypass"],
              "Bounty": "25,000",
              "PublicationDate": "2019-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BugBounty | A Simple SSRF",
                    "Link": "https://jinone.github.io/bugbounty-a-simple-ssrf/"
                 }
              ],
              "Authors": ["Jinone (@jinonehk)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "DNS rebinding"],
              "Bounty": "1,500",
              "PublicationDate": "2019-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS will never die",
                    "Link": "https://medium.com/@04sabsas/xss-will-never-die-eb3584081a5f"
                 }
              ],
              "Authors": ["Oleksandr Opanasiuk (@Lekssik2)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-11-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Filling in the Blanks: Exploiting Null Byte Buffer Overflow for a $40,000 Bounty",
                    "Link": "https://samcurry.net/filling-in-the-blanks-exploiting-null-byte-buffer-overflow-for-a-40000-bounty/"
                 }
              ],
              "Authors": ["Sam Curry (@samwcyo)"],
              "Programs": ["-"],
              "Bugs": ["Null byte buffer overflow", "Memory corruption"],
              "Bounty": "40,000",
              "PublicationDate": "2019-11-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Download this tool and you win",
                    "Link": "https://medium.com/@z0id/finding-open-redirects-like-a-pro-3b87fa474cfd"
                 }
              ],
              "Authors": ["zoid (@z0idsec)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-10-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Live Video facebook application (Android) its not expired when log out the device on https://www.facebook.com/settings?tab=security&section=sessions&view",
                    "Link": "https://medium.com/@naufalseptiadi/live-video-facebook-application-android-its-not-expired-when-log-out-the-device-on-4d4e0b67b362"
                 }
              ],
              "Authors": ["Naufal Septiadi"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2019-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GraphQL introspection leads to sensitive data disclosure.",
                    "Link": "https://medium.com/@R0X4R/graphql-introspection-leads-to-sensitive-data-disclosure-714f1d9d9d4a"
                 }
              ],
              "Authors": ["Eshan Singh (@R0X4R)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "5,000 USD XSS Issue at Avast Desktop AntiVirus for Windows (Yes, Desktop!)",
                    "Link": "https://medium.com/bugbountywriteup/5-000-usd-xss-issue-at-avast-desktop-antivirus-for-windows-yes-desktop-1e99375f0968"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["Avast"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2019-10-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cross Site Request Forgery Critical Exploitable IN Infected Site?",
                    "Link": "https://medium.com/@Hossam.Mesbah/cross-site-request-forgery-critical-exploitable-in-infected-site-a271aedeed2f"
                 }
              ],
              "Authors": ["Hossam Mesbah"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-10-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS to Account Takeover",
                    "Link": "https://noobe.io/articles/2019-10/xss-to-account-takeover"
                 }
              ],
              "Authors": ["Tomi (@noobe_io)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-10-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Leak] Can I take the user information, please?!!",
                    "Link": "https://flex0geek.blogspot.com/2019/10/leak-can-i-take-user-information-please.html"
                 }
              ],
              "Authors": ["Mohamed Sayed (@FlEx0Geek)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-10-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked 50+ Companies in 6 hrs",
                    "Link": "https://medium.com/vault-infosec/how-i-hacked-50-companies-in-6-hrs-7ec0368a9196"
                 }
              ],
              "Authors": ["Vignesh C (@pwn_r00t)"],
              "Programs": ["-"],
              "Bugs": ["SSTI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-10-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Android Reddit App leaks images",
                    "Link": "http://www.hydrogen18.com/blog/reddit-android-app-leaks-images.html"
                 }
              ],
              "Authors": ["Eric Urban"],
              "Programs": ["Reddit"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-10-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Illegal Rendered at Download Feature in Several Apps (including Opera Mini) that Lead to Extension Manipulation (with RTLO)",
                    "Link": "http://firstsight.me/2019/10/illegal-rendered-at-download-feature-in-several-apps-including-opera-mini-that-lead-to-extension-manipulation-with-rtlo/"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["Opera"],
              "Bugs": ["RTLO"],
              "Bounty": "-",
              "PublicationDate": "2019-10-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to Takover a ldap server.",
                    "Link": "https://medium.com/@D0rkerDevil/how-i-tookover-a-ldap-server-703209161001"
                 }
              ],
              "Authors": ["Ashish Kunwar (@D0rkerDevil)"],
              "Programs": ["-"],
              "Bugs": ["Misconfigured LDAP server"],
              "Bounty": "-",
              "PublicationDate": "2019-10-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Session Expiration Bypass in Facebook Creator App",
                    "Link": "https://medium.com/@evilboyajay/session-expiration-bypass-in-facebook-creator-app-b4f65cc64ce4"
                 }
              ],
              "Authors": ["Ajay Gautam (@evilboyajay)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Session expiration issue"],
              "Bounty": "1,500",
              "PublicationDate": "2019-10-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Responsible denial of service with web cache poisoning",
                    "Link": "https://portswigger.net/research/responsible-denial-of-service-with-web-cache-poisoning"
                 }
              ],
              "Authors": ["James Kettle (@albinowax)"],
              "Programs": ["Tesla", "HackerOne", "Deliveroo", "Bitbucket", "Paypal", "Meta / Facebook", "Twitter"],
              "Bugs": ["DoS", "Web cache poisoning", "CPDoS"],
              "Bounty": "22,300",
              "PublicationDate": "2019-10-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned $$$$ by finding confidential customer data including plain-text passwords!",
                    "Link": "https://medium.com/@saurabh5392/how-i-earned-by-finding-confidential-customer-data-including-plain-text-passwords-f93c4ce2631"
                 }
              ],
              "Authors": ["Sushant Soni (@sushantsoni5392)"],
              "Programs": ["-"],
              "Bugs": ["Directory listing", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-10-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "NFC Beaming Bypasses Security Controls in Android [CVE-2019-2114]",
                    "Link": "https://wwws.nightwatchcybersecurity.com/2019/10/24/nfc-beaming-bypasses-security-controls-in-android-cve-2019-2114/"
                 }
              ],
              "Authors": ["Nightwatch Cybersecurity (@nightwatchcyber)"],
              "Programs": ["Google"],
              "Bugs": ["NFC", "Android"],
              "Bounty": "-",
              "PublicationDate": "2019-10-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CPDoS: Cache Poisoned Denial of Service",
                    "Link": "https://cpdos.org"
                 }
              ],
              "Authors": ["Hoai Viet Nguyen (@hvnguyen86)", "Luigi Lo Iacono, and Hannes Federrath"],
              "Programs": ["Microsoft", "Amazon", "Akamai", "Cloudflare", "Yahoo! / Verizon Media", "Play Framework"],
              "Bugs": ["DoS", "Web cache poisoning", "CPDoS"],
              "Bounty": "-",
              "PublicationDate": "2019-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "(POC) Disclose members in any closed Facebook group",
                    "Link": "https://medium.com/@edmundaa222/poc-disclose-members-in-any-closed-facebook-group-259783fa4bf"
                 }
              ],
              "Authors": ["Ahmad Talahmeh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "3,000",
              "PublicationDate": "2019-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[ BUG BOUNTY ] Flaw in Authentication ( Hall of Fame Google )",
                    "Link": "https://medium.com/@danangtriatmaja/bug-bounty-flaw-in-authentication-get-hall-of-fame-google-6196726ee5b9"
                 }
              ],
              "Authors": ["Danang Tri Atmaja (@danangtriatmj)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2019-10-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How PayPal helped me to generate XSS",
                    "Link": "https://medium.com/@pflash0x0punk/how-paypal-helped-me-to-generate-xss-9408c0931add"
                 }
              ],
              "Authors": ["Pflash Punk (@PflashPunk)"],
              "Programs": ["Paypal"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "250",
              "PublicationDate": "2019-10-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating Privileges like a Pro",
                    "Link": "https://gauravnarwani.com/escalating-privileges-like-a-pro/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2019-10-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting for bounties antihack.me case study",
                    "Link": "https://0xsha.io/posts/hunting-for-bounties-antihackme-case-study"
                 }
              ],
              "Authors": ["0xSha (@0xsha)"],
              "Programs": ["AntiHack.me"],
              "Bugs": ["RCE", "XSS", "Logic flaw", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-10-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Tale of Exploitation in Spreadsheet File Conversions",
                    "Link": "https://buer.haus/2019/10/18/a-tale-of-exploitation-in-spreadsheet-file-conversions/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)", "Cody Brocious (@daeken)", "Sam Erb (@erbbysam)", "Olivier Beg (@smiegles)"],
              "Programs": ["Slack"],
              "Bugs": ["Local file disclosure (LFD)", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-10-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "1-800-Flowers Credentials and message log leak via facebook.com/facebook",
                    "Link": "https://philippeharewood.com/1-800-flowers-credentials-and-message-log-leak-via-facebook-com-facebook/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2019-10-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to bypass OTP code requirement in Razer [The story of a critical bug]",
                    "Link": "https://medium.com/bugbountywriteup/how-i-was-able-to-bypass-otp-token-requirement-in-razer-the-story-of-a-critical-bug-fc63a94ad572"
                 }
              ],
              "Authors": ["Ananda Dhakal (@dhakal_ananda)"],
              "Programs": ["Razer"],
              "Bugs": ["OTP bypass"],
              "Bounty": "1,000",
              "PublicationDate": "2019-10-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found RCE But Got Duplicated",
                    "Link": "https://medium.com/@smilehackerofficial/how-i-found-rce-but-got-duplicated-ea7b8b010990"
                 }
              ],
              "Authors": ["Smile Hacker"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-10-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I bypassed 2 Factor Authentication",
                    "Link": "https://medium.com/@manralhemant10/how-i-bypassed-2-factor-authentication-899750421331"
                 }
              ],
              "Authors": ["Hemant Singh Manral"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "250",
              "PublicationDate": "2019-10-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An inconsistent CSRF",
                    "Link": "https://smaranchand.com.np/2019/10/an-inconsistent-csrf/"
                 }
              ],
              "Authors": ["Smaran Chand (@smaranchand)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-10-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding SQL injections fast with white-box analysis — a recent bug example",
                    "Link": "https://medium.com/@frycos/finding-sql-injections-fast-with-white-box-analysis-a-recent-bug-example-ca449bce6c76"
                 }
              ],
              "Authors": ["Florian Hauser (@frycos)"],
              "Programs": ["Zoho"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2019-10-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Whitehat test accounts can act as Hidden Admin with Business manager / Ad Accounts.",
                    "Link": "https://medium.com/@rohitcoder/whitehat-test-accounts-can-act-as-hidden-admin-with-business-manager-ad-accounts-ce75ead5ffff"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass Uppercase filters like a PRO (XSS Advanced Methods)",
                    "Link": "https://medium.com/@Master_SEC/bypass-uppercase-filters-like-a-pro-xss-advanced-methods-daf7a82673ce"
                 }
              ],
              "Authors": ["MasterSEC (@MasterSEC_AR)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2019-10-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i Hacked BASF Company !!",
                    "Link": "https://medium.com/@r99tiq/how-i-hacked-basf-company-3b75ef39c74f"
                 }
              ],
              "Authors": ["Murtada Kamil"],
              "Programs": ["BASF"],
              "Bugs": ["Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2019-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "EXIF Geolocation Data Not Stripped From Uploaded Images",
                    "Link": "https://medium.com/@souravnewatia/exif-geolocation-data-not-stripped-from-uploaded-images-794d20d2fa7d"
                 }
              ],
              "Authors": ["Sourav Newatia (@souravnewatia)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2019-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerability To Bypass Clickjacking Protection In Youtube",
                    "Link": "https://spidersec.ninja/Youtube-X-frame-options-Bypass-Vulnerability"
                 }
              ],
              "Authors": ["spidersec (@SpiderSec)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2019-10-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How “Recon” helped Samsung protect their production repositories of SamsungTv, eCommerce / eStores",
                    "Link": "https://blog.usejournal.com/how-recon-helped-samsung-protect-their-production-repositories-of-samsungtv-ecommerce-estores-4c51d6ec4fdd"
                 }
              ],
              "Authors": ["Prateek Tiwari"],
              "Programs": ["Samsung"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-10-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Multiple IDORs leading to Code Execution on a different Host Container",
                    "Link": "https://rahulr.in/idor-to-rce/"
                 }
              ],
              "Authors": ["Rahul (@Rahul_R95)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-10-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made 1000$ with AT&T Bug Bounty(H1)",
                    "Link": "https://web.archive.org/web/20201128230506/https://medium.com/@adeshkolte/how-i-made-1000-at-t-bug-bounty-h1-14e68b284e2f"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["AT&T"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "1,000",
              "PublicationDate": "2019-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "REST framework Admin Panel bypass and how I recon for this vulnerability",
                    "Link": "https://medium.com/@hackerb0y/rest-framework-admin-panel-bypass-and-how-i-recon-for-this-vulnerability-a0ee41b01102"
                 }
              ],
              "Authors": ["Aziz Hakim (@hackerb0y_)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GraphQL Introspection leads to Sensitive Data Disclosure.",
                    "Link": "https://medium.com/@pranaybafna/graphql-introspection-leads-to-sensitive-data-disclosure-65b385452d7f"
                 }
              ],
              "Authors": ["Pranay Bafna"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How a double-free bug in WhatsApp turns to RCE",
                    "Link": "https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/"
                 }
              ],
              "Authors": ["Awakened"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Memory corruption", "RCE", "Android"],
              "Bounty": "-",
              "PublicationDate": "2019-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to get RCE on AEM instance without Java knowledge",
                    "Link": "https://medium.com/@byq/how-to-get-rce-on-aem-instance-without-java-knowledge-a995ceab0a83"
                 }
              ],
              "Authors": ["byq (@ByQwert)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "1,000",
              "PublicationDate": "2019-10-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing login credentials with Reflected XSS",
                    "Link": "https://medium.com/@mehulcodes/stealing-login-credentials-with-reflected-xss-7cb450bf5710"
                 }
              ],
              "Authors": ["mehulpanchal007 (@007_sharky)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "100",
              "PublicationDate": "2019-10-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One Way to Find Hidden IDOR Vulnerability",
                    "Link": "https://web.archive.org/web/20200807155301/https://gh0st.cn/archives/2019-10-01/1"
                 }
              ],
              "Authors": ["Vulkey_Chen (@Vulkey_Chen)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "28",
              "PublicationDate": "2019-10-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Hunting: Xss On Cookie Popup Warning",
                    "Link": "https://web.archive.org/web/20191211081434/https://victoni.github.io/bug-hunting-xss-on-cookie-popup-warning/"
                 },
                 {
                  "Title": "Alternative link",
                  "Link": "https://0x00sec.org/t/xss-on-cookie-pop-up/19580"
               }
               ],
              "Authors": ["vict0ni (@vict0ni)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-09-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spear texting via parameter injection",
                    "Link": "https://b3nac.com/posts/2019-09-02-Spear-Texting-Via-Parameter-Injection.html"
                 }
              ],
              "Authors": ["Kyle (@B3nac)"],
              "Programs": ["-"],
              "Bugs": ["Parameter tampering"],
              "Bounty": "900",
              "PublicationDate": "2019-09-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stories Of IDOR",
                    "Link": "https://medium.com/@hackrider/stories-of-idor-4966369e6d82"
                 }
              ],
              "Authors": ["Shivbihari Pandey (@ninja_pandit_)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-09-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OnePlus Open/Unvalidated Redirects & Forwards",
                    "Link": "https://web.archive.org/web/20191217020747/https://medium.com/@tech96bot/oneplus-open-unvalidated-redirects-forwards-234185215f33"
                 }
              ],
              "Authors": ["Mainak Sadhukhan"],
              "Programs": ["OnePLus"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-09-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Analysis of CVE-2019-14994 – Jira Service Desk Path Traversal leads to Massive Information Disclosure",
                    "Link": "https://samcurry.net/analysis-of-cve-2019-14994/"
                 }
              ],
              "Authors": ["Sam Curry (@samwcyo)"],
              "Programs": ["Atlassian"],
              "Bugs": ["Path traversal"],
              "Bounty": "11,000",
              "PublicationDate": "2019-09-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Information Disclosure at PayPal and Xoom (PayPal Acquisition) via Simple Google Dork - 1,000 USD",
                    "Link": "https://medium.com/bugbountywriteup/information-disclosure-at-paypal-and-xoom-paypal-acquisition-via-simple-google-dork-1-000-usd-b726fe628a05"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["Paypal"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,000",
              "PublicationDate": "2019-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ONEPLUS XSS vulnerability in Customer Support Portal",
                    "Link": "https://web.archive.org/web/20191218184636/https://medium.com/@tech96bot/oneplus-xss-vulnerability-in-customer-support-portal-d5887a7367f4"
                 }
              ],
              "Authors": ["Mainak Sadhukhan"],
              "Programs": ["OnePLus"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fuzzing {{7*7}} Till {{P1}}",
                    "Link": "http://verneet.com/fuzzing-77-till-p1/"
                 }
              ],
              "Authors": ["Verneet (@err0rrrrr)"],
              "Programs": ["-"],
              "Bugs": ["SSTI"],
              "Bounty": "-",
              "PublicationDate": "2019-09-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Link Hijacking - s3 buckets",
                    "Link": "https://tutorgeeks.blogspot.com/2019/09/broken-link-hijacking-s3-buckets.html"
                 }
              ],
              "Authors": ["Tutorgeeks (@tutorgeeks)"],
              "Programs": ["Google"],
              "Bugs": ["Broken link hijacking"],
              "Bounty": "-",
              "PublicationDate": "2019-09-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Bug Bounty] Exploiting Cookie Based XSS by Finding RCE",
                    "Link": "https://noobe.io/articles/2019-09/exploiting-cookie-based-xss-by-finding-rce"
                 }
              ],
              "Authors": ["Tomi (@noobe_io)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "SQL injection", "Authentication bypass", "Unrestricted file upload", "RCE", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-09-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Case Study] OAuth Misconfiguration leads to Account Takeover",
                    "Link": "https://medium.com/@0xgaurang/case-study-oauth-misconfiguration-leads-to-account-takeover-d3621fe8308b"
                 }
              ],
              "Authors": ["Gaurang Bhatnagar (@0xgaurang)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Workplace Privilege Escalation Vulnerability To Change The Post Privacy As Public",
                    "Link": "https://medium.com/bugbountywriteup/facebook-workplace-privilege-escalation-vulnerability-to-change-the-post-privacy-as-public-634f1c995780"
                 }
              ],
              "Authors": ["Guhan Raja (@havocgwen)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "500",
              "PublicationDate": "2019-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Simple bypass of Registration Activation that Lead to many Bug -",
                    "Link": "https://web.archive.org/web/20191214144210/https://medium.com/bugbountywriteup/a-simple-bypass-of-registration-activation-that-lead-to-many-bug-a-story-about-how-my-friend-5df0889f1062"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "IDOR", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug or Feature? GitHub Adventure #001",
                    "Link": "https://medium.com/oad-earth/bug-or-feature-github-adventure-001-eae9bea48ae8"
                 }
              ],
              "Authors": ["Dominik Opyd (@oad_earth)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on Zendesk via Macro’s PART 2",
                    "Link": "https://medium.com/@hariharan21/stored-xss-on-zendesk-via-macros-part-2-676cefee4616"
                 }
              ],
              "Authors": ["Hariharan.s (@DJHARIZ1)"],
              "Programs": ["Zendesk"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I able to Takeover 10 subdomains in a Private Program ?",
                    "Link": "https://web.archive.org/web/20201102112116/https://www.mohamedharon.com/2019/09/how-i-able-to-takeover-10-subdomains-in.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "500",
              "PublicationDate": "2019-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business ID leak via Creative Hub redirect",
                    "Link": "https://philippeharewood.com/business-id-leak-via-creative-hub-redirect/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Admin hijacked by Sea Surf Pirates",
                    "Link": "https://gauravnarwani.com/admin-hijacked-by-sea-surf-pirates/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["Dolibarr"],
              "Bugs": ["Stored XSS", "CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF | Reading Local Files from DownNotifier server",
                    "Link": "https://www.openbugbounty.org/blog/leonmugen/ssrf-reading-local-files-from-downnotifier-server/"
                 }
              ],
              "Authors": ["Dr.FarFar (@3XS0)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-09-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE with Flask Jinja Template Injection",
                    "Link": "https://medium.com/@akshukatkar/rce-with-flask-jinja-template-injection-ea5d0201b870"
                 }
              ],
              "Authors": ["AkShAy KaTkAr (@AkShAy KaTkAr)"],
              "Programs": ["-"],
              "Bugs": ["SSTI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-09-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Client, not client!",
                    "Link": "https://medium.com/@tungpun/client-not-client-aa448cfdedd2"
                 }
              ],
              "Authors": ["Tung Pun"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "1,000",
              "PublicationDate": "2019-09-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Referer Leak Bug",
                    "Link": "https://medium.com/@jayateerthag/google-referer-leak-bug-434f6293ce66"
                 }
              ],
              "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
              "Programs": ["Google"],
              "Bugs": ["Referer leakage", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-09-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found a simple and weird Account takeover bug",
                    "Link": "https://web.archive.org/web/20200820030055/https://pwnsec.ninja/2019/09/14/how-i-found-a-simple-and-weird-account-takeover-bug/"
                 }
              ],
              "Authors": ["Bijan Murmu (@0xBijan)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2019-09-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OTP Manipulation",
                    "Link": "https://kishanchoudhary.com/OTP/otp_manipulation.html"
                 }
              ],
              "Authors": ["Kishan choudhary (@choudhary_1337)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass"],
              "Bounty": "300",
              "PublicationDate": "2019-09-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Race Condition that could Result to RCE - (A story with an App that temporary stored an uploaded file within 2 seconds before moving it to Amazon S3)",
                    "Link": "https://medium.com/bugbountywriteup/race-condition-that-could-result-to-rce-a-story-with-an-app-that-temporary-stored-an-uploaded-9a4065368ba3"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["-"],
              "Bugs": ["Race condition", "RCE", "Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2019-09-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I Could Have Hacked All Uber Accounts- But I Chose to Report it Instead",
                    "Link": "https://hackernoon.com/how-i-could-have-hacked-all-uber-accounts-rtzl3z72"
                 }
              ],
              "Authors": ["Anand Prakash (@anandpraka_sh)"],
              "Programs": ["Uber"],
              "Bugs": ["Information disclosure"],
              "Bounty": "6,500",
              "PublicationDate": "2019-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How two dead accounts allowed remote crash of any instagram android user",
                    "Link": "https://www.valbrux.it/blog/2019/09/13/how-two-dead-users-allowed-remote-crash-of-any-instagram-android-user/"
                 }
              ],
              "Authors": ["Valerio brussani (@val_brux)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2019-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthorized access to all user information leaks",
                    "Link": "https://medium.com/@cc1h2e1/unauthorized-access-to-all-user-information-leaks-5db95746aecf"
                 }
              ],
              "Authors": ["C1h2e1 (@C1h2e11)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HTTP Request Smuggling CL.TE",
                    "Link": "https://memn0ps.github.io/http-request-smuggling-cl-te/"
                 }
              ],
              "Authors": ["memN0ps (@memN0ps)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "-",
              "PublicationDate": "2019-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting File Uploads Pt. 2 – A Tale of a $3k worth RCE.",
                    "Link": "https://anotherhackerblog.com/exploiting-file-uploads-pt-2/"
                 }
              ],
              "Authors": ["HackerOn2Wheels (@HackerOn2Wheels)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "3,000",
              "PublicationDate": "2019-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook employee internal tool and conversations leaked in Facebook video",
                    "Link": "https://philippeharewood.com/facebook-employee-internal-tool-and-conversations-and-leaked-in-facebook-video/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-09-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How does my recon win $250 in 15 minutes",
                    "Link": "https://medium.com/@heinthantzin/how-does-my-recon-win-250-in-15-minutes-a1992508b911"
                 }
              ],
              "Authors": ["Hein Thant Zin (@H3Lowr)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "250",
              "PublicationDate": "2019-09-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Add users to roles on Facebook pages without an invitation consent",
                    "Link": "https://philippeharewood.com/add-users-to-roles-on-facebook-pages-without-an-invitation-consent/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-09-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwn Them All #BugBounty",
                    "Link": "https://medium.com/@bilalmerokhel/pwn-them-all-bugbounty-4ee60e13c83"
                 }
              ],
              "Authors": ["Bilal Khan (@bilalmerokhel)"],
              "Programs": ["-"],
              "Bugs": ["Host header injection", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2019-09-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subscribe to the list of requesters to join a Facebook live video using MQTT",
                    "Link": "https://philippeharewood.com/subscribe-to-the-list-of-requesters-to-join-a-facebook-live-video-using-mqtt/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "H1-4420: From Quiz to Admin - Chaining Two 0-Days to Compromise An Uber Wordpress",
                    "Link": "https://www.rcesecurity.com/2019/09/H1-4420-From-Quiz-to-Admin-Chaining-Two-0-Days-to-Compromise-an-Uber-Wordpress/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["Uber"],
              "Bugs": ["Stored XSS", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2019-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Telegram addresses another privacy issue",
                    "Link": "https://www.inputzero.io/2019/09/telegram-privacy-fails-again.html"
                 }
              ],
              "Authors": ["Dhiraj (@RandomDhiraj)"],
              "Programs": ["Telegram"],
              "Bugs": ["Logic flaw", "Privacy issue"],
              "Bounty": "2,500",
              "PublicationDate": "2019-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accessing 2 million Verizon Pay Monthly contracts",
                    "Link": "https://web.archive.org/web/20191109194557/https://daleys.space/writeup/0day/2019/09/09/verizon-leak.html"
                 }
              ],
              "Authors": ["Daley Bee (@daley)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Information disclosure", "Authentication bypass", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Oculus identity verification bypass through brute-force",
                    "Link": "https://medium.com/@karthiksoft007/oculus-identity-verification-bypass-through-brute-force-dbd0c0d3c37e"
                 }
              ],
              "Authors": ["karthik kumar reddy (@karthiksunny007)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["OTP bypass", "Lack of rate limiting"],
              "Bounty": "750",
              "PublicationDate": "2019-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Zoho Mail",
                    "Link": "https://www.hackerinside.me/2019/09/xss-in-zoho-mail.html"
                 }
              ],
              "Authors": ["Anas Mahmood (@AnasIsHere)"],
              "Programs": ["Zoho"],
              "Bugs": ["XSS"],
              "Bounty": "200",
              "PublicationDate": "2019-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting JSONP and Bypassing Referer Check",
                    "Link": "https://medium.com/@osamaavvan/exploiting-jsonp-and-bypassing-referer-check-2d6e40dfa24"
                 }
              ],
              "Authors": ["Osama Avvan (@osamaavvan)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "JSONP"],
              "Bounty": "-",
              "PublicationDate": "2019-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write up of two HTTP Requests Smuggling",
                    "Link": "https://medium.com/@cc1h2e1/write-up-of-two-http-requests-smuggling-ff211656fe7d"
                 }
              ],
              "Authors": ["C1h2e1 (@C1h2e11)"],
              "Programs": ["-"],
              "Bugs": ["HTTP request smuggling"],
              "Bounty": "-",
              "PublicationDate": "2019-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding Gem in Someone’s Report: Instant $500USD at HackerOne Platform",
                    "Link": "https://medium.com/@hisokamorou12/finding-gem-in-someones-report-instant-500usd-at-hackerone-platform-9a1afa0df813"
                 }
              ],
              "Authors": ["Hisoka Morou"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2019-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Super Glamorous Recon with Intended Functionalities",
                    "Link": "https://hateshape.github.io/general/2019/09/06/SuperGlamorousReconwithIntendedFunctionalities.html"
                 }
              ],
              "Authors": ["hateshape (@hateshaped)"],
              "Programs": ["-"],
              "Bugs": ["SSTI", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-09-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM Based XSS in Private Program",
                    "Link": "https://web.archive.org/web/20201222140349/https://www.mohamedharon.com/2019/09/dom-based-xss-in-private-program.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["DOM XSS"],
              "Bounty": "500",
              "PublicationDate": "2019-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Readme.com Account Takeover",
                    "Link": "https://medium.com/@0xankush/readme-com-account-takeover-bugbounty-fulldisclosure-a36ddbe915be"
                 }
              ],
              "Authors": ["Ankush Goel (@0xankush)"],
              "Programs": ["Readme.com"],
              "Bugs": ["Password reset"],
              "Bounty": "-",
              "PublicationDate": "2019-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exposed Jenkins to RCE on 8 Adobe Experience Managers",
                    "Link": "https://corben.io/blog/19-9-04-jenkins-to-full-pwnage"
                 }
              ],
              "Authors": ["Corben Leo (@hacker_)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Exposed Jenkins instance"],
              "Bounty": "-",
              "PublicationDate": "2019-09-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Add new user with Admin permission and takeover the organization",
                    "Link": "https://medium.com/@tarekmohamed_20773/add-new-user-with-admin-permission-and-takeover-the-organization-6318ee10154a"
                 }
              ],
              "Authors": ["Tarek Mohamed (@Conan0x3)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2019-09-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE using Path Traversal",
                    "Link": "https://web.archive.org/web/20201120053519/https://incogbyte.github.io/pathtraversal/"
                 }
              ],
              "Authors": ["inc0gbyt3 (@incogbyte)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2019-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HTML to PDF converter bug leads to RCE in Facebook server",
                    "Link": "https://ysamm.com/?p=280"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["RCE"],
              "Bounty": "1,000",
              "PublicationDate": "2019-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Cloud Blog platform vulnerability",
                    "Link": "https://www.loosebyte.com/google-cloud-vulnerability/"
                 }
              ],
              "Authors": ["Alexandru Coltuneac (@dekeeu)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-09-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Graphql Bug to Steal Anyone’s Address",
                    "Link": "https://blog.usejournal.com/graphql-bug-to-steal-anyones-address-fc34f0374417"
                 }
              ],
              "Authors": ["Pratik Yadav (@PratikY9967)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "GraphQL"],
              "Bounty": "-",
              "PublicationDate": "2019-09-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First LFI",
                    "Link": "https://cyberzombie.in/my-first-lfi/"
                 }
              ],
              "Authors": ["Tirtha Mandal (@tirtha_mandal)"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "1,000",
              "PublicationDate": "2019-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Shodan is your friend!!! If you ignore him you will lose many…",
                    "Link": "https://medium.com/@bathinivijaysimhareddy/shodan-is-your-friend-if-you-lose-him-you-will-lose-many-657d07472f75"
                 }
              ],
              "Authors": ["Vijaysimha Reddy Bathini (@fatratfatrat)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-08-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Address bar spoofing in Firefox Lite for Android ...and the idiocy that followed",
                    "Link": "https://blog.0x48piraj.com/address-bar-spoofing-in-firefox-lite-for-android-and-the-idiocy-that-followed/"
                 }
              ],
              "Authors": ["Piyush Raj (@0x48piraj)"],
              "Programs": ["Mozilla"],
              "Bugs": ["Address Bar Spoofing", "URL spoofing"],
              "Bounty": "-",
              "PublicationDate": "2019-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to look for JS files Vulnerability for fun and profit?",
                    "Link": "https://medium.com/@Skylinearafat/how-to-look-for-js-files-vulnerability-for-fun-and-profit-78bfdfbd6731"
                 }
              ],
              "Authors": ["Yeasir Arafat"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-08-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Private bug bounty $$,$$$ USD: “RCE as root on Marathon-Mesos instance”",
                    "Link": "https://omespino.com/write-up-private-bug-bounty-usd-rce-as-root-on-marathon-instance/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-08-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to exploit the same endpoint 2 times ( multiple xss & open Redirection on 10 subdomain)",
                    "Link": "https://medium.com/@ratnadip1998/how-i-was-able-to-exploit-the-same-endpoint-2-times-multiple-xss-open-redirection-on-10-5d12886f823d"
                 }
              ],
              "Authors": ["Ratnadip Gajbhiye (@scspcommunity)"],
              "Programs": ["Sanity.io"],
              "Bugs": ["XSS", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-08-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked Instagram Again",
                    "Link": "https://thezerohack.com/hack-instagram-again"
                 }
              ],
              "Authors": ["Laxman Muthiyah (@LaxmanMuthiyah)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "10,000",
              "PublicationDate": "2019-08-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty: Bypassing a crappy WAF to exploit a blind SQL injection",
                    "Link": "https://robinverton.de/blog/2019/08/25/bug-bounty-bypassing-a-crappy-waf-to-exploit-a-blind-sql-injection/"
                 }
              ],
              "Authors": ["Robin Verton (@robinverton)"],
              "Programs": ["-"],
              "Bugs": ["Blind SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2019-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Create living room polls as a Facebook page analyst",
                    "Link": "https://philippeharewood.com/create-living-room-polls-as-a-facebook-page-analyst/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "5,000",
              "PublicationDate": "2019-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Github Recon To Account Takeover",
                    "Link": "https://addictivehackers.blogspot.com/2019/08/from-github-recon-to-account-takeover.html"
                 }
              ],
              "Authors": ["Dipak kumar Das (@d1pakdas)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cookie worth a fortune",
                    "Link": "https://gauravnarwani.com/cookie-worth-a-fortune/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-08-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One Bug To Rule Them All: Modern Android Password Managers and FLAG_SECURE Misuse",
                    "Link": "https://blog.doyensec.com/2019/08/22/modern-password-managers-flag-secure.html"
                 }
              ],
              "Authors": ["Lorenzo Stella (@lorenzostella)"],
              "Programs": ["1Password", "Keeper", "Dashlane"],
              "Bugs": ["Information disclosure", "Content leak"],
              "Bounty": "-",
              "PublicationDate": "2019-08-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Rights Manager Graph API Disclosure of business employee to non business employee",
                    "Link": "https://www.updatelap.com/2019/08/Rights-Manager-Graph-API-Disclosure-of-business-employee-to-non-business-employee.html"
                 }
              ],
              "Authors": ["Jafar Abo Nada (@Jafar_Abo_Nada)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-08-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Instagram account is reactivated without entering 2FA ($500)",
                    "Link": "https://bugbountypoc.com/instagram-account-is-reactivated-without-entering-2fa/"
                 }
              ],
              "Authors": ["Aman Shahid (@amansmughal)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["2FA / MFA bypass", "Broken authentication"],
              "Bounty": "500",
              "PublicationDate": "2019-08-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sending Message as page being an analyst/ advertiser?",
                    "Link": "https://medium.com/@baibhavanandjha/sending-message-as-page-being-an-analyst-advertiser-eb0317376f43"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-08-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I made my first $$$ from finding a bug in Facebook",
                    "Link": "https://medium.com/@aayushpokhrel/how-i-made-my-first-from-finding-a-bug-in-facebook-da3b11e550f0"
                 }
              ],
              "Authors": ["Aayush Pokhrel (@aayushpok)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-08-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I upgraded my privileges to the administrator of Odnoklassniki’s url shortener",
                    "Link": "https://medium.com/@iframe_h1/how-i-upgraded-my-privileges-to-the-administrator-of-odnoklassnikis-url-shortener-2c58f996d02c"
                 }
              ],
              "Authors": ["Sergey Kashatov (@iframe0x01)"],
              "Programs": ["ok.ru"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "500",
              "PublicationDate": "2019-08-20",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Kaspersky in the Middle – what could possibly go wrong?",
                  "Link": "https://palant.info/2019/08/19/kaspersky-in-the-middle--what-could-possibly-go-wrong/"
               }
            ],
            "Authors": ["Wladimir Palant (@WPalant)"],
            "Programs": ["Kaspersky"],
            "Bugs": ["Clickjacking", "Universal XSS", "MiTM"],
            "Bounty": "-",
            "PublicationDate": "2019-08-19",
            "AddedDate": "2022-12-09"
         },
           {
              "Links": [
                 {
                    "Title": "Facebook Bug Bounty: Reading WhatsApp contacts list without unlocking the device",
                    "Link": "https://medium.com/@ar_arvind/facebook-bug-bounty-reading-whatsapp-contacts-list-without-unlocking-the-device-a40e9c660a42"
                 }
              ],
              "Authors": ["Arvind (@ar_arv1nd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-08-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "U.S. Department of Defense - Info Disclosure and SQLi Writeup",
                    "Link": "https://aaronesau.com/blog/posts/5"
                 }
              ],
              "Authors": ["Aaron Esau (@arinerron)"],
              "Programs": ["U.S. Dept Of Defense"],
              "Bugs": ["Information disclosure", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2019-08-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Removing profile pictures for any Facebook user",
                    "Link": "https://philippeharewood.com/removing-profile-pictures-for-any-facebook-user/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "2,500",
              "PublicationDate": "2019-08-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Add users to roles on Facebook pages without an invitation consent (revisited)",
                    "Link": "https://philippeharewood.com/add-users-to-roles-on-facebook-pages-without-an-invitation-consent-revisited/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-08-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to earn 1000$ with just 10 minutes of bug bounty?",
                    "Link": "https://ninadmathpati.com/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty/"
                 }
              ],
              "Authors": ["Ninad Mathpati (@ninad_mathpati)"],
              "Programs": ["-"],
              "Bugs": ["Password reset"],
              "Bounty": "1,000",
              "PublicationDate": "2019-08-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ByPassing fix of Domain Blocking feature in Business Manager",
                    "Link": "https://medium.com/@rohitcoder/bypassing-fix-of-domain-blocking-feature-in-business-manager-41949a18460c"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-08-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Messenger exposing deleted messages using [Remove for Everyone]",
                    "Link": "https://medium.com/@renwa/facebook-messenger-disclosing-deleted-messages-that-has-been-deleted-by-remove-for-everyone-1fb5a52cc7df"
                 }
              ],
              "Authors": ["Renwa (@RenwaX23)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-08-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BookMyShow account takeover using social login",
                    "Link": "https://medium.com/@madguyyy/bookmyshow-account-takeover-using-social-login-84178f116e42"
                 }
              ],
              "Authors": ["Sukhmeet Singh (@MadGuyyy)"],
              "Programs": ["BookMyShow"],
              "Bugs": ["OAuth", "Account takeover"],
              "Bounty": "28",
              "PublicationDate": "2019-08-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Business Logic] Bypassing Nickname Feature",
                    "Link": "https://web.archive.org/web/20200722032242/https://kntx.xyz/Bypassing-Nickname-Feature/"
                 }
              ],
              "Authors": ["Kent Bayron / kntx (@bayronkentoy)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "50",
              "PublicationDate": "2019-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BugBounty WriteUp — take attention and get Stored XSS",
                    "Link": "https://medium.com/@04sabsas/bugbounty-writeup-take-attention-and-get-stored-xss-495dd6eab07e"
                 }
              ],
              "Authors": ["Oleksandr Opanasiuk (@Lekssik2)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I XSSed Admin Account",
                    "Link": "https://gauravnarwani.com/how-i-xssed-admin-account/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-08-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF Vulnerability in https://app.[REDACTED].com",
                    "Link": "https://blog.evanricafort.com/2019/08/ssrf-vulnerability-in.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-08-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reporting - Amazon 1 click device XSS",
                    "Link": "https://github.com/sneakerhax/Posts/blob/2454456529ddeedb17237b4e9678f7d58d0ffdca/posts/Amazon_1_click_device_XSS.md"
                 }
              ],
              "Authors": ["Sneakerhax (@sneakerhax)"],
              "Programs": ["Amazon"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Clickjacking DOM XSS on Google.org",
                    "Link": "https://websecblog.com/vulns/clickjacking-xss-on-google-org/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking", "DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Application Level Denial of Service [DoS] using SVG file in https://[REDACTED].com (Write Up)",
                    "Link": "https://blog.evanricafort.com/2019/08/application-level-denial-of-service-dos.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["-"],
              "Bugs": ["Application-level DoS"],
              "Bounty": "300",
              "PublicationDate": "2019-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Two Easy RCE in Atlassian Products",
                    "Link": "https://medium.com/@valeriyshevchenko/two-easy-rce-in-atlassian-products-e8480eacdc7f"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["Atlassian"],
              "Bugs": ["Credential stuffing"],
              "Bounty": "-",
              "PublicationDate": "2019-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Read other user support tickets in https://support..com (Write Up)",
                    "Link": "https://blog.evanricafort.com/2019/08/read-other-user-support-tickets-in.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "120",
              "PublicationDate": "2019-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation using Api endpoint",
                    "Link": "https://medium.com/@ronak_9889/privilege-escalation-using-api-endpoint-fce841caaff3"
                 }
              ],
              "Authors": ["Ronak Patel (@ronak_9889)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2019-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Writing my Medium blog to complete account takeover",
                    "Link": "https://medium.com/@reiss.r/writing-my-medium-blog-to-complete-account-takeover-e65d455c16b"
                 }
              ],
              "Authors": ["Rotem Reiss (@rotem_reiss)"],
              "Programs": ["Medium"],
              "Bugs": ["Stored XSS", "Account takeover"],
              "Bounty": "1,000",
              "PublicationDate": "2019-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "LAN-Based Blind SSRF Attack Primitive for Windows Systems (switcheroo)",
                    "Link": "https://initblog.com/2019/switcheroo/"
                 }
              ],
              "Authors": ["initstring (@init_string)"],
              "Programs": ["Microsoft"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                {
                   "Title": "break and bypass verification email",
                   "Link": "https://medium.com/@protostar0/break-and-bypass-verification-email-ac3359041272"
                }
              ],
              "Authors": ["Abdelhak Kharroubi"],
              "Programs": ["Bukalapak"],
              "Bugs": ["Open redirect", "Email verification bypass", "Weak crypto"],
              "Bounty": "-",
              "PublicationDate": "2019-08-07",
              "AddedDate": "2022-10-12"
            },
           {
              "Links": [
                {
                   "Title": "CRLF injection allow => cookie injection in root domain & xss",
                   "Link": "https://medium.com/@protostar0/crlf-injection-allow-cookie-injection-in-root-domain-xss-812cd807ba5b"
                }
              ],
              "Authors": ["Abdelhak Kharroubi"],
              "Programs": ["Bukalapak"],
              "Bugs": ["CRLF injection"],
              "Bounty": "-",
              "PublicationDate": "2019-08-06",
              "AddedDate": "2022-10-12"
            },
            {
              "Links": [
                {
                   "Title": "self XSS to stored XSS [ think out the box]",
                   "Link": "https://medium.com/@protostar0/self-xss-to-stored-xss-think-out-the-box-44b094f113f9"
                }
              ],
              "Authors": ["Abdelhak Kharroubi"],
              "Programs": ["TIBCO"],
              "Bugs": ["Self-XSS", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-08-06",
              "AddedDate": "2022-10-12"
            },
            {
              "Links": [
                 {
                    "Title": "Exploiting Out Of Band XXE using internal network and php wrappers",
                    "Link": "http://mahmoudsec.blogspot.com/2019/08/exploiting-out-of-band-xxe-using.html"
                 }
              ],
              "Authors": ["Mahmoud Gamal (@Zombiehelp54)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2019-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BugBounty WriteUp — Creative thinking is our everything (Race Condition + Business Logic Error)",
                    "Link": "https://medium.com/@04sabsas/bugbounty-writeup-creative-thinking-is-our-everything-race-condition-business-logic-error-2f3e82b9aa17"
                 }
              ],
              "Authors": ["Oleksandr Opanasiuk (@Lekssik2)"],
              "Programs": ["-"],
              "Bugs": ["Race condition", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on LaporBug.id",
                    "Link": "https://learn.hackersid.com/2019/08/stored-xss-on-laporbugid.html"
                 }
              ],
              "Authors": ["rizal (@sayadarijawa)"],
              "Programs": ["LaporBug.id"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leveraging AngularJS-based XSS to Privilege Escalation",
                    "Link": "https://www.shawarkhan.com/2019/08/leveraging-angularjs-based-xss-to-privilege-escalation.html"
                 }
              ],
              "Authors": ["Shawar Khan (@ShawarkOFFICIAL)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2019-08-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found XSS By Searching In Shodan",
                    "Link": "https://blog.usejournal.com/how-i-found-xss-by-searching-in-shodan-6943b799e648"
                 }
              ],
              "Authors": ["D1vy4n5hu 5hukl4 (@justm0rph3u5)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-08-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "No Rate limiting eligible for bounty ?",
                    "Link": "https://smaranchand.com.np/2019/08/no-rate-limiting-eligible-for-bounty"
                 }
              ],
              "Authors": ["Smaran Chand (@smaranchand)"],
              "Programs": ["-"],
              "Bugs": ["Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2019-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Sub domain Takeover to Open-Redirect",
                    "Link": "https://medium.com/@aniltom/https-medium-com-aniltom-from-sub-domain-takeover-to-open-redirect-b5be4906e1a4"
                 }
              ],
              "Authors": ["Anil Tom (mr_4nk)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover", "Open redirect"],
              "Bounty": "150",
              "PublicationDate": "2019-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One Misconfig (JIRA) to Leak Them All- Including NASA and Hundreds of Fortune 500 Companies!",
                    "Link": "https://medium.com/@logicbomb_1/one-misconfig-jira-to-leak-them-all-including-nasa-and-hundreds-of-fortune-500-companies-a70957ef03c7"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-08-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Download predictions details of ads plans of any business.",
                    "Link": "https://ysamm.com/?p=291"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Internal path disclosure in Instagram server",
                    "Link": "https://ysamm.com/?p=321"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Internal path disclosure", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Access portal of Facebook mobile retailers and see earnings and referrals reports.",
                    "Link": "https://ysamm.com/?p=314"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2019-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "View orders and financial reports lists for any page shop.",
                    "Link": "https://ysamm.com/?p=281"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2019-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing CORS",
                    "Link": "https://medium.com/@saadahmedx/bypassing-cors-13e46987a45b"
                 }
              ],
              "Authors": ["Saad Ahmed (@XSaadAhmedX)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2019-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE in Ruby using Mustache Templates",
                    "Link": "https://web.archive.org/web/20191219015349/https://rhys.io/post/rce-in-ruby-using-mustache-templates"
                 }
              ],
              "Authors": ["Rhys Elsmore (@rhyselsmore)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reposted [2017]: LinkedIn Hacker’s Experience",
                    "Link": "https://medium.com/@dekeeu/reposted-2017-linkedin-hackers-experience-8465c1848c88"
                 }
              ],
              "Authors": ["Alexandru Coltuneac (@dekeeu)"],
              "Programs": ["LinkedIn"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reposted [2019]: Hacking YouTube for #fun and #profit",
                    "Link": "https://medium.com/@dekeeu/reposted-2019-hacking-youtube-for-fun-and-profit-8685dd475e30"
                 }
              ],
              "Authors": ["Alexandru Coltuneac (@dekeeu)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Paypal bug $10K - All Secondary users account takeover leads to unauthorized money transfer from paypal business accounts",
                    "Link": "https://web.archive.org/web/20210124152317/https://whitehathaji.blogspot.com/2019/07/paypal-bug-10k-all-secondary-users.html"
                 }
              ],
              "Authors": ["Mohd haji (@mohdhaji24)"],
              "Programs": ["Paypal"],
              "Bugs": ["IDOR"],
              "Bounty": "10,500",
              "PublicationDate": "2019-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection in private-site.com/login.php",
                    "Link": "https://web.archive.org/web/20200928234656/https://www.mohamedharon.com/2019/07/sql-injection-in-private-sitecomloginphp.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2019-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "1st Bounty Story | Rewarded 300$ (IDOR)",
                    "Link": "https://medium.com/@mdhridoy_4607/1st-bounty-story-rewarded-300-idor-bc4e1708e8e0"
                 }
              ],
              "Authors": ["Md Hridoy"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "300",
              "PublicationDate": "2019-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of an IDOR via Email",
                    "Link": "https://footstep.ninja/posts/idor-via-email/"
                 }
              ],
              "Authors": ["Shuaib Oladigbolu (@_sawzeeyy)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Old GitHub Profile Takeover!",
                    "Link": "https://web.archive.org/web/20200928235705/https://www.mohamedharon.com/2019/07/github-takeover.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["Github account takeover"],
              "Bounty": "1,000",
              "PublicationDate": "2019-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining Cache Poisoning To Stored XSS",
                    "Link": "https://medium.com/@nahoragg/chaining-cache-poisoning-to-stored-xss-b910076bda4f"
                 }
              ],
              "Authors": ["Rohan aggarwal (@nahoragg)"],
              "Programs": ["-"],
              "Bugs": ["Web cache poisoning", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Solr Injection by abusing Local Parameters on Zomato.com",
                    "Link": "https://medium.com/@ronak_9889/solr-injection-by-abusing-local-parameters-on-zomato-com-a5cb7bef10d5"
                 }
              ],
              "Authors": ["Ronak Patel (@ronak_9889)"],
              "Programs": ["Zomato"],
              "Bugs": ["Solr injection"],
              "Bounty": "700",
              "PublicationDate": "2019-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story about Facebook Oauth Account Takeover",
                    "Link": "https://medium.com/@androgaming1912/story-about-facebook-oauth-account-takeover-6537ff32281b"
                 }
              ],
              "Authors": ["Zerb0a"],
              "Programs": ["iLOTTE"],
              "Bugs": ["Account takeover", "OAuth"],
              "Bounty": "150",
              "PublicationDate": "2019-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook BugBounty: Tale of an Instagram bug disclosing user’s phone number via checkpoint",
                    "Link": "https://web.archive.org/web/20200826192345/https://pwnsec.ninja/2019/07/26/facebook-bugbounty-tale-of-an-instagram-bug-disclosing-users-phone-number-via-checkpoint/"
                 }
              ],
              "Authors": ["Bijan Murmu (@0xBijan)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full Account Takeover via Changing Email And Password of any User through API Parameters",
                    "Link": "https://web.archive.org/web/20201008153910/https://medium.com/@adeshkolte/full-account-takeover-changing-email-and-password-of-any-user-through-api-parameters-3d527ab27240"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Price Parameter Tampering On Bukalapak",
                    "Link": "https://apapedulimu.click/price-parameter-tampering-on-bukalapak/"
                 }
              ],
              "Authors": ["apapedulimu / Nosa Shandy (@LocalHost31337)"],
              "Programs": ["Bukalapak"],
              "Bugs": ["Parameter tampering", "Payment tampering"],
              "Bounty": "150",
              "PublicationDate": "2019-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found the most critical bug in live bug bounty event?",
                    "Link": "https://medium.com/@innocenthacker/how-i-found-the-most-critical-bug-in-live-bug-bounty-event-7a88b3aa97b3"
                 }
              ],
              "Authors": ["Lakshay (@inn0c3ntd3v1L)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose any main and 3rd party contributors email address and movie local path thru XML file in Plex TV - plex.tv (Write Up)",
                    "Link": "https://blog.evanricafort.com/2019/07/business-logic-plex-tv.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Plex"],
              "Bugs": ["Information disclosure", "Internal path disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XX to XXX in one day",
                    "Link": "https://medium.com/@baibhavanandjha/xx-to-xxx-in-one-day-9578858b6286"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["WePay"],
              "Bugs": ["Account takeover", "Parameter tampering"],
              "Bounty": "-",
              "PublicationDate": "2019-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwning child company to get access to ParentCompany's Slack Team",
                    "Link": "https://blog.parthmalhotra.com/pwning-child-company-to-get-access-to-parentcompanys-slack-team/"
                 }
              ],
              "Authors": ["Parth Malhotra (@Parth_Malhotra)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "Default credentials"],
              "Bounty": "-",
              "PublicationDate": "2019-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS On Twitter [Worth 1120$]",
                    "Link": "https://medium.com/@bywalks/xss-on-twitter-worth-1120-914dcd28ee18"
                 }
              ],
              "Authors": ["Bywalks (@bywalkss)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "1,120",
              "PublicationDate": "2019-07-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS in Ebay.com",
                    "Link": "https://medium.com/@madguyyy/reflected-xss-in-ebay-com-60a9d61e26cd"
                 }
              ],
              "Authors": ["Sukhmeet Singh (@MadGuyyy)"],
              "Programs": ["Ebay"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-07-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Not a fancy bug, just HTML Injection in Clause - clause.io (Write Up)",
                    "Link": "https://blog.evanricafort.com/2019/07/html-injection-in-clause-email.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Clause"],
              "Bugs": ["HTML injection"],
              "Bounty": "250",
              "PublicationDate": "2019-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subscribe to typing notifications for any Instagram user",
                    "Link": "https://philippeharewood.com/subscribe-to-typing-notifications-for-any-instagram-user/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "5,750",
              "PublicationDate": "2019-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Shopping Products For Free- Parameter Tampering Vulnerability",
                    "Link": "https://blog.usejournal.com/shopping-products-for-free-parameter-tampering-vulnerability-8e09e1471596"
                 }
              ],
              "Authors": ["D1vy4n5hu 5hukl4 (@justm0rph3u5)"],
              "Programs": ["-"],
              "Bugs": ["Parameter tampering", "Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2019-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting a Tricky Blind SQL Injection inside LIMIT clause",
                    "Link": "https://www.noob.ninja/2019/07/exploiting-tricky-blind-sql-injection.html"
                 }
              ],
              "Authors": ["Rahul Maini (@iamnoooob)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2019-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Get Page Inbox notifications for any Facebook page",
                    "Link": "https://philippeharewood.com/get-page-inbox-notifications-for-any-facebook-page/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft ID Open Redirect",
                    "Link": "https://burninatorsec.blogspot.com/2019/07/microsoft-id-open-redirect.html"
                 }
              ],
              "Authors": ["Burninator Sec"],
              "Programs": ["Microsoft"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Office 365 - Outlook XSS",
                    "Link": "https://leucosite.com/Microsoft-Office-365-Outlook-XSS/"
                 }
              ],
              "Authors": ["Abdulrahman Alqabandi (@Qab)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection in Forget Password Function",
                    "Link": "https://medium.com/@kgaber99/sql-injection-in-forget-password-function-3c945512e3cb"
                 }
              ],
              "Authors": ["Khaled Gaber"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2019-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to lock a GitHub user out of their repos (bug or feature?)",
                    "Link": "https://blog.teserakt.io/2019/07/18/how-to-lock-a-github-user-out-of-their-repos-bug-or-feature/"
                 }
              ],
              "Authors": ["Teserakt AG"],
              "Programs": ["GitHub"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2019-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Сookie-based XSS exploitation | $2300 Bug Bounty story",
                    "Link": "https://medium.com/@iSecMax/сookie-based-xss-exploitation-2300-bug-bounty-story-9bc532ffa564"
                 }
              ],
              "Authors": ["Max (@iSecMax)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "2,300",
              "PublicationDate": "2019-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover Vulnerability :)",
                    "Link": "https://medium.com/@sumitcfe/account-takeover-vulnerability-7e6e039a4dd3"
                 }
              ],
              "Authors": ["Sumit Jain (@sumit_cfe)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Recon helped me to to find a Facebook domain takeover",
                    "Link": "https://medium.com/@sudhanshur705/how-recon-helped-me-to-to-find-a-facebook-domain-takeover-58163de0e7d5"
                 }
              ],
              "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "500",
              "PublicationDate": "2019-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Informative Bug From Triaged",
                    "Link": "https://medium.com/@circleninja/facebook-informative-bug-from-triaged-76738e4d5938"
                 }
              ],
              "Authors": ["Circle Ninja (@circleninja)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2019-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF Email Confirmation Vulnerability for Gmail & G-Suite in Facebook",
                    "Link": "https://medium.com/@lokeshdlk77/csrf-email-confirmation-vulnerability-for-gmail-g-suite-in-facebook-5ab551a0a526"
                 }
              ],
              "Authors": ["Lokesh Kumar (@lokeshdlk77)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "3,000",
              "PublicationDate": "2019-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass CSRF With ClickJacking Worth $1250",
                    "Link": "https://medium.com/@saadahmedx/bypass-csrf-with-clickjacking-worth-1250-6c70cc263f40"
                 }
              ],
              "Authors": ["Saad Ahmed (@XSaadAhmedX)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Clickjacking"],
              "Bounty": "1,250",
              "PublicationDate": "2019-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "What do Netcat, SMTP and self XSS have in common? Stored XSS",
                    "Link": "https://medium.com/bugbountywriteup/what-do-netcat-smtp-and-self-xss-have-in-common-stored-xss-a05648b72002"
                 }
              ],
              "Authors": ["Plenum (@plenumlab)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Could Get The Instagram Username of Anyone on Tinder",
                    "Link": "https://medium.com/bugbountywriteup/wrong-swipe-tinder-29fe1eb0203c"
                 }
              ],
              "Authors": ["Shahar Albeck"],
              "Programs": ["Tinder"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Bugs Are Out There, Hiding in Plain Sight",
                    "Link": "https://medium.com/a-bugz-life/the-bugs-are-out-there-hiding-in-plain-sight-12d056613ea3"
                 }
              ],
              "Authors": ["A Bug’z Life (@abugzlife1)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "SSRF", "Information disclosure", "CORS misconfiguration"],
              "Bounty": "9,000",
              "PublicationDate": "2019-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "500$ bounty: Man in the Middle on Slack",
                    "Link": "https://sysrant.com/500-bounty-man-in-the-middle-on-slack/"
                 }
              ],
              "Authors": ["Wiard van Rij / Sysrant (@RijWiard)"],
              "Programs": ["Slack"],
              "Bugs": ["MiTM"],
              "Bounty": "500",
              "PublicationDate": "2019-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Bug : Sending messages as a page with jobmanager permission",
                    "Link": "https://medium.com/@0x01devansh/facebook-bug-sending-messages-as-a-page-with-jobmanager-permission-763dc0d8e32c"
                 }
              ],
              "Authors": ["Devansh batham (@devanshwolf)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2019-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[TOKOPEDIA] Site-wide CSRF through GraphQL request",
                    "Link": "https://yeraisci.com/tokopedia-site-wide-csrf-through-graphql-request"
                 }
              ],
              "Authors": ["Rafie Muhammad (@rafiem777)"],
              "Programs": ["Tokopedia"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Could Have Hacked Any Instagram Account",
                    "Link": "https://thezerohack.com/hack-any-instagram"
                 }
              ],
              "Authors": ["Laxman Muthiyah (@LaxmanMuthiyah)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Race condition", "Rate limiting bypass"],
              "Bounty": "30,000",
              "PublicationDate": "2019-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cracking my windshield and earning $10,000 on the Tesla Bug Bounty Program",
                    "Link": "https://samcurry.net/cracking-my-windshield-and-earning-10000-on-the-tesla-bug-bounty-program/"
                 }
              ],
              "Authors": ["Sam Curry (@samwcyo)"],
              "Programs": ["Tesla"],
              "Bugs": ["Blind XSS"],
              "Bounty": "10,000",
              "PublicationDate": "2019-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking intoTinder’s Premium Model",
                    "Link": "https://medium.com/@sansyrox/hacking-tinders-premium-model-43f9f699d44"
                 }
              ],
              "Authors": ["Sanskar Jethi (@sansyrox)"],
              "Programs": ["Tinder"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-07-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account takeover on Airbnb acquisition | An Unusual Bug Part-2 🐛",
                    "Link": "https://medium.com/@princechaddha/account-takeover-on-airbnb-acquisition-an-unusual-bug-part-2-45fab11dc407"
                 }
              ],
              "Authors": ["PRince CHaddha (@princechaddha)"],
              "Programs": ["Airbnb"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Bug bounty page admin disclose bug {Facebook Android app}",
                    "Link": "https://medium.com/@yusuffurkan/facebook-bug-bounty-page-admin-disclose-bug-facebook-android-app-c0fa50459177"
                 }
              ],
              "Authors": ["Yusuf Furkan (@h1_yusuf)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2019-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS on Google Custom Search Engine",
                    "Link": "https://thesecurityexperts.wordpress.com/2019/07/11/xss-on-google-custom-search-engine/"
                 }
              ],
              "Authors": ["KL Sreeram (@kl_sree)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-07-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of my Biggest Bounty ever : Command Execution on Jenkins",
                    "Link": "https://medium.com/@janijay007/story-of-my-biggest-bounty-evecommand-execution-on-jenkin-a73f5242b1e2"
                 }
              ],
              "Authors": ["Jay Jani (@JayJani007)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Exposed Jenkins instance"],
              "Bounty": "8,000",
              "PublicationDate": "2019-07-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection Bug Bounty POC!",
                    "Link": "https://medium.com/@ariffadhlullah2310/sql-injection-bug-bounty-110e92e71ec3"
                 }
              ],
              "Authors": ["Arif-ITSEC111"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "5,000",
              "PublicationDate": "2019-07-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tale of account takeover — Sensitive info Disclosure + Broken Access Control",
                    "Link": "https://medium.com/@sakyb7/tale-of-account-takeover-sensitive-info-disclosure-broken-access-control-cea0a5e3a1fd"
                 }
              ],
              "Authors": ["Md Saqib (@sakyb7)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "2,650",
              "PublicationDate": "2019-07-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OAuth authentication bypass on Airbnb acquisition using 1-char Open Redirect",
                    "Link": "https://xp.ht/oauth-authentication-bypass-on-airbnb-acquisition-using-weird-1-char-open-redirect/"
                 }
              ],
              "Authors": ["Evgeniy Yakovchuk (@h1_sp1d3r)"],
              "Programs": ["Airbnb"],
              "Bugs": ["Open redirect", "Token leak", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-07-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A malicious editor of a page can support to a community action which can’t be unsupported by the admin!",
                    "Link": "https://medium.com/@hazzaazi31/a-malicious-editor-of-a-page-can-support-to-a-community-action-which-cant-be-unsupported-by-the-f568c3762042"
                 }
              ],
              "Authors": ["mAshraf"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Information Disclosure via Misconfigured AWS to AWS Bucket Takeover",
                    "Link": "https://medium.com/@pratyush1337/information-disclosure-via-misconfigured-aws-to-aws-bucket-takeover-6a6a66470d0e"
                 }
              ],
              "Authors": ["Pratyush Anjan Sarangi"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2019-07-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cleartext password in LocalStorage (Writeup)",
                    "Link": "https://medium.com/@ruvlol/cleartext-password-in-localstorage-writeup-245294762829"
                 }
              ],
              "Authors": ["ruvlol"],
              "Programs": ["-"],
              "Bugs": ["Violation of secure design principles"],
              "Bounty": "1,500",
              "PublicationDate": "2019-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind (time-based) SQLi - Bug Bounty",
                    "Link": "https://jspin.re/fileupload-blind-sqli/"
                 }
              ],
              "Authors": ["jspin (@jespinhara)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2019-07-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This is how I managed to win $2000 through Facebook Bug Bounty",
                    "Link": "https://medium.com/@saugatpokharel/this-is-how-i-managed-to-win-2000-through-facebook-bug-bounty-a7d531d5097e"
                 }
              ],
              "Authors": ["Saugat Pokharel (@saugatscript)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "2,000",
              "PublicationDate": "2019-07-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Vulnerability: Unremovable Co-Host in facebook page events",
                    "Link": "https://medium.com/@ritishkumarsingh/facebook-vulnerability-unremovable-co-host-in-facebook-page-events-695729d6a09d"
                 }
              ],
              "Authors": ["Ritish Kumar Singh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "DoS"],
              "Bounty": "500",
              "PublicationDate": "2019-07-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover Using CSRF(json-based)",
                    "Link": "https://medium.com/@shub66452/account-takeover-using-csrf-json-based-a0e6efd1bffc"
                 }
              ],
              "Authors": ["shub rathore (@shub66452)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "1,000",
              "PublicationDate": "2019-07-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of a stored xss to full account takeover vulnerability(N/A to accepted)",
                    "Link": "https://medium.com/@nandwanajatin25/story-of-a-stored-xss-to-full-account-takeover-vulnerability-n-a-to-accepted-8478aa5e0d8e"
                 }
              ],
              "Authors": ["Jatin Aesthetic (@techyfreakk)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-07-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding hidden gems vol. 4: Rakefile a.k.a. how to get AWS keys again",
                    "Link": "https://medium.com/@mateusz.olejarka/finding-hidden-gems-vol-4-rakefile-a-k-a-how-to-get-aws-keys-again-ed0d840e0ec"
                 }
              ],
              "Authors": ["Mateusz Olejarka (@molejarka)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-07-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Yeah! I got P2 in 1 minute - Stored XSS via Markdown Editor",
                    "Link": "https://medium.com/@schopath/yeah-i-got-p2-in-1-minute-stored-xss-via-markdown-editor-7872dba3f158"
                 }
              ],
              "Authors": ["Schopath"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Injecting {{6*200}} to $1200",
                    "Link": "https://gauravnarwani.com/injecting-6200-to-1200/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["SSTI"],
              "Bounty": "1,200",
              "PublicationDate": "2019-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Another Download Protection Bypass in Google Chrome – BIN files in Mac OS",
                    "Link": "https://wwws.nightwatchcybersecurity.com/2019/07/02/another-download-protection-bypass-in-google-chrome-bin-files-in-mac-os/"
                 }
              ],
              "Authors": ["Nightwatch Cybersecurity (@nightwatchcyber)"],
              "Programs": ["Google"],
              "Bugs": ["Browser hacking"],
              "Bounty": "1,000",
              "PublicationDate": "2019-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I escalated RFI into LFI",
                    "Link": "http://hassankhanyusufzai.com/RFI_LFI_writeup/"
                 }
              ],
              "Authors": ["Hassan Khan Yusufzai (@Splint3r7)"],
              "Programs": ["-"],
              "Bugs": ["RFI", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2019-07-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accidental IDOR",
                    "Link": "https://medium.com/@saadahmedx/accidental-idor-8987a2728d4"
                 }
              ],
              "Authors": ["Saad Ahmed (@XSaadAhmedX)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-07-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on Indeed",
                    "Link": "https://cyberzombie.in/stored-xss-on-indeed/"
                 }
              ],
              "Authors": ["Tirtha Mandal (@tirtha_mandal)"],
              "Programs": ["Indeed"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,500",
              "PublicationDate": "2019-06-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One more Parameter manipulation bug (🤑)",
                    "Link": "https://medium.com/@kanchansinghyadav/one-more-parameter-manipulation-bug-7fa0551a6021"
                 }
              ],
              "Authors": ["Kanchan Singh Yadav (@KanchanSingh0)"],
              "Programs": ["-"],
              "Bugs": ["Parameter tampering"],
              "Bounty": "-",
              "PublicationDate": "2019-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook BugBounty : Short story on Page admin disclosure",
                    "Link": "https://web.archive.org/web/20200928092650/https://pwnsec.ninja/2019/06/28/facebook-bugbounty-short-story-on-page-admin-disclosure/"
                 }
              ],
              "Authors": ["Bijan Murmu (@0xBijan)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2019-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Nuget/Squirrel uncontrolled endpoints leads to arbitrary code execution",
                    "Link": "https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12"
                 }
              ],
              "Authors": ["Reegun J (@reegun21)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Gain adfly SMTP access with SSRF via Gopher Protocol",
                    "Link": "https://medium.com/@androgaming1912/gain-adfly-smtp-access-with-ssrf-via-gopher-protocol-26a26d0ec2cb"
                 }
              ],
              "Authors": ["Zerb0a"],
              "Programs": ["Adf.ly"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "View Facebook payouts for any Facebook Trivia Game",
                    "Link": "https://philippeharewood.com/view-facebook-payouts-for-any-facebook-trivia-game/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "1-Click Account Takeover in Virgool.io — a Nice Case Study",
                    "Link": "https://medium.com/@y.shahinzadeh/1-click-account-takeover-in-virgool-io-a-nice-case-study-6bfc3cb98ef2"
                 }
              ],
              "Authors": ["Yashar Shahinzadeh (@YShahinzadeh)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CORS To CSRF Attack",
                    "Link": "https://medium.com/@osamaavvan/cors-to-csrf-attack-c33a595d441"
                 }
              ],
              "Authors": ["Osama Avvan (@osamaavvan)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Toggle Group Rules Agreement as a non-member",
                    "Link": "https://philippeharewood.com/toggle-group-rules-agreement-as-a-non-member/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-06-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sensitive Information Disclosure: Web Cache Deception Attack",
                    "Link": "https://medium.com/@dr.spitfire/sensitive-information-disclosure-web-cache-deception-attack-bcac6cb9cd86?sk=a2557f0c557ff38876141c2d94b296dd"
                 }
              ],
              "Authors": ["Wasim Shaikh (@Wa_sim_sim)"],
              "Programs": ["Intuit"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-06-26",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "F5 Networks Endpoint Inspector – Browser-to-RCE?",
                  "Link": "https://www.pentestpartners.com/security-blog/f5-networks-endpoint-inspector-browser-to-rce/"
               }
            ],
            "Authors": ["Dave U. Ramdon"],
            "Programs": ["F5"],
            "Bugs": ["RCE"],
            "Bounty": "-",
            "PublicationDate": "2019-06-26",
            "AddedDate": "2022-11-14"
         },
           {
              "Links": [
                 {
                    "Title": "Download .arexport files for any public AR Studio Effect",
                    "Link": "https://philippeharewood.com/download-arexport-files-for-any-public-ar-studio-effect/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSV injection at Comment Section.",
                    "Link": "https://medium.com/@navne3t/csv-injection-at-comment-section-d5009ddd176"
                 }
              ],
              "Authors": ["Navneet (@na5n33t)"],
              "Programs": ["-"],
              "Bugs": ["CSV injection"],
              "Bounty": "-",
              "PublicationDate": "2019-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Password Reset Vulnerability — Full Account takeover (Insecure Direct Object Reference)",
                    "Link": "https://web.archive.org/web/20201001064738/https://medium.com/@protector47/password-reset-vulnerability-full-account-takeover-insecure-direct-object-reference-c4a9a3ea8268"
                 }
              ],
              "Authors": ["Muhammad Asim Shahzad (@protector47)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "IDOR", "Account takeover"],
              "Bounty": "1,200",
              "PublicationDate": "2019-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Page Admin Disclosure | Facebook Bug Bounty 2019",
                    "Link": "https://medium.com/@evilboyajay/page-admin-disclosure-facebook-bug-bounty-2019-ee9920e768eb"
                 }
              ],
              "Authors": ["Ajay Gautam (@evilboyajay)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "1,000",
              "PublicationDate": "2019-06-22",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Operation Crack: Hacking IDA Pro Installer PRNG from an Unusual Way",
                  "Link": "https://devco.re/blog/2019/06/21/operation-crack-hacking-IDA-Pro-installer-PRNG-from-an-unusual-way-en/"
               }
            ],
            "Authors": ["Shaolin"],
            "Programs": ["Hex-Rays (IDA Pro)"],
            "Bugs": ["Bruteforce", "Hardcoded credentials", "Thick client"],
            "Bounty": "-",
            "PublicationDate": "2019-06-21",
            "AddedDate": "2024-08-22"
         },
           {
              "Links": [
                 {
                    "Title": "How I Hacked the Microsoft Outlook Android App and Found CVE-2019-1105",
                    "Link": "https://www.f5.com/labs/articles/threat-intelligence/how-i-hacked-the-microsoft-outlook-android-app-and-found-cve-2019-1105"
                 }
              ],
              "Authors": ["Bryan Appleby (@bryapp)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-06-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Catching support emails from my internet service provider",
                    "Link": "https://blog.lent.ink/post/klanteservice/"
                 }
              ],
              "Authors": ["Sander Lentink"],
              "Programs": ["T-Mobile"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-06-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$1800 worth Clickjacking",
                    "Link": "https://medium.com/@osamaavvan/1800-worth-clickjacking-1f92e79d0414"
                 }
              ],
              "Authors": ["Osama Avvan (@osamaavvan)"],
              "Programs": ["-"],
              "Bugs": ["Clickjacking"],
              "Bounty": "1,800",
              "PublicationDate": "2019-06-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "About a Sucuri RCE...and How Not to Handle Bug Bounty Reports",
                    "Link": "https://www.rcesecurity.com/2019/06/about-a-sucuri-rce-and-how-not-to-handle-bug-bounty-reports/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["Sucuri"],
              "Bugs": ["RCE"],
              "Bounty": "750",
              "PublicationDate": "2019-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR: Payment Fraud",
                    "Link": "https://medium.com/@Vibhurushi_Chotaliya/idor-payment-fraud-99d330879c0d"
                 }
              ],
              "Authors": ["Vibhurushi Chotaliya (@_Vibhurushi_)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2019-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Self XSS To Evil XSS",
                    "Link": "https://medium.com/@saadahmedx/self-xss-to-evil-xss-bcf2494a82a4"
                 }
              ],
              "Authors": ["Saad Ahmed (@XSaadAhmedX)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Fight For Duplicate Marked Bug: Story of BBC Hall Of Fame",
                    "Link": "https://medium.com/@dr.spitfire/a-fight-for-duplicate-marked-bug-story-of-bbc-hall-of-fame-16f9c8215315?sk=9269454dd3557dc8ea9c1ec26be033dd"
                 }
              ],
              "Authors": ["Wasim Shaikh (@Wa_sim_sim)"],
              "Programs": ["BBC"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How a classical XSS can lead to persistent ATO Vulnerability?",
                    "Link": "https://hackademic.co.in/how-a-classical-xss-can-lead-to-persistent-ato-vulnerability/"
                 }
              ],
              "Authors": ["Milind Purswani (@MilindPurswani)", "Yash Sodha (@y_sodha)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Vulnerability: Unremovable Co-Host in facebook group events",
                    "Link": "https://medium.com/@ritishkumarsingh/facebook-vulnerability-unremovable-co-host-in-facebook-group-events-13a9ea28b302"
                 }
              ],
              "Authors": ["Ritish Kumar Singh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2019-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover with Clickjacking",
                    "Link": "https://medium.com/@osamaavvan/account-taker-with-clickjacking-ace744842ec3"
                 }
              ],
              "Authors": ["Osama Avvan (@osamaavvan)"],
              "Programs": ["-"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2019-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Filter Evasion",
                    "Link": "https://m0z.co/XSS-Filter-Evasion/"
                 }
              ],
              "Authors": ["m0z (@LooseSecurity)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business user Employees could have applied block list to all ad accounts listed in the business manager.",
                    "Link": "https://medium.com/@rohitcoder/business-user-employees-can-add-edit-change-or-apply-block-list-to-a-business-account-7b3e8aae667e"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2019-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS in Tokopedia Train Ticket",
                    "Link": "https://visat.me/security/reflected-xss-in-tokopedia-train-ticket/"
                 }
              ],
              "Authors": ["Jon Bottarini (@jon_bottarini)"],
              "Programs": ["New Relic"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "212",
              "PublicationDate": "2019-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Using Burp Suite match and replace settings to escalate your user privileges and find hidden features",
                    "Link": "https://www.jonbottarini.com/2019/06/17/using-burp-suite-match-and-replace-settings-to-escalate-your-user-privileges-and-find-hidden-features/"
                 }
              ],
              "Authors": ["Jon Bottarini (@jon_bottarini)"],
              "Programs": ["New Relic"],
              "Bugs": ["Client-side enforcement of server-side security"],
              "Bounty": "500",
              "PublicationDate": "2019-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Parameter Pollution issue in API resulting $XXX",
                    "Link": "https://smaranchand.com.np/2019/06/parameter-pollution-issue-in-api-resulting-xxx/"
                 }
              ],
              "Authors": ["Smaran Chand (@smaranchand)"],
              "Programs": ["-"],
              "Bugs": ["HTTP parameter pollution"],
              "Bounty": "-",
              "PublicationDate": "2019-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQl Injection",
                    "Link": "https://medium.com/@saadahmedx/sql-injection-c87a390afdd3"
                 }
              ],
              "Authors": ["Saad Ahmed (@XSaadAhmedX)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "500",
              "PublicationDate": "2019-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing XSS filter and Stealing User Payment Data",
                    "Link": "https://medium.com/@osamaavvan/bypassing-xss-filter-and-stealing-user-credit-card-data-100f247ed5eb"
                 }
              ],
              "Authors": ["Osama Avvan (@osamaavvan)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-06-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Password Bypass and Something Else…",
                    "Link": "https://medium.com/@Vibhurushi_Chotaliya/password-bypass-and-something-else-cded0847c9df"
                 }
              ],
              "Authors": ["Vibhurushi Chotaliya (@_Vibhurushi_)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "600",
              "PublicationDate": "2019-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned $1,500 in just 15 mins due to Amazon S3 bucket misconfiguration?",
                    "Link": "https://web.archive.org/web/20201107231430/https://medium.com/@protector47/how-i-earned-1-500-in-just-15-mins-due-to-amazon-s3-bucket-misconfiguration-953b28242f95"
                 }
              ],
              "Authors": ["Muhammad Asim Shahzad (@protector47)"],
              "Programs": ["Dropbox"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "1,500",
              "PublicationDate": "2019-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover Worth $900",
                    "Link": "https://medium.com/@saadahmedx/account-takeover-worth-900-cacbe10de58e"
                 }
              ],
              "Authors": ["Saad Ahmed (@XSaadAhmedX)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "CSRF"],
              "Bounty": "900",
              "PublicationDate": "2019-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing Cookies to Login in any Account",
                    "Link": "https://medium.com/@osamaavvan/stealing-cookies-to-login-in-any-account-52ca33df0318"
                 }
              ],
              "Authors": ["Osama Avvan (@osamaavvan)"],
              "Programs": ["-"],
              "Bugs": ["Cookie theft"],
              "Bounty": "900",
              "PublicationDate": "2019-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty - Information Disclosure through error message + WAF Bypass led to Local File Inclusion",
                    "Link": "https://spenkk.github.io/bugbounty/Local-File-Inclusion/"
                 }
              ],
              "Authors": ["Λявєη (@spenkkkkk)", "Çlirim Emini (@0xcela)"],
              "Programs": ["-"],
              "Bugs": ["WAF bypass", "LFI", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Complete Web Server Access",
                    "Link": "https://medium.com/@saadahmedx/complete-web-server-access-46d19279a2b"
                 }
              ],
              "Authors": ["Saad Ahmed (@XSaadAhmedX)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "500",
              "PublicationDate": "2019-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fullscreen API Attack’s Revisited and the FaceBook NA Story",
                    "Link": "https://medium.com/bug-bounty-hunting/fullscreen-api-attacks-revisited-and-the-fb-na-story-cbea3ca383c5"
                 }
              ],
              "Authors": ["Circle Ninja (@circleninja)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Phishing"],
              "Bounty": "-",
              "PublicationDate": "2019-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSSing Google Employees — Blind XSS on googleplex.com",
                    "Link": "https://websecblog.com/vulns/googleplex-com-blind-xss/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Google"],
              "Bugs": ["Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Admin Account total Information Disclosure",
                    "Link": "https://medium.com/@nishantrustlingup/admin-account-total-information-disclosure-72ec60da4a78"
                 }
              ],
              "Authors": ["Nishant Saurav (@inishantsinha)"],
              "Programs": ["-"],
              "Bugs": ["Source code disclosure", "Information disclosure"],
              "Bounty": "200",
              "PublicationDate": "2019-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "v1 Instance Metadata Service protections bypass",
                    "Link": "https://lf.lc/vrp/135276622/"
                 }
              ],
              "Authors": ["Anthony Weems"],
              "Programs": ["Google"],
              "Bugs": ["SSRF"],
              "Bounty": "5,000",
              "PublicationDate": "2019-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR — Account Takeover",
                    "Link": "https://medium.com/@saadahmedx/idor-account-takeover-1ff5a2d03b8b"
                 }
              ],
              "Authors": ["Saad Ahmed (@XSaadAhmedX)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "500",
              "PublicationDate": "2019-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How spending our Saturday hacking earned us 20k",
                    "Link": "https://web.archive.org/web/20201028215444/http://incidentsecurity.com/how-spending-our-saturday-hacking-earned-us-20k/"
                 }
              ],
              "Authors": ["Matti Bijnens (@MattiBijnens)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "20,000",
              "PublicationDate": "2019-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining Improper Authorization To Race Condition To Harvest Credit Card Details : A Bug Bounty Story",
                    "Link": "https://medium.com/@ciph3r7r0ll/chaining-improper-authorization-to-race-condition-to-harvest-credit-card-details-a-bug-bounty-effe6e0f5076"
                 }
              ],
              "Authors": ["Mandeep Jadon (@1337tr0lls)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization", "Race condition"],
              "Bounty": "-",
              "PublicationDate": "2019-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Redstrom Denial Of Service — Write Up",
                    "Link": "https://medium.com/@androgaming1912/redstrom-denial-of-service-write-up-d8fd97f18335"
                 }
              ],
              "Authors": ["Zerb0a"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2019-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS on Error Page",
                    "Link": "https://noobe.io/articles/2019-06/reflected-xss-on-error-page"
                 }
              ],
              "Authors": ["Tomi (@noobe_io)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Vulnerability: Non-unfriendable user in /hacked workflow",
                    "Link": "https://medium.com/@ritishkumarsingh/facebook-vulnerability-non-unfriendable-user-in-hacked-workflow-5a3b392a2a98"
                 }
              ],
              "Authors": ["Ritish Kumar Singh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,500",
              "PublicationDate": "2019-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account takeover using IDOR and the misleading case of error 403.",
                    "Link": "https://medium.com/bugbountywriteup/account-takeover-using-idor-and-the-misleading-case-of-error-403-cb42c96ea310"
                 }
              ],
              "Authors": ["Plenum (@plenumlab)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR Leads To Project Takeover",
                    "Link": "https://medium.com/@hariharan21/idor-leads-to-project-takeover-548a1bfd4d66"
                 }
              ],
              "Authors": ["Hariharan.s (@DJHARIZ1)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-06-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Don’t underestimates the Errors They can provide good $$$ Bounty!",
                    "Link": "https://medium.com/@noob.assassin/dont-underestimates-the-errors-they-can-provide-good-bounty-d437ecca6596"
                 }
              ],
              "Authors": ["Aditya Sharma (@Assass1nmarcos)"],
              "Programs": ["Mamba"],
              "Bugs": ["Information disclosure", "Internal path disclosure"],
              "Bounty": "200",
              "PublicationDate": "2019-06-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to get private ticket response panel and FortiGate web panel via blind XSS",
                    "Link": "https://web.archive.org/web/20200928091625/https://pwnsec.ninja/2019/06/06/how-i-was-able-to-get-private-ticket-response-panel-and-fortigate-web-panel-via-blind-xss/"
                 }
              ],
              "Authors": ["Bijan Murmu (@0xBijan)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS"],
              "Bounty": "1,250",
              "PublicationDate": "2019-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Edge Extensions Host Permission Bypass (CVE-2019-0678)",
                    "Link": "https://payatu.com/microsoft-edge-extensions-host-permission-bypass-cve-2019-0678/"
                 }
              ],
              "Authors": ["Nikhil Mittal (@c0d3G33k)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Browser hacking"],
              "Bounty": "15,000",
              "PublicationDate": "2019-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unicode vs WAF — XSS WAF Bypass",
                    "Link": "https://medium.com/bugbountywriteup/unicode-vs-waf-xss-waf-bypass-128cd9972a30"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing CSP with policy injection",
                    "Link": "https://portswigger.net/blog/bypassing-csp-with-policy-injection"
                 }
              ],
              "Authors": ["Gareth Heyes (@garethheyes)"],
              "Programs": ["Paypal"],
              "Bugs": ["CSP bypass"],
              "Bounty": "900",
              "PublicationDate": "2019-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "REMOTE CODE EXECUTION ! 😜 Recon Wins",
                    "Link": "https://medium.com/@vishnu0002/remote-code-execution-recon-wins-e9c1db79f3da"
                 }
              ],
              "Authors": ["Vishnuraj"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining multiple low-impact bugs to arbitrary file read in GitLab",
                    "Link": "https://blog.nyangawa.me/security/GitLab-Local-File-Read/"
                 }
              ],
              "Authors": ["Li Rongxi (@nyan_gawa)"],
              "Programs": ["GitLab"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2019-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Simple PathTraversal bypass",
                    "Link": "https://medium.com/@frostnull/hi-guys-again-here-bringing-an-experience-to-share-with-you-as-usual-i-will-overshadow-some-f85a1d5a8d8c"
                 }
              ],
              "Authors": ["fr0stNuLL"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2019-06-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Missing access control at play store",
                    "Link": "https://vishwarajbhattrai.wordpress.com/2019/06/03/missing-access-control-at-play-store/"
                 }
              ],
              "Authors": ["Vishwaraj Bhattrai (@vishwaraj101)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-06-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Unusual Case of Status code- 301 Redirection to AWS Security Credentials Compromise",
                    "Link": "https://medium.com/@logicbomb_1/the-unusual-case-of-open-redirection-to-aws-security-credentials-compromise-59acc312f02b"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "RFI"],
              "Bounty": "-",
              "PublicationDate": "2019-06-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of a uri based xss with some simple google dorking",
                    "Link": "https://medium.com/@nandwanajatin25/story-of-a-uri-based-xss-with-some-simple-google-dorking-e1999254aa55"
                 }
              ],
              "Authors": ["Jatin Aesthetic (@techyfreakk)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-06-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Edmodo Account Deactivation Vulnerability",
                    "Link": "https://medium.com/@trapp3rhat/edmodo-account-deactivation-vulnerability-1116613bed2b"
                 }
              ],
              "Authors": ["Shankar R"],
              "Programs": ["Edmodo"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2019-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First CSRF to Account Takeover worth $750",
                    "Link": "https://medium.com/@nishantrustlingup/my-first-csrf-to-account-takeover-worth-750-1332641d4304"
                 }
              ],
              "Authors": ["Nishant Saurav (@inishantsinha)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "750",
              "PublicationDate": "2019-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting File Uploads Pt. 1 – MIME Sniffing to Stored XSS #bugbounty",
                    "Link": "https://anotherhackerblog.com/exploiting-file-uploads-pt1/"
                 }
              ],
              "Authors": ["HackerOn2Wheels (@HackerOn2Wheels)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "MIME sniffing"],
              "Bounty": "-",
              "PublicationDate": "2019-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on Edmodo",
                    "Link": "https://medium.com/@matarpan33r/stored-xss-on-edmodo-67b244824fa5"
                 }
              ],
              "Authors": ["Rohit Verma (@rv0x00)"],
              "Programs": ["Edmodo"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An unexploited CORS misconfiguration reflecting further issues.",
                    "Link": "https://smaranchand.com.np/2019/05/an-unexploited-cors-misconfiguration-reflecting-further-issues/"
                 }
              ],
              "Authors": ["Smaran Chand (@smaranchand)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2019-05-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How did I bypass a Custom Brute Force protection and why that solution is not a good idea?",
                    "Link": "https://medium.com/@dortz/how-did-i-bypass-a-custom-brute-force-protection-and-why-that-solution-is-not-a-good-idea-4bec705004f9"
                 }
              ],
              "Authors": ["dortz"],
              "Programs": ["-"],
              "Bugs": ["Bruteforce", "Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2019-05-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose files content from Facebook internal CDNs",
                    "Link": "https://ysamm.com/?p=272"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Weak encryption", "Weak crypto"],
              "Bounty": "12,500",
              "PublicationDate": "2019-05-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple API issues due to Fixed Authorization token.",
                    "Link": "https://medium.com/@mustafakhan_89646/multiple-api-issues-due-to-fixed-authorization-token-17365056f17a"
                 }
              ],
              "Authors": ["Mustafa Khan (@by6153)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-05-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From file upload to email:pass",
                    "Link": "https://medium.com/@frostnull/from-file-upload-to-email-pass-dc7141aa1ff6"
                 }
              ],
              "Authors": ["fr0stNuLL"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2019-05-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Security assessment on the staging domains",
                    "Link": "https://tutorgeeks.blogspot.com/2019/05/security-assessment-on-staging-domains.html"
                 }
              ],
              "Authors": ["Tutorgeeks (@tutorgeeks)"],
              "Programs": ["-"],
              "Bugs": ["Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2019-05-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Instagram GitHub Token with public_scope found In Travis CI Build Logs",
                    "Link": "https://philippeharewood.com/instagram-github-token-with-public_scope-found-in-travis-ci-build-logs/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-05-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I acquired $XXX bounty by investing 99 cents",
                    "Link": "https://smaranchand.com.np/2019/05/how-i-acquired-xxx-bounty-by-investing-99-cents/"
                 }
              ],
              "Authors": ["Smaran Chand (@smaranchand)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-05-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating subdomain takeovers to steal cookies by abusing document.domain",
                    "Link": "https://blog.takemyhand.xyz/2019/05/escalating-subdomain-takeovers-to-steal.html"
                 }
              ],
              "Authors": ["Ameya (@iamTakeMyHand)"],
              "Programs": ["Postmates"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-05-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Determine a Facebook user from an email address",
                    "Link": "https://philippeharewood.com/determine-a-user-from-an-email-address/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,000",
              "PublicationDate": "2019-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Adwords(Privilege Escalation): Read-only user able to add YouTube channels via Linked accounts",
                    "Link": "https://whitehatfamilyguy.blogspot.com/2019/06/google-adwordsprivilege-escalation-read.html"
                 }
              ],
              "Authors": ["Family guy"],
              "Programs": ["Google"],
              "Bugs": ["Privilege escalation", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Local File Inclusion in peering.google.com",
                    "Link": "https://www.updatelap.com/2019/05/local-file-inclusion-in-peeringgooglecom.html"
                 }
              ],
              "Authors": ["Jafar Abo Nada (@Jafar_Abo_Nada)"],
              "Programs": ["Google"],
              "Bugs": ["LFI"],
              "Bounty": "3,133.7",
              "PublicationDate": "2019-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaking OpenID tokens with “ — the bug right infront of you",
                    "Link": "https://medium.com/@zseano/leaking-openid-tokens-with-the-bug-right-infront-of-you-95c1fb4a86e9"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://blog.bugbountyhunter.com/leaking-openid-tokens/"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["OIDC", "Open redirect", "Token leak"],
              "Bounty": "-",
              "PublicationDate": "2019-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WRITE UP – GOOGLE BUG BOUNTY: LFI ON PRODUCTION SERVERS in “springboard.google.com” – $13,337 USD",
                    "Link": "https://omespino.com/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Google"],
              "Bugs": ["LFI"],
              "Bounty": "13,337",
              "PublicationDate": "2019-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open-redirect to Account Takeover.",
                    "Link": "https://medium.com/@__rishabh__/open-redirect-to-account-takeover-e939006a9f24"
                 }
              ],
              "Authors": ["Rishabh (@____cypher____)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A base64 encoded parameter.",
                    "Link": "https://medium.com/@navne3t/a-base64-encoded-parameter-c6fb6b177d68"
                 }
              ],
              "Authors": ["Navneet (@na5n33t)"],
              "Programs": ["-"],
              "Bugs": ["HTML injection"],
              "Bounty": "75",
              "PublicationDate": "2019-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSSed my way to 1000$",
                    "Link": "https://gauravnarwani.com/xssed-my-way-to-1000/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "1,100",
              "PublicationDate": "2019-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing Downloads from Slack Users",
                    "Link": "https://medium.com/tenable-techblog/stealing-downloads-from-slack-users-be6829a55f63"
                 }
              ],
              "Authors": ["David Wells"],
              "Programs": ["Slack"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Instagram’s stories restriction",
                    "Link": "https://medium.com/@baibhavanandjha/bypassing-instagrams-stories-restriction-5936f8a4f079"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2019-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "‘Try-Harder’ for XSS",
                    "Link": "https://medium.com/@fbotes2/try-harder-for-xss-7aa3657255a1"
                 }
              ],
              "Authors": ["Frans Hendrik Botes (@initroott)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From parameter pollution to XSS",
                    "Link": "https://medium.com/@momenbasel/from-parameter-pollution-to-xss-d095e13be060"
                 }
              ],
              "Authors": ["Mo'men Basel"],
              "Programs": ["-"],
              "Bugs": ["HTTP parameter pollution", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-05-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "You do not need to run 80 reconnaissance tools to get access to user accounts",
                    "Link": "https://gist.github.com/stefanocoding/8cdc8acf5253725992432dedb1c9c781"
                 }
              ],
              "Authors": ["Stefano Vettorazzi (@stefanohablando)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-05-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Is MIME Sniffing XSS a real thing? [The story of weird Google bug bounties]",
                    "Link": "https://www.komodosec.com/post/mime-sniffing-xss"
                 }
              ],
              "Authors": ["Komodo Security"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS", "MIME sniffing"],
              "Bounty": "-",
              "PublicationDate": "2019-05-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Think Outside the Scope: Advanced CORS Exploitation Techniques",
                    "Link": "https://medium.com/@sandh0t/think-outside-the-scope-advanced-cors-exploitation-techniques-dad019c68397"
                 }
              ],
              "Authors": ["Ayoub (@sandh0t)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "1,500",
              "PublicationDate": "2019-05-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on Techprofile Microsoft",
                    "Link": "https://medium.com/@kang_ali/stored-xss-on-techprofile-microsoft-d21757588cc1"
                 }
              ],
              "Authors": ["Mohammad Ali Syarief"],
              "Programs": ["Microsoft"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-05-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BLIND SSRF in *.stripe.com due to Sentry Misconfiguration",
                    "Link": "https://web.archive.org/web/20190515123715/https://medium.com/@0ktavandi/blind-ssrf-in-stripe-com-due-to-sentry-misconfiguration-60ebb6a40b5"
                 }
              ],
              "Authors": ["Oktavandi (@0ktavandi)"],
              "Programs": ["Stripe"],
              "Bugs": ["Blind SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-05-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "4x CSRFs Chained For Company Account Takeover",
                    "Link": "https://medium.com/a-bugz-life/4x-csrfs-chained-for-company-account-takeover-f9fada416986"
                 }
              ],
              "Authors": ["A Bug’z Life (@abugzlife1)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "3,000",
              "PublicationDate": "2019-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL injection through User-Agent",
                    "Link": "https://medium.com/@frostnull1337/sql-injection-through-user-agent-44a1150f6888"
                 }
              ],
              "Authors": ["fr0stNuLL"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2019-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain takeover [Awarded $200]",
                    "Link": "https://medium.com/@friendly_/subdomain-takeover-awarded-200-8296f4abe1b0"
                 }
              ],
              "Authors": ["Friendly (@SkeletorKeys)"],
              "Programs": ["ownCloud"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "200",
              "PublicationDate": "2019-05-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Server Side Request Forgery(SSRF){port issue hidden approch }",
                    "Link": "https://medium.com/@w_hat_boy/server-side-request-forgery-ssrf-port-issue-hidden-approch-f4e67bd8cc86"
                 }
              ],
              "Authors": ["Deepak Holani (@w_hat_boy)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-05-03",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "ESI Injection Part 2: Abusing specific implementations",
                  "Link": "https://www.gosecure.net/blog/2019/05/02/esi-injection-part-2-abusing-specific-implementations/"
               }
            ],
            "Authors": ["Philippe Arteau (@h3xstream)", "Benoit Côté-Jodoin (@Becojo)"],
            "Programs": ["-"],
            "Bugs": ["ESI injection", "RCE", "SSRF", "HTTP header injection"],
            "Bounty": "-",
            "PublicationDate": "2019-05-02",
            "AddedDate": "2023-03-08"
         },
           {
              "Links": [
                 {
                    "Title": "Tale of a Wormable Twitter XSS",
                    "Link": "https://www.virtuesecurity.com/tale-of-a-wormable-twitter-xss/"
                 }
              ],
              "Authors": ["Ahmed Elsobky"],
              "Programs": ["Twitter"],
              "Bugs": ["XSS"],
              "Bounty": "2,940",
              "PublicationDate": "2019-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Why You Shouldn't Use a Password Manager For Your Linode Account",
                    "Link": "https://utkusen.com/blog/why-you-shouldnt-use-password-manager-for-linode.html"
                 }
              ],
              "Authors": ["Utku Şen (@utkusen)"],
              "Programs": ["Linode"],
              "Bugs": ["Account takeover", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS attacks on Googlebot allow search index manipulation",
                    "Link": "http://www.tomanthony.co.uk/blog/xss-attacks-googlebot-index-manipulation/"
                 }
              ],
              "Authors": ["Tom Anthony (@TomAnthonySEO)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-05-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote code execution On Microsoft edge using URL Protocol",
                    "Link": "https://medium.com/@mattharr0ey/remote-code-execution-on-microsoft-edge-url-protocol-a67d0f96b32d"
                 }
              ],
              "Authors": ["Matt harr0ey (@harr0ey)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-05-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From NA to $3000 : Facebook’s URL spoofing vulnerability",
                    "Link": "https://medium.com/@kankrale.rahul/from-na-to-3000-facebooks-url-spoofing-vulnerability-b4be1a3c63b1"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["URL spoofing"],
              "Bounty": "3,000",
              "PublicationDate": "2019-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reply To Instagram Stories where privacy of who can reply is set to ‘Nobody’.",
                    "Link": "https://baibhavjha.com.np/blogs/instagramstory/"
                 }
              ],
              "Authors": ["Baibhav Anand (@SpongeBhav)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2019-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Reflected XSS to Account Takeover — Showing XSS Impact",
                    "Link": "https://medium.com/a-bugz-life/from-reflected-xss-to-account-takeover-showing-xss-impact-9bc6dd35d4e6"
                 }
              ],
              "Authors": ["A Bug’z Life (@abugzlife1)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Don’t Follow The Masses: Bug Hunting in JavaScript Engines",
                    "Link": "https://labs.bluefrostsecurity.de/blog/2019/04/29/dont-follow-the-masses-bug-hunting-in-javascript-engines/"
                 }
              ],
              "Authors": ["Dimitri Fourny (@dimitrifourny)"],
              "Programs": ["Google"],
              "Bugs": ["Buffer Overflow", "Memory corruption"],
              "Bounty": "7,500",
              "PublicationDate": "2019-04-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Two-Factor Authentication Bypass",
                    "Link": "https://gauravnarwani.com/two-factor-authentication-bypass/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-04-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Access: Posting to Google private groups through any user in the group",
                    "Link": "https://medium.com/@elberandre/broken-access-posting-to-google-private-groups-through-any-user-in-the-group-3becfa818894"
                 }
              ],
              "Authors": ["Elber Andre (@Elber333)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "\"CI Knew There Would Be Bugs Here\" — Exploring Continuous Integration Services as a Bug Bounty Hunter",
                    "Link": "https://edoverflow.com/2019/ci-knew-there-would-be-bugs-here/"
                 }
              ],
              "Authors": ["EdOverflow (@EdOverflow)", "Justin Gardner (@Rhynorater)", "Corben Leo (@hacker_)", "Karim Rahal (@KarimPwnz)", "streaak (@streaak)", "d0nut (@d0nutptr)", "BBAC"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "CI/CD"],
              "Bounty": "-",
              "PublicationDate": "2019-04-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Denial of Service using Cookie Bombing",
                    "Link": "https://medium.com/@ronak_9889/denial-of-service-using-cookie-bombing-55c2d0ef808c"
                 }
              ],
              "Authors": ["Ronak Patel (@ronak_9889)"],
              "Programs": ["-"],
              "Bugs": ["DoS", "Cookie bomb"],
              "Bounty": "350",
              "PublicationDate": "2019-04-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to bypass a 2FA with a HTTP header",
                    "Link": "https://medium.com/@YumiSec/how-to-bypass-a-2fa-with-a-http-header-ce82f7927893"
                 }
              ],
              "Authors": ["Yumi"],
              "Programs": ["-"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-04-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "for PayPal security team,“get user balances and transaction details” is not a vulnerability!",
                    "Link": "https://medium.com/@tod4ro/for-paypal-security-team-get-user-balances-and-transaction-details-is-not-a-vulnerability-2e5b7f8780de"
                 }
              ],
              "Authors": ["Todaro (@tod4ro)"],
              "Programs": ["Paypal"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-04-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                {
                   "Title": "[sidefx][Poc] user enumeration & no rate limeted in send message function",
                   "Link": "https://medium.com/@protostar0/sidefx-poc-user-enumeration-no-rate-limeted-in-send-message-function-953f1662d41"
                }
              ],
              "Authors": ["Abdelhak Kharroubi"],
              "Programs": ["SideFX"],
              "Bugs": ["Username enumeration", "Lack of rate limiting"],
              "Bounty": "100",
              "PublicationDate": "2019-04-26",
              "AddedDate": "2022-10-12"
            },
           {
              "Links": [
                 {
                    "Title": "Missing Authorization check while deleting App Review for Marketing API",
                    "Link": "https://whitehatfamilyguy.blogspot.com/2019/04/missing-authorization-check-while.html"
                 }
              ],
              "Authors": ["Family guy"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing local storage data through XSS",
                    "Link": "http://blog.h4rsh4d.com/2019/04/stealing-local-storage-data-through-xss.html"
                 }
              ],
              "Authors": ["Harshad Gaikwad (@h4rsh4d)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "Account takeover"],
              "Bounty": "800",
              "PublicationDate": "2019-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The journey of Web Cache + Firewall Bypass to SSRF to AWS credentials compromise!",
                    "Link": "https://medium.com/@logicbomb_1/the-journey-of-web-cache-firewall-bypass-to-ssrf-to-aws-credentials-compromise-b250fb40af82"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["LFI", "SSRF", "WAF bypass", "Cloudflare bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF Attack can lead to Stored XSS",
                    "Link": "https://medium.com/bugbountywriteup/csrf-attack-can-lead-to-stored-xss-f40ba91f1e4f"
                 }
              ],
              "Authors": ["Mohamed Sayed (@FlEx0Geek)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A picture that steals data",
                    "Link": "https://medium.com/@iframe_h1/a-picture-that-steals-data-ff604ba1012"
                 }
              ],
              "Authors": ["Sergey Kashatov (@iframe0x01)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-04-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Getting access to Zendesk’s Google Cloud and Artifactory from GitHub dotfile repos",
                    "Link": "https://blog.assetnote.io/bug-bounty/2019/04/23/getting-access-zendesk-gcp/"
                 }
              ],
              "Authors": ["Ruby Nealon (@_ruby)"],
              "Programs": ["Zendesk"],
              "Bugs": ["Information disclosure"],
              "Bounty": "3,000",
              "PublicationDate": "2019-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook’s Burglary Shopping List",
                    "Link": "https://www.7elements.co.uk/resources/blog/facebooks-burglary-shopping-list/"
                 }
              ],
              "Authors": ["John Moss (@x41x41x41)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "5,000",
              "PublicationDate": "2019-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The neglected bug that can infect All Facebook users who pay for leads ads.",
                    "Link": "https://medium.com/@heshamwatany/the-neglected-bug-that-can-infect-all-facebook-users-who-pay-for-leads-ads-8c374cd64d76"
                 }
              ],
              "Authors": ["Hesham Watany"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSV injection"],
              "Bounty": "-",
              "PublicationDate": "2019-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Yet Other Examples of Abusing CSRF in Logout",
                    "Link": "https://soroush.secproject.com/blog/2019/04/yet-other-examples-of-abusing-csrf-in-logout/"
                 }
              ],
              "Authors": ["Soroush Dalili (@irsdl)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[XSS] Reflected XSS Bypass Filter",
                    "Link": "https://medium.com/bugbountywriteup/xss-reflected-xss-bypass-filter-de41d35239a3"
                 }
              ],
              "Authors": ["Mohamed Sayed (@FlEx0Geek)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose the content of internal Facebook Javascript modules.",
                    "Link": "https://ysamm.com/?p=256"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-04-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Ssrf to Read Local Files and Abusing the AWS metadata",
                    "Link": "https://medium.com/@pratiky054/ssrf-to-read-local-files-and-abusing-the-aws-metadata-8621a4bf382"
                 }
              ],
              "Authors": ["Pratik Yadav (@PratikY9967)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[CONFIRMATION BYPASS ]",
                    "Link": "https://medium.com/@navne3t/confirmation-bypass-ab57c29ae413"
                 }
              ],
              "Authors": ["Navneet (@na5n33t)"],
              "Programs": ["-"],
              "Bugs": ["Email verification bypass", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Twitter - protected tweets exposure",
                    "Link": "https://terjanq.github.io/Bug-Bounty/Twitter/protected-tweets-exposure-efvju8i785y1/"
                 }
              ],
              "Authors": ["Terjanq (@terjanq)"],
              "Programs": ["Twitter"],
              "Bugs": ["Information disclosure"],
              "Bounty": "560",
              "PublicationDate": "2019-04-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Responsible disclosure: improper access control in Gitlab private project.",
                    "Link": "https://rpadovani.com/gitlab-responsible-disclosure"
                 }
              ],
              "Authors": ["Riccardo Padovani (@rpadovani93)"],
              "Programs": ["GitLab"],
              "Bugs": ["Broken authorization"],
              "Bounty": "2,000",
              "PublicationDate": "2019-04-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Scary Tickets😨",
                    "Link": "https://sites.google.com/securifyinc.com/secblogs/scary-tickets"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["-"],
              "Bugs": ["Ticket Trick"],
              "Bounty": "-",
              "PublicationDate": "2019-04-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PDFReacter SSRF to ROOT Level Local File Read which led to RCE",
                    "Link": "https://medium.com/@armaanpathan/pdfreacter-ssrf-to-root-level-local-file-read-which-led-to-rce-eb460ffb3129"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Code execution - Evernote",
                    "Link": "https://www.inputzero.io/2019/04/evernote-cve-2019-10038.html"
                 }
              ],
              "Authors": ["Dhiraj (@mishradhiraj_)"],
              "Programs": ["Evernote"],
              "Bugs": ["RCE", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2019-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Banner Grabbing to DoS and Memory Corruption",
                    "Link": "https://medium.com/bugbountywriteup/banner-grabbing-to-dos-and-memory-corruption-2442b1c25bbb"
                 }
              ],
              "Authors": ["Daniel V. (@d4niel_v)"],
              "Programs": ["-"],
              "Bugs": ["DoS", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-04-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A $5000 IDOR…",
                    "Link": "https://medium.com/@mr_hacker/a-5000-idor-f4268fffcd2e"
                 }
              ],
              "Authors": ["Mr.Hacker (@mr_hacker0007)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "5,000",
              "PublicationDate": "2019-04-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i found credential enriched redis dump",
                    "Link": "https://medium.com/@D0rkerDevil/how-i-found-credential-enriched-redis-dump-2b9e808024c4"
                 }
              ],
              "Authors": ["Ashish Kunwar (@D0rkerDevil)"],
              "Programs": ["-"],
              "Bugs": ["File disclosure", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-04-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Just 5 minute to get my 2nd stored XSS on Edmodo.com",
                    "Link": "https://medium.com/@ZishanAdThandar/just-5-minute-to-get-my-2nd-stored-xss-on-edmodo-com-fe2ee559e00d"
                 }
              ],
              "Authors": ["ZishanAdThandar (@ZishanAdThandar)"],
              "Programs": ["Edmodo"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked Vending Machine",
                    "Link": "https://medium.com/@valeriyshevchenko/how-i-hacked-vending-machine-5b5a80bd5ffe"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["-"],
              "Bugs": ["Violation of secure design principles"],
              "Bounty": "300",
              "PublicationDate": "2019-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Groups Authorization Bypass",
                    "Link": "https://medium.com/@daniel.marad/post-komodosec-google-groups-authorization-bypass-500-bounty-adb371d16ab6"
                 }
              ],
              "Authors": ["Daniel Marad"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2019-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Outlook Winner is Dash",
                    "Link": "https://blog.ettic.ca/the-outlook-winner-is-dash-ac15dbc4098d"
                 }
              ],
              "Authors": ["marcan2020 (@marcan2020)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I gained access to revenue and traffic data of thousands of Shopify stores",
                    "Link": "https://blog.usejournal.com/how-i-gained-access-to-revenue-and-traffic-data-of-thousands-of-shopify-stores-b6fe360cc369"
                 }
              ],
              "Authors": ["Ayoub Fathi (@_ayoubfathi_)"],
              "Programs": ["Shopify"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Web Cache Deception to API endpoint attack using cached token header",
                    "Link": "https://medium.com/@kunal94/web-cache-deception-to-api-endpoint-attack-using-cached-token-header-b01a604a5ccd"
                 }
              ],
              "Authors": ["Kunal pandey (@kunalp94)"],
              "Programs": ["-"],
              "Bugs": ["Web cache deception"],
              "Bounty": "250",
              "PublicationDate": "2019-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[RCE] Remote code execution at api.PrivateProgram.com (CVE-2017-5638)",
                    "Link": "https://web.archive.org/web/20200929013706/https://www.mohamedharon.com/2019/04/apache-strust-rce.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "2,250",
              "PublicationDate": "2019-04-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated Account Takeover Through HTTP Leak",
                    "Link": "https://medium.com/@mrnikhilsri/unauthenticated-account-takeover-through-http-leak-33386bb0ba0b"
                 }
              ],
              "Authors": ["Nikhil (niks) (@niksthehacker)"],
              "Programs": ["-"],
              "Bugs": ["HTML injection", "HTTP Leak", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-04-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover by chaining two vulnerabilities.",
                    "Link": "https://web.archive.org/web/20191218195406/https://medium.com/@sherazkhalid_60362/account-takeover-by-chaining-two-vulnerabilities-bb447753b089"
                 }
              ],
              "Authors": ["Sheraz Khalid"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Open redirect", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-04-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple xss in *.skype.com",
                    "Link": "https://medium.com/@jayateerthag/multiple-xss-in-skype-com-81d65919ed24"
                 },
                 {
                    "Title": "Multiple xss in *.skype.com (2)",
                    "Link": "https://medium.com/@jayateerthag/multiple-xss-in-skype-com-2-18cfed39edbd"
                 }
              ],
              "Authors": ["Jayateertha Guruprasad (@JayateerthaG)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-04-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spokeo Bug bounty Experience",
                    "Link": "https://medium.com/@nuraalamdipu/spokeo-bug-bounty-experience-3f5caba52416"
                 }
              ],
              "Authors": ["Nur A Alam Dipu (@Dipu1A)"],
              "Programs": ["Spokeo"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-04-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Dell KACE K1000 Remote Code Execution — the Story of Bug K1–18652",
                    "Link": "https://www.rcesecurity.com/2019/04/dell-kace-k1000-remote-code-execution-the-story-of-bug-k1-18652/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["Dropbox"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-04-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SSRF Tips: SSRF/XSPA in Microsoft’s Bing Webmaster Central",
                    "Link": "https://medium.com/@elberandre/ssrf-trick-ssrf-xspa-in-microsofts-bing-webmaster-central-8015b5d487fb"
                 }
              ],
              "Authors": ["Elber Andre (@Elber333)"],
              "Programs": ["Microsoft"],
              "Bugs": ["SSRF", "XSPA"],
              "Bounty": "-",
              "PublicationDate": "2019-04-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Obtaining XSS Using Moodle Features and Minor Bugs",
                    "Link": "https://medium.com/@daniel.thatcher/obtaining-xss-using-moodle-features-and-minor-bugs-2035665989cc"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://blog.long.lat/2019/04/09/obtaining-xss-using-moodle-features-and-minor-bugs/"
                 }
              ],
              "Authors": ["Daniel Thatcher (@_danielthatcher)"],
              "Programs": ["Moodle"],
              "Bugs": ["Login CSRF", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-04-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got a trip to amsterdam through bug bounty",
                    "Link": "https://ninadmathpati.com/how-i-got-a-trip-to-amsterdam-through-bug-bounty/"
                 }
              ],
              "Authors": ["Ninad Mathpati (@ninad_mathpati)"],
              "Programs": ["-"],
              "Bugs": ["Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2019-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Old but GOLD Dot Dot Slash to Get the Flag — Uber Microservice",
                    "Link": "https://ngailong.wordpress.com/2019/04/07/old-but-gold-dot-dot-slash-to-get-the-flag-uber-microservice/amp/"
                 }
              ],
              "Authors": ["Ron Chan (@ngalongc)"],
              "Programs": ["Uber"],
              "Bugs": ["SSRF", "Path traversal", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Email content spoofing at IKEA.com",
                    "Link": "https://medium.com/@jonathanbouman/email-content-spoofing-at-ikea-com-ea76c17605ee"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Ikea"],
              "Bugs": ["Email content spoofing"],
              "Bounty": "50",
              "PublicationDate": "2019-04-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Edmodo — IDOR to view private files of any class",
                    "Link": "https://medium.com/@rohan_x3/edmodo-idor-to-view-private-files-of-any-class-2280676c84b8"
                 }
              ],
              "Authors": ["Rohan Pagey (@rohan_x3)"],
              "Programs": ["Edmodo"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-04-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Scary Bug in Burp Suite Upstream Proxy Allows Hackers to Hack Hackers",
                    "Link": "https://medium.com/@armaanpathan/scary-bug-in-burp-suite-upstream-proxy-allows-hackers-to-hack-hackers-e6fc9a8d60a"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["PortSwigger"],
              "Bugs": ["MiTM"],
              "Bounty": "-",
              "PublicationDate": "2019-04-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Same-Origin Policy: From birth until today",
                    "Link": "https://research.aurainfosec.io/same-origin-policy/"
                 }
              ],
              "Authors": ["Alex Nikolova (@AaylaSecura1138)"],
              "Programs": ["Mozilla", "Google (Chrome)", "Opera"],
              "Bugs": ["SOP bypass", "Browser hacking", "CSRF", "CORS"],
              "Bounty": "-",
              "PublicationDate": "2019-04-04",
              "AddedDate": "2022-10-06"
           },
           {
              "Links": [
                 {
                    "Title": "Google Ads — Information Disclosure via null pointer exception",
                    "Link": "https://www.valbrux.it/blog/2019/04/04/google-ads-information-disclosure-via-null-pointer-exception/"
                 }
              ],
              "Authors": ["Valerio brussani (@val_brux)"],
              "Programs": ["Google"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Handlebars template injection and RCE in a Shopify app",
                    "Link": "https://mahmoudsec.blogspot.com/2019/04/handlebars-template-injection-and-rce.html"
                 }
              ],
              "Authors": ["Mahmoud Gamal (@Zombiehelp54)"],
              "Programs": ["Shopify"],
              "Bugs": ["SSTI", "RCE"],
              "Bounty": "10,000",
              "PublicationDate": "2019-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaked Salesforce API access token at IKEA.com",
                    "Link": "https://medium.com/@jonathanbouman/leaked-salesforce-api-access-token-at-ikea-com-132eea3844e0"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Ikea"],
              "Bugs": ["Information disclosure", "Salesforce"],
              "Bounty": "250",
              "PublicationDate": "2019-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DownNotifier SSRF",
                    "Link": "http://archive.ingredous.com/notes/downnotifer-ssrf/"
                 }
              ],
              "Authors": ["_m_q_t (@_m_q_t)"],
              "Programs": ["DownNotifier"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-04-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I am able to hijack you.",
                    "Link": "https://medium.com/bugbountywriteup/how-i-am-able-to-hijack-you-1cab793a01d1"
                 }
              ],
              "Authors": ["Terjanq (@terjanq)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-04-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Vulnerability: Hiding from Facebook Page Admin(s) in /hacked workflow",
                    "Link": "https://medium.com/@ritishkumarsingh/https-medium-com-ritishkumarsingh-facebook-vulnerability-hiding-from-facebook-page-admin-in-hacked-workflow-86f366f183c6"
                 }
              ],
              "Authors": ["Ritish Kumar Singh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2019-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "FileZilla Untrusted Search Path",
                    "Link": "https://medium.com/tenable-techblog/filezilla-untrusted-search-path-bc3a7b3ae51e"
                 },
                 {
                    "Title": "FileZilla 'fzsftp' Untrusted Search Path",
                    "Link": "https://www.tenable.com/security/research/tra-2019-14"
                 }
              ],
              "Authors": ["Chris Lyne (@lynerc)"],
              "Programs": ["FileZilla (EU-FOSSA 2)"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to get your facebook private friend list [Responsible Disclosure]",
                    "Link": "https://medium.com/@rajsek/how-i-was-able-to-get-your-facebook-private-friend-list-responsible-disclosure-91984606e682"
                 }
              ],
              "Authors": ["Raja Sekar Durairaj"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "10,000",
              "PublicationDate": "2019-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "EdM0d0 IDOR Vulnerabilities",
                    "Link": "https://medium.com/@pratyush1337/edm0d0-idor-vulnerabilities-95ca8600ee1c"
                 }
              ],
              "Authors": ["Pratyush Anjan Sarangi"],
              "Programs": ["Edmodo"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Comma is forbidden! No worries!! Inject in insert/update queries without it",
                    "Link": "https://blog.redforce.io/sql-injection-in-insert-update-query-without-comma/"
                 }
              ],
              "Authors": ["Ahmed Sultan (@0x4148)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "10,000",
              "PublicationDate": "2019-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Recon in 2 minutes and got $250 easy",
                    "Link": "https://cryptograph3r.blogspot.com/2021/02/recon-in-2-minutes-and-got-250-easy.html"
                 }
              ],
              "Authors": ["Cryptographer (@justluthra)"],
              "Programs": ["Snapchat"],
              "Bugs": ["Missing secure flag"],
              "Bounty": "250",
              "PublicationDate": "2019-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to turn self xss into reflected xss",
                    "Link": "https://medium.com/@heinthantzin/how-i-was-able-to-turn-self-xss-into-reflected-xss-850e3d5a2beb"
                 }
              ],
              "Authors": ["Hein Thant Zin (@H3Lowr)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "300",
              "PublicationDate": "2019-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "alert(“A tale of 3 XSS!”)",
                    "Link": "https://gauravnarwani.com/a-tale-of-3-xss/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-03-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My very first bug: a dreaded dupe and then an IDOR jackpot!",
                    "Link": "https://medium.com/h4x00r/my-very-first-bug-a-dreaded-dupe-and-then-an-idor-jackpot-d01b69f6fbae"
                 }
              ],
              "Authors": ["John H4X00R (@JohnH4X00R)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["IDOR"],
              "Bounty": "5,000",
              "PublicationDate": "2019-03-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could have hijacked a victim’s YouTube notifications! (Google VRP Writeup)",
                    "Link": "https://hackademic.co.in/youtube-bug/"
                 }
              ],
              "Authors": ["Yash Sodha (@y_sodha)"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "3,133.70",
              "PublicationDate": "2019-03-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An Unusual Bug 🐛 on Braintree [PayPal]",
                    "Link": "https://blog.usejournal.com/an-unusal-bug-on-braintree-paypal-b8d3ec662414"
                 }
              ],
              "Authors": ["PRince CHaddha (@princechaddha)"],
              "Programs": ["Paypal"],
              "Bugs": ["DoS"],
              "Bounty": "3,200",
              "PublicationDate": "2019-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Twitter Denial of Service bug or How i could prevent all followers from reading or accessing literally ANY tweets!",
                    "Link": "https://www.seekurity.com/blog/general/twitter-denial-of-service-bug-or-how-i-could-prevent-all-followers-from-reading-or-accessing-literally-any-tweets/"
                 }
              ],
              "Authors": ["Seif Elsallamy (@seifelsallamy)"],
              "Programs": ["Twitter"],
              "Bugs": ["DoS"],
              "Bounty": "1,120",
              "PublicationDate": "2019-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Marketing Confidential Call Transcript",
                    "Link": "https://philippeharewood.com/facebook-marketing-confidential-call-transcript/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2019-03-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Books X-Hacking",
                    "Link": "https://medium.com/@terjanq/google-books-x-hacking-29c249862f19"
                 }
              ],
              "Authors": ["Terjanq (@terjanq)"],
              "Programs": ["Google"],
              "Bugs": ["XS-Search"],
              "Bounty": "1,337",
              "PublicationDate": "2019-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to hunt for Malvertising ads on Android",
                    "Link": "https://b3nac.com/posts/2019-02-16-How-to-hunt-for-Malvertising-ads-on-Android.html"
                 }
              ],
              "Authors": ["Kyle (@B3nac)"],
              "Programs": ["-"],
              "Bugs": ["Android"],
              "Bounty": "-",
              "PublicationDate": "2019-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A real XSS in OLX Bug Bounty",
                    "Link": "https://medium.com/@paulorcchoupina/a-real-xss-in-olx-7727ae89c640"
                 }
              ],
              "Authors": ["Paulo Choupina (@PauloChoupina)"],
              "Programs": ["OLX"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Slack announcement-only channel post restriction bypass",
                    "Link": "https://www.rodneybeede.com/security/slack-announcement-only-channel-post-restriction-bypass.html"
                 }
              ],
              "Authors": ["Rodney Beede"],
              "Programs": ["Slack"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-03-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Fizz integer overflow vulnerability (CVE-2019-3560)",
                    "Link": "https://securitylab.github.com/research/facebook-fizz-CVE-2019-3560/"
                 }
              ],
              "Authors": ["Kevin Backhouse (@kevin_backhouse)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Integer overflow", "Memory corruption"],
              "Bounty": "10,000",
              "PublicationDate": "2019-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Discovering a zero day and getting code execution on Mozilla's AWS Network",
                    "Link": "https://blog.assetnote.io/bug-bounty/2019/03/19/rce-on-mozilla-zero-day-webpagetest/"
                 }
              ],
              "Authors": ["Shubham Shah (@infosec_au)", "Mathias Karlsson (@avlidienbrunn)"],
              "Programs": ["Mozilla"],
              "Bugs": ["RCE"],
              "Bounty": "500",
              "PublicationDate": "2019-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DoS Across Facebook Endpoints",
                    "Link": "https://medium.com/@maxpasqua/dos-across-facebook-endpoints-1d7d0bc27c7f"
                 }
              ],
              "Authors": ["Max Pasqua"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS"],
              "Bounty": "750",
              "PublicationDate": "2019-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From http:// domain to res:// domain xss by using IE Adobe’s PDF ActiveX plugin",
                    "Link": "https://medium.com/@80vul/from-http-domain-to-res-domain-xss-by-using-ie-adobes-pdf-activex-plugin-9f2a72a87aff"
                 }
              ],
              "Authors": ["Heige (@80vul)"],
              "Programs": ["Microsoft"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-03-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Should you be concerned about LastPass uploading your passwords to its server?",
                    "Link": "https://palant.info/2019/03/18/should-you-be-concerned-about-lastpass-uploading-your-passwords-to-its-server/"
                 }
              ],
              "Authors": ["Wladimir Palant (@WPalant)"],
              "Programs": ["LastPass"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-03-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclosure of Pending Roles for any Facebook Page",
                    "Link": "https://medium.com/@avinash_/disclosure-of-pending-roles-for-any-facebook-page-ab6e4e219f8e"
                 }
              ],
              "Authors": ["Avinash Kumar (@itsavinash_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "4,000",
              "PublicationDate": "2019-03-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Target Finds Cross-Site Scripting in Microsoft SharePoint",
                    "Link": "https://tech.target.com/2019/03/15/SharePoint-Cross-Site-Scripting.html"
                 }
              ],
              "Authors": ["Target"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to pwned 30000+ user’s webhook",
                    "Link": "https://medium.com/@vis_hacker/how-i-was-able-to-pwned-30000-users-webhook-d26dc3420703"
                 }
              ],
              "Authors": ["gujjuboy10x00 (@vis_hacker)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege escalation on private program.",
                    "Link": "https://medium.com/@imranparray/privilege-escalation-on-private-program-a2a5548cde09"
                 }
              ],
              "Authors": ["Imran Parray (@imranparray101)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "User Account Takeover [Password Change]— Nice Catch!",
                    "Link": "https://medium.com/@rohitcoder/user-account-takeover-password-change-nice-catch-2293f4d272b2"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2019-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write up – $1,000 usd in 5 minutes, xss stored in outlook.com (ios browsers)",
                    "Link": "https://omespino.com/write-up-1000-usd-in-5-minutes-xss-stored-in-outlook-com-ios-browsers/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2019-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WordPress 5.1 CSRF to Remote Code Execution",
                    "Link": "https://www.sonarsource.com/blog/wordpress-csrf-to-rce/"
                 }
              ],
              "Authors": ["Simon Scannell (@scannell_simon)"],
              "Programs": ["WordPress"],
              "Bugs": ["CSRF", "RCE", "HTML injection"],
              "Bounty": "950",
              "PublicationDate": "2019-03-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OLX Bug Bounty: Reflected XSS",
                    "Link": "https://medium.com/@abaykandotcom/olx-bug-bounty-reflected-xss-adb3095cd525"
                 }
              ],
              "Authors": ["Mukhammad Akbar (@abaykandotcom)"],
              "Programs": ["OLX"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-03-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Stored XSS on Edmodo.com",
                    "Link": "https://medium.com/@ZishanAdThandar/my-first-stored-xss-on-edmodo-com-540a33349662"
                 }
              ],
              "Authors": ["ZishanAdThandar (@ZishanAdThandar)"],
              "Programs": ["Edmodo"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-03-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hack Your Form-New vector for Blind XSS",
                    "Link": "https://medium.com/@GeneralEG/hack-your-form-new-vector-for-blind-xss-b7a50b808016"
                 }
              ],
              "Authors": ["Youssef A. Mohamed (@GeneralEG64)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS", "Stored XSS"],
              "Bounty": "800",
              "PublicationDate": "2019-03-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found Blind XSS Vulnerability in redacted.com",
                    "Link": "https://medium.com/@newp_th/how-i-find-blind-xss-vulnerability-in-redacted-com-33af18b56869"
                 }
              ],
              "Authors": ["ssid (@newp_th)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Brute Forcing User IDS via CSRF To Delete all Users with CSRF attack.",
                    "Link": "https://medium.com/@armaanpathan/brute-forcing-user-ids-via-csrf-to-delete-all-users-with-csrf-attack-216ccd4d832c"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2019-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating SSRF to RCE",
                    "Link": "https://medium.com/cesppa/escalating-ssrf-to-rce-f28c482eb8b9"
                 }
              ],
              "Authors": ["Youssef A. Mohamed (@GeneralEG64)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-03-25",
              "AddedDate": "2022-09-12"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2018-16794 on fs.thefacebook.com",
                    "Link": "https://philippeharewood.com/cve-2018-16794-on-fs-thefacebook-com/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["SSRF"],
              "Bounty": "1,000",
              "PublicationDate": "2019-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Inserting malware into anyone’s Google Earth Projects Archive",
                    "Link": "https://websecblog.com/vulns/google-earth-studio-vulnerability/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR", "XSS", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-03-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL injection for $50 bounty, but still worth reading!!",
                    "Link": "https://medium.com/@orthonviper/sql-injection-for-50-bounty-but-still-worth-reading-468442c1cc1a"
                 }
              ],
              "Authors": ["Ronaldo Messi"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "50",
              "PublicationDate": "2019-03-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover Using Cross-Site WebSocket Hijacking (CSWH)",
                    "Link": "https://medium.com/@sharan.panegav/account-takeover-using-cross-site-websocket-hijacking-cswh-99cf9cea6c50"
                 }
              ],
              "Authors": ["Sharan Panegav (@PanegavSharan)"],
              "Programs": ["-"],
              "Bugs": ["Cross-Site WebSocket Hijacking (CSWH)", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vimeo SSRF with code execution potential.",
                    "Link": "https://medium.com/@rootxharsh_90844/vimeo-ssrf-with-code-execution-potential-68c774ba7c1e"
                 }
              ],
              "Authors": ["Harsh Jaiswal (@rootxharsh)"],
              "Programs": ["Vimeo"],
              "Bugs": ["SSRF"],
              "Bounty": "5,000",
              "PublicationDate": "2019-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Mapping Communication Between Facebook Accounts Using a Browser-Based Side Channel Attack",
                    "Link": "https://www.imperva.com/blog/mapping-communication-between-facebook-accounts-using-a-browser-based-side-channel-attack/"
                 }
              ],
              "Authors": ["Ron Masas (@RonMasas)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Side-channel attack", "Cross-Site Frame Leakage (CSFL)"],
              "Bounty": "-",
              "PublicationDate": "2019-03-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Messenger server random memory exposure through corrupted GIF image",
                    "Link": "https://www.vulnano.com/2019/03/facebook-messenger-server-random-memory.html"
                 }
              ],
              "Authors": ["Dzmitry Lukyanenka (@vulnano)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "10,000",
              "PublicationDate": "2019-03-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "3 XSS in ProtonMail for iOS",
                    "Link": "https://medium.com/@vladimirmetnew/3-xss-in-protonmail-for-ios-95f8e4b17054"
                 }
              ],
              "Authors": ["Vladimir Metnew (@vladimir_metnew)"],
              "Programs": ["Apple"],
              "Bugs": ["XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2019-03-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fixed : Register any email address on Facebook Account",
                    "Link": "https://medium.com/@addictrao20/fixed-register-any-email-address-on-facebook-account-c6d1c3eb810d"
                 }
              ],
              "Authors": ["Sameer Rao"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-03-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fixed : Brute-force Instagram account’s passwords",
                    "Link": "https://medium.com/@addictrao20/fixed-brute-force-instagram-accounts-passwords-938471b6e9d4"
                 }
              ],
              "Authors": ["Sameer Rao"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Bruteforce", "Rate limiting bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-03-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook exploit – Confirm website visitor identities",
                    "Link": "http://www.tomanthony.co.uk/blog/facebook-bug-confirm-user-identities/"
                 }
              ],
              "Authors": ["Tom Anthony (@TomAnthonySEO)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "IDOR"],
              "Bounty": "1,000",
              "PublicationDate": "2019-03-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Auditing GitHub Repo Wikis for Fun and Profit",
                    "Link": "https://www.smeegesec.com/2019/03/auditing-github-repo-wikis-for-fun-and.html"
                 }
              ],
              "Authors": ["Smeege (@SmeegeSec)"],
              "Programs": ["-"],
              "Bugs": ["Misconfigured Github wiki"],
              "Bounty": "500",
              "PublicationDate": "2019-03-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Edmodo within 5 Minute (My First Bug Bounty)",
                    "Link": "https://medium.com/@valakeyur/xss-in-edmodo-within-5-minute-my-first-bug-bounty-889e3da6167d"
                 }
              ],
              "Authors": ["Vala Keyur (@valakeyur)"],
              "Programs": ["Edmodo"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-03-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A simple Account takeover misusing JWT late expiration",
                    "Link": "http://obsidianterminal.blogspot.com/2019/03/a-simple-account-takeover-misusing-jwt.html"
                 }
              ],
              "Authors": ["Scalar (@mrprajapati_360)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-03-03",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Universal RCE with Ruby YAML.load",
                  "Link": "https://staaldraad.github.io/post/2019-03-02-universal-rce-ruby-yaml-load/"
               }
            ],
            "Authors": ["Etienne Stalmans (@_staaldraad)"],
            "Programs": ["-"],
            "Bugs": ["Insecure deserialization", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2019-03-02",
            "AddedDate": "2023-08-08"
         },
           {
              "Links": [
                 {
                    "Title": "Bypassing a restrictive JS sandbox",
                    "Link": "https://licenciaparahackear.github.io/en/posts/bypassing-a-restrictive-js-sandbox/"
                 }
              ],
              "Authors": ["Licencia para Hackear"],
              "Programs": ["-"],
              "Bugs": ["JS sandbox breakout", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Yet Another (unexpected) Hack for Bounty",
                    "Link": "https://medium.com/@pumudu88/yet-another-unexpected-hack-for-bounty-295cee0ecc24"
                 }
              ],
              "Authors": ["Pumudu Ruhunage"],
              "Programs": ["Sli.do"],
              "Bugs": ["Information disclosure"],
              "Bounty": "150",
              "PublicationDate": "2019-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Horizontal Privilege Escalation on Quora which can compromise all users on Quora",
                    "Link": "https://spyclub.tech/2019/02/26/horizontal-privilege-escalation-on-quora/"
                 }
              ],
              "Authors": ["SpyD3r (@TarunkantG)"],
              "Programs": ["Quora"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2019-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Still work] Redirect Yahoo Subdomain XSS Reflected from americangreetings.com",
                    "Link": "https://web.archive.org/web/20200929000850/https://www.mohamedharon.com/2019/02/still-work-redirect-yahoo-subdomain-xss.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I alert(1) in Azure DevOps",
                    "Link": "https://5alt.me/2019/02/xss-in-azure-devops/"
                 }
              ],
              "Authors": ["SpyD3r (@TarunkantG)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS", "CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-02-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Web Cache Deception Attack leads to user info disclosure",
                    "Link": "https://medium.com/@kunal94/web-cache-deception-attack-leads-to-user-info-disclosure-805318f7bb29"
                 }
              ],
              "Authors": ["Kunal pandey (@kunalp94)"],
              "Programs": ["-"],
              "Bugs": ["Web cache deception", "Information disclosure"],
              "Bounty": "300",
              "PublicationDate": "2019-02-25",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "SHAREit Multiple Vulnerabilities Enable Unrestricted Access to Adjacent Devices’ Files",
                  "Link": "https://blog.redforce.io/shareit-vulnerabilities-enable-unrestricted-access-to-adjacent-devices-files/"
               }
            ],
            "Authors": ["Abdulrahman Nour (@aboodnour)"],
            "Programs": ["SHAREit"],
            "Bugs": ["Android", "Arbitrary file download", "Authentication bypass"],
            "Bounty": "-",
            "PublicationDate": "2019-02-25",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Chain of hacks leading to Database Compromise!",
                    "Link": "https://medium.com/@logicbomb_1/chain-of-hacks-leading-to-database-compromise-b2bc2b883915"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["LFI", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-02-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty 101 — Always Check The Source Code",
                    "Link": "https://medium.com/@spazzyy/bug-bounty-101-always-check-the-source-code-1adaf3f59567"
                 }
              ],
              "Authors": ["Spazzy"],
              "Programs": ["-"],
              "Bugs": ["Lack of rate limiting", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-02-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Download any organisation Data — S3 amazonaws Misconfiguration",
                    "Link": "https://medium.com/@ChandSingh/download-any-organisation-data-s3-amazonaws-64059847e06"
                 }
              ],
              "Authors": ["Chand Singh (@Chand_42)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "2,500",
              "PublicationDate": "2019-02-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Misconfiguration lead to AWS S3 Buckets Reader",
                    "Link": "https://web.archive.org/web/20200929003949/https://www.mohamedharon.com/2019/02/subdomain-aws-s3-buckets-reader.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "800",
              "PublicationDate": "2019-02-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Google Calendars",
                    "Link": "https://sites.google.com/securifyinc.com/secblogs/exploitingcalendars"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)", "Brandon Nguyen (@cmdrsnuggle)"],
              "Programs": ["Uber", "Shopify", "Netflix"],
              "Bugs": ["Broken authorization", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-02-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Swiss_E-Voting_Publications",
                    "Link": "https://github.com/setuid0-sec/Swiss_E-Voting_Publications"
                 }
              ],
              "Authors": ["setuid0 (@_setuid0_)"],
              "Programs": ["Swiss E-Voting"],
              "Bugs": ["XSS", "XXE", "RCE", "Missing authentication", "Broken authentication", "Hardcoded credentials"],
              "Bounty": "-",
              "PublicationDate": "2019-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing autoresponders and email bounces",
                    "Link": "https://medium.com/intigriti/abusing-autoresponders-and-email-bounces-9b1995eb53c2"
                 }
              ],
              "Authors": ["Inti De Ceukelaire (@securinti)"],
              "Programs": ["Google", "Intigriti"],
              "Bugs": ["Information disclosure", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS at https://photos.shopify.com",
                    "Link": "https://medium.com/@modam3r5/reflected-xss-at-https-photos-shopify-com-ea696db3915c"
                 }
              ],
              "Authors": ["Ahamed Morad (@Modam3r5)"],
              "Programs": ["Shopify"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Registered Multiple Accounts in PrivateInternetAccess VPN Service for FREE",
                    "Link": "https://medium.com/@spade.com/how-i-registered-multiple-accounts-in-privateinternetaccess-vpn-service-for-free-a2068642f418"
                 }
              ],
              "Authors": ["Spade"],
              "Programs": ["PrivateInternetAccess VPN"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2019-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Writeup: FBCTF IDOR",
                    "Link": "https://georgeosterweil.com/2019-02-20-fbctf-idor/"
                 }
              ],
              "Authors": ["George Osterweil"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leakage of Client Secret, Server tokens of all Uber developer applications",
                    "Link": "https://medium.com/@appsecure/leakage-of-client-secret-server-tokens-of-all-uber-developer-applications-657d9d7fd30e"
                 }
              ],
              "Authors": ["Anand Prakash (@anandpraka_sh)"],
              "Programs": ["Uber"],
              "Bugs": ["Information disclosure"],
              "Bounty": "5,000",
              "PublicationDate": "2019-02-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Stored XSS On Tokopedia",
                    "Link": "https://apapedulimu.click/multiple-stored-xss-on-tokopedia/"
                 }
              ],
              "Authors": ["apapedulimu / Nosa Shandy (@LocalHost31337)"],
              "Programs": ["Tokopedia"],
              "Bugs": ["Stored XSS", "Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-02-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Using URI to pop shells via the Discord Client",
                    "Link": "https://0x00sec.org/t/using-uri-to-pop-shells-via-the-discord-client/11673"
                 }
              ],
              "Authors": ["RagSec (@rag_sec)"],
              "Programs": ["Discord"],
              "Bugs": ["URI abuse", "Social engineering"],
              "Bounty": "-",
              "PublicationDate": "2019-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DoS on WAF Protected Sites by Abusing Cookie",
                    "Link": "https://www.hackerinside.me/2019/02/dos-on-waf-protected-sites-by-abusing.html"
                 }
              ],
              "Authors": ["Anas Mahmood (@AnasIsHere)"],
              "Programs": ["Upwork"],
              "Bugs": ["DoS"],
              "Bounty": "400",
              "PublicationDate": "2019-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "2 Subdomains Takeover via Unbounce in a Private Program",
                    "Link": "https://web.archive.org/web/20201117123227/https://www.mohamedharon.com/2019/02/2-subdomains-takeover-via-unbounce-in.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on Edmodo",
                    "Link": "https://medium.com/@futaacmcyber/stored-xss-on-edmodo-11a3fbc6b6d0"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Edmodo"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$1.000 SSRF in Slack",
                    "Link": "https://medium.com/@elberandre/1-000-ssrf-in-slack-7737935d3884"
                 }
              ],
              "Authors": ["Elber Andre (@Elber333)"],
              "Programs": ["Slack"],
              "Bugs": ["SSRF"],
              "Bounty": "1,000",
              "PublicationDate": "2019-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass password confirmation in Facebook “DYI” feature",
                    "Link": "https://ysamm.com/?p=240"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook/Workplace Bug Exposed Offsite Employee Events, Sensitive emails Putting Employees at Risk",
                    "Link": "https://medium.com/@rohitcoder/facebook-workplace-bug-exposed-offsite-employee-events-sensitive-emails-putting-employees-at-risk-813d77a0c0ab"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,000",
              "PublicationDate": "2019-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover via Wufoo Service in a Private Program",
                    "Link": "https://web.archive.org/web/20200929010534/https://www.mohamedharon.com/2019/02/subdomain-takeover-via-wufoo-service-in.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open Redirect in SLACK",
                    "Link": "https://medium.com/@abaykandotcom/open-redirect-in-slack-385eb34b7c5f"
                 }
              ],
              "Authors": ["Mukhammad Akbar (@abaykandotcom)"],
              "Programs": ["Slack"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-02-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing rate limit abusing misconfiguration rules",
                    "Link": "https://medium.com/bugbountywriteup/bypassing-rate-limit-abusing-misconfiguration-rules-dcd38e4e1028"
                 }
              ],
              "Authors": ["Daniel V. (@d4niel_v)"],
              "Programs": ["-"],
              "Bugs": ["Rate limiting bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover via HubSpot",
                    "Link": "https://web.archive.org/web/20200928234202/https://www.mohamedharon.com/2019/02/subdomain-takeover-via-hubspot.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Souq.com Subdomain Takeover via jazzhr.com service",
                    "Link": "https://web.archive.org/web/20200929012457/https://www.mohamedharon.com/2019/02/souqcom-subdomain-takeover-via.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Souq.com"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Never Stop at Banner Grabbing",
                    "Link": "https://gauravnarwani.com/never-stop-at-banner-grabbing/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "241.93",
              "PublicationDate": "2019-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Third Party Android App Storing Facebook Data Insecurely (Facebook Data Abuse Program)",
                    "Link": "https://wwws.nightwatchcybersecurity.com/2019/02/14/third-party-android-app-storing-facebook-data-insecurely/"
                 }
              ],
              "Authors": ["Nightwatch Cybersecurity (@nightwatchcyber)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Missing authentication"],
              "Bounty": "-",
              "PublicationDate": "2019-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[SSRF] Server Side Request Forgery in a private Program developers.example.com",
                    "Link": "https://web.archive.org/web/20200929022152/https://www.mohamedharon.com/2019/02/ssrf-server-side-request-forgery-in.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "200",
              "PublicationDate": "2019-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose private attachments in Facebook Messenger Infrastructure - 15,000$",
                    "Link": "https://medium.com/bugbountywriteup/disclose-private-attachments-in-facebook-messenger-infrastructure-15-000-ae13602aa486"
                 }
              ],
              "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "15,000",
              "PublicationDate": "2019-02-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook CSRF protection bypass which leads to Account Takeover",
                    "Link": "https://ysamm.com/?p=185"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "25,000",
              "PublicationDate": "2019-02-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking YouTube for #fun and #profit",
                    "Link": "https://www.linkedin.com/pulse/hacking-youtube-fun-profit-alexandru-coltuneac/"
                 }
              ],
              "Authors": ["Alexandru Coltuneac (@dekeeu)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-02-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Export Facebook audience network reports of any business",
                    "Link": "https://ysamm.com/?p=214"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-02-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I Found Clickjacking on Google CSE. Is This Important?",
                    "Link": "https://medium.com/@abaykandotcom/clickjacking-on-google-cse-6636bba72d20"
                 }
              ],
              "Authors": ["Mukhammad Akbar (@abaykandotcom)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2019-02-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Csrf Bypass Using Cross Frame Scripting",
                    "Link": "https://medium.com/@mr_hacker/csrf-bypass-using-cross-frame-scripting-c349d6f33eb6"
                 }
              ],
              "Authors": ["Mr.Hacker (@mr_hacker0007)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2019-02-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked ASUS?",
                    "Link": "https://mustafakemalcan.com/asus-rce-vulnerability-on-rma-asus-europe-eu/"
                 }
              ],
              "Authors": ["Mustafa Kemal Can (@muskecan)"],
              "Programs": ["Asus"],
              "Bugs": ["Unrestricted file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-02-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Setting Up Gitrob and using it to find Leaking Repository of an Employee in a hackerone private program.",
                    "Link": "https://medium.com/@pig.wig45/setting-up-gitrob-and-using-it-to-find-leaking-repository-of-an-employee-in-a-hackerone-private-e4c40da1bc85"
                 }
              ],
              "Authors": ["Sahil Tikoo (@viperbluff)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-02-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Internal paths disclosure due to improper exception handling",
                    "Link": "https://ysamm.com/?p=158"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-02-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leak of private/in-development app ids, names and translation requests",
                    "Link": "https://ysamm.com/?p=171"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-02-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to dump SqlDB | Simple bug",
                    "Link": "https://clever-idi0t.com/2019/02/07/how-i-was-able-to-dump-sqldb-simple-bug/"
                 }
              ],
              "Authors": ["clever idi0t"],
              "Programs": ["-"],
              "Bugs": ["Directory listing", "SQL injection", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-02-07",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "X Forwarded for SQL injection",
                  "Link": "https://outpost24.com/blog/X-forwarded-for-SQL-injection"
               }
            ],
            "Authors": ["Nikos Danopoulos"],
            "Programs": ["-"],
            "Bugs": ["SQL injection"],
            "Bounty": "-",
            "PublicationDate": "2019-02-06",
            "AddedDate": "2022-12-09"
         },
           {
              "Links": [
                 {
                    "Title": "Cache Deception: How I discovered a vulnerability in Medium and helped them fix it",
                    "Link": "https://medium.freecodecamp.org/cache-deception-how-i-discovered-a-vulnerability-in-medium-and-helped-them-fix-it-31cec2a3938b"
                 }
              ],
              "Authors": ["Yuval Shprinz"],
              "Programs": ["Medium"],
              "Bugs": ["Web cache deception"],
              "Bounty": "100",
              "PublicationDate": "2019-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Code Execution via Path Traversal in the Device Metadata Authoring Wizard",
                    "Link": "https://posts.specterops.io/remote-code-execution-via-path-traversal-in-the-device-metadata-authoring-wizard-a0d5839fc54f"
                 }
              ],
              "Authors": ["Lee Christensen (@tifkin_)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Path traversal", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Jumping Over The Fence",
                    "Link": "https://medium.com/@albeckshahar/jumping-over-the-fence-ce0fe5f9a3a2"
                 }
              ],
              "Authors": ["Shahar Albeck"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked 40,000 user accounts of Microsoft using 2FA bypass(outlook.live.com)",
                    "Link": "https://medium.com/@goyalvartul/how-i-hacked-40-000-user-accounts-of-microsoft-using-2fa-bypass-outlook-live-com-13258785ec2f"
                 }
              ],
              "Authors": ["Vartul Goyal (@hackvartul)"],
              "Programs": ["Microsoft"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Detecting and exploiting mass-assignments in order to manipulate user columns and read private messages",
                    "Link": "https://dannewitz.ninja/posts/detecting-and-exploiting-mass-assignments"
                 }
              ],
              "Authors": ["Paul (@padannewitz)"],
              "Programs": ["-"],
              "Bugs": ["Mass assignment"],
              "Bounty": "5,000",
              "PublicationDate": "2019-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reverse RDP Attack: Code Execution on RDP Clients",
                    "Link": "https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/"
                 }
              ],
              "Authors": ["Eyal Itkin"],
              "Programs": ["Microsoft"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2019-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Unique XSS Scenario in SmartSheet || $1000 bounty",
                    "Link": "https://medium.com/@rohanchavan/a-unique-xss-scenario-1000-bounty-347f8f92fcc6"
                 }
              ],
              "Authors": ["Rohan Chavan (@rohanchavan1918)"],
              "Programs": ["Smartsheet"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2019-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to Extract Information of Other Users- Exploiting IDOR",
                    "Link": "https://medium.com/@rupika.luhach/how-i-was-able-to-extract-information-of-other-users-exploiting-idor-9f03aa72dd06"
                 }
              ],
              "Authors": ["Rupika Luhach (@Rup_Ki_Rani)"],
              "Programs": ["Knowyourmeds.com"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "LFI in Apigee portals",
                    "Link": "https://offensi.com/2019/01/31/lfi-in-apigee-portals"
                 }
              ],
              "Authors": ["wtm@offensi.com (@wtm_offensi)"],
              "Programs": ["Google"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2019-01-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found a simple bug in Facebook without any Test",
                    "Link": "https://medium.com/bugbountywriteup/how-i-found-a-simple-bug-in-facebook-without-any-test-3bc8cf5e2ca2"
                 }
              ],
              "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-01-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$7.5k Google Cloud Platform organization issue",
                    "Link": "https://www.ezequiel.tech/2019/01/75k-google-cloud-platform-organization.html"
                 }
              ],
              "Authors": ["Ezequiel Pereira (@epereiralopez)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "7,500",
              "PublicationDate": "2019-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked a website integrated w/ Facebook having 1.1 mil. users under 45 seconds.",
                    "Link": "https://medium.com/@0x48piraj/how-i-hacked-a-website-integrated-w-facebook-having-1-1-mil-users-under-45-seconds-e4adcfe8ccd6"
                 }
              ],
              "Authors": ["Piyush Raj (@0x48piraj)"],
              "Programs": ["WeeQuizz"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Publish tweets by any other user",
                    "Link": "https://medium.com/@kedrisec/publish-tweets-by-any-other-user-6c9d892708e3"
                 }
              ],
              "Authors": ["Kedrisec (@kedrisec)"],
              "Programs": ["Twitter"],
              "Bugs": ["IDOR"],
              "Bounty": "7,560",
              "PublicationDate": "2019-01-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Guest blog: Eray Mitrani - Hacking isn’t an exact science",
                    "Link": "https://blog.detectify.com/2019/01/29/hacking-isnt-an-exact-science/"
                 }
              ],
              "Authors": ["Eray Mitrani (@ErayMitrani)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-01-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Protonmail XSS — Stored",
                    "Link": "https://medium.com/@ChandSingh/protonmail-xss-stored-b733031ac3b5"
                 }
              ],
              "Authors": ["Chand Singh (@Chand_42)"],
              "Programs": ["Proton Mail"],
              "Bugs": ["Stored XSS", "Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2019-01-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unsecured access to personal data of a million Leo Express users",
                    "Link": "https://websecblog.com/vulns/leoexpress-personal-data/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Leo Express"],
              "Bugs": ["Broken authorization", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-01-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hijacking accounts by retrieving JWT tokens via unvalidated redirects",
                    "Link": "https://www.shawarkhan.com/2019/01/hijacking-accounts-by-retrieving-jwt.html"
                 }
              ],
              "Authors": ["Shawar Khan (@ShawarkOFFICIAL)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Token leak"],
              "Bounty": "-",
              "PublicationDate": "2019-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A short tale of Account verification bypass",
                    "Link": "https://medium.com/@satboy.fb/a-short-tale-of-account-verification-bypass-22045b38a8b1"
                 }
              ],
              "Authors": ["Satyendra Kumar"],
              "Programs": ["-"],
              "Bugs": ["Email verification bypass", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining Tricky OAuth Exploitation To Stored XSS",
                    "Link": "https://medium.com/@nahoragg/chaining-tricky-oauth-exploitation-to-stored-xss-b67eaea4aabd"
                 }
              ],
              "Authors": ["Rohan aggarwal (@nahoragg)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "OAuth"],
              "Bounty": "-",
              "PublicationDate": "2019-01-27",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Baking Flask cookies with your secrets",
                  "Link": "https://blog.paradoxis.nl/defeating-flasks-session-management-65706ba9d3ce"
               }
            ],
            "Authors": ["Luke Paris"],
            "Programs": ["-"],
            "Bugs": ["Session management issue"],
            "Bounty": "-",
            "PublicationDate": "2019-01-26",
            "AddedDate": "2024-02-06"
         },
           {
              "Links": [
                 {
                    "Title": "Misconfiguration-Whatsapp Messenger",
                    "Link": "https://medium.com/@pratheesh.p.narayanan/misconfiguration-whatsapp-messenger-1f0f1cf3ef00"
                 }
              ],
              "Authors": ["Pratheesh P Narayanan"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2019-01-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AntiHack IDOR on Create Submission",
                    "Link": "https://medium.com/@sahruldotid/antihack-idor-on-create-submission-ddb3cf40c26b"
                 }
              ],
              "Authors": ["Syahrul Akbar Rohmani (@sahruldotid)"],
              "Programs": ["AntiHack.me"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-01-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Change Product Availability as a PageAnalyst",
                    "Link": "https://www.symbo1.com/articles/2019/01/25/fb-change-product-availability-as-pageanalyst.html"
                 }
              ],
              "Authors": ["onehackzero"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I abused 2FA to maintain persistence after a password change (Google, Microsoft, Instagram, Cloudflare, etc)",
                    "Link": "https://medium.com/@lukeberner/how-i-abused-2fa-to-maintain-persistence-after-a-password-change-google-microsoft-instagram-7e3f455b71a1"
                 }
              ],
              "Authors": ["Luke Berner"],
              "Programs": ["Google", "Microsoft", "Meta / Facebook"],
              "Bugs": ["Logic flaw","Broken authentication"],
              "Bounty": "-",
              "PublicationDate": "2019-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Magento – RCE & Local File Read with low privilege admin rights",
                    "Link": "https://blog.scrt.ch/2019/01/24/magento-rce-local-file-read-with-low-privilege-admin-rights/"
                 }
              ],
              "Authors": ["Daniel Le Gall (@Blaklis_)"],
              "Programs": ["Magento"],
              "Bugs": ["LFI", "RCE", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2019-01-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Antihack.me Blind XSS To PHP File Upload Vulnerability",
                    "Link": "https://blog.saycure.io/2019/01/24/antihack-xss-2-php-upload/"
                 }
              ],
              "Authors": ["SayCure (@SaycureIO)"],
              "Programs": ["AntiHack.me"],
              "Bugs": ["Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-01-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation to Highest Admin Privileges",
                    "Link": "https://gauravnarwani.com/priv-esc-highest-admin/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2019-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Frappé Technologies ERPNext Server Side Template Injection",
                    "Link": "https://medium.com/bugbountywriteup/frapp%C3%A9-technologies-erpnext-server-side-template-injection-74e1c95ec872"
                 }
              ],
              "Authors": ["Brian Hyde (@0xHyde)"],
              "Programs": ["ERPNext"],
              "Bugs": ["SSTI"],
              "Bounty": "-",
              "PublicationDate": "2019-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Enroll in Facebook Ad-break program without Facebook approval",
                    "Link": "https://ysamm.com/?p=68"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose page’s admins and its Monetization payout details",
                    "Link": "https://ysamm.com/?p=60"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose page violations and its eligibility to use Ad-breaks",
                    "Link": "https://ysamm.com/?p=64"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose Instagram business account linked to a Facebook page",
                    "Link": "https://ysamm.com/?p=56"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Change payment account of any Facebook commerce page",
                    "Link": "https://ysamm.com/?p=50"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Expose business email and payment account balance of any Facebook commerce page.",
                    "Link": "https://ysamm.com/?p=45"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reveal if a Facebook merchant page has pending or completed orders.",
                    "Link": "https://ysamm.com/?p=42"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bruteforce Instagram account’s passwords (lack of rate limiting protection).",
                    "Link": "https://ysamm.com/?p=38"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Bruteforce", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Generate Access Tokens for any Facebook user",
                    "Link": "https://ysamm.com/?p=35"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Modify users profiles of techprep.fb.com",
                    "Link": "https://ysamm.com/?p=30"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Uploading files to api.techprep.fb.com",
                    "Link": "https://ysamm.com/?p=12"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS", "File upload"],
              "Bounty": "-",
              "PublicationDate": "2019-01-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS in Zomato",
                    "Link": "https://medium.com/@sudhanshur705/reflected-xss-in-zomato-f892d6887147"
                 }
              ],
              "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
              "Programs": ["Zomato"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "250",
              "PublicationDate": "2019-01-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Simple CORS Misconfig Leaked Private Post Of Twitter, Facebook & Instagram",
                    "Link": "https://medium.com/@nahoragg/a-simple-cors-misconfig-leaked-private-post-of-twitter-facebook-instagram-5f1a634feb9d"
                 }
              ],
              "Authors": ["Rohan aggarwal (@nahoragg)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2019-01-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Oauth Misconfiguration lead to complete account takeover",
                    "Link": "https://medium.com/@Jacksonkv22/oauth-misconfiguration-lead-to-complete-account-takeover-c8e4e89a96a"
                 }
              ],
              "Authors": ["Jackson kv (@Jacksonkv22)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "OAuth", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2019-01-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Through SWF file!",
                    "Link": "https://medium.com/@friendly_/xss-through-swf-file-4f04af7b0f59"
                 }
              ],
              "Authors": ["Friendly (@SkeletorKeys)"],
              "Programs": ["-"],
              "Bugs": ["Flash XSS"],
              "Bounty": "200",
              "PublicationDate": "2019-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass Content Security Policy framing restriction rule - OLX",
                    "Link": "https://blog.ibrahimdraidia.com/bypass-csp-framing-restriction-rule-olx/"
                 }
              ],
              "Authors": ["Taha Ibrahim Draidia"],
              "Programs": ["OLX"],
              "Bugs": ["CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2019-01-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Command Injection PoC",
                    "Link": "https://medium.com/bugbountywriteup/command-injection-poc-72cc3743f10d"
                 }
              ],
              "Authors": ["NoGe (@p4c3n0g3)"],
              "Programs": ["-"],
              "Bugs": ["OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2019-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Vulnerability: Unremovable facebook group admin",
                    "Link": "https://medium.com/@ritishkumarsingh/facebook-vulnerability-unremovable-facebook-group-admin-2cbf4faf55c1"
                 }
              ],
              "Authors": ["Ritish Kumar Singh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2019-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty How I Hack Billion $ Company",
                    "Link": "https://medium.com/@sadiqwest01/bugbounty-how-i-hack-billion-company-5529a3ebe999"
                 }
              ],
              "Authors": ["Sadiq West"],
              "Programs": ["-"],
              "Bugs": ["Directory listing"],
              "Bounty": "500",
              "PublicationDate": "2019-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing MySQL clients to get LFI from the server/client",
                    "Link": "https://www.vesiluoma.com/abusing-mysql-clients/"
                 }
              ],
              "Authors": ["Jarkko Vesiluoma (@jvesiluoma)"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2019-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Gaining access to Uber's user data through AMPScript evaluation",
                    "Link": "https://blog.assetnote.io/bug-bounty/2019/01/14/gaining-access-to-ubers-user-data-through-ampscript-evaluation/"
                 }
              ],
              "Authors": ["Shubham Shah (@infosec_au)"],
              "Programs": ["Uber"],
              "Bugs": ["AMPScript injection"],
              "Bounty": "23,000",
              "PublicationDate": "2019-01-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Turning Self XSS to good XSS via access control",
                    "Link": "https://hacklad.github.io/blog/2019/01/13/Xss-it.html"
                 }
              ],
              "Authors": ["Yusuf Yazir (@Hacklad)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "Self-XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-01-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Workplace Logo ID to workplace owner name Disclosure Facebook Bug Bounty",
                    "Link": "https://medium.com/@evilboyajay/workplace-logo-id-to-workplace-owner-name-disclosurefacebook-bug-bounty-e745db59d0bd"
                 }
              ],
              "Authors": ["Ajay Gautam (@evilboyajay)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-01-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook PageAnalyst Could Add oneself as Moderator on Group",
                    "Link": "https://www.symbo1.com/articles/2019/01/11/fb-pageanalyst-could-add-oneself-as-moderator-on-group.html"
                 }
              ],
              "Authors": ["onehackzero"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-01-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "View the contact list for a Messenger Kid as a parent-approved contact",
                    "Link": "https://philippeharewood.com/view-the-contact-list-for-a-messenger-kid-as-a-parent-approved-contact/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-01-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tips for bug bounty beginners from a real life experience",
                    "Link": "https://renaudmarti.net/posts/first-bug-bounty-submission/"
                 }
              ],
              "Authors": ["Renaud Martinet (@karouf)"],
              "Programs": ["YNAB"],
              "Bugs": ["XSS", "SQL injection"],
              "Bounty": "1,500",
              "PublicationDate": "2019-01-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "When Cookie Hijacking + HTML Injection become dangerous",
                    "Link": "https://medium.com/bugbountywriteup/when-cookie-hijacking-html-injection-become-dangerous-3c649f7f6c88"
                 }
              ],
              "Authors": ["Daniel V. (@d4niel_v)"],
              "Programs": ["-"],
              "Bugs": ["Cookie hijacking", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2019-01-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS ON ASUS.",
                    "Link": "https://medium.com/@thejuskrishnan911/reflected-xss-on-asus-568ce0541171"
                 }
              ],
              "Authors": ["Thejus Krishnan"],
              "Programs": ["Asus"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-01-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS Via Alternate Text At Zendesk Support",
                    "Link": "https://medium.com/@hariharan21/stored-xss-via-alternate-text-at-zendesk-support-8bfee68413e4"
                 }
              ],
              "Authors": ["Hariharan.s (@DJHARIZ1)"],
              "Programs": ["Zendesk"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-01-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked Altervista.org",
                    "Link": "https://medium.com/@jacopotediosi/how-i-hacked-altervista-org-f23d011cdb96"
                 }
              ],
              "Authors": ["Jacopo Tediosi (@jacopotediosi)"],
              "Programs": ["Altervista"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2019-01-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Android Application",
                    "Link": "https://www.ash-king.co.uk/downloading-any-file-via-facebook-android.html"
                 }
              ],
              "Authors": ["Ashley King (@AshleyKingUK)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "750",
              "PublicationDate": "2019-01-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could have taken over any Pinterest account",
                    "Link": "http://infosecflash.com/2019/01/05/how-i-could-have-taken-over-any-pinterest-account/"
                 }
              ],
              "Authors": ["Arnold Anthony (@armold9anthony)"],
              "Programs": ["Pinterest"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "2,400",
              "PublicationDate": "2019-01-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I stumbled upon a Stored XSS(My first bug bounty story).",
                    "Link": "https://medium.com/@parthshah14031998/how-i-stumbled-upon-a-stored-xss-my-first-bug-bounty-story-2793300d82bb"
                 }
              ],
              "Authors": ["Parth Shah"],
              "Programs": ["Edmodo"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2019-01-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing Side-Channel Attack Tokens in Facebook Account Switcher",
                    "Link": "https://medium.com/@maxpasqua/stealing-side-channel-attack-tokens-in-facebook-account-switcher-90c5944e3b58"
                 }
              ],
              "Authors": ["Max Pasqua"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Token leak"],
              "Bounty": "1,000",
              "PublicationDate": "2019-01-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Yes I can see your OTP",
                    "Link": "https://web.archive.org/web/20191217045127/https://medium.com/vulnerables/yes-i-can-see-your-otp-9334cd27f021"
                 }
              ],
              "Authors": ["Vulnerables"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2019-01-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Tricky Open Redirect",
                    "Link": "https://www.hackerinside.me/2019/01/a-tricky-open-redirect.html"
                 }
              ],
              "Authors": ["Anas Mahmood (@AnasIsHere)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "200",
              "PublicationDate": "2019-01-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to Harvest other Vine users IP address",
                    "Link": "https://bugbountypoc.com/how-i-was-able-to-harvest-other-vine-users-ip-address"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["Vine"],
              "Bugs": ["IDOR"],
              "Bounty": "5,040",
              "PublicationDate": "2019-01-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i found web shell on AntiHack.me and Awarded Gold Coin And SWAG",
                    "Link": "https://rudr4sarkar.blogspot.com/2019/01/how-i-found-web-shell-on-antihackme-and.html"
                 }
              ],
              "Authors": ["AntiHack.me"],
              "Programs": ["Rudra Sarkar (@rudr4_sarkar)"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2019-01-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Curious Case From Little To Complete Email Verification Bypass",
                    "Link": "https://medium.com/@N0_M3ga_Hacks/a-curious-case-from-little-to-complete-email-verification-bypass-2c7570040e7e"
                 }
              ],
              "Authors": ["Megaman (@N0_M3ga_Hacks)"],
              "Programs": ["-"],
              "Bugs": ["Email verification bypass", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2019-01-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tale of a Misconfiguration in Password Reset",
                    "Link": "https://footstep.ninja/posts/password-reset/"
                 }
              ],
              "Authors": ["Shuaib Oladigbolu (@_sawzeeyy)"],
              "Programs": ["-"],
              "Bugs": ["Password reset"],
              "Bounty": "-",
              "PublicationDate": "2018-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Access Control in a Program on Hackerone !!",
                    "Link": "https://medium.com/@pig.wig45/bypassing-access-control-in-a-program-on-hackerone-ef213ab34703"
                 }
              ],
              "Authors": ["Sahil Tikoo (@viperbluff)"],
              "Programs": ["HackerOne"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to delete Google Gallery Data [IDOR]",
                    "Link": "https://medium.com/@yogeshtantak7788/how-i-was-able-to-delete-google-gallery-data-idor-53d2f303efff"
                 }
              ],
              "Authors": ["Yogesh Tantak"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing ACL Permissions to Overwrite other User’s Uploaded Files/Videos on s3 Bucket",
                    "Link": "https://medium.com/@armaanpathan/abusing-acl-permissions-to-overwrite-other-users-uploaded-files-videos-on-s3-bucket-162c8877728"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["-"],
              "Bugs": ["Unrestricted file upload", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Takeover Wordpress Admin fiiipay.my",
                    "Link": "https://medium.com/@sahruldotid/how-i-takeover-wordpress-admin-fiiipay-my-1bdede83635d"
                 }
              ],
              "Authors": ["Syahrul Akbar Rohmani (@sahruldotid)"],
              "Programs": ["FiiiPay"],
              "Bugs": ["Account takeover", "CMS default files"],
              "Bounty": "408",
              "PublicationDate": "2018-12-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Was Able To Takeover All User Account And Admin Panel",
                    "Link": "https://addictivehackers.blogspot.com/2018/12/how-i-was-able-to-takeover-all-user.html"
                 }
              ],
              "Authors": ["Dipak kumar Das (@d1pakdas)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "1,500",
              "PublicationDate": "2018-12-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS on ws-na.amazon-adsystem.com(Amazon)",
                    "Link": "https://medium.com/@newp_th/reflected-xss-on-ws-na-amazon-adsystem-com-amazon-f1e55f1d24cf"
                 }
              ],
              "Authors": ["ssid (@newp_th)"],
              "Programs": ["Amazon"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Hunting for a Laptop to Hunting down Remote Code Execution",
                    "Link": "https://medium.com/@aniltom/from-hunting-for-a-laptop-to-hunting-down-remote-code-execution-72cce2761846"
                 }
              ],
              "Authors": ["Anil Tom (mr_4nk)"],
              "Programs": ["Asus"],
              "Bugs": ["RCE", "WebDAV"],
              "Bounty": "-",
              "PublicationDate": "2018-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE in nokia.com",
                    "Link": "https://medium.com/@sampanna/rce-in-nokia-com-59b308e4e882"
                 }
              ],
              "Authors": ["Sampanna Chimoriya"],
              "Programs": ["Nokia"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated user can upload an attachment at HackerOne",
                    "Link": "https://medium.com/@modam3r5/unauthenticated-user-can-upload-an-attachment-at-hackerone-aff2a0c573b8"
                 }
              ],
              "Authors": ["Ahamed Morad (@Modam3r5)"],
              "Programs": ["HackerOne"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tokopedia Account Takeover Bug Worth 8 Million IDR",
                    "Link": "https://medium.com/@ironfisto/tokopedia-account-takeover-bug-worth-8-million-idr-5474cb5b5cc9"
                 }
              ],
              "Authors": ["Mukul Lohar (@ironfisto)"],
              "Programs": ["Tokopedia"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Server-side Request Forgery in OpenID support",
                    "Link": "https://medium.com/@putracraft.theworld/server-side-request-forgery-in-openid-support-defcc64d5e41"
                 }
              ],
              "Authors": ["Putra Adhari"],
              "Programs": ["Liberapay"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-12-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Client side validation strikes again: PIN code bypass !",
                    "Link": "http://blog.randorisec.fr/client-side-validation/"
                 }
              ],
              "Authors": ["Davy (@RandoriSec)"],
              "Programs": ["Netflix", "Linxo"],
              "Bugs": ["Client-side enforcement of server-side security", "Authentication bypass", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-12-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I accidentally found a clickjacking “feature” in Facebook",
                    "Link": "https://malfind.com/index.php/2018/12/21/how-i-accidentaly-found-clickjacking-in-facebook/"
                 }
              ],
              "Authors": ["Lasq (@lasq88)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2018-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS worm – A creative use of web application vulnerability",
                    "Link": "https://blog.compass-security.com/2018/12/xss-worm-a-creative-use-of-web-application-vulnerability/"
                 }
              ],
              "Authors": ["Nicolas Heiniger (@NicolasHeiniger)"],
              "Programs": ["Swisscom"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook BugBounty — Disclosing page members",
                    "Link": "https://medium.com/@tnirmalz/facebook-bugbounty-disclosing-page-members-1178595cc520"
                 }
              ],
              "Authors": ["Nirmal Thapa (@tnirmalz)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-12-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook BugBounty - Disclosing page members",
                    "Link": "https://www.tnirmal.com.np/2018/12/facebook-bugbounty-disclosing.html"
                 }
              ],
              "Authors": ["Nirmal Thapa / mpz (@tnirmalz)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-12-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of my two (but actually three) RCEs in SharePoint in 2018",
                    "Link": "https://soroush.secproject.com/blog/2018/12/story-of-two-published-rces-in-sharepoint-workflows/"
                 }
              ],
              "Authors": ["Soroush Dalili (@irsdl)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-12-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Two Endpoints to get Account Takeover",
                    "Link": "https://medium.com/@hritik.3hs/exploiting-two-endpoints-to-get-account-takeover-651813d0a33b"
                 }
              ],
              "Authors": ["Hritik Sharma"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2018-12-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Asus’S Admin Panel Auth Bypass",
                    "Link": "https://medium.com/@mustafakhan_89646/asuss-admin-panel-auth-bypass-af5062584ddf"
                 }
              ],
              "Authors": ["Mustafa Khan (@by6153)"],
              "Programs": ["Asus"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-12-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WordPress Privilege Escalation through Post Types",
                    "Link": "https://www.sonarsource.com/blog/wordpress-post-type-privilege-escalation/"
                 }
              ],
              "Authors": ["Simon Scannell (@scannell_simon)"],
              "Programs": ["WordPress"],
              "Bugs": ["Privilege escalation", "Stored XSS", "Object injection"],
              "Bounty": "-",
              "PublicationDate": "2018-12-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover — New Level",
                    "Link": "https://medium.com/bugbountywriteup/subdomain-takeover-new-level-43f88b55e0b2"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-12-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reading ASP secrets for $17,000",
                    "Link": "https://samcurry.net/reading-asp-secrets-for-17000/"
                 }
              ],
              "Authors": ["Sam Curry (@samwcyo)"],
              "Programs": ["-"],
              "Bugs": ["Local file disclosure (LFD)"],
              "Bounty": "17,000",
              "PublicationDate": "2018-12-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accessing VoIP Internal service via Port 8009: Routing traffic through local Apache proxy",
                    "Link": "https://medium.com/@ahmedasherif/accessing-voip-internal-service-via-port-8009-routing-traffic-through-local-apache-proxy-54a4ff539c5f"
                 }
              ],
              "Authors": ["Ahmed A. Sherif"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-12-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Self XSS to Interesting Stored XSS",
                    "Link": "https://nahoragg.github.io/bugbounty/2018/12/15/Self-XSS-to-Interesting-Stored-XSS.html"
                 }
              ],
              "Authors": ["Rohan aggarwal (@nahoragg)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2018-20139 - Daikin Emura Series - Arbitrary Remote Control via DNS Rebinding",
                    "Link": "https://voidzone.me/cve-2018-20139-daikin-emura-series-arbitrary-remote-control-via-dns-rebinding/"
                 }
              ],
              "Authors": ["void (@voidz0r)"],
              "Programs": ["Daikin Europe"],
              "Bugs": ["DNS rebinding"],
              "Bounty": "-",
              "PublicationDate": "2018-12-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Code Execution on a Facebook server",
                    "Link": "https://blog.scrt.ch/2018/08/24/remote-code-execution-on-a-facebook-server/"
                 }
              ],
              "Authors": ["Daniel Le Gall (@Blaklis_)"],
              "Programs": ["phpMyAdmin"],
              "Bugs": ["LFI", "RCE", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-12-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSSing Google Code-in thanks to improperly escaped JSON data",
                    "Link": "https://websecblog.com/vulns/google-code-in-xss/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-12-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$3k Bug Bounty - Twitter's OAuth Mistakes",
                    "Link": "https://shkspr.mobi/blog/2018/12/twitter-bug-bounty/"
                 }
              ],
              "Authors": ["Terence Eden (@edent)"],
              "Programs": ["Twitter"],
              "Bugs": ["OAuth"],
              "Bounty": "2,940",
              "PublicationDate": "2018-12-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unremovable Tags In Facebook Page Reviews",
                    "Link": "https://medium.com/@maxpasqua/unremovable-tags-in-facebook-page-reviews-656e095e69aa"
                 }
              ],
              "Authors": ["Max Pasqua"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "500",
              "PublicationDate": "2018-12-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining Two Vulnerabilities to Break Facebook Appointment Times For the Second Time",
                    "Link": "https://medium.com/@maxpasqua/chaining-two-vulnerabilities-to-break-facebook-appointment-times-for-the-second-time-ac639f8c8773"
                 }
              ],
              "Authors": ["Max Pasqua"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Application-level DoS"],
              "Bounty": "500",
              "PublicationDate": "2018-12-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — “User Account Takeover-I just need your email id to login into your shopping portal account”",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-user-account-takeover-i-just-need-your-email-id-to-login-into-your-shopping-portal-7fd4fdd6dd56"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "Authentication bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-12-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting XXE with local DTD files",
                    "Link": "https://mohemiv.com/all/exploiting-xxe-with-local-dtd-files/"
                 }
              ],
              "Authors": ["Arseniy Sharoglazov (@_mohemiv)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-12-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Open redirect] Developers are lazy(or maybe busy)",
                    "Link": "https://medium.com/bugbountywriteup/open-redirect-developers-are-lazy-or-maybe-busy-6c51718b10e4"
                 }
              ],
              "Authors": ["KatsuragiCSL (@ZuuitterE)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "150",
              "PublicationDate": "2018-12-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Second bite on GitLab, and some interesting Ruby functions/features",
                    "Link": "https://blog.nyangawa.me/security/CVE-2018-18649-Gitlab-RCE/"
                 }
              ],
              "Authors": ["Nyangawa"],
              "Programs": ["GitLab"],
              "Bugs": ["RCE"],
              "Bounty": "10,000",
              "PublicationDate": "2018-12-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From blind XXE to root-level file read access",
                    "Link": "https://honoki.net/2018/12/from-blind-xxe-to-root-level-file-read-access/"
                 }
              ],
              "Authors": ["Pieter Hiele (@honoki)"],
              "Programs": ["-"],
              "Bugs": ["Blind XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-12-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to pwned application by Bypassing Cloudflare WAF",
                    "Link": "https://medium.com/bugbountywriteup/bypass-cloudflare-waf-to-pwned-application-2c9e4f862319"
                 }
              ],
              "Authors": ["gujjuboy10x00 (@vis_hacker)"],
              "Programs": ["-"],
              "Bugs": ["WAF bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-12-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Account Takeover Vulnerability Affecting 400 Million Users",
                    "Link": "https://www.safetydetective.com/blog/microsoft-outlook/"
                 }
              ],
              "Authors": ["Aviva Zacks"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Subdomain takeover", "OAuth"],
              "Bounty": "-",
              "PublicationDate": "2018-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could have stolen your photos from Google",
                    "Link": "https://avatao.com/blog-how-i-could-have-stolen-your-photos-from-google-my-first-3-bug-bounty-writeups/"
                 }
              ],
              "Authors": ["Gergő Turcsányi (@GergoTurcsanyi)"],
              "Programs": ["Google"],
              "Bugs": ["Parameter tampering", "Broken authorization", "IDOR"],
              "Bounty": "4,133.7",
              "PublicationDate": "2018-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to generate Access Tokens for any Facebook user.",
                    "Link": "https://medium.com/bugbountywriteup/how-i-was-able-to-generate-access-tokens-for-any-facebook-user-6b84392d0342"
                 }
              ],
              "Authors": ["Youssef Sammouda (@samm0uda)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Token Brute-Force to Account Take-over to Privilege Escalation to Organization Take-Over",
                    "Link": "https://medium.com/bugbountywriteup/token-brute-force-to-account-take-over-to-privilege-escalation-to-organization-take-over-650d14c7ce7f"
                 }
              ],
              "Authors": ["Plenum (@plenumlab)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Privilege escalation", "Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2018-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first bug bounty writeup",
                    "Link": "https://medium.com/@sampanna/self-xss-in-indeed-com-e0c99c104cba"
                 }
              ],
              "Authors": ["Sampanna Chimoriya"],
              "Programs": ["Indeed"],
              "Bugs": ["XSS", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2018-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Change Anyone’s profile picture-Exploiting IDOR",
                    "Link": "https://medium.com/@rupika.luhach/change-anyones-profile-picture-exploiting-idor-41369f5acf75"
                 }
              ],
              "Authors": ["Rupika Luhach (@Rup_Ki_Rani)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Proof Of Concept Nokia Cross Site Scripting",
                    "Link": "https://web.archive.org/web/20191219015356/https://medium.com/@adeshkolte/proof-of-concept-nokia-cross-site-scripting-5bb47c3b9529"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["Nokia"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was Able To Bypass Email Verification",
                    "Link": "https://blog.securitybreached.org/2018/12/08/how-i-was-able-to-bypass-email-verification/"
                 }
              ],
              "Authors": ["Muzammil Kayani (@muzammilabbas2)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "200",
              "PublicationDate": "2018-12-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE in Hubspot with EL injection in HubL",
                    "Link": "https://www.betterhacker.com/2018/12/rce-in-hubspot-with-el-injection-in-hubl.html"
                 }
              ],
              "Authors": ["Fyoorer (@ƒyoorer)"],
              "Programs": ["HubSpot"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-12-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook WhiteHat: Able to access group plan even after leaving the group",
                    "Link": "https://whitehatfamilyguy.blogspot.com/2018/12/able-to-access-facebook-group-plan-even.html"
                 }
              ],
              "Authors": ["Family guy"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-12-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Billion Laugh Attack in https://sites.google.com",
                    "Link": "https://blog.intothesymmetry.com/2018/12/billion-laugh-attack-in.html"
                 }
              ],
              "Authors": ["Antonio Sanso (@asanso)"],
              "Programs": ["Google"],
              "Bugs": ["Billion laugh attack", "DoS"],
              "Bounty": "500",
              "PublicationDate": "2018-12-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS to XXE in Prince v10 and below (CVE-2018-19858)",
                    "Link": "https://corben.io/blog/18-12-5-XSS-to-XXE-in-Prince"
                 }
              ],
              "Authors": ["Corben Leo (@hacker_)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-12-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Complete User Account Takeover on an Android Application",
                    "Link": "https://gauravnarwani.com/android-acc-takeover/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "OTP bypass", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2018-12-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Taking over Google calendar of a company",
                    "Link": "https://medium.com/bugbountywriteup/taking-over-google-calendar-of-a-company-1c49071f6a9"
                 }
              ],
              "Authors": ["Daniel V. (@d4niel_v)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-12-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to accidentally find a XSS in ProtonMail iOS app",
                    "Link": "https://www.secu.ninja/2018/12/04/how-to-accidentally-find-a-xss-in-protonmail-ios-app/"
                 }
              ],
              "Authors": ["SecuNinja (@secuninja)"],
              "Programs": ["Proton Mail"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-12-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GitHub Desktop RCE (OSX)",
                    "Link": "https://pwning.re/2018/12/04/github-desktop-rce/"
                 }
              ],
              "Authors": ["André Baptista (@0xacb)"],
              "Programs": ["GitHub"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-12-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Digging in to SCP Command Injection",
                    "Link": "https://dylankatz.com/digging-in-to-scp-command-injection/"
                 }
              ],
              "Authors": ["Dylan Katz (@Plazmaz)"],
              "Programs": ["JSch"],
              "Bugs": ["OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2018-12-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[BBP系列三] Hijack the JS File of Uber's Website",
                    "Link": "http://zhchbin.github.io/2018/12/03/Hijack-the-JS-File-of-Uber-s-Website/"
                 }
              ],
              "Authors": ["Chaobin Zhang"],
              "Programs": ["Uber"],
              "Bugs": ["JS file hijacking"],
              "Bounty": "6,000",
              "PublicationDate": "2018-12-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remotely Hijacking Zoom Clients",
                    "Link": "https://medium.com/tenable-techblog/remotely-exploiting-zoom-meetings-5a811342ba1d"
                 }
              ],
              "Authors": ["David Wells"],
              "Programs": ["Zoom"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-12-03",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "How I managed to get an @Google.com email address, bypassing their previous patch!",
                  "Link": "https://www.andmp.com/2018/12/how-i-managed-to-get-google.html"
               }
            ],
            "Authors": ["Gopal Singh (@gopalsinghcse)"],
            "Programs": ["Google"],
            "Bugs": ["Logic flaw"],
            "Bounty": "3,133.70",
            "PublicationDate": "2018-12-01",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Love Story Of A Account Takeover (Chaining Host Header Injection To Takeover Someones Account)",
                    "Link": "https://chainlover.blogspot.com/2018/11/love-story-of-account-takeover-chaining.html"
                 }
              ],
              "Authors": ["Logical Bimboo"],
              "Programs": ["-"],
              "Bugs": ["Host header injection"],
              "Bounty": "-",
              "PublicationDate": "2018-11-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story about my first bug bounty",
                    "Link": "https://medium.com/@sudhanshur705/story-about-my-first-bug-bounty-9fe710be8241"
                 }
              ],
              "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
              "Programs": ["Alibaba"],
              "Bugs": ["XSS"],
              "Bounty": "100",
              "PublicationDate": "2018-11-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting post message to steal and replace user’s cookies",
                    "Link": "https://medium.com/@yassergersy/exploiting-post-message-to-steal-users-cookies-7df43a00289a"
                 }
              ],
              "Authors": ["Yasser Gersy (@yassergersy)"],
              "Programs": ["-"],
              "Bugs": ["postMessage"],
              "Bounty": "-",
              "PublicationDate": "2018-11-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of Stored Xss",
                    "Link": "https://medium.com/@hossainwalid93/story-of-store-xss-d24c3ab862f0"
                 }
              ],
              "Authors": ["Walid Hossain (@NoobWalid)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-11-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Authentication — Bug Bounty",
                    "Link": "https://web.archive.org/web/20191221105442/https://medium.com/bugbountywriteup/broken-authentication-bug-bounty-5c941a4a5f48"
                 }
              ],
              "Authors": ["Vulnerables"],
              "Programs": ["-"],
              "Bugs": ["Session management issue"],
              "Bounty": "50",
              "PublicationDate": "2018-11-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IRCTC — Millions of Passenger Details left at huge risk!",
                    "Link": "https://medium.com/@logicbomb_1/irctc-millions-of-passenger-details-left-at-huge-risk-18c5ecc09d7f"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["IRCTC"],
              "Bugs": ["Information disclosure", "Lack of rate limiting"],
              "Bounty": "-",
              "PublicationDate": "2018-11-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwning eBay - How I Dumped eBay Japan's Website Source Code",
                    "Link": "https://slashcrypto.org/2018/11/28/eBay-source-code-leak/"
                 }
              ],
              "Authors": ["David (@slashcrypto)"],
              "Programs": ["Ebay"],
              "Bugs": [".git folder disclosure", "Source code disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-11-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Instagram Multi-factor authentication Bypass",
                    "Link": "https://medium.com/@vishnu0002/instagram-multi-factor-authentication-bypass-924d963325a1"
                 }
              ],
              "Authors": ["Vishnuraj"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["2FA / MFA bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-11-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose contact_email of any Facebook application",
                    "Link": "https://www.amolbaikar.com/disclose-contact_email-of-any-facebook-application/"
                 }
              ],
              "Authors": ["Amol Baikar (@AmolBaikar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-11-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS on Facebook’s acquisition Oculus CDN",
                    "Link": "https://www.amolbaikar.com/xss-on-facebooks-acquisition-oculus-cdn/"
                 }
              ],
              "Authors": ["Amol Baikar (@AmolBaikar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS"],
              "Bounty": "1,500",
              "PublicationDate": "2018-11-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS on Facebook-Instagram CDN Server bypassing signature protection.",
                    "Link": "https://www.amolbaikar.com/xss-on-facebook-instagram-cdn-server-bypassing-signature-protection/"
                 }
              ],
              "Authors": ["Amol Baikar (@AmolBaikar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS"],
              "Bounty": "1,500",
              "PublicationDate": "2018-11-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Amol Baikar (@AmolBaikar)",
                    "Link": "https://www.amolbaikar.com/facebook-source-code-disclosure-in-ads-api/"
                 }
              ],
              "Authors": ["Amol Baikar (@AmolBaikar)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Source code disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-11-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From CTFs to Bug Bounty Booty",
                    "Link": "https://medium.com/@benjitobias/from-ctfs-to-bug-bounty-booty-81bab999b70d"
                 }
              ],
              "Authors": ["Benji Tobias"],
              "Programs": ["Tailor Store"],
              "Bugs": ["Information disclosure"],
              "Bounty": "200",
              "PublicationDate": "2018-11-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Journey To The Google Hall Of Fame",
                    "Link": "https://www.secjuice.com/google-hall-of-fame/"
                 }
              ],
              "Authors": ["Abartan Dhakal (@imhaxormad)"],
              "Programs": ["Google"],
              "Bugs": ["Open redirect", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-11-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS Vulnerability in Jotform and H1C Private Site",
                    "Link": "https://www.hackerinside.me/2018/11/critical-stored-xss-vulnerability.html"
                 }
              ],
              "Authors": ["Anas Mahmood (@AnasIsHere)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2018-11-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Scratch Cards On Google Pay",
                    "Link": "https://medium.com/@pratheesh.p.narayanan/bypassing-scratch-cards-on-google-pay-8915d5423385"
                 }
              ],
              "Authors": ["Pratheesh P Narayanan"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-11-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting SSRF like a Boss — Escalation of an SSRF to Local File Read!",
                    "Link": "https://medium.com/@zain.sabahat/exploiting-ssrf-like-a-boss-c090dc63d326"
                 }
              ],
              "Authors": ["Zain Sabahat (@Zain_Sabahat)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2018-11-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An interesting XXE in SAP.",
                    "Link": "https://medium.com/@zain.sabahat/an-interesting-xxe-in-sap-8b35fec6ef33"
                 }
              ],
              "Authors": ["Zain Sabahat (@Zain_Sabahat)"],
              "Programs": ["SAP"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-11-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i Found Information Disclosure on Scribd.com",
                    "Link": "https://medium.com/@androgaming1912/how-i-found-password-bypass-vulnerability-on-private-document-at-scribd-com-c0905e8dcc9a"
                 }
              ],
              "Authors": ["Zerb0a"],
              "Programs": ["Scribd.com"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-11-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked Netflix users & Use it free forever",
                    "Link": "https://medium.com/@vignesh4303/how-i-hacked-netflix-users-use-it-free-forever-9febb1427262"
                 }
              ],
              "Authors": ["Blueberryinfosec (@bbinfosec)"],
              "Programs": ["Netflix"],
              "Bugs": ["Cookie injection", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2018-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XS-Searching Google’s bug tracker to find out vulnerable source code",
                    "Link": "https://medium.com/@luanherrera/xs-searching-googles-bug-tracker-to-find-out-vulnerable-source-code-50d8135b7549"
                 }
              ],
              "Authors": ["Luan Herrera (@lbherrera_)"],
              "Programs": ["Google"],
              "Bugs": ["XS-Search", "Information disclosure"],
              "Bounty": "9,400",
              "PublicationDate": "2018-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Youtube - Open redirection",
                    "Link": "https://quitten.github.io/Youtube/"
                 }
              ],
              "Authors": ["Barak Tawily (@quitten11)"],
              "Programs": ["Google"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2018-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS bypass using META tag in realestate.postnl.nl",
                    "Link": "https://medium.com/bugbountywriteup/xss-bypass-using-meta-tag-in-realestate-postnl-nl-32db25db7308"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["post.nl"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Security Misconfiguration to Gaining Access of SMTP server",
                    "Link": "https://medium.com/bugbountywriteup/from-security-misconfiguration-to-gaining-access-of-smtp-server-ed833e757e6e"
                 }
              ],
              "Authors": ["Daniel V. (@d4niel_v)"],
              "Programs": ["-"],
              "Bugs": ["File disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Edmodo XSS Bug",
                    "Link": "https://web.archive.org/web/20200907110700/https://medium.com/@sameerphad72/edmodo-xss-bug-9c0fc9bdd0bf"
                 }
              ],
              "Authors": ["Sameer Phad (@sameerphad72)"],
              "Programs": ["Edmodo"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing “How I hacked Google’s bug tracking system itself for $15,600 in bounties.”",
                    "Link": "https://medium.com/@gopalsingh/bypassing-how-i-hacked-googles-bug-tracking-system-itself-for-15-600-in-bounties-16134466ab15"
                 }
              ],
              "Authors": ["Gopal Singh (@gopalsinghcse)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "3,133.70",
              "PublicationDate": "2018-11-17",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "New technique to find Blind-XSS",
                  "Link": "https://medium.com/@renwa/new-technique-to-find-blind-xss-c2efcd377cc2"
               }
            ],
            "Authors": ["Renwa (@RenwaX23)"],
            "Programs": ["-"],
            "Bugs": ["Blind XSS"],
            "Bounty": "-",
            "PublicationDate": "2018-11-16",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "How I Managed to Create Unauthorized Comments on Facebook Live Stream",
                    "Link": "https://www.askbuddie.com/blog/unauthorized-comments-on-facebook-live-stream/"
                 }
              ],
              "Authors": ["Binit Ghimire (@WHOISbinit)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "750",
              "PublicationDate": "2018-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft BingPlaces Business - (url) Redirect Vulnerability",
                    "Link": "https://www.vulnerability-db.com/?q=articles/2018/11/16/microsoft-bingplaces-business-url-redirect-vulnerability"
                 }
              ],
              "Authors": ["Benjamin K.M."],
              "Programs": ["Microsoft"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2018-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in hidden input fields",
                    "Link": "https://portswigger.net/blog/xss-in-hidden-input-fields"
                 }
              ],
              "Authors": ["Gareth Heyes (@garethheyes)", "Liam (@MetalF0X)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[POC] Cross-Site Scripting on Garuda Indonesia Website",
                    "Link": "https://medium.com/@ariffadhlullah2310/poc-cross-site-scripting-on-garuda-indonesia-website-452f4864f615"
                 }
              ],
              "Authors": ["Arif-ITSEC111"],
              "Programs": ["Garuda Indonesia"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HackenProof Customer Story: Uklon",
                    "Link": "https://blog.hackenproof.com/customer-stories/hackenproof-customer-story-uklon/"
                 }
              ],
              "Authors": ["HackenProof (@hackenproof)"],
              "Programs": ["Uklon"],
              "Bugs": ["XSS", "IDOR", "Blind XSS", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spoofing file extensions on HackerOne",
                    "Link": "https://cooltrickshome.blogspot.com/2018/11/spoofing-file-extensions-on-hackerone.html"
                 }
              ],
              "Authors": ["Anurag Jain (@csanuragjain)"],
              "Programs": ["HackerOne"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2018-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Creating unauthorized comments on Facebook Live Stream!",
                    "Link": "https://publish.whoisbinit.me/unauthorized-comments-on-facebook-live-stream"
                 }
              ],
              "Authors": ["Binit Ghimire (@WHOISbinit)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Privilege escalation", "Broken authorization"],
              "Bounty": "750",
              "PublicationDate": "2018-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose Page Admins via Gaming Dashboard Bans",
                    "Link": "https://philippeharewood.com/disclose-page-admins-via-gaming-dashboard-bans/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Vulnerability: Hiding from the view of Business Admin in the Business Manager",
                    "Link": "https://medium.com/@ritishkumarsingh/facebook-vulnerability-hiding-from-the-view-of-business-admin-in-the-business-manager-a04515fee9dd"
                 }
              ],
              "Authors": ["Ritish Kumar Singh"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2018-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Discovered XSS that Affects around 20 Uber Subdomains",
                    "Link": "https://blog.fadyothman.com/how-i-discovered-xss-that-affects-over-20-uber-subdomains/"
                 }
              ],
              "Authors": ["Fady Othman (@Fady_Othman)"],
              "Programs": ["Uber"],
              "Bugs": ["XSS"],
              "Bounty": "2,500",
              "PublicationDate": "2018-11-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Breaking Appointments and Job Interview Schedules With Malformed Times",
                    "Link": "https://medium.com/@maxpasqua/breaking-appointments-and-job-interview-schedules-with-malformed-times-edef103e46ba"
                 }
              ],
              "Authors": ["Max Pasqua"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS"],
              "Bounty": "500",
              "PublicationDate": "2018-11-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spoof All Domains Containing 'd' in Apple Products [CVE-2018-4277]",
                    "Link": "https://xlab.tencent.com/en/2018/11/13/cve-2018-4277/"
                 }
              ],
              "Authors": ["Tencent's Xuanwu Lab"],
              "Programs": ["Apple"],
              "Bugs": ["Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2018-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OOB XXE in PrizmDoc (CVE-2018–15805)",
                    "Link": "https://medium.com/@mrnikhilsri/oob-xxe-in-prizmdoc-cve-2018-15805-dfb1e474345c"
                 }
              ],
              "Authors": ["Nik srivastava"],
              "Programs": ["PrizmDoc"],
              "Bugs": ["OOB XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[DOM based XSS] Or why you should not rely on Cloudflare too much",
                    "Link": "https://medium.com/bugbountywriteup/dom-based-xss-or-why-you-should-not-rely-on-cloudflare-too-much-a1aa9f0ead7d"
                 }
              ],
              "Authors": ["KatsuragiCSL (@ZuuitterE)"],
              "Programs": ["-"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Patched Facebook Vulnerability Could Have Exposed Private Information About You and Your Friends",
                    "Link": "https://www.imperva.com/blog/facebook-privacy-bug"
                 }
              ],
              "Authors": ["Ron Masas (@RonMasas)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chain exploitation of XSS",
                    "Link": "https://mike-n1.github.io/Chain_XSS"
                 }
              ],
              "Authors": ["Mikhail Klyuchnikov (@__Mn1__)"],
              "Programs": ["-"],
              "Bugs": ["DOM XSS", "Clickjacking", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "OLX Reflected XSS on Resend Code link !!",
                    "Link": "http://blog.h4rsh4d.com/2018/03/olx-reflected-xss-on-resend-code-link.html"
                 }
              ],
              "Authors": ["Harshad Gaikwad (@h4rsh4d)"],
              "Programs": ["OLX"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Clickjacking on Google MyAccount Worth 7,500$",
                    "Link": "https://apapedulimu.click/clickjacking-on-google-myaccount-worth-7500/"
                 }
              ],
              "Authors": ["apapedulimu / Nosa Shandy (@LocalHost31337)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "7,500",
              "PublicationDate": "2018-11-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2018-9539: Use-after-free vulnerability in privileged Android service",
                    "Link": "https://blog.zimperium.com/cve-2018-9539-use-free-vulnerability-privileged-android-service/"
                 }
              ],
              "Authors": ["Tamir Zahavi-Brunner (@tamir_zb)"],
              "Programs": ["Google"],
              "Bugs": ["Memory corruption", "Use-After-Free"],
              "Bounty": "-",
              "PublicationDate": "2018-11-09",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Ruby 2.x Universal RCE Deserialization Gadget Chain",
                  "Link": "https://www.elttam.com/blog/ruby-deserialization/"
               }
            ],
            "Authors": ["Luke Jahnke (@lukejahnke)"],
            "Programs": ["Ruby"],
            "Bugs": ["Insecure deserialization", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2018-11-08",
            "AddedDate": "2023-08-08"
         },
           {
              "Links": [
                 {
                    "Title": "#bugbounty How I Takeover Microsoft Store.",
                    "Link": "https://medium.com/@sadiqwest01/bugbounty-how-i-takeover-microsoft-store-a58c1b785aa0"
                 }
              ],
              "Authors": ["Sadiq West"],
              "Programs": ["Microsoft"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-11-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Object name Exposure — ING Bank Responsible Disclosure Program",
                    "Link": "https://medium.com/@rohitcoder/object-name-exposure-ing-bank-responsible-disclosure-program-1f8f808cc789"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["ING Bank"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-11-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned 5040$ from Twitter by showing a way to Harvest other users IP address",
                    "Link": "https://medium.com/bugbountywriteup/how-i-earned-5040-from-twitter-by-showing-a-way-to-harvest-other-users-ip-address-e9f43c931e9a"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["Twitter"],
              "Bugs": ["Information disclosure"],
              "Bounty": "5,040",
              "PublicationDate": "2018-11-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vine User’s Private information disclosure",
                    "Link": "https://medium.com/@prial261/vine-users-private-information-disclosure-f1c55a3abbb6"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["Vine"],
              "Bugs": ["IDOR", "Information disclosure"],
              "Bounty": "7,560",
              "PublicationDate": "2018-11-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Dynamics 365",
                    "Link": "https://medium.com/@tim.kent/xss-in-dynamics-365-25c800aac473"
                 }
              ],
              "Authors": ["Tim Kent (@__timk)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-11-06",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "WordPress Design Flaw Leads to WooCommerce RCE",
                  "Link": "https://www.sonarsource.com/blog/wordpress-design-flaw-leads-to-woocommerce-rce/"
               }
            ],
            "Authors": ["Simon Scannell (@scannell_simon)"],
            "Programs": ["Automattic (WooCommerce)"],
            "Bugs": ["RCE"],
            "Bounty": "-",
            "PublicationDate": "2018-11-05",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Evernote For Windows Read Local File and Command Execute Vulnerabilities",
                    "Link": "https://paper.seebug.org/737/"
                 }
              ],
              "Authors": ["TongQing Zhu"],
              "Programs": ["Evernote"],
              "Bugs": ["Stored XSS", "LFI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Duplicate but still cool",
                    "Link": "https://medium.com/bugbountywriteup/duplicate-but-still-cool-236835685075"
                 }
              ],
              "Authors": ["Plenum (@plenumlab)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated RSFTP to Command Injection",
                    "Link": "http://codegrazer.com/blog/rsftp-to-command-injection.html"
                 }
              ],
              "Authors": ["Nicodemo Gawronski"],
              "Programs": ["-"],
              "Bugs": ["Path traversal", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-11-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full Account Takeover via Referer Header (OAuth token Steal, Open Redirect Vulnerability Chaining)",
                    "Link": "https://web.archive.org/web/20201030131757/https://medium.com/@protector47/full-account-takeover-via-referrer-header-oauth-token-steal-open-redirect-vulnerability-chaining-324a14a1567"
                 }
              ],
              "Authors": ["Muhammad Asim Shahzad (@protector47)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Token leak", "Account takeover"],
              "Bounty": "1,200",
              "PublicationDate": "2018-11-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Outdated JIRA Instances suffers from multiple security vulnerabilities?",
                    "Link": "https://medium.com/@Skylinearafat/how-outdated-jira-instances-suffers-from-multiple-security-vulnerabilities-6a88c45e9ec6"
                 }
              ],
              "Authors": ["Yeasir Arafat"],
              "Programs": ["Visma"],
              "Bugs": ["XSS", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Imagemagick GIF coder vulnerability leads to memory disclosure (Hackerone)",
                    "Link": "https://medium.com/@kunal94/imagemagick-gif-coder-vulnerability-leads-to-memory-disclosure-hackerone-e9975a6a560e"
                 }
              ],
              "Authors": ["Kunal pandey (@kunalp94)"],
              "Programs": ["HackerOne"],
              "Bugs": ["Memory leak", "Outdated component with a known vulnerability" ],
              "Bounty": "500",
              "PublicationDate": "2018-11-02",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "CVE-2018-11759 – Apache mod_jk access control bypass",
                  "Link": "https://www.immunit.ch/blog/2018/11/01/cve-2018-11759-apache-mod_jk-access-bypass/"
               }
            ],
            "Authors": ["Raphaël Arrouas", "Jean Lejeune"],
            "Programs": ["Apache HTTP Server"],
            "Bugs": ["Path traversal"],
            "Bounty": "-",
            "PublicationDate": "2018-11-01",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Finding hidden gems vol. 3: quick win with .sh file",
                    "Link": "https://medium.com/@mateusz.olejarka/finding-hidden-gems-vol-3-quick-win-with-sh-file-722e58636ded"
                 }
              ],
              "Authors": ["Mateusz Olejarka (@molejarka)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-11-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "P1 Like a Boss | Information Disclosure via Github leads to Employee Account Takeover | Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2018/11/03/p1-like-a-boss-information-disclosure-via-github-leads-to-employee-account-takeover/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,500",
              "PublicationDate": "2018-11-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in Bug Bounty",
                    "Link": "https://medium.com/bugbountywriteup/stored-xss-in-bug-bounty-13c08e6f5636"
                 }
              ],
              "Authors": ["KatsuragiCSL (@ZuuitterE)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-11-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass HackerOne 2FA requirement and reporter blacklist",
                    "Link": "https://medium.com/japzdivino/bypass-hackerone-2fa-requirement-and-reporter-blacklist-46d7959f1ee5"
                 }
              ],
              "Authors": ["Japz Divino (@japzdivino)"],
              "Programs": ["HackerOne"],
              "Bugs": ["Logic flaw", "2FA / MFA bypass", "Broken authentication"],
              "Bounty": "10,000",
              "PublicationDate": "2018-10-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "It’s all in the detail: Email leak & Account takeover thanks to WayBackMachine & extensive knowledge about the program",
                    "Link": "https://medium.com/@zseano/its-all-in-the-detail-email-leak-account-takeover-thanks-to-waybackmachine-extensive-4be365580dd7"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://blog.bugbountyhunter.com/email-leak-with-wayback/"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Authentication bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF 'protection' bypass on xvideos",
                    "Link": "https://web.archive.org/web/20181030103042/https://zseano.com/blogs/4.html"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["xvideos"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR in JWT and the shortest token you will ever see {}.{“uid”: “1234567890”}",
                    "Link": "https://medium.com/@plenumlab/idor-in-jwt-and-the-shortest-token-you-will-ever-see-uid-1234567890-4e02377ea03a"
                 }
              ],
              "Authors": ["Plenum (@plenumlab)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "1,500",
              "PublicationDate": "2018-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2018-9411: New critical vulnerability in multiple high-privileged Android services",
                    "Link": "https://blog.zimperium.com/cve-2018-9411-new-critical-vulnerability-multiple-high-privileged-android-services/"
                 }
              ],
              "Authors": ["Tamir Zahavi-Brunner (@tamir_zb)"],
              "Programs": ["Google"],
              "Bugs": ["Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2018-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Improper CSRF token handling leads to site-wide CSRF issue, chained with clickjacking = woot! Multiple sites vulnerable",
                    "Link": "https://zseano.medium.com/site-wide-csrf-issue-chained-with-clickjacking-multiple-sites-vulnerable-6201abab0d3e"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://blog.bugbountyhunter.com/improper-csrf-handling/"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2018-10-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Journey through Google referer leakage bugs.",
                    "Link": "https://thesecurityexperts.wordpress.com/2018/10/28/journey-through-google-referer-leakage-bugs/"
                 }
              ],
              "Authors": ["KL Sreeram (@kl_sree)"],
              "Programs": ["Google"],
              "Bugs": ["Information disclosure", "Referer leakage"],
              "Bounty": "4,633.7",
              "PublicationDate": "2018-10-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — How I was able to download the Source Code of India’s Largest Telecom Service Provider including dozens of more popular websites!",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-how-i-was-able-to-download-the-source-code-of-indias-largest-telecom-service-52cf5c5640a1"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": [".git folder disclosure", "Source code disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-10-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privilege Escalation like a Boss",
                    "Link": "https://blog.securitybreached.org/2018/10/27/privilege-escalation-like-a-boss/"
                 }
              ],
              "Authors": ["Jay Jani (@JayJani007)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-10-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How Misconfigured API leaked user private information?",
                    "Link": "https://medium.com/@Skylinearafat/how-misconfigured-api-leaked-user-private-information-e3e8c13e52e4"
                 }
              ],
              "Authors": ["Yeasir Arafat"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-10-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A very useful technique to bypass the CSRF protection for fun and profit.",
                    "Link": "https://medium.com/@Skylinearafat/a-very-useful-technique-to-bypass-the-csrf-protection-for-fun-and-profit-471af64da276"
                 }
              ],
              "Authors": ["Yeasir Arafat"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-10-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSRF account takeover Explained Automated/Manual — Bug Bounty",
                    "Link": "https://web.archive.org/web/20191217012635/https://medium.com/bugbountywriteup/csrf-account-takeover-explained-automated-manual-bug-bounty-447e4b96485b"
                 }
              ],
              "Authors": ["Vulnerables"],
              "Programs": ["OpenMenu"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "250",
              "PublicationDate": "2018-10-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain takeover dew to missconfigured project settings for Custom domain .",
                    "Link": "https://medium.com/@prial261/subdomain-takeover-dew-to-missconfigured-project-settings-for-custom-domain-46e90e702969"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["Flock"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-10-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DoS on Facebook Android app using 65530 characters of ZERO WIDTH NO-BREAK SPACE.",
                    "Link": "https://medium.com/@kankrale.rahul/dos-on-facebook-android-app-using-65530-characters-of-zero-width-no-break-space-db41ca8ded89"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2018-10-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SOAP- Based Unauthenticated Out-of-Band XML External Entity (OOB-XXE) in a Help Desk Software",
                    "Link": "https://medium.com/@mrnikhilsri/soap-based-unauthenticated-out-of-band-xml-external-entity-oob-xxe-in-a-help-desk-software-c27a6abf182a"
                 }
              ],
              "Authors": ["Nikhil (niks) (@niksthehacker)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-10-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook hidden redirection vulnerability",
                    "Link": "https://medium.com/@egeken/facebook-hidden-redirection-vulnerability-aeaaac0b9d73"
                 }
              ],
              "Authors": ["Ege Ken"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2018-10-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS with HTML and how to convert the HTML into charcode()",
                    "Link": "https://medium.com/@ariffadhlullah2310/xss-deface-with-html-and-how-to-convert-the-html-into-charcode-f0c62dd5ef3f"
                 }
              ],
              "Authors": ["Arif-ITSEC111"],
              "Programs": ["Purinar Logistics"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google sites and exploiting same origin policy",
                    "Link": "https://medium.com/@raushanraj_65039/google-sites-and-exploiting-same-origin-policy-d400bf569964"
                 }
              ],
              "Authors": ["Raushan Raj (@raushan_rajj)"],
              "Programs": ["Google"],
              "Bugs": ["SOP bypass"],
              "Bounty": "3,133.70",
              "PublicationDate": "2018-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cookie-based-injection XSS making exploitable with-out exploiting other Vulns",
                    "Link": "https://medium.com/@agrawalsmart7/cookie-based-injection-xss-making-exploitable-with-out-exploiting-other-vulns-81132ca01d67"
                 }
              ],
              "Authors": ["Utkarsh Agrawal (@agrawalsmart7)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Harvesting all private invites using leave program fast-tracked invitation and security@ email forwarding feature",
                    "Link": "https://medium.com/japzdivino/harvesting-all-private-invites-using-leave-program-fast-tracked-invitation-and-security-email-a01c8b3ce76f"
                 }
              ],
              "Authors": ["Japz Divino (@japzdivino)"],
              "Programs": ["HackerOne"],
              "Bugs": ["Logic flaw"],
              "Bounty": "2,500",
              "PublicationDate": "2018-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A possibility of Account Takeover in Medium",
                    "Link": "https://medium.com/@notsoshant/a-possibility-of-account-takeover-in-medium-8d950e547639"
                 }
              ],
              "Authors": ["Prashant Kumar (@notsoshant)"],
              "Programs": ["Medium"],
              "Bugs": ["Account takeover", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-10-20",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "A Story of mishandling the Chunked Data (CVE-2018-17082)",
                  "Link": "https://github.com/cymtrick/lol/blob/d17ed765129b26a1bf8060757e5aebd4e237c908/_posts/2018-10-20-CVE-2018-17082-PHP-XSS-A-Story-of-Chunked-Requests.md"
               },
               {
                  "Title": "Original report",
                  "Link": "https://bugs.php.net/bug.php?id=76582"
               }
            ],
            "Authors": ["Prashanth Varma (@cymtrick)"],
            "Programs": ["PHP"],
            "Bugs": ["XSS"],
            "Bounty": "-",
            "PublicationDate": "2018-10-20",
            "AddedDate": "2022-10-28"
         },
           {
              "Links": [
                 {
                    "Title": "XSS with PUT in Ghost Blog",
                    "Link": "https://www.itsecguy.com/xss-with-put-in-ghost-blog/"
                 }
              ],
              "Authors": ["Derek (@StackCrash)"],
              "Programs": ["Ghost"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-10-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Add comment on a private Oculus Developer bug report",
                    "Link": "https://medium.com/bugbountywriteup/add-comment-on-a-private-oculus-developer-bug-report-93f35bc80b2c"
                 }
              ],
              "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-10-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Security teams Internal attachments can be exported via \"Export as .zip\" feature on HackerOne",
                    "Link": "https://medium.com/japzdivino/security-teams-internal-attachments-can-be-exported-via-export-as-zip-feature-on-hackerone-35ca6ec2bf8b"
                 }
              ],
              "Authors": ["Japz Divino (@japzdivino)"],
              "Programs": ["HackerOne"],
              "Bugs": ["Logic flaw"],
              "Bounty": "12,500",
              "PublicationDate": "2018-10-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XXE in IBM’s MaaS360 Platform",
                    "Link": "https://blog.netspi.com/xxe-in-ibms-maas360-platform/"
                 }
              ],
              "Authors": ["Cody Wass"],
              "Programs": ["IBM"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-10-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Path traversal while uploading results in RCE",
                    "Link": "https://blog.harshjaiswal.com/path-traversal-while-uploading-results-in-rce"
                 }
              ],
              "Authors": ["Harsh Jaiswal (@rootxharsh)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-10-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Brave Browser Script Blocker Bypass Vulnerability",
                    "Link": "https://medium.com/bugbountywriteup/brave-browser-script-blocker-bypass-vulnerability-fffd659c5a7"
                 }
              ],
              "Authors": ["Xiaoyin Liu"],
              "Programs": ["Brave Software"],
              "Bugs": ["Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2018-10-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft CSRF Vulnerability",
                    "Link": "https://web.archive.org/web/20200825165404/https://medium.com/@adeshkolte/how-i-got-500-from-microsoft-for-csrf-vulnerability-700accaf48b9"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["Microsoft"],
              "Bugs": ["CSRF"],
              "Bounty": "500",
              "PublicationDate": "2018-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Bug bounty | mail.ru] Access to the admin panel of the partner site and data disclosure of 2 million users",
                    "Link": "https://medium.com/bugbountywriteup/bug-bounty-mail-ru-234fa6f5a5a"
                 }
              ],
              "Authors": ["Max (@iSecMax)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["Authentication bypass", "Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Magic XSS with two parameters",
                    "Link": "https://medium.com/@m4shahab1/magic-xss-with-two-parameters-463559b03949"
                 }
              ],
              "Authors": ["Mahmood Shahabi (@m4shahab1)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Add description to Instagram Posts on behalf of other users - 6500$",
                    "Link": "https://medium.com/bugbountywriteup/add-description-to-instagram-posts-on-behalf-of-other-users-6500-7d55b4a24c5a"
                 }
              ],
              "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "6,500",
              "PublicationDate": "2018-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Edge Remote Code Execution",
                    "Link": "https://leucosite.com/Microsoft-Edge-RCE/"
                 }
              ],
              "Authors": ["Abdulrahman Alqabandi (@Qab)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-10-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Access to staging environment via User-Agent string",
                    "Link": "https://medium.com/@yassergersy/access-to-staging-environment-via-user-agent-string-23470546577f"
                 }
              ],
              "Authors": ["Yasser Gersy (@yassergersy)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Symantec Messaging Gateway authentication bypass",
                    "Link": "https://artkond.com/2018/10/10/symantec-authentication-bypass/"
                 }
              ],
              "Authors": ["Artem Kondratenko (@artkond)"],
              "Programs": ["Symantec"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Payment bypass",
                    "Link": "https://pratikyadav0.blogspot.com/2018/10/hello-everyone-took-some-time-from-my.html"
                 }
              ],
              "Authors": ["Pratik Yadav (@PratikY9967)"],
              "Programs": ["-"],
              "Bugs": ["Payment bypass", "Logic flaw"],
              "Bounty": "442.73",
              "PublicationDate": "2018-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Business Takeover",
                    "Link": "https://philippeharewood.com/facebook-business-takeover/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "27,500",
              "PublicationDate": "2018-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Get as image function pulls any Insights/NRQL data from any New Relic account (IDOR)",
                    "Link": "https://jonbottarini.com/2018/10/09/get-as-image-function-pulls-any-insights-nrql-data-from-any-new-relic-account-idor/"
                 }
              ],
              "Authors": ["Jon Bottarini (@jon_bottarini)"],
              "Programs": ["New Relic"],
              "Bugs": ["IDOR"],
              "Bounty": "2,500",
              "PublicationDate": "2018-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM-XSS Bug Affecting Tinder, Shopify, Yelp, and More",
                    "Link": "https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/"
                 }
              ],
              "Authors": ["VPN Mentor (@vpnmentor)"],
              "Programs": ["Tinder"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Make any Unit in Facebook Groups Undeletable",
                    "Link": "https://medium.com/bugbountywriteup/make-any-unit-in-facebook-groups-undeletable-efb68e26adb9"
                 }
              ],
              "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "IDOR", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Critical] Bypass CSRF protection on IBM",
                    "Link": "https://medium.com/bugbountywriteup/critical-bypass-csrf-protection-on-ibm-313ffb68dd0c"
                 }
              ],
              "Authors": ["Mohamed Sayed (@FlEx0Geek)"],
              "Programs": ["IBM"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-10-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com",
                    "Link": "https://medium.com/@jonathanbouman/persistent-xss-unvalidated-open-graph-embed-at-linkedin-com-db6188acedd9"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["LinkedIn"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-10-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First 0day Exploit (CSP Bypass + Reflected XSS) #BUGBOUNTY",
                    "Link": "https://medium.com/@alicanact60/my-first-0day-exploit-csp-bypass-reflected-xss-bugbounty-c7efa4bed3d7"
                 }
              ],
              "Authors": ["Ali Tütüncü(@alicanact60)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-10-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Web Cache Poisoning Countermeasures",
                    "Link": "https://portswigger.net/research/bypassing-web-cache-poisoning-countermeasures"
                 }
              ],
              "Authors": ["James Kettle (@albinowax)"],
              "Programs": ["Cloudflare"],
              "Bugs": ["Web cache poisoning"],
              "Bounty": "-",
              "PublicationDate": "2018-10-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind XML External Entities Out-Of-Band Channel Vulnerability : PayPal Case Study",
                    "Link": "https://r00thunt.com/2018/10/05/blind-xml-external-entities-out-of-band-channel-vulnerability-paypal-case-study/"
                 }
              ],
              "Authors": ["Abdelmoughite Eljoaydi"],
              "Programs": ["Paypal"],
              "Bugs": ["Blind XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-10-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Clickjacking in Google Docs and Voice typing feature.",
                    "Link": "https://medium.com/@raushanraj_65039/clickjacking-in-google-docs-and-voice-typing-feature-c481d00b020a"
                 }
              ],
              "Authors": ["Raushan Raj (@raushan_rajj)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "2,337",
              "PublicationDate": "2018-10-05",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Apache Struts double evaluation RCE lottery",
                  "Link": "https://securitylab.github.com/research/apache-struts-double-evaluation/"
               }
            ],
            "Authors": ["Man Yue Mo (@mmolgtm)"],
            "Programs": ["Apache Struts"],
            "Bugs": ["RCE", "Double OGNL evaluation"],
            "Bounty": "-",
            "PublicationDate": "2018-10-04",
            "AddedDate": "2022-12-05"
         },
           {
              "Links": [
                 {
                    "Title": "GoogleMeetRoulette: Joining random meetings",
                    "Link": "https://www.martinvigo.com/googlemeetroulette"
                 }
              ],
              "Authors": ["Martin Vigo (@martin_vigo)"],
              "Programs": ["Google"],
              "Bugs": ["Bruteforce", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-10-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An interesting Google vulnerability that got me 3133.7 reward.",
                    "Link": "https://www.sec-down.com/wordpress/?p=809"
                 }
              ],
              "Authors": ["Ebrahem Hegazy (@Zigoo0)"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "3,133.7",
              "PublicationDate": "2018-10-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Persistent XSS (Unvalidated oEmbed) at Medium.com",
                    "Link": "https://medium.com/@jonathanbouman/stored-xss-unvalidated-embed-at-medium-com-528b0d6d4982"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Medium"],
              "Bugs": ["Stored XSS"],
              "Bounty": "100",
              "PublicationDate": "2018-10-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting an unknown vulnerability",
                    "Link": "https://medium.com/bugbountywriteup/exploiting-an-unknown-vulnerability-a752272ffd7f"
                 }
              ],
              "Authors": ["Abhishek Bundela (@abhibundela)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2018-10-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Bug Bounty: Email Id, Phone Number Can be exposed Through Business Manager",
                    "Link": "https://medium.com/@rohitcoder/email-id-phone-number-can-be-exposed-through-business-manager-e79b970ea288"
                 }
              ],
              "Authors": ["Rohit kumar (@rohitcoder)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Information disclosure"],
              "Bounty": "3,000",
              "PublicationDate": "2018-10-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AWS takeover through SSRF in JavaScript",
                    "Link": "http://10degres.net/aws-takeover-through-ssrf-in-javascript/"
                 }
              ],
              "Authors": ["Gwendal Le Coguic (@gwendallecoguic)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Applying a small bypass to steal Facebook Session tokens in Uber",
                    "Link": "https://medium.com/@saamux/applying-a-small-bypass-to-steal-facebook-session-tokens-in-uber-5b9638b7a18c"
                 }
              ],
              "Authors": ["Samuel (@saamux)"],
              "Programs": ["Uber"],
              "Bugs": ["XSS", "CSP bypass", "OAuth"],
              "Bounty": "2,000",
              "PublicationDate": "2018-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i found Stored xss on your-domain.redacted.com",
                    "Link": "https://rudr4sarkar.blogspot.com/2018/10/how-i-found-stored-xss-on-your.html"
                 }
              ],
              "Authors": ["Rudra Sarkar (@rudr4_sarkar)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Collecting Shells by the Sea of NAS Vulnerabilities",
                    "Link": "https://blog.securityevaluators.com/collecting-shells-by-the-sea-of-nas-vulnerabilities-155a0bd7c525"
                 }
              ],
              "Authors": ["Rick Ramgattie (@RRamgattie)"],
              "Programs": ["Lenovo"],
              "Bugs": ["OS command injection", "XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-10-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover via Shopify Vendor ( blog.exchangemarketplace.com ) with Steps",
                    "Link": "https://web.archive.org/web/20200929001941/https://www.mohamedharon.com/2018/10/subdomain-takeover-via-shopify-vendor.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Shopify"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-10-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to takeover account's of an Earning App",
                    "Link": "https://medium.com/@alexali5080/how-i-was-able-to-takeover-accounts-of-an-earning-app-c22d07d8ce9"
                 }
              ],
              "Authors": ["Abbas Wafa"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-10-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking the Subway Android app",
                    "Link": "https://ls-la.fyi/2018/09/28/subway-xposed/"
                 }
              ],
              "Authors": ["Wesley Gahr (@wesley_gahr)"],
              "Programs": ["Subway"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-09-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR, Content Spoofing and Url Redirection via unsubscribe email in Confluent",
                    "Link": "https://medium.com/@justmorpheus/idor-content-spoofing-and-url-redirection-via-unsubscribe-email-in-confluent-1fa7398cfe7a"
                 }
              ],
              "Authors": ["Divyanshu Shukla (@justm0rph3u5)"],
              "Programs": ["Confluent"],
              "Bugs": ["IDOR", "Content spoofing", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2018-09-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Just another tale of severe bugs on a private program.",
                    "Link": "https://medium.com/@sivakrishnasamireddi/just-another-tale-of-severe-bugs-on-a-private-program-405870b03532"
                 }
              ],
              "Authors": ["Siva Krishna Samireddi (@le4rner)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "SSRF", "IDOR", "Logic flaw"],
              "Bounty": "1,623",
              "PublicationDate": "2018-09-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — From finding Jenkins instance to Command Execution.Secure your Jenkins Instance!",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-from-finding-jenkins-instance-to-command-execution-secure-your-jenkins-instance-9bd1e75c2288"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Exposed Jenkins instance"],
              "Bounty": "-",
              "PublicationDate": "2018-09-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Thick Client — Attacking databases the fun/easy way",
                    "Link": "https://medium.com/@mantissts/thick-client-attacking-databases-the-fun-easy-way-6e31162b1335"
                 }
              ],
              "Authors": ["Richard Clifford (@MantisSTS)"],
              "Programs": ["-"],
              "Bugs": ["Thick client", "Credentials sent over unencrypted channel"],
              "Bounty": "-",
              "PublicationDate": "2018-09-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Arbitrary File Read in one of the largest CRMs",
                    "Link": "https://medium.com/@mantissts/arbitrary-file-read-in-one-of-the-largest-crms-658caa2f05d2"
                 }
              ],
              "Authors": ["Richard Clifford (@MantisSTS)"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2018-09-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got $4000 from Visma for RCE",
                    "Link": "https://medium.com/@ratnadip1998/how-i-got-4000-from-visma-for-rce-d541e6042086"
                 }
              ],
              "Authors": ["Ratnadip Gajbhiye (@scspcommunity)"],
              "Programs": ["Visma"],
              "Bugs": ["RCE"],
              "Bounty": "4,000",
              "PublicationDate": "2018-09-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[XSS] survey.dropbox.com",
                    "Link": "https://www.kumar.ninja/2018/09/xss-surveydropboxcom.html"
                 }
              ],
              "Authors": ["Kumar"],
              "Programs": ["Dropbox"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-09-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Weaponizing XSS Attacking Internal System",
                    "Link": "https://medium.com/@rahulraveendran06/weaponizing-xss-attacking-internal-domains-d8ba1cbd106d"
                 }
              ],
              "Authors": ["Rahul R"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-09-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover via Unsecured S3 Bucket Connected to the Website",
                    "Link": "https://blog.securitybreached.org/2018/09/24/subdomain-takeover-via-unsecured-s3-bucket/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Responsible disclosure: retrieving a user's private Facebook friends.",
                    "Link": "https://rpadovani.com/facebook-responsible-disclosure"
                 }
              ],
              "Authors": ["Riccardo Padovani (@rpadovani93)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization", "Information disclosure"],
              "Bounty": "3,000",
              "PublicationDate": "2018-09-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I XSS’ed Uber and Bypassed CSP",
                    "Link": "https://medium.com/@efkan162/how-i-xssed-uber-and-bypassed-csp-9ae52404f4c5"
                 }
              ],
              "Authors": ["Efkan (@mefkansec)"],
              "Programs": ["Uber"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "2,000",
              "PublicationDate": "2018-09-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "R-XSS -> CSRF bypass to account takeover/",
                    "Link": "https://nirmaldahal.com.np/posts/2019/11/r-xss-leading-csrf-bypass-to-account-takeover/"
                 }
              ],
              "Authors": ["Nirmal Dahal (@TheNittam)"],
              "Programs": ["-"],
              "Bugs": ["Reflected XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Firebase authorization to create custom goo.gl subdomains",
                    "Link": "https://websecblog.com/vulns/bypassing-firebase-authorization-to-create-custom-goo-gl-subdomains/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Another XSS in Google Colaboratory",
                    "Link": "https://blog.bentkowski.info/2018/09/another-xss-in-google-colaboratory.html"
                 }
              ],
              "Authors": ["Michał Bentkowski (@SecurityMB)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Shopify Athena Bug",
                    "Link": "https://sites.google.com/securifyinc.com/secblogs/shopify-athena-bug"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Shopify"],
              "Bugs": ["Broken authorization", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Local file inclusion at IKEA.com",
                    "Link": "https://medium.com/@jonathanbouman/local-file-inclusion-at-ikea-com-e695ed64d82f"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Ikea"],
              "Bugs": ["LFI"],
              "Bounty": "250",
              "PublicationDate": "2018-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Authentication Using Javascript Debugger.",
                    "Link": "https://mohitdabas.wordpress.com/2018/09/18/bypassing-authentication-using-javascript-debugger/"
                 }
              ],
              "Authors": ["Mohit Dabas (@mohitdabas08)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-09-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i bypassed AKAMAI KONA WAF , XSS in overstock.com !",
                    "Link": "https://web.archive.org/web/20190320205543/https://medium.com/@0ktavandi/how-i-bypassed-akamai-kona-waf-xss-in-overstock-com-f205b0e71a0d"
                 }
              ],
              "Authors": ["Oktavandi (@0ktavandi)"],
              "Programs": ["Overstock.com"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-09-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook $750 Reward for a Simple Bug",
                    "Link": "https://bugbounty.blog/2018/09/18/facebook-750-reward-for-a-simple-bug/"
                 }
              ],
              "Authors": ["Aman Shahid (@amansmughal)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Authentication bypass", "Logic flaw"],
              "Bounty": "750",
              "PublicationDate": "2018-09-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chain The Bugs to Pwn an Organisation ( LFI + Unrestricted File Upload = Remote Code Execution )",
                    "Link": "https://medium.com/@armaanpathan/chain-the-bugs-to-pwn-an-organisation-lfi-unrestricted-file-upload-remote-code-execution-93dfa78ecce"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["-"],
              "Bugs": ["LFI", "Unrestricted file upload", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-09-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS at Philips.com",
                    "Link": "https://medium.com/@jonathanbouman/reflected-xss-at-philips-com-e48bf8f9cd3c"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Philips"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-09-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Vulnerabilities in Multiple iFrame Busters Affecting Top Tier Sites",
                    "Link": "https://randywestergren.com/xss-vulnerabilities-in-multiple-iframe-busters-affecting-top-tier-sites/"
                 }
              ],
              "Authors": ["Randy Westergren (@RandyWestergren)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-09-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "User Account takeover in India’s largest digital business company",
                    "Link": "https://medium.com/bugbountywriteup/user-account-takeover-in-indias-largest-digital-business-company-c7b6d61dadb9"
                 }
              ],
              "Authors": ["Minali Arora (@AroraMinali)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-09-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR User Account Takeover By Connecting My Facebook Account with victims Account",
                    "Link": "https://blog.securitybreached.org/2018/09/16/idor-account-takeover-using-facebook/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "1,200",
              "PublicationDate": "2018-09-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Persistent Cross-Site Scripting on redacted worth $2,000",
                    "Link": "https://web.archive.org/web/20200811013311/https://medium.com/@protector47/persistent-cross-site-scripting-on-redacted-worth-2-000-1e760617ccab"
                 }
              ],
              "Authors": ["Muhammad Asim Shahzad (@protector47)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "2,000",
              "PublicationDate": "2018-09-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hijacked your account when you opened my cat picture",
                    "Link": "https://medium.com/intigriti/how-i-hijacked-your-account-when-you-opened-my-cat-picture-9a0a0acca9e8"
                 }
              ],
              "Authors": ["Matti Bijnens (@MattiBijnens)"],
              "Programs": ["-"],
              "Bugs": ["Logout CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-09-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking your own antivirus for fun and profit (Safe browsing gone wrong)",
                    "Link": "https://medium.com/@Mthirup/hacking-your-own-antivirus-for-fun-and-profit-safe-browsing-gone-wrong-365db9d1d3f7"
                 }
              ],
              "Authors": ["Martin Thirup Christensen (@Mthirup)"],
              "Programs": ["Bullguard"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-09-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover worth 200$",
                    "Link": "https://medium.com/@alirazzaq/subdomain-takeover-worth-200-ed73f0a58ffe"
                 }
              ],
              "Authors": ["Ali Razzaq (@AliRazzaq_)"],
              "Programs": ["Netlify"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "200",
              "PublicationDate": "2018-09-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected DOM XSS and CLICKJACKING on https://silvergoldbull.de/bt.html",
                    "Link": "https://medium.com/@maxon3/reflected-dom-xss-and-clickjacking-on-https-silvergoldbull-de-bt-html-daa36bdf7bf0"
                 }
              ],
              "Authors": ["Daniel Maksimovic"],
              "Programs": ["Silver Gold Bull"],
              "Bugs": ["DOM XSS", "Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2018-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open-Redirect Vulnerability in udacity.com",
                    "Link": "https://medium.com/@aniltom/open-redirect-vulnerability-in-udacity-com-7cba7abcfd48"
                 }
              ],
              "Authors": ["Anil Tom (mr_4nk)"],
              "Programs": ["Udacity"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2018-09-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking a Crypto Debit Card Service",
                    "Link": "https://medium.com/@mahitman1/hacking-a-crypto-debit-card-service-730f287aaee7"
                 }
              ],
              "Authors": ["Muhammad Abdullah"],
              "Programs": ["Plutus"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-09-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XXE at Bol.com",
                    "Link": "https://medium.com/@jonathanbouman/xxe-at-bol-com-7d331186de54"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Bol.com"],
              "Bugs": ["XXE"],
              "Bounty": "500",
              "PublicationDate": "2018-09-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to do 55.000+ Subdomain Takeover in a Blink of an Eye",
                    "Link": "https://medium.com/@thebuckhacker/how-to-do-55-000-subdomain-takeover-in-a-blink-of-an-eye-a94954c3fc75"
                 }
              ],
              "Authors": ["BuckHacker (@thebuckhacker)"],
              "Programs": ["Shopify"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authentication Bypass Using SQL Injection AutoTrader Webmail – Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2018/09/10/sqli-login-bypass-autotraders/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["AutoTrader"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Apple Safari & Microsoft Edge Browser Address Bar Spoofing - Writeup",
                    "Link": "https://www.rafaybaloch.com/2018/09/apple-safari-microsoft-edge-browser.html"
                 }
              ],
              "Authors": ["Rafay Baloch (@rafaybaloch)"],
              "Programs": ["Microsoft", "Apple"],
              "Bugs": ["Address Bar Spoofing"],
              "Bounty": "-",
              "PublicationDate": "2018-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS Vulnerability in H1C Private site",
                    "Link": "https://www.hackerinside.me/2018/09/stored-xss-vulnerability-in-h1c-private.html"
                 }
              ],
              "Authors": ["Anas Mahmood (@AnasIsHere)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "900",
              "PublicationDate": "2018-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Making the Facebook app more secure - $8500 bounty",
                    "Link": "https://ash-king.co.uk/facebook-bug-bounty-09-18.html"
                 }
              ],
              "Authors": ["Ashley King (@AshleyKingUK)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "8,500",
              "PublicationDate": "2018-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ZOL Zimbabwe Authentication Bypass to XSS & SQLi Vulnerability – Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2018/09/09/zol-zimbabwe-authbypass-sqli-xss/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["ZOL Zimbabwe"],
              "Bugs": ["XSS", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I find Open-Redirect Vulnerability in redacted.com (One of the top online payment processing service website)",
                    "Link": "https://web.archive.org/web/20200904145527/https://medium.com/@protector47/how-i-find-open-redirect-vulnerability-in-redacted-com-one-of-the-top-payment-gateway-e9b92afdc114"
                 }
              ],
              "Authors": ["Muhammad Asim Shahzad (@protector47)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2018-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS Vulnerability in Tumblr",
                    "Link": "https://www.hackerinside.me/2018/09/stored-xss-vulnerability-in-tumblr.html"
                 }
              ],
              "Authors": ["Anas Mahmood (@AnasIsHere)"],
              "Programs": ["Automattic"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2018-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS in Google Code Jam",
                    "Link": "https://websecblog.com/vulns/reflected-xss-in-google-code-jam/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Google"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection Vulnerability bootcamp.nutanix.com | Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2018/09/08/sqli-bootcampnutanix-com-bug-bounty-poc/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["Nutanix"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Hotstar Premium with DOM manipulation and some JavaScript",
                    "Link": "https://opsecx.com/index.php/2018/09/07/bypassing-hotstar-premium-with-dom-manipulation-and-some-javascript/"
                 }
              ],
              "Authors": ["OpSecX (@OpSecX)"],
              "Programs": ["Hotstar"],
              "Bugs": ["Logic flaw", "Payment bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE Unsecure Jenkins Instance | Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2018/09/07/rce-jenkins-instance-dosomething-org-bug-bounty-poc/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Exposed Jenkins instance"],
              "Bounty": "-",
              "PublicationDate": "2018-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Write-up - Love story, from closed as informative to $3,500 USD, XSS stored in Yahoo! iOS MaiL app",
                    "Link": "http://omespino.com/write-up-lovestory-from-closed-as-informative-to-xx00-usd-in-yahoo-ios-mail-app/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Stored XSS"],
              "Bounty": "3,500",
              "PublicationDate": "2018-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Simple Login Brute Force / Current Password Requirement Bypass",
                    "Link": "https://medium.com/@ciph3r7r0ll/simple-login-brute-force-current-password-requirement-bypass-e8f58931e257"
                 }
              ],
              "Authors": ["Mandeep Jadon (@1337tr0lls)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover", "Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2018-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — How Naaptol (India’s popular home shopping company) Kept their Millions of User Data at Risk!",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-how-naaptol-indias-popular-home-shopping-company-kept-their-millions-of-user-data-e414cd4151c"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["Naaptol"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could download the source code of an Indian e-commerce website!!",
                    "Link": "https://medium.com/@aroraminali21/how-i-could-download-the-source-code-of-an-indian-e-commerce-website-30cb8310b6e4"
                 }
              ],
              "Authors": ["Minali Arora (@AroraMinali)"],
              "Programs": ["-"],
              "Bugs": ["File disclosure", "Source code disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "P1 Vulnerability in 60 seconds",
                    "Link": "https://medium.com/@Wh11teW0lf/p1-vulnerability-in-60-seconds-85ef93d42b99"
                 }
              ],
              "Authors": ["Wh11teW0lf (@wh11tew0lf)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "File disclosure"],
              "Bounty": "1,500",
              "PublicationDate": "2018-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Bug Bounty! {Permission Bug}",
                    "Link": "https://medium.com/@alicanact60/facebook-bug-bounty-permission-bug-19c9358d2297"
                 }
              ],
              "Authors": ["Ali Tütüncü (@alicanact60)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "750",
              "PublicationDate": "2018-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could have launched a spear phishing campaign with Starbucks email servers",
                    "Link": "https://b3nac.github.io/bugs/2018/09/01/How-I-could-have-launched-a-spear-phishing-campaign-with-Starbucks-newsletter-signup.html"
                 }
              ],
              "Authors": ["Kyle (@B3nac)"],
              "Programs": ["Starbucks"],
              "Bugs": ["Host header injection"],
              "Bounty": "150",
              "PublicationDate": "2018-09-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Send request to Martians. Earthlings are already your friends.",
                    "Link": "https://blog.sagarvd.me/2018/09/youtube-csrf.html"
                 }
              ],
              "Authors": ["Sagar VD"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-09-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "https://medium.com/@mahitman1/i-own-your-customers-22e965761abd",
                    "Link": "https://medium.com/@mahitman1/i-own-your-customers-22e965761abd"
                 }
              ],
              "Authors": ["Muhammad Abdullah"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure", "Hardcoded credentials", "AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2018-09-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pwned Together: Hacking dev.to",
                    "Link": "https://dev.to/antogarand/pwned-together-hacking-devto-hkd"
                 }
              ],
              "Authors": ["Antony Garand (@AntoGarand)"],
              "Programs": ["Dev.to"],
              "Bugs": ["Stored XSS"],
              "Bounty": "150",
              "PublicationDate": "2018-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$100 Bounty in 300 seconds isn’t bad !!!",
                    "Link": "https://medium.com/@rohanchavan/100-bounty-in-300-seconds-isnt-bad-4f4112c102ef"
                 }
              ],
              "Authors": ["Rohan Chavan (@rohanchavan1918)"],
              "Programs": ["Zoho"],
              "Bugs": ["Stored XSS"],
              "Bounty": "100",
              "PublicationDate": "2018-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS in Django REST Framework Api at MapBox Subdomain",
                    "Link": "https://web.archive.org/web/20200929012934/https://www.mohamedharon.com/2018/08/mapboxxss.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Mapbox"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "500",
              "PublicationDate": "2018-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding hidden gems vol. 2: REAMDE.md, the story of a bit too helpful readme file",
                    "Link": "https://medium.com/@mateusz.olejarka/finding-hidden-gems-vol-2-reamde-md-the-story-of-a-bit-too-helpful-readme-file-12d6bb51e77f"
                 }
              ],
              "Authors": ["Mateusz Olejarka (@molejarka)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Infinite Loop Story.",
                    "Link": "https://medium.com/@D0rkerDevil/a-infinite-loop-story-f2bc05771a88"
                 }
              ],
              "Authors": ["Ashish Kunwar (@D0rkerDevil)"],
              "Programs": ["-"],
              "Bugs": ["DoS"],
              "Bounty": "100",
              "PublicationDate": "2018-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A $1000 Bounty",
                    "Link": "https://gauravnarwani.com/a-1000-bounty/"
                 }
              ],
              "Authors": ["Gaurav Narwani (@gauravnarwani97)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,000",
              "PublicationDate": "2018-08-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected Swf XSS at ( https://plugins.svn.wordpress.org )",
                    "Link": "https://web.archive.org/web/20200929004149/https://www.mohamedharon.com/2018/08/wordpressXSS.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["WordPress"],
              "Bugs": ["Flash XSS", "Reflected XSS"],
              "Bounty": "350",
              "PublicationDate": "2018-09-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i found a 1500$ worth Deserialization vulnerability",
                    "Link": "https://medium.com/@D0rkerDevil/how-i-found-a-1500-worth-deserialization-vulnerability-9ce753416e0a"
                 }
              ],
              "Authors": ["Ashish Kunwar (@D0rkerDevil)"],
              "Programs": ["-"],
              "Bugs": ["Misconfigured JSF ViewState", "Insecure deserialization"],
              "Bounty": "1,500",
              "PublicationDate": "2018-08-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR FACEBOOK: malicious person add people to the “Top Fans”",
                    "Link": "https://medium.com/@UpdateLap/idor-facebook-malicious-person-add-people-to-the-top-fans-4f1887aad85a"
                 }
              ],
              "Authors": ["Jafar Abo Nada (@Jafar_Abo_Nada)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-08-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Traversing the Path to RCE",
                    "Link": "https://blog.hawkeyesecurity.com/2018/08/27/traversing-the-path-to-rce/"
                 }
              ],
              "Authors": ["hawkinsecurity"],
              "Programs": ["-"],
              "Bugs": ["Path traversal", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-08-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My first valid xss(@Hackerone)",
                    "Link": "https://medium.com/@nandwanajatin25/my-first-valid-xss-hackerone-f8ba0a7c647"
                 }
              ],
              "Authors": ["Jatin Aesthetic (@techyfreakk)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "100",
              "PublicationDate": "2018-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Code Execution on a Facebook server",
                    "Link": "https://blog.scrt.ch/2018/08/24/remote-code-execution-on-a-facebook-server/"
                 }
              ],
              "Authors": ["Daniel Le Gall (@Blaklis_)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["RCE"],
              "Bounty": "5,000",
              "PublicationDate": "2018-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Privileged Escalation in Facebook Messenger Rooms",
                    "Link": "https://medium.com/@UpdateLap/privileged-escalation-in-facebook-messenger-rooms-e71cb7275101"
                 }
              ],
              "Authors": ["Jafar Abo Nada (@Jafar_Abo_Nada)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Privilege escalation", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection Vulnerability In University Of Cambridge",
                    "Link": "https://web.archive.org/web/20200829220607/https://medium.com/@adeshkolte/sql-injection-vulnerability-in-university-of-cambridge-b4c8d0381e1"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["Cambridge"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Liking GitHub repositories on behalf of other users — Stored XSS in WebComponents.org",
                    "Link": "https://websecblog.com/vulns/stored-xss-in-webcomponents-org/"
                 }
              ],
              "Authors": ["Thomas Orlita (@ThomasOrlita)"],
              "Programs": ["Webcomponents.org"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-08-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "API key: The real goldmine",
                    "Link": "https://medium.com/@YumiSec/api-key-the-real-goldmine-84490a56b7c4"
                 }
              ],
              "Authors": ["Yumi"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-08-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "https://www.updatelap.com/2018/08/privileged-escalation-in-facebook-rooms.html",
                    "Link": "https://www.updatelap.com/2018/08/privileged-escalation-in-facebook-rooms.html"
                 }
              ],
              "Authors": ["Jafar Abo Nada (@Jafar_Abo_Nada)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2018-08-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "User credential are sent in clear text in Whatsapp web— FIXED | Facebook Bug Bounty",
                    "Link": "https://medium.com/@Thuva11/user-credentials-are-sent-in-clear-text-fixed-facebook-bug-bounty-7f1e05ecedd9"
                 }
              ],
              "Authors": ["Thuvarakan Nakarajah"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Credentials sent over unencrypted channel"],
              "Bounty": "-",
              "PublicationDate": "2018-08-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "YAHOO IDOR -elimination of any comment",
                    "Link": "https://medium.com/@black_b/yahoo-idor-elimination-of-any-comment-e898f4f955f1"
                 }
              ],
              "Authors": ["Bada Diaz (@bada77)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-08-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "3 Minutes & XSS!",
                    "Link": "https://medium.com/bugbountywriteup/3-minutes-xss-71e3340ad66b"
                 }
              ],
              "Authors": ["Ashish Jha"],
              "Programs": ["Edmodo"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-08-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR leads to account takeover",
                    "Link": "https://web.archive.org/web/20220309092244/https://s0cket7.com/idor-account-takeover/"
                 }
              ],
              "Authors": ["s0cket7 (@s0cket7)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-08-16",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "An XSS Story",
                  "Link": "https://swisskyrepo.github.io/An-XSS-Story/"
               }
            ],
            "Authors": ["Swissky (@pentest_swissky)"],
            "Programs": ["-"],
            "Bugs": ["XSS"],
            "Bounty": "-",
            "PublicationDate": "2018-08-14",
            "AddedDate": "2024-05-11"
         },
           {
              "Links": [
                 {
                    "Title": "Another \"TicketTrick\" story",
                    "Link": "https://sites.google.com/securifyinc.com/secblogs/uber-business-support-bug"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Uber"],
              "Bugs": ["Ticket Trick", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-08-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS at Hubspot and XSS in email areas.",
                    "Link": "https://medium.com/@friendly_/xss-at-hubspot-and-xss-in-email-areas-674fa39d5248"
                 }
              ],
              "Authors": ["Friendly (@SkeletorKeys)"],
              "Programs": ["HubSpot"],
              "Bugs": ["XSS"],
              "Bounty": "450",
              "PublicationDate": "2018-08-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR leads to getting Access tokens of users linked to Google Drive on Edmodo",
                    "Link": "https://medium.com/bugbountywriteup/idor-leads-to-getting-access-tokens-of-users-linked-to-google-drive-on-edmodo-3978017134bd"
                 }
              ],
              "Authors": ["Aagam shah (@neutrinoguy)"],
              "Programs": ["Edmodo"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Distorted and Undeletable Posts in Facebook Group",
                    "Link": "https://medium.com/bugbountywriteup/distorted-and-undeletable-posts-in-facebook-group-9424e15f5551"
                 }
              ],
              "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Chained 4 Bugs(Features?) into RCE on Amazon Collaboration System",
                    "Link": "http://blog.orange.tw/2018/08/how-i-chained-4-bugs-features-into-rce-on-amazon.html"
                 }
              ],
              "Authors": ["Orange Tsai (@orange_8361)"],
              "Programs": ["Amazon"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-08-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "S3 Bucket Misconfiguration in Amazon",
                    "Link": "https://medium.com/@justmorpheus/s3-bucket-misconfiguration-in-amazon-a7da6a6e02ea"
                 }
              ],
              "Authors": ["Divyanshu Shukla (@justm0rph3u5)"],
              "Programs": ["Amazon"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2018-08-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Adminer Script Results to Pwning Server?, Private Bug Bounty Program",
                    "Link": "https://medium.com/bugbountywriteup/adminer-script-results-to-pwning-server-private-bug-bounty-program-fe6d8a43fe6f"
                 }
              ],
              "Authors": ["Yashar Shahinzadeh (@YShahinzadeh)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-08-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Misconfigured JIRA setting - Apigee",
                    "Link": "https://www.tutorgeeks.net/2018/08/misconfigured-jira-setting-apigee.html"
                 }
              ],
              "Authors": ["Tutorgeeks"],
              "Programs": ["Google", "Atlassian"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Twitter Bug Bounty] Misconfigured JSON endpoint on ads.twitter.com lead to Access control issue and Information Disclosure of role privileged users.",
                    "Link": "https://web.archive.org/web/20191219011242/https://medium.com/@zk34911/twitter-bug-bounty-misconfigured-json-endpoint-on-ads-twitter-com-2771ec83a82"
                 }
              ],
              "Authors": ["Peerzada Fawaz Ahmad Qureshi"],
              "Programs": ["Twitter"],
              "Bugs": ["Broken authorization", "Information disclosure"],
              "Bounty": "280",
              "PublicationDate": "2018-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Practical Web Cache Poisoning",
                    "Link": "https://portswigger.net/research/practical-web-cache-poisoning"
                 }
              ],
              "Authors": ["James Kettle (@albinowax)"],
              "Programs": ["Mozilla", "HubSpot", "Cloudflare", "Binary.com", "Amazon (CloudFront)"],
              "Bugs": ["Web cache poisoning"],
              "Bounty": "-",
              "PublicationDate": "2018-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover: Yet another Starbucks case",
                    "Link": "https://0xpatrik.com/subdomain-takeover-starbucks-ii/"
                 }
              ],
              "Authors": ["Patrik Hudak (@0xpatrik)"],
              "Programs": ["Starbucks"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "2,000",
              "PublicationDate": "2018-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From TOMCAT to NT AUTHORITY\\SYSTEM",
                    "Link": "https://medium.com/bugbountywriteup/from-tomcat-to-nt-authority-system-a79fa09c4abb"
                 }
              ],
              "Authors": ["Rahul R"],
              "Programs": ["-"],
              "Bugs": ["Default credentials"],
              "Bounty": "-",
              "PublicationDate": "2018-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Disclosed Report about Basic auth Api details at Reverb.com",
                    "Link": "https://web.archive.org/web/20201006184247/https://www.mohamedharon.com/2018/08/reverb-api.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Reverb"],
              "Bugs": ["Information disclosure"],
              "Bounty": "100",
              "PublicationDate": "2018-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This is how can I spoof ANY Sentry.Io log infinitely and create fake error-logs",
                    "Link": "https://medium.com/@carlosdanielgiovanella/this-is-how-can-i-spoof-any-sentry-log-infinitely-and-create-fake-error-logs-74406367f4ba"
                 }
              ],
              "Authors": ["Carlos Daniel Giovanella"],
              "Programs": ["HackerOne", "Sentry"],
              "Bugs": ["Content spoofing"],
              "Bounty": "-",
              "PublicationDate": "2018-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Critical Report",
                    "Link": "https://medium.com/mcorral74/my-first-critical-report-9ceeb15f20c3"
                 }
              ],
              "Authors": ["Miguel Corral (@mcorral74)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "2,500",
              "PublicationDate": "2018-08-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked a Crypto Exchange (Bug Bounty Writeup)",
                    "Link": "https://steemit.com/cryptocurrency/@mabdullah22/how-i-hacked-a-crypto-exchange-bug-bounty-writeup"
                 }
              ],
              "Authors": ["Muhammad Abdullah"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From data leak to account takeover",
                    "Link": "https://dev.to/antogarand/from-data-leak-to-account-takeover-1kck"
                 }
              ],
              "Authors": ["Antony Garand (@AntoGarand)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "Information disclosure", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2018-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I gained commit access to Homebrew in 30 minutes",
                    "Link": "https://medium.com/@vesirin/how-i-gained-commit-access-to-homebrew-in-30-minutes-2ae314df03ab"
                 }
              ],
              "Authors": ["Eric Holmes (@vesirin)"],
              "Programs": ["Homebrew"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sending out phishing e-mails from @microsoft.com",
                    "Link": "https://medium.com/bugbountywriteup/sending-out-phishing-e-mails-from-microsoft-com-84c3b918ada2"
                 }
              ],
              "Authors": ["SI9INT (@si9int)"],
              "Programs": ["Microsoft"],
              "Bugs": ["HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2018-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "FakesApp: A Vulnerability in WhatsApp",
                    "Link": "https://research.checkpoint.com/2018/fakesapp-a-vulnerability-in-whatsapp/"
                 }
              ],
              "Authors": ["Dikla Barda", "Roman Zaikin (@R0m4nZ41k1n)", "Oded Vanunu (@Od3dV)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Content spoofing", "Broken authorization", "Privacy issue"],
              "Bounty": "-",
              "PublicationDate": "2018-08-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauth meetings access",
                    "Link": "https://sites.google.com/securifyinc.com/vrp-writeups/google-meet/authorization-bugs"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Self XSS leads to blind XSS and reflected XSS.",
                    "Link": "https://medium.com/@friendly_/self-xss-leads-to-blind-xss-and-reflected-xss-950b1dc24647"
                 }
              ],
              "Authors": ["Friendly (@SkeletorKeys)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS", "Reflected XSS"],
              "Bounty": "700",
              "PublicationDate": "2018-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS Primagames.com",
                    "Link": "https://medium.com/@friendly_/reflected-xss-primagames-com-c7a641912626"
                 }
              ],
              "Authors": ["Friendly (@SkeletorKeys)"],
              "Programs": ["Prima Games"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My First Swag Pack : A Logical Bug on Edmodo",
                    "Link": "https://www.secjuice.com/logical-bug-at-edmodo/"
                 }
              ],
              "Authors": ["Abartan Dhakal (@imhaxormad)"],
              "Programs": ["Edmodo"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind-XSS in Chrome Experiments - Google (Write Up)",
                    "Link": "https://blog.evanricafort.com/2018/08/blind-xss-in-chrome-experiments-google.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Google"],
              "Bugs": ["Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in GameSkinny",
                    "Link": "https://medium.com/@friendly_/stored-xss-in-gameskinny-aa26c6a6ae40"
                 }
              ],
              "Authors": ["Friendly (@SkeletorKeys)"],
              "Programs": ["GameSkinny"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind-XSS in Chrome Experiments - Google (Write Up)",
                    "Link": "https://blog.evanricafort.com/2018/08/blind-xss-in-chrome-experiments-google.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Google"],
              "Bugs": ["Blind XSS"],
              "Bounty": "100",
              "PublicationDate": "2018-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — @Paytm Customer Information is at risk — India’s largest digital wallet company",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-paytm-customer-information-is-at-risk-indias-largest-digital-wallet-company-6f7116d4b2d5"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["Paytm"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Discovering and Exploiting a Vulnerability in Android’s Personal Dictionary (CVE-2018-9375)",
                    "Link": "https://ioactive.com/discovering-and-exploiting-a-vulnerability-in-androids-personal-dictionary/"
                 }
              ],
              "Authors": ["Daniel Kachakil (@Kachakil)"],
              "Programs": ["Google"],
              "Bugs": ["Privilege escalation", "Android"],
              "Bounty": "-",
              "PublicationDate": "2018-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting a Microsoft Edge Vulnerability to Steal Files",
                    "Link": "https://www.netsparker.com/blog/web-security/stealing-local-files-with-simple-html-file/"
                 }
              ],
              "Authors": ["Ziyahan Albeniz (@ziyaxanalbeniz)"],
              "Programs": ["Microsoft"],
              "Bugs": ["SOP bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Shipt Subdomain TakeOver via HeroKu ( test.shipt.com )",
                    "Link": "https://web.archive.org/web/20201022195925/https://www.mohamedharon.com/2018/08/Shipttakeover.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Shipt"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CRLF Injection Into PHP’s cURL Options",
                    "Link": "https://medium.com/@tomnomnom/crlf-injection-into-phps-curl-options-e2e0d7cfe545"
                 }
              ],
              "Authors": ["TomNomNom (@tomnomnom)"],
              "Programs": ["-"],
              "Bugs": ["CRLF injection"],
              "Bounty": "-",
              "PublicationDate": "2018-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could access your internal servers, steal and modify your image repository",
                    "Link": "https://medium.com/@thehackerish/how-i-could-access-your-internal-servers-steal-and-modify-your-image-repository-d477f79b329a"
                 }
              ],
              "Authors": ["thehackerish (@thehackerish)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Imgur for Fun and Profit",
                    "Link": "https://medium.freecodecamp.org/hacking-imgur-for-fun-and-profit-3b2ec30c9463"
                 }
              ],
              "Authors": ["Nathan (@NathOnSecurity)"],
              "Programs": ["Imgur"],
              "Bugs": ["Outdated component with a known vulnerability", "Information disclosure"],
              "Bounty": "5,500",
              "PublicationDate": "2018-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Yahoo — Two XSSi vulnerabilities chained to steal user information. ($750 Bounty)",
                    "Link": "https://medium.com/@0xHyde/yahoo-two-xssi-vulnerabilities-chained-to-steal-user-information-750-bounty-e9bc6a41a40a"
                 }
              ],
              "Authors": ["Brian Hyde (@0xHyde)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["XSSI"],
              "Bounty": "750",
              "PublicationDate": "2018-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Office 365 Stored XSS",
                    "Link": "https://www.youtube.com/watch?v=0oKHov6y6mw"
                 }
              ],
              "Authors": ["Pethuraj (@Pethuraj)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Making a Blind SQL Injection a Little Less Blind",
                    "Link": "https://medium.com/@tomnomnom/making-a-blind-sql-injection-a-little-less-blind-428dcb614ba8"
                 }
              ],
              "Authors": ["TomNomNom (@tomnomnom)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Binary.com ClickJacking Vulnerability — Exploiting HTML5 Security Features",
                    "Link": "https://medium.com/@ameerassadi/binary-com-clickjacking-vulnerability-exploiting-html5-security-features-368c1ff2219d"
                 }
              ],
              "Authors": ["Ameer Assadi (@AmeerAssadi)"],
              "Programs": ["Binary.com"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2018-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found XSS on Amazon?",
                    "Link": "https://medium.com/@codingkarma/how-i-found-xss-on-amazon-f62b50f1c336"
                 }
              ],
              "Authors": ["Coding_Karma (@karma_coded)"],
              "Programs": ["Amazon (CloudFront)"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exfiltration via CSS Injection",
                    "Link": "https://medium.com/@d0nut/exfiltration-via-css-injection-4e999f63097d"
                 }
              ],
              "Authors": ["d0nut (@d0nutptr)"],
              "Programs": ["-"],
              "Bugs": ["CSS injection"],
              "Bounty": "-",
              "PublicationDate": "2018-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection and A silly WAF",
                    "Link": "https://mahmoudsec.blogspot.com/2018/07/sql-injection-and-silly-waf.html"
                 }
              ],
              "Authors": ["Mahmoud Gamal (@Zombiehelp54)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-07-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploitation of Server Side Template Injection with Craft CMS plugin SEOmatic <=3.1.3 [CVE-2018-14716]",
                    "Link": "http://ha.cker.info/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic/"
                 }
              ],
              "Authors": ["Sebastian (ha.cker.info)"],
              "Programs": ["SEOmatic CMS plugin"],
              "Bugs": ["SSTI"],
              "Bounty": "-",
              "PublicationDate": "2018-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerability in Hangouts Chat a.k.a. how Electron makes open redirect great again",
                    "Link": "https://blog.bentkowski.info/2018/07/vulnerability-in-hangouts-chat-aka-how.html"
                 }
              ],
              "Authors": ["Michał Bentkowski (@SecurityMB)"],
              "Programs": ["Google"],
              "Bugs": ["Open redirect", "RCE"],
              "Bounty": "7,500",
              "PublicationDate": "2018-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Finding hidden gems vol. 1: forging OAuth tokens using discovered client id and client secret",
                    "Link": "https://medium.com/@mateusz.olejarka/finding-hidden-gems-vol-1-forging-oauth-tokens-using-discovered-client-id-and-client-secret-467f1cd21714"
                 }
              ],
              "Authors": ["Mateusz Olejarka (@molejarka)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "3,133.7",
              "PublicationDate": "2018-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR FACEBOOK: malicious person add people to the \"Top Fans\"",
                    "Link": "https://www.updatelap.com/2018/07/the-malicious-person-add-people-to-top.html"
                 }
              ],
              "Authors": ["Jafar Abo Nada (@Jafar_Abo_Nada)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unclaimed Medium Publication takeover in WeTransfer",
                    "Link": "https://medium.com/@prial261/unclaimed-medium-publication-takeover-in-wetransfer-c268cdb51e2f"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["WeTransfer"],
              "Bugs": ["Medium publication takeover", "Broken link hijacking"],
              "Bounty": "100",
              "PublicationDate": "2018-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Assistant Bug Worth $3133.7 !",
                    "Link": "https://medium.com/bug-bounty-hunting/google-assistant-bug-worth-3133-7-830a03724a04"
                 }
              ],
              "Authors": ["Circle Ninja (@circleninja)"],
              "Programs": ["Google"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "3,133.7",
              "PublicationDate": "2018-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE due to ShowExceptions",
                    "Link": "https://sites.google.com/view/harshjaiswalblog/rce-due-to-showexceptions"
                 }
              ],
              "Authors": ["Harsh Jaiswal (@rootxharsh)"],
              "Programs": ["-"],
              "Bugs": ["RCE", "Information disclosure", "Debugging enabled"],
              "Bounty": "5,000",
              "PublicationDate": "2018-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Into the Borg – SSRF inside Google production network",
                    "Link": "https://opnsec.com/2018/07/into-the-borg-ssrf-inside-google-production-network/"
                 }
              ],
              "Authors": ["Enguerran Gillier (@opnsec)"],
              "Programs": ["Google"],
              "Bugs": ["SSRF"],
              "Bounty": "13,337",
              "PublicationDate": "2018-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The call is coming from inside the house — DNS rebinding in EOSIO keosd wallet",
                    "Link": "https://medium.com/@root_31068/the-call-is-coming-from-inside-the-house-dns-rebinding-in-eosio-keosd-wallet-e11deae05974"
                 }
              ],
              "Authors": ["François Proulx (@francoisproulx)"],
              "Programs": ["EOSIO"],
              "Bugs": ["DNS rebinding"],
              "Bounty": "-",
              "PublicationDate": "2018-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE on Yahoo Luminate",
                    "Link": "https://sites.google.com/securifyinc.com/secblogs/yahoo-luminate-rce"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to delete 13k+ Microsoft Translator projects",
                    "Link": "https://haiderm.com/how-i-was-able-to-delete-13k-microsoft-translator-projects/"
                 }
              ],
              "Authors": ["Haider Mahmood (@haiderinfosec)"],
              "Programs": ["Microsoft"],
              "Bugs": ["CSRF", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-07-19",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Oracle WebLogic - Multiple SAML Vulnerabilities (CVE-2018-2998/CVE-2018-2933)",
                  "Link": "https://pulsesecurity.co.nz/advisories/WebLogic-SAML-Vulnerabilities"
               }
            ],
            "Authors": ["Denis Andzakovic"],
            "Programs": ["Oracle (WebLogic)"],
            "Bugs": ["SAML", "Authentication bypass"],
            "Bounty": "-",
            "PublicationDate": "2018-07-18",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Hey Developer, Give me your API keys.!!",
                    "Link": "https://medium.com/devanshwolf/hey-developer-give-me-your-api-keys-b8c99ab1c4f5"
                 }
              ],
              "Authors": ["Devansh batham (@devanshwolf)"],
              "Programs": ["Crowdin"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass Admin approval, Mute Member and Posting Permissions for Only admins in Facebook groups",
                    "Link": "https://medium.com/bugbountywriteup/bypass-admin-approval-mute-member-and-posting-permissions-for-only-admins-in-facebook-groups-ef476cb3d524"
                 }
              ],
              "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking thousands of companies through their helpdesk",
                    "Link": "https://medium.com/@khaled.hassan/hacking-thousands-of-companies-through-their-helpdesk-8f180a8595ef"
                 }
              ],
              "Authors": ["Khaled Hassan"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "DoS", "Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-07-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2018-13784: PrestaShop 1.6.x Privilege Escalation",
                    "Link": "https://www.ambionics.io/blog/prestashop-privilege-escalation"
                 }
              ],
              "Authors": ["Charles Fol (@cfreal_)"],
              "Programs": ["PrestaShop"],
              "Bugs": ["Privilege escalation", "Session management issue"],
              "Bounty": "-",
              "PublicationDate": "2018-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WRITE UP – TELEGRAM BUG BOUNTY – WHATSAPP N/A [“Blind” XSS Stored iOS in messengers twins, who really care about your security?]",
                    "Link": "http://omespino.com/write-up-telegram-bug-bounty-whatsapp-n-a-blind-xss-stored-ios-in-messengers-twins-who-really-care-about-your-security/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Attacking PostgreSQL Database",
                    "Link": "https://medium.com/@vishnu0002/attacking-postgresql-database-834a9a3471bc"
                 }
              ],
              "Authors": ["Vishnuraj"],
              "Programs": ["-"],
              "Bugs": ["Bruteforce", "Weak credentials"],
              "Bounty": "-",
              "PublicationDate": "2018-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty at Bangladeshi Site.",
                    "Link": "https://medium.com/@SQLiBasic/bug-bounty-at-bangladeshi-site-21da8b7eb687"
                 }
              ],
              "Authors": ["Shaifullah Shaon"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "120",
              "PublicationDate": "2018-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Should this be public though?",
                    "Link": "https://sites.google.com/securifyinc.com/secblogs/finding-leaked-sensitive-data"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Shopify", "Uber"],
              "Bugs": ["Information disclosure"],
              "Bounty": "500",
              "PublicationDate": "2018-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Microsoft subdomain",
                    "Link": "https://medium.com/@sudhanshur705/xss-in-microsoft-subdomain-81c4e46d6631"
                 }
              ],
              "Authors": ["Sudhanshu Rajbhar (@sudhanshur705)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Gsuite Hangouts Chat 5k IDOR",
                    "Link": "https://secreltyhiddenwriteups.blogspot.com/2018/07/gsuite-hangouts-chat-5k-idor.html"
                 }
              ],
              "Authors": ["Cam (@SecretlyHidden1)"],
              "Programs": ["Google"],
              "Bugs": ["IDOR"],
              "Bounty": "5,000",
              "PublicationDate": "2018-07-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Persistent XSS at AH.nl",
                    "Link": "https://medium.com/@jonathanbouman/persistent-xss-at-ah-nl-198fe7b4c781"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["AH.nl"],
              "Bugs": ["Stored XSS"],
              "Bounty": "200",
              "PublicationDate": "2018-07-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty - Compromising User Account- \"How I was able to compromise user account via HTTP Parameter Pollution(HPP)\"",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-compromising-user-account-how-i-was-able-to-compromise-user-account-via-http-4288068b901f"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["HTTP parameter pollution", "Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Server Side Request Forgery on Vanilla Forums",
                    "Link": "https://www.linkedin.com/feed/update/urn:li:activity:6421357227923337216"
                 }
              ],
              "Authors": ["Vikash Chaudhary (@OffensiveHunter)"],
              "Programs": ["Vanilla Forums"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2018-8819",
                    "Link": "https://hateshape.github.io/general/2018/06/07/CVE-2018-8819.html"
                 }
              ],
              "Authors": ["hateshape (@hateshaped)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2016-3473",
                    "Link": "https://hateshape.github.io/general/2018/07/05/CVE-2016-3473.html"
                 }
              ],
              "Authors": ["hateshape (@hateshaped)"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-07-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Latex to RCE, Private Bug Bounty Program",
                    "Link": "https://medium.com/bugbountywriteup/latex-to-rce-private-bug-bounty-program-6a0b5b33d26a"
                 }
              ],
              "Authors": ["Yashar Shahinzadeh (@YShahinzadeh)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-07-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The $12,000 Intersection between Clickjacking, XSS, and Denial of Service",
                    "Link": "https://samcurry.net/the-12000-intersection-between-clickjacking-xss-and-denial-of-service/"
                 }
              ],
              "Authors": ["Sam Curry (@samwcyo)"],
              "Programs": ["Bustabit"],
              "Bugs": ["Clickjacking", "XSS", "DoS"],
              "Bounty": "12,000",
              "PublicationDate": "2018-07-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining Multiple Vulnerabilities to Gain Admin Access",
                    "Link": "https://www.nahamsec.com/posts/chaining-multiple-vulnerabilities-to-gain-admin-access"
                 }
              ],
              "Authors": ["Ben Sadeghipour (@nahamsec)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-07-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "https://leigh-annegalloway.com/tumblr/",
                    "Link": "https://leigh-annegalloway.com/tumblr/"
                 }
              ],
              "Authors": ["Leigh-Anne Galloway (@L_AGalloway)"],
              "Programs": ["Automattic"],
              "Bugs": ["Captcha bypass", "Username enumeration", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unauthenticated Command Injection Vulnerability in VMware NSX SD-WAN by VeloCloud",
                    "Link": "https://www.cyberonesecurity.com/blog/unauthenticated-command-injection-vulnerability-in-vmware-nsx-sd-wan-by-velocloud"
                 }
              ],
              "Authors": ["Brian Sullivan"],
              "Programs": ["VMware"],
              "Bugs": ["OS command injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This popular Facebook app publicly exposed your data for years",
                    "Link": "https://medium.com/@intideceukelaire/this-popular-facebook-app-publicly-exposed-your-data-for-years-12483418eff8"
                 }
              ],
              "Authors": ["Inti De Ceukelaire (@securinti)"],
              "Programs": ["Meta / Facebook", "Nametests.com"],
              "Bugs": ["Information disclosure", "Broken authorization"],
              "Bounty": "4,000",
              "PublicationDate": "2018-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Take Advantage of Out-of-Scope Domains in Bug Bounty Programs",
                    "Link": "https://ahussam.me/Take-Advantage-of-Out-of-Scope-Domains-in-Bug-Bounty/"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "1,250",
              "PublicationDate": "2018-06-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How re-signing up for an account lead to account takeover",
                    "Link": "https://zseano.medium.com/how-re-signing-up-for-an-account-lead-to-account-takeover-3a63a628fd9f"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://blog.bugbountyhunter.com/account-takeover-bugbounty/"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-06-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover: Starbucks points to Azure",
                    "Link": "https://0xpatrik.com/subdomain-takeover-starbucks/"
                 }
              ],
              "Authors": ["Patrik Hudak (@0xpatrik)"],
              "Programs": ["Starbucks"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "2,000",
              "PublicationDate": "2018-06-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Take over via reset password",
                    "Link": "https://medium.com/@yassergersy/account-take-over-via-reset-password-f2e9d887bce1"
                 }
              ],
              "Authors": ["Yasser Gersy (@yassergersy)"],
              "Programs": ["-"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "1,500",
              "PublicationDate": "2018-06-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got access to local AWS info via Jira",
                    "Link": "https://www.coengoedegebure.com/how-i-got-access-to-local-aws-info-via-jira/"
                 }
              ],
              "Authors": ["Coen Goedegebure (@CoenHimself)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fastest Fix on Open Bug Bounty Platform",
                    "Link": "https://kongwenbin.com/fastest-fix-on-open-bug-bounty-platform"
                 }
              ],
              "Authors": ["Wen Bin KONG (@kongwenbin)"],
              "Programs": ["Kevag Telekom GmbH"],
              "Bugs": ["Reflected XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked Apple.com (Unrestricted File Upload)",
                    "Link": "https://medium.com/@jonathanbouman/how-i-hacked-apple-com-unrestricted-file-upload-bcda047e27e3"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Apple"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2018-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Google Colaboratory + CSP bypass",
                    "Link": "https://blog.bentkowski.info/2018/06/xss-in-google-colaboratory-csp-bypass.html"
                 }
              ],
              "Authors": ["Michał Bentkowski (@SecurityMB)"],
              "Programs": ["Google"],
              "Bugs": ["XSS", "CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-06-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Using a GitHub app to escalate to an organization owner for a $10,000 bounty",
                    "Link": "https://medium.com/@cachemoney/using-a-github-app-to-escalate-to-an-organization-owner-for-a-10-000-bounty-4ec307168631"
                 }
              ],
              "Authors": ["Tanner Emek (@itscachemoney)"],
              "Programs": ["GitHub"],
              "Bugs": ["Broken authorization", "IDOR"],
              "Bounty": "10,000",
              "PublicationDate": "2018-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Setting arbitrary request headers in Chromium via CRLF injection",
                    "Link": "https://blog.bentkowski.info/2018/06/setting-arbitrary-request-headers-in.html"
                 }
              ],
              "Authors": ["Michał Bentkowski (@SecurityMB)"],
              "Programs": ["Google"],
              "Bugs": ["CRLF injection"],
              "Bounty": "-",
              "PublicationDate": "2018-06-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I discovered a browser bug",
                    "Link": "https://jakearchibald.com/2018/i-discovered-a-browser-bug/"
                 }
              ],
              "Authors": ["Jake Archibald (@jaffathecake)"],
              "Programs": ["Mozilla", "Microsoft"],
              "Bugs": ["Browser hacking"],
              "Bounty": "-",
              "PublicationDate": "2018-06-20",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Manage Engine OpManager Multiple Authenticated RCE Vulnerabilities",
                  "Link": "https://pulsesecurity.co.nz/advisories/ManageEngine-OpManager-RCE"
               }
            ],
            "Authors": ["Denis Andzakovic"],
            "Programs": ["Zoho (ManageEngine)"],
            "Bugs": ["RCE", "Path traversal", "Unrestricted file upload", "Information disclosure", "Arbitrary file write"],
            "Bounty": "-",
            "PublicationDate": "2018-06-18",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "[Responsible disclosure] How I could have booked movie tickets through other user accounts",
                    "Link": "https://medium.com/bugbountywriteup/responsible-disclosure-how-i-could-have-booked-movie-tickets-through-other-user-accounts-2db26a037b4c"
                 }
              ],
              "Authors": ["Bharathvaj Ganesan"],
              "Programs": ["AGS Cinemas"],
              "Bugs": ["Password reset", "Account takeover", "Bruteforce", "OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-06-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i found blind XSS in Apple",
                    "Link": "https://web.archive.org/web/20191217223802/https://medium.com/@tahasmily2013m/how-i-found-blind-xss-in-apple-c890775e745a"
                 }
              ],
              "Authors": ["Taha Smily (@tahakhantaha)"],
              "Programs": ["Apple"],
              "Bugs": ["Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-06-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected Client XSS at Amazon.com",
                    "Link": "https://medium.com/@jonathanbouman/reflected-client-xss-amazon-com-7b0d3cec787"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Amazon"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-06-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS in 360totalsecurity",
                    "Link": "https://web.archive.org/web/20191219011308/https://medium.com/@tahasmily2013m/i-have-found-vulnerability-in-360totalsecurity-is-reflected-xss-in-3a6bd602bb5a"
                 }
              ],
              "Authors": ["Taha Smily (@tahakhantaha)"],
              "Programs": ["360totalsecurity"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The 2.5 BTC Stored XSS",
                    "Link": "https://medium.com/@khaled.hassan/the-2-5-btc-stored-xss-f2f9393417f2"
                 }
              ],
              "Authors": ["Khaled Hassan"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got paid premium plan for free on many popular websites",
                    "Link": "https://medium.com/@khaled.hassan/how-i-got-paid-premium-plan-for-free-on-many-popular-websites-90e62a52416a"
                 }
              ],
              "Authors": ["Khaled Hassan"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerability Netflix (cross-site-scripting) XSS",
                    "Link": "https://medium.com/@black_b/vulnerability-netflix-cross-site-scripting-xss-d44010142e2c"
                 }
              ],
              "Authors": ["Bada Diaz (@bada77)"],
              "Programs": ["Netflix"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-06-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unvalidated Open Redirect Bol.com",
                    "Link": "https://medium.com/@jonathanbouman/unvalidated-open-redirect-bol-com-b270151380e6"
                 }
              ],
              "Authors": ["Jonathan Bouman (@JonathanBouman)"],
              "Programs": ["Bol.com"],
              "Bugs": ["Open redirect"],
              "Bounty": "100",
              "PublicationDate": "2018-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full account Takeover via reset password function",
                    "Link": "https://medium.com/@khaled.hassan/full-account-takeover-via-reset-password-function-8b6ef15f346f"
                 }
              ],
              "Authors": ["Khaled Hassan"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover", "Password reset"],
              "Bounty": "1,250",
              "PublicationDate": "2018-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Server-Side Spreadsheet Injection – Formula Injection to Remote Code Execution",
                    "Link": "https://www.bishopfox.com/blog/2018/06/server-side-spreadsheet-injections/"
                 }
              ],
              "Authors": ["Jake Miller"],
              "Programs": ["Google"],
              "Bugs": ["CSV injection", "Server side spreadsheet injection", "Formula injection", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Found CVE-2018-8819: Out-of-Band (OOB) XXE in WebCTRL",
                    "Link": "https://www.coalfire.com/The-Coalfire-Blog/June-2018/How-I-Found-CVE-2018-8819-Out-of-Band-(OOB)-XXE"
                 }
              ],
              "Authors": ["Darrell Damstedt"],
              "Programs": ["-"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2018-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[PayPal BBP] I could’ve deleted All SMC messages. Using Brute-Force technique.",
                    "Link": "https://blog.ayoubaitelmokhtar.com/2018/06/paypal-bbp-i-couldve-deleted-all-smc.html"
                 }
              ],
              "Authors": ["Ayoub Ait Elmokhtar (@aessadek)"],
              "Programs": ["Paypal"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Steam, Fire, and Paste – A Story of UXSS via DOM-XSS & Clickjacking in Steam Inventory Helper",
                    "Link": "https://thehackerblog.com/steam-fire-and-paste-a-story-of-uxss-via-dom-xss-clickjacking-in-steam-inventory-helper/index.html"
                 }
              ],
              "Authors": ["Matthew Bryant (@IAmMandatory)"],
              "Programs": ["-"],
              "Bugs": ["DOM XSS", "Universal XSS", "Clickjacking", "Browser extension hacking"],
              "Bounty": "-",
              "PublicationDate": "2018-06-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to list some internal information from PayPal #BugBounty",
                    "Link": "https://medium.com/@adrien_jeanneau/how-i-was-able-to-list-some-internal-information-from-paypal-bugbounty-ca8d217a397c"
                 }
              ],
              "Authors": ["Adrien Jeanneau (@adrien_jeanneau)"],
              "Programs": ["Paypal"],
              "Bugs": ["Expression Language Injection (JSTL)", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-06-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found XSS via SSRF vulnerability -Adesh Kolte",
                    "Link": "https://web.archive.org/web/20210117211538/https://medium.com/@adeshkolte/how-i-found-xss-via-ssrf-vulnerability-adesh-kolte-873b30a6b89f"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["CERT-EU", "Motorola", "Stanford"],
              "Bugs": ["SSRF", "XSS"],
              "Bounty": "750",
              "PublicationDate": "2018-06-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty —\" Database hacked of India’s Popular Sports company\"-Bypassing Host Header to SQL injection to dumping Database — An unusual case of SQL injection.",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-database-hacked-of-indias-popular-sports-company-bypassing-host-header-to-sql-7b9af997c610"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Zero to Account Takeover: How I ‘Impersonated’ Someone Else Using Auth0",
                    "Link": "https://www.imperva.com/blog/2018/06/how-i-impersonated-someone-else-using-auth0/"
                 }
              ],
              "Authors": ["Daniel Svartman"],
              "Programs": ["Auth0"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Searching for XSS found LDAP injection",
                    "Link": "https://www.nc-lp.com/blog/searching-for-xss-found-ldap-injection"
                 }
              ],
              "Authors": ["Davide Tampellini (@tampe125)"],
              "Programs": ["-"],
              "Bugs": ["LDAP injection"],
              "Bounty": "-",
              "PublicationDate": "2018-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Are you sure this is a trusted email?",
                    "Link": "https://medium.com/@khaled.hassan/are-you-sure-this-is-a-trusted-email-291121028320"
                 }
              ],
              "Authors": ["Khaled Hassan"],
              "Programs": ["-"],
              "Bugs": ["Open mail relay"],
              "Bounty": "900",
              "PublicationDate": "2018-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected)",
                    "Link": "https://thehackerblog.com/reading-your-emails-with-a-readwrite-chrome-extension-same-origin-policy-bypass-8-million-users-affected/index.html"
                 }
              ],
              "Authors": ["Matthew Bryant (@IAmMandatory)"],
              "Programs": ["-"],
              "Bugs": ["SOP bypass", "Browser extension hacking"],
              "Bounty": "-",
              "PublicationDate": "2018-06-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked Fotor & Got “Nothing”",
                    "Link": "https://hk.saowen.com/a/a8d21c0bdf39e733395aefc0e331998e3d618558f90cf06135aa4df411804e59"
                 }
              ],
              "Authors": ["Somdev Sangwan (s0md3v)"],
              "Programs": ["Fotor"],
              "Bugs": ["SSRF", "RFI"],
              "Bounty": "-",
              "PublicationDate": "2018-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Getting PHP Code Execution and leverage access to panels,databases,server",
                    "Link": "http://www.shawarkhan.com/2018/06/getting-php-code-execution-and-leverage.html"
                 }
              ],
              "Authors": ["Shawar Khan (@ShawarkOFFICIAL)"],
              "Programs": ["-"],
              "Bugs": ["Code injection"],
              "Bounty": "-",
              "PublicationDate": "2018-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i converted SSRF to XSS in Jira.",
                    "Link": "https://medium.com/@D0rkerDevil/how-i-convert-ssrf-to-xss-in-a-ssrf-vulnerable-jira-e9f37ad5b158"
                 }
              ],
              "Authors": ["Ashish Kunwar (@D0rkerDevil)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "XSS"],
              "Bounty": "50",
              "PublicationDate": "2018-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Earned $750 Bounty Reward From AT&T bug Bounty -Adesh Kolte",
                    "Link": "https://web.archive.org/web/20200814185643/https://medium.com/@adeshkolte/how-i-earned-750-bounty-reward-from-at-t-bug-bounty-adesh-kolte-ae62dea44083"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["AT&T"],
              "Bugs": ["RCE", "Clickjacking", "XSS", "Same Origin Method Execution"],
              "Bounty": "750",
              "PublicationDate": "2018-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#Bug Bounty — How I booked a rental house for just 1.00 INR — Price Manipulation in Citrus Pay",
                    "Link": "https://medium.com/@raghav2039/bug-bounty-how-i-booked-a-rental-house-for-just-1-00-inr-price-manipulation-in-citrus-pay-318ff6e0d8a8"
                 }
              ],
              "Authors": ["Raghavendra Reddy"],
              "Programs": ["-"],
              "Bugs": ["Parameter tampering"],
              "Bounty": "-",
              "PublicationDate": "2018-05-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS in Yahoo Subdomain ( hk.movies.yahoo.com )",
                    "Link": "https://web.archive.org/web/20200929003129/https://www.mohamedharon.com/2018/05/reflected-xss-in-hk-yahoo.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "5k$ for path traversal on *.paypal-corp.com subdomain",
                    "Link": "https://twitter.com/0x01alka/status/1001763583447969792"
                 }
              ],
              "Authors": ["lalka (@0x01alka)"],
              "Programs": ["Paypal"],
              "Bugs": ["Path traversal"],
              "Bounty": "5,000",
              "PublicationDate": "2018-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover and Blind XSS! Go Pro, get Bugs!",
                    "Link": "https://blog.witcoat.com/2018/05/30/account-takeover-and-blind-xss-go-pro-get-bugs/"
                 }
              ],
              "Authors": ["Tabahi (@_tabahi)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Stored XSS", "Account takeover", "Blind XSS"],
              "Bounty": "3,500",
              "PublicationDate": "2018-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found 5 store XSS on a private program. Each worth \"1,016.66$\"",
                    "Link": "http://cybristerboy.blogspot.com/2018/05/how-i-found-5-store-xss-on-private.html"
                 }
              ],
              "Authors": ["Shahzad Sadiq (@ShahzadSadiq25)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "5,083.3",
              "PublicationDate": "2018-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got hall of fame in two fortune 500 companies — An RCE story…",
                    "Link": "https://medium.com/@emenalf/how-i-got-hall-of-fame-in-two-fortune-500-companies-an-rce-story-9c89cead81ff"
                 }
              ],
              "Authors": ["Alfie (@emenalf)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to get admin panel on a private program",
                    "Link": "http://cybristerboy.blogspot.com/2018/05/how-i-was-able-to-get-admin-panel-on.html"
                 }
              ],
              "Authors": ["Shahzad Sadiq (@ShahzadSadiq25)"],
              "Programs": ["-"],
              "Bugs": ["Weak credentials"],
              "Bounty": "1,500",
              "PublicationDate": "2018-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "reCAPTCHA bypass via HTTP Parameter Pollution",
                    "Link": "https://andresriancho.com/recaptcha-bypass-via-http-parameter-pollution"
                 }
              ],
              "Authors": ["Andres Riancho (@AndresRiancho)"],
              "Programs": ["Google"],
              "Bugs": ["Captcha bypass", "HTTP parameter pollution"],
              "Bounty": "500",
              "PublicationDate": "2018-05-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Persistent XSS to Steal Passwords – Paypal",
                    "Link": "https://wesecureapp.com/blog/persistent-xss-to-steal-passwords-paypal/"
                 }
              ],
              "Authors": ["Akhil Reni (@akhilreni_hs)"],
              "Programs": ["Paypal"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-05-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to see any private album passwrod in Picturepush — IDOR",
                    "Link": "https://medium.com/@r99tiq/idor-how-i-was-able-to-see-any-private-album-passwrod-in-picturepush-264913f45e10"
                 }
              ],
              "Authors": ["Murtada Kamil"],
              "Programs": ["PicturePush"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-05-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — \"How I was able to hack any user account via password reset?\"",
                    "Link": "https://medium.com/@BgxDoc/bugbounty-how-i-was-able-to-hack-any-user-account-via-password-reset-9009d84d94ff"
                 }
              ],
              "Authors": ["Bikash Gupta (@BgxDoc)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2018-05-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE by uploading a web.config",
                    "Link": "https://poc-server.com/blog/2018/05/22/rce-by-uploading-a-web-config"
                 }
              ],
              "Authors": ["003random (@rub003)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AWS Security Flaw which can grant admin access!",
                    "Link": "https://medium.com/ymedialabs-innovation/an-aws-managed-policy-that-allowed-granting-root-admin-access-to-any-role-51b409ea7ff0"
                 }
              ],
              "Authors": ["Sharath AV"],
              "Programs": ["Amazon"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Getting read access on Edmodo Production Server by exploiting SSRF",
                    "Link": "https://www.shawarkhan.com/2018/05/getting-read-access-on-edmodo.html"
                 }
              ],
              "Authors": ["Shawar Khan (@ShawarkOFFICIAL)"],
              "Programs": ["Edmodo"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Self-XSS + CSRF to Stored XSS",
                    "Link": "https://medium.com/@renwa/self-xss-csrf-to-stored-xss-54f9f423a7f1"
                 }
              ],
              "Authors": ["Renwa (@RenwaX23)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "CSRF", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$36k Google App Engine RCE",
                    "Link": "https://web.archive.org/web/20180523180902/https://sites.google.com/site/testsitehacking/-36k-google-app-engine-rce"
                 }
              ],
              "Authors": ["Ezequiel Pereira (@epereiralopez)"],
              "Programs": ["Google"],
              "Bugs": ["RCE"],
              "Bounty": "36,337",
              "PublicationDate": "2018-05-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fastest Fix on Open Bug Bounty Platform",
                    "Link": "https://medium.com/@kongwenbin/fastest-fix-on-open-bug-bounty-platform-4bb03ff846e8"
                 }
              ],
              "Authors": ["Wen Bin KONG (@kongwenbin)"],
              "Programs": ["Kevag Telekom GmbH"],
              "Bugs": ["XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i got 100$ from one private website",
                    "Link": "https://medium.com/@aayushpokhrel/how-i-got-100-from-one-private-website-3c62c27f6b5d"
                 }
              ],
              "Authors": ["Aayush Pokhrel (@aayushpok)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "100",
              "PublicationDate": "2018-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i HACKED admin account via password reset IDOR function of one private currency exchanger site",
                    "Link": "https://medium.com/@aayushpokhrel/how-i-hacked-admin-account-via-password-reset-idor-of-one-private-currency-exchanger-site-51723c7c8704"
                 }
              ],
              "Authors": ["Aayush Pokhrel (@aayushpok)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2018-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in Yahoo and all subdomains!",
                    "Link": "https://medium.com/@ozil.hakim/stored-xss-in-yahoo-and-all-subdomains-bbcaa7c3b8d"
                 }
              ],
              "Authors": ["Hakim Bencella (@H4kst3r)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,500",
              "PublicationDate": "2018-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Xss in Microsoft",
                    "Link": "https://medium.com/@hacker_eth/xss-in-microsoft-7a70416aee75"
                 }
              ],
              "Authors": ["hacker_eth"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to get subscription of $120/year For Free",
                    "Link": "https://blog.securitybreached.org/2018/05/18/get-subscription-of-120-year-for-free-bug-bounty-poc"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["WeTransfer"],
              "Bugs": ["Payment bypass"],
              "Bounty": "500",
              "PublicationDate": "2018-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Whatsapp- DOS vulnerability on Android/iOS/Web",
                    "Link": "https://medium.com/@pratheesh.p.narayanan/whatsapp-dos-vulnerability-on-android-ios-web-7628077d21d4"
                 }
              ],
              "Authors": ["Pratheesh P Narayanan (@PRATHEESH_PPN)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS"],
              "Bounty": "500",
              "PublicationDate": "2018-05-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "HSTS Bypass Vulnerability in IE Preview",
                    "Link": "https://medium.com/bugbountywriteup/hsts-bypass-vulnerability-in-ie-preview-fa956161fa8"
                 }
              ],
              "Authors": ["Xiaoyin Liu (@general_nfs)"],
              "Programs": ["Microsoft"],
              "Bugs": ["HSTS bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-05-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I used a simple Google query to mine passwords from dozens of public Trello boards",
                    "Link": "https://medium.freecodecamp.org/discovering-the-hidden-mine-of-credentials-and-sensitive-information-8e5ccfef2724"
                 }
              ],
              "Authors": ["Kushagra Pathak (@xKushagra)"],
              "Programs": ["Trello"],
              "Bugs": ["Broken authorization", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-05-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Internet Safety for Kids & Families — Trend Micro Bypass DOM XSS",
                    "Link": "https://medium.com/@honcbb/internet-safety-for-kids-families-trend-micro-dom-xss-db34c9bbb120"
                 }
              ],
              "Authors": ["Honc (@honcbb)"],
              "Programs": ["Trend Micro"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Asus Control Center – An Information Disclosure and a database connection Clear-Text password leakage Vulnerability",
                    "Link": "https://www.seekurity.com/blog/general/asus-control-center-an-information-disclosure-and-a-database-connection-clear-text-password-leakage-vulnerability/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Asus"],
              "Bugs": ["Broken authorization", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Five Minute SQL-I",
                    "Link": "https://web.archive.org/web/20200904133318/https://medium.com/bugbountywriteup/a-five-minute-sql-i-16ab75b20fe4"
                 }
              ],
              "Authors": ["Ashish Jha"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-05-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Got Paid $0 From the India’s largest online gifting portal — Bug Bounty Program",
                    "Link": "https://medium.com/bugbountywriteup/how-i-got-paid-0-from-the-indias-largest-online-gifting-portal-bug-bounty-program-fd9e14f9ca20"
                 }
              ],
              "Authors": ["Hariom Vashisth"],
              "Programs": ["-"],
              "Bugs": ["Payment tampering", "Parameter tampering"],
              "Bounty": "-",
              "PublicationDate": "2018-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$4500 bounty - How I got lucky",
                    "Link": "https://medium.com/bugbountywriteup/4500-bounty-how-i-got-lucky-99d8bc933f75"
                 }
              ],
              "Authors": ["Eray Mitrani (@ErayMitrani)"],
              "Programs": ["-"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "4,500",
              "PublicationDate": "2018-05-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disclose Private Video Thumbnail from Facebook WorkPlace",
                    "Link": "https://medium.com/bugbountywriteup/disclose-private-video-thumbnail-from-facebook-workplace-52b6ec4d73b7"
                 }
              ],
              "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "3,000",
              "PublicationDate": "2018-05-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing money from one account to another account",
                    "Link": "https://medium.com/@evilboyajay/stealing-money-from-one-account-to-another-account-d7c5ee68922b"
                 }
              ],
              "Authors": ["Ajay Gautam (@evilboyajay)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-05-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story Of a Stored XSS Bypass",
                    "Link": "https://medium.com/@prial261/story-of-a-stored-xss-bypass-26e6659f807b"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["Zerocopter"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2018-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple security vulnerabilities in domains belonging to Google",
                    "Link": "https://sysdream.com/news/lab/2018-04-30-multiple-security-vulnerabilities-in-domains-belonging-to-google/"
                 }
              ],
              "Authors": ["Sysdreams"],
              "Programs": ["Google"],
              "Bugs": ["Broken Access Control", "Path traversal", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found 2.9 RCE at Yahoo! Bug Bounty program",
                    "Link": "https://medium.com/@kedrisec/how-i-found-2-9-rce-at-yahoo-bug-bounty-program-20ab50dbfac7"
                 }
              ],
              "Authors": ["Kedrisec (@kedrisec)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-04-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — How I was able to bypass firewall to get RCE and then went from server shell to get root user account!",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-how-i-was-able-to-bypass-firewall-to-get-rce-and-then-went-from-server-shell-to-get-783f71131b94"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-04-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS on Stack Overflow",
                    "Link": "https://medium.com/@newp_th/reflected-xss-on-stack-overflow-b8366a855472"
                 }
              ],
              "Authors": ["ssid (@newp_th)"],
              "Programs": ["Stack Overflow"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing the Confirmation Email for Newsletter (bof.nl)",
                    "Link": "https://medium.com/@mdisrail2468/bypassing-the-confirmation-email-for-newsletter-bof-nl-682c05cb927f"
                 }
              ],
              "Authors": ["Mohammed Israil (@mdisrail2468)"],
              "Programs": ["Bits of Freedom"],
              "Bugs": ["Broken authorization", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-04-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I earned 60K+ from private program",
                    "Link": "https://medium.com/@sivakrishnasamireddi/how-i-earned-60k-from-private-program-71bd51554490"
                 }
              ],
              "Authors": ["Siva Krishna Samireddi (@le4rner)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect", "Subdomain takeover", "XSS", "HTTP parameter pollution"],
              "Bounty": "880",
              "PublicationDate": "2018-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Unknown Hero-App Logic Bugs",
                    "Link": "https://medium.com/bug-bounty-hunting/application-logic-bugs-600245fb5bf0"
                 }
              ],
              "Authors": ["Circle Ninja (@circleninja)"],
              "Programs": ["Canva"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS “403 forbidden” bypass write up",
                    "Link": "https://medium.com/@nuraalamdipu/xss-403-forbidden-bypass-write-up-e070de52bc06"
                 }
              ],
              "Authors": ["Nur A Alam Dipu (@Dipu1A)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-04-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How we got LFI in apache Drill (Recon like a boss)",
                    "Link": "https://medium.com/bugbountywriteup/how-we-got-lfi-in-apache-drill-recon-like-a-boss-6f739a79d87d"
                 }
              ],
              "Authors": ["gujjuboy10x00 (@vis_hacker)"],
              "Programs": ["-"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2018-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM XSS in Google VRView library",
                    "Link": "http://blog.mindedsecurity.com/2018/04/dom-based-cross-site-scripting-in.html"
                 }
              ],
              "Authors": ["Federico Fazzi (@federicofazzi)"],
              "Programs": ["Google"],
              "Bugs": ["DOM XSS"],
              "Bounty": "3,133.7",
              "PublicationDate": "2018-04-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Three Cases, Three Open Redirect Bypasses",
                    "Link": "https://medium.com/@malcolmx0x/three-cases-three-open-redirect-bypasses-887bda60b38c"
                 }
              ],
              "Authors": ["Mmohammed Eldeeb (@malcolmx0x)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2018-04-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Turning Self-XSS into non-Self Stored-XSS via Authorization Issue at “PayPal Tech-Support and Brand Central Portal",
                    "Link": "https://medium.com/@YoKoKho/turning-self-xss-into-non-self-stored-xss-via-authorization-issue-at-paypal-tech-support-and-brand-3046f52ac16b"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["Paypal"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story Of a Stored XSS Bypass",
                    "Link": "https://medium.com/@prial261/story-of-a-stored-xss-bypass-26e6659f807b"
                 }
              ],
              "Authors": ["Prial Islam Khan (@prial261)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-04-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — \"Journey from LFI to RCE!!!\"-How I was able to get the same in one of the India’s popular property buy/sell company.",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-journey-from-lfi-to-rce-how-a69afe5a0899"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["LFI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-04-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing the Current Password Protection at PayPal TechSupport Portal",
                    "Link": "https://medium.com/@YoKoKho/bypassing-the-current-password-protection-at-techsupport-portal-b9005ee17e64"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["Paypal"],
              "Bugs": ["Broken authorization", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-04-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Bug: Posting on groups as any user’s behalf",
                    "Link": "https://medium.com/@newp_th/google-bug-posting-on-groups-as-any-users-behalf-c24e7f524be5"
                 }
              ],
              "Authors": ["ssid (@newp_th)"],
              "Programs": ["Google"],
              "Bugs": ["Email spoofing"],
              "Bounty": "-",
              "PublicationDate": "2018-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Whatsapp user’s IP disclosure with Link Preview feature",
                    "Link": "https://medium.com/@kankrale.rahul/whatsapp-users-ip-disclosure-with-link-preview-feature-39a477f54fba"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Ribose — IDOR with Simple CSRF Bypass — Unrestricted Changes and Deletion to other Photo Profile",
                    "Link": "https://medium.com/@YoKoKho/ribose-idor-with-simple-csrf-bypass-unrestricted-changes-and-deletion-to-other-photo-profile-e4393305274e"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["Ribose"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Get the Name of the Hotel (and other Data) that you ever Stay - Personal Data Leaks: Private Bug Bounty Program",
                    "Link": "https://medium.com/@YoKoKho/idor-at-private-bug-bounty-program-that-could-leads-to-personal-data-leaks-d2536d026bf5"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR (at Private Bug Bounty Program) that could Leads to Personal Data Leaks",
                    "Link": "http://firstsight.me/2018/04/idor-at-private-bug-bounty-program-that-could-leads-to-personal-data-leaks/"
                 }
              ],
              "Authors": ["YoKo Kho (@YokoAcc)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got stored XSS using file upload",
                    "Link": "https://medium.com/@vis_hacker/how-i-got-stored-xss-using-file-upload-5c33e19df51e"
                 }
              ],
              "Authors": ["gujjuboy10x00 (@vis_hacker)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From an error message to DB disclosure",
                    "Link": "https://medium.com/@YumiSec/from-an-error-message-to-db-diclosure-1af879c74474"
                 }
              ],
              "Authors": ["Yumi"],
              "Programs": ["-"],
              "Bugs": ["Hardcoded credentials"],
              "Bounty": "-",
              "PublicationDate": "2018-04-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Spoof an user to create a description of a group in Flickr",
                    "Link": "https://medium.com/@saamux/spoof-a-user-to-create-a-description-of-a-group-in-flickr-72b6b8432404"
                 }
              ],
              "Authors": ["Samuel (@saamux)"],
              "Programs": ["Flickr"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-04-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Captcha Like a Boss",
                    "Link": "https://medium.com/bugbountywriteup/bypassing-captcha-like-a-boss-d0edcc3a1c1"
                 }
              ],
              "Authors": ["Ak1T4 (@akita_zen)"],
              "Programs": ["-"],
              "Bugs": ["Captcha bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-04-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$5k Service dependencies",
                    "Link": "https://web.archive.org/web/20180706194218/https://sites.google.com/site/testsitehacking/-5k-service-dependencies"
                 }
              ],
              "Authors": ["Ezequiel Pereira (@epereiralopez)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "5,000",
              "PublicationDate": "2018-04-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#SecurityBreach — \"How I was able to book hotel room for 1.50₹!\"",
                    "Link": "https://medium.com/bugbountywriteup/securitybreach-how-i-was-able-to-book-hotel-room-for-1-50-9b35f18e49e8"
                 }
              ],
              "Authors": ["Hariom Vashisth"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2018-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass CSP by Abusing XSS Filter in Edge",
                    "Link": "https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754"
                 }
              ],
              "Authors": ["Xiaoyin Liu (@general_nfs)"],
              "Programs": ["Microsoft"],
              "Bugs": ["CSP bypass"],
              "Bounty": "1,500",
              "PublicationDate": "2018-04-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked companies related to the crypto currency and earned $60,000",
                    "Link": "https://medium.com/@iSecMax/how-i-hacked-companies-related-to-the-crypto-currency-and-earned-60-000-93e9b3299f4e"
                 }
              ],
              "Authors": ["Max (@0xw2w)"],
              "Programs": ["okex.com", "livecoin.net"],
              "Bugs": ["Broken authorization", "CSRF", "IDOR", "Stored XSS", "HTML injection"],
              "Bounty": "59,400",
              "PublicationDate": "2018-04-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I bypassed Ebay process on redirect",
                    "Link": "https://medium.com/@flex0geek/how-i-bypassed-ebay-process-on-redirect-98739384b4bc"
                 }
              ],
              "Authors": ["Mohamed Sayed (@FlEx0Geek)"],
              "Programs": ["Ebay"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2018-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hijacking User’s Private Information access_token from Microsoft Office360 facebook App",
                    "Link": "https://www.seekurity.com/blog/general/hijacking-users-private-information-access_token-from-microsoft-office360-facebook-app"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Microsoft"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Please email me your password",
                    "Link": "https://web.archive.org/web/20191217083137/http://blog.jr0ch17.com/2018/Please-email-me-your-password/"
                 }
              ],
              "Authors": ["Jasmin Laundry (@JR0ch17)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS", "Blind SQL injection", "SMTP injection", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-04-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I broke into Google Issue Tracker",
                    "Link": "https://medium.com/bugbountywriteup/how-i-broke-into-google-issue-tracker-667b9e33e931"
                 }
              ],
              "Authors": ["Abhishek Bundela (@abhibundela)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-04-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Source Code Analysis in YSurvey — Luminate bug",
                    "Link": "https://medium.com/@rojanrijal/source-code-analysis-in-ysurvey-luminate-bug-c86dc29b70c4"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Authentication bypass", "Broken authorization", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-04-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Piercing the veil: Server Side Request Forgery to NIPRNet access",
                    "Link": "https://medium.com/bugbountywriteup/piercing-the-veil-server-side-request-forgery-to-niprnet-access-c358fd5e249a"
                 }
              ],
              "Authors": ["Alyssa Herrera (@Alyssa_Herrera_)"],
              "Programs": ["U.S. Dept Of Defense"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-04-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing HttpOnly Cookie via XSS",
                    "Link": "https://medium.com/@yassergersy/xss-to-session-hijack-6039e11e6a81"
                 }
              ],
              "Authors": ["Yasser Gersy (@yassergersy)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-04-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS on www.zomato.com By Mustafa Hasan",
                    "Link": "https://web.archive.org/web/20200929003337/https://www.mohamedharon.com/2018/04/reflected-xss-on-wwwzomatocom-by.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Zomato"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "100",
              "PublicationDate": "2018-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "“Exploiting a Single Parameter”",
                    "Link": "https://medium.com/@hisham.mir/exploiting-a-single-parameter-6f4ba2acf523"
                 }
              ],
              "Authors": ["Hisham Mir (@Hishammir1)"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "XSS"],
              "Bounty": "2,500",
              "PublicationDate": "2018-04-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Link injection on 2 Twitter Subdomain",
                    "Link": "https://web.archive.org/web/20201123204445/https://www.mohamedharon.com/2018/04/link-injection-on-2-twitter-subdomain.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Twitter"],
              "Bugs": ["Hyperlink injection"],
              "Bounty": "280",
              "PublicationDate": "2018-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — ” Your details are saved into my account”-User info disclosure Vulnerability in Practo (India’s biggest healthcare app)",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-your-details-are-saved-into-my-account-user-info-disclosure-vulnerability-in-practo-fe36930a1246"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-04-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I caught Multiple vulnerabilities in Udemy.com, But not rewarded for serious XSS vulnerability :(",
                    "Link": "https://medium.com/@satboy.fb/how-i-caught-multiple-vulnerabilities-in-udemy-com-14012a8a1421"
                 }
              ],
              "Authors": ["Satyendra Shrivastava"],
              "Programs": ["Udemy"],
              "Bugs": ["XSS", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2018-04-05",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Beyond XSS: Edge Side Include Injection",
                  "Link": "https://www.gosecure.net/blog/2018/04/03/beyond-xss-edge-side-include-injection/"
               }
            ],
            "Authors": ["Louis Dion-Marcil (@ldionmarcil)"],
            "Programs": ["Squid", "Varnish"],
            "Bugs": ["ESI injection", "SSRF", "XSS"],
            "Bounty": "-",
            "PublicationDate": "2018-04-03",
            "AddedDate": "2023-03-08"
         },
           {
              "Links": [
                 {
                    "Title": "Facebook BugBounty: Intercept incoming friend requests of Victim add/accept to your facebook account",
                    "Link": "https://whitehatfamilyguy.blogspot.com/2019/04/hijacking-friend-requests-facebook.html"
                 }
              ],
              "Authors": ["Family guy"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-04-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Best Small Report Bounty Report in Private Program ( Django REST framework Admin Login ByPass )",
                    "Link": "https://web.archive.org/web/20201022201335/https://www.mohamedharon.com/2018/04/my-best-small-report-bounty-report-in.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "Authentication bypass", "Account takeover"],
              "Bounty": "2,000",
              "PublicationDate": "2018-04-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS in Yahoo Subdomain",
                    "Link": "https://web.archive.org/web/20200929004520/https://www.mohamedharon.com/2018/03/xss-in-subdomain-httpsyefgrantsyahoocom.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Flash XSS"],
              "Bounty": "600",
              "PublicationDate": "2018-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS In sports.tw.campaign.yahoo.net",
                    "Link": "https://web.archive.org/web/20200928235353/https://www.mohamedharon.com/2018/03/xss-in-sportstwcampaignyahoonet.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked one cryptocurrency service",
                    "Link": "https://medium.com/@valeriyshevchenko/how-i-hacked-one-cryptocurrency-service-db3cb0f81d6c"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["PayKassa"],
              "Bugs": ["Blind XSS", "Reflected XSS", "CSRF"],
              "Bounty": "300",
              "PublicationDate": "2018-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Could Have Promoted Any Facebook Page For Free.",
                    "Link": "https://medium.com/bugbountywriteup/how-i-could-have-promoted-any-facebook-page-for-free-70b0f4fc0feb"
                 }
              ],
              "Authors": ["Anees Khan (@AneesEthical)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-03-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Creating Test Conversion using any App",
                    "Link": "https://medium.com/bugbountywriteup/creating-test-conversion-using-any-app-8b32ee0a735"
                 }
              ],
              "Authors": ["Joshua Regio"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Parameter tampering"],
              "Bounty": "3,000",
              "PublicationDate": "2018-03-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google bug bounty for security exploit that influences search results",
                    "Link": "http://www.tomanthony.co.uk/blog/google-xml-sitemap-auth-bypass-black-hat-seo-bug-bounty/"
                 }
              ],
              "Authors": ["Tom Anthony (@TomAnthonySEO)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "5,000",
              "PublicationDate": "2018-03-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS Moogaloop SWF ( Version < 6.2.x )",
                    "Link": "https://web.archive.org/web/20200929015014/https://www.mohamedharon.com/2018/03/reflected-xss-moogaloop-swf-version-62x.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Vimeo"],
              "Bugs": ["Flash XSS", "Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-03-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Misconfiguration of Demographics Privacy in a Page",
                    "Link": "https://medium.com/@markchristiandeduyo/misconfiguration-of-demographics-privacy-in-a-page-682feb1179f2"
                 }
              ],
              "Authors": ["Mark Christian Deduyo"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "750",
              "PublicationDate": "2018-03-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — Rewarded by securing vulnerabilities in Bookmyshow (India’s largest online movie & event booking portal)",
                    "Link": "https://medium.com/@logicbomb_1/bugbounty-rewarded-by-securing-vulnerabilities-in-bookmyshow-indias-largest-online-movie-bb81dba9b82"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["BookMyShow"],
              "Bugs": ["Host header injection", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Oracle in 5 Minutes",
                    "Link": "https://medium.com/bugbountywriteup/hacking-oracle-in-5-minutes-b52107a6124c"
                 }
              ],
              "Authors": ["Rahul R"],
              "Programs": ["Oracle"],
              "Bugs": ["Directory listing"],
              "Bounty": "-",
              "PublicationDate": "2018-03-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google adwords 3133.7$ Stored XSS",
                    "Link": "https://medium.com/@Alra3ees/google-adwords-3133-7-stored-xss-27bb083b8d27"
                 }
              ],
              "Authors": ["Emad Shanab (@Alra3ees)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS"],
              "Bounty": "3,133.7",
              "PublicationDate": "2018-03-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaking WordPress CSRF Tokens for Fun, $1337 bounty, and CVE-2017-5489",
                    "Link": "https://ahussam.me/Leaking-WordPress-CSRF-Tokens/"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["WordPress"],
              "Bugs": ["CSRF"],
              "Bounty": "1,337",
              "PublicationDate": "2018-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2017-13253: Buffer overflow in multiple Android DRM services",
                    "Link": "https://blog.zimperium.com/cve-2017-13253-buffer-overflow-multiple-android-drm-services/"
                 }
              ],
              "Authors": ["Tamir Zahavi-Brunner (@tamir_zb)"],
              "Programs": ["Google"],
              "Bugs": ["Memory corruption", "Local Privilege Escalation"],
              "Bounty": "-",
              "PublicationDate": "2018-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GraphQL abuse: Bypass account level permissions through parameter smuggling",
                    "Link": "https://labs.detectify.com/2018/03/14/graphql-abuse/"
                 }
              ],
              "Authors": ["Jon Bottarini (@jon_bottarini)"],
              "Programs": ["New Relic"],
              "Bugs": ["GraphQL", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2018-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — “Let me reset your password and login into your account “-How I was able to Compromise any User Account via Reset Password Functionality",
                    "Link": "https://medium.com/bugbountywriteup/bugbounty-how-i-was-able-to-compromise-any-user-account-via-reset-password-functionality-a11bb5f863b3"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw", "Password reset", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-03-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Union Based Sql injection Write up ->A private Company Site",
                    "Link": "https://medium.com/@nuraalamdipu/union-based-sql-injection-write-up-a-private-company-site-273f89a49ed9"
                 }
              ],
              "Authors": ["Nur A Alam Dipu (@Dipu1A)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2018-03-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked 74k users of a website.",
                    "Link": "https://medium.com/@agrawalsmart7/how-i-hacked-74k-users-of-a-website-869e8a0b319"
                 }
              ],
              "Authors": ["Utkarsh Agrawal (@agrawalsmart7)"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2018-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Getting any Facebook user's friend list and partial payment card details",
                    "Link": "https://www.josipfranjkovic.com/blog/facebook-friendlist-paymentcard-leak"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS, and SSRF in Google using the Dataset Publishing Language",
                    "Link": "https://s1gnalcha0s.github.io/dspl/2018/03/07/Stored-XSS-and-SSRF-Google.html"
                 }
              ],
              "Authors": ["Craig Arendt (@signalchaos)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS", "SSRF"],
              "Bounty": "18,337",
              "PublicationDate": "2018-03-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Clickjackings in Google worth 12644.7$",
                    "Link": "https://medium.com/@raushanraj_65039/google-clickjacking-6a04132b918a"
                 }
              ],
              "Authors": ["Raushan Raj (@raushan_rajj)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "12,644.7",
              "PublicationDate": "2018-03-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Bug Bounty Reports",
                    "Link": "https://medium.com/@raushanraj_65039/facebook-bug-bounty-reports-1c1b8b55c050"
                 }
              ],
              "Authors": ["Raushan Raj (@raushan_rajj)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw", "Information disclosure"],
              "Bounty": "6,000",
              "PublicationDate": "2018-03-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — How I could book cab using your wallet money in India’s largest auto transportation company!",
                    "Link": "https://medium.com/bugbountywriteup/bugbounty-how-i-could-book-cab-using-your-wallet-money-in-indias-largest-auto-transportation-e0c4252ca1a3"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-03-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found A Surprising XSS Vulnerability on Oracle NetSuite ?",
                    "Link": "https://medium.com/bug-bounty-hunting/how-i-found-a-surprising-xss-vulnerability-on-oracle-netsuite-2d48b7fcf0c8"
                 }
              ],
              "Authors": ["Circle Ninja (@circleninja)"],
              "Programs": ["Oracle"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-03-02",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Duo Finds SAML Vulnerabilities Affecting Multiple Implementations",
                  "Link": "https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations"
               }
            ],
            "Authors": ["Kelby Ludwig (@kelbyludwig)"],
            "Programs": ["Duo", "OneLogin", "CERT/CC"],
            "Bugs": ["SAML", "SSO"],
            "Bounty": "-",
            "PublicationDate": "2018-02-27",
            "AddedDate": "2024-02-01"
         },
           {
              "Links": [
                 {
                    "Title": "The 2.5mins or 2.5k$ hawk-eye bug – A Facebook Pages Admins Disclosure Vulnerability!",
                    "Link": "https://www.seekurity.com/blog/general/the-2-5mins-or-2-5k-hawk-eye-bug-a-facebook-pages-admins-disclosure-vulnerability/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "2,500",
              "PublicationDate": "2018-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Re-dressing Instagram – Leaking Application Tokens via Instagram ClickJacking Vulnerability!",
                    "Link": "https://www.seekurity.com/blog/general/redressing-instagram-leaking-application-tokens-via-instagram-clickjacking-vulnerability/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2018-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i Hacked into a bugcrowd. public program",
                    "Link": "https://infosecwriteups.com/how-i-hacked-into-a-bugcrowd-public-program-fcfdd4fb1b69"
                 }
              ],
              "Authors": ["Vishnuraj"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — API keys leakage, Source code disclosure in India’s largest e-commerce health care company.",
                    "Link": "https://medium.com/bugbountywriteup/bugbounty-api-keys-leakage-source-code-disclosure-in-indias-largest-e-commerce-health-care-c75967392c7e"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2018-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to delete any image in Facebook community question forum",
                    "Link": "https://medium.com/@JubaBaghdad/how-i-was-able-to-delete-any-image-in-facebook-community-question-forum-a03ea516e327"
                 }
              ],
              "Authors": ["Sarmad Hassan (@JubaBaghdad)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "1,500",
              "PublicationDate": "2018-02-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Google’s authentication to access their Internal Admin panels",
                    "Link": "https://medium.com/bugbountywriteup/bypassing-googles-fix-to-access-their-internal-admin-panels-12acd3d821e3"
                 }
              ],
              "Authors": ["Vishnu Prasad P G (@vishnuprasadnta)"],
              "Programs": ["Google"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "13,337",
              "PublicationDate": "2018-02-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Fuzz…The Bug..The Action – A Race Condition bug in Facebook Chat Groups leads to spy on conversations!",
                    "Link": "https://www.seekurity.com/blog/general/the-fuzz-the-bug-the-action-a-race-condition-bug-in-facebook-chat-groups-leads-to-spy-on-conversations"
                 }
              ],
              "Authors": ["Seif Elsallamy (@seifelsallamy)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Race condition"],
              "Bounty": "-",
              "PublicationDate": "2018-02-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Modifying any Ad Space and Placement",
                    "Link": "https://medium.com/@joshuaregio/modifying-any-ad-space-and-placement-e22c7cec050f"
                 }
              ],
              "Authors": ["Joshua Regio"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-02-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "POODLE SSLv3 bug on multiple twitter smtp servers",
                    "Link": "http://omespino.com/write-up-twitter-bug-bounty-my-1st-bugbounty-poodle-sslv3-bug-on-multiple-twitter-smtp-servers/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Twitter"],
              "Bugs": ["Cryptographic issues"],
              "Bounty": "280",
              "PublicationDate": "2018-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[RCE] Remote Code Execution in Wordpress iOS Application (version 9.3)",
                    "Link": "https://blog.evanricafort.com/2018/02/rce-remote-code-execution-in-wordpress.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["WordPress"],
              "Bugs": ["RCE", "iOS"],
              "Bounty": "-",
              "PublicationDate": "2018-02-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked Tinder accounts using Facebook’s Account Kit and earned $6,250 in bounties",
                    "Link": "https://medium.freecodecamp.org/hacking-tinder-accounts-using-facebook-accountkit-d5cc813340d1"
                 },
                 {
                  "Title": "Alternative link",
                  "Link": "https://www.pingsafe.com/blog/how-tinder-accounts-could-be-hacked-using-facebook-account-kit"
               }
               ],
              "Authors": ["Anand Prakash (@anandpraka_sh)"],
              "Programs": ["Tinder", "Meta / Facebook"],
              "Bugs": ["Account takeover", "Broken authorization"],
              "Bounty": "6,250",
              "PublicationDate": "2018-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google bugs stories and the shiny pixelbook.",
                    "Link": "https://bughunt1307.herokuapp.com/googlebugs.html"
                 }
              ],
              "Authors": ["Missoum Said (@missoum1307)"],
              "Programs": ["Google"],
              "Bugs": ["DOM XSS", "Stored XSS", "Logic flaw", "Reflected XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-02-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting CORS Miss configuration using XSS",
                    "Link": "https://bugbaba.blogspot.com/2018/02/exploiting-cors-miss-configuration.html"
                 }
              ],
              "Authors": ["Noman Shaikh (@nomanali181)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2018-02-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — Exploiting CRLF Injection can lands into a nice bounty",
                    "Link": "https://medium.com/bugbountywriteup/bugbounty-exploiting-crlf-injection-can-lands-into-a-nice-bounty-159525a9cb62"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["CRLF injection"],
              "Bounty": "250",
              "PublicationDate": "2018-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to remotely crash any android user’s instagram app and was paid a mere 500$ for it.",
                    "Link": "https://medium.com/bugbountywriteup/how-i-was-able-to-remotely-crash-any-android-users-instagram-app-and-was-paid-a-mere-500-for-it-d4420721290e"
                 }
              ],
              "Authors": ["Waleed Ahmed"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Android", "DoS"],
              "Bounty": "500",
              "PublicationDate": "2018-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$7.5k Google services mix-up",
                    "Link": "https://web.archive.org/web/20200420235005/https://sites.google.com/site/testsitehacking/-7-5k-Google-services-mix-up"
                 }
              ],
              "Authors": ["Ezequiel Pereira (@epereiralopez)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "7,500",
              "PublicationDate": "2018-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An analysis of logic flaws in web-of-trust services",
                    "Link": "https://edoverflow.com/2018/logic-flaws-in-wot-services"
                 }
              ],
              "Authors": ["EdOverflow (@EdOverflow)"],
              "Programs": ["Keybase"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2018-02-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — “How I was able to shop for free!”- Payment Price Manipulation",
                    "Link": "https://medium.com/bugbountywriteup/bugbounty-how-i-was-able-to-shop-for-free-payment-price-manipulation-b29355a8e68e"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["Parameter tampering", "Payment tampering"],
              "Bounty": "-",
              "PublicationDate": "2018-02-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Oracle Cross Site Scripting Vulnerability -Adesh Kolte",
                    "Link": "https://web.archive.org/web/20200818084242/https://medium.com/@adeshkolte/oracle-cross-site-scripting-vulnerability-adesh-kolte-ddc5d9f279be"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["Oracle"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-02-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on Snapchat",
                    "Link": "https://medium.com/@mrityunjoy/stored-xss-on-snapchat-5d704131d8fd"
                 }
              ],
              "Authors": ["Mrityunjoy (@mitunjoy11)"],
              "Programs": ["Snapchat"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-02-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I figured out a way to hack any of Facebook’s 2 billion accounts, and they paid me a $15,000 bounty for it",
                    "Link": "https://medium.freecodecamp.org/responsible-disclosure-how-i-could-have-hacked-all-facebook-accounts-f47c0252ae4d"
                 }
              ],
              "Authors": ["Anand Prakash (@anandpraka_sh)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Bruteforce", "Account takeover"],
              "Bounty": "15,000",
              "PublicationDate": "2018-02-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Taking over Facebook accounts using Free Basics partner portal",
                    "Link": "https://www.josipfranjkovic.com/blog/facebook-partners-portal-account-takeover"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-02-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug bounty left over (and rant) Part III (Google and Twitter)",
                    "Link": "https://blog.intothesymmetry.com/2018/02/bug-bounty-left-over-and-rant-part-iii.html"
                 }
              ],
              "Authors": ["Antonio Sanso (@asanso)"],
              "Programs": ["Google", "Twitter"],
              "Bugs": ["OAuth", "Broken authentication", "Information disclosure"],
              "Bounty": "5,540",
              "PublicationDate": "2018-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I gained access to Sony’s database",
                    "Link": "https://medium.com/bugbountywriteup/how-i-gained-access-to-sonys-database-f3ba08d0e035"
                 }
              ],
              "Authors": ["Rahul R"],
              "Programs": ["Sony"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2018-02-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL injection with load file and into outfile",
                    "Link": "https://medium.com/bugbountywriteup/sql-injection-with-load-file-and-into-outfile-c62f7d92c4e2"
                 }
              ],
              "Authors": ["NoGe (@p4c3n0g3)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "750",
              "PublicationDate": "2018-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found IDOR on Twitter’s Acquisition – Mopub.com",
                    "Link": "https://blog.securitybreached.org/2018/02/05/how-i-found-idor-on-twitters-acquisition-mopub-com/"
                 }
              ],
              "Authors": ["Jay Jani (@JayJani007)"],
              "Programs": ["Twitter"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook mailto injection leads to social engineering & spam attack",
                    "Link": "https://medium.com/@kankrale.rahul/facebook-mailto-injection-leads-to-social-engineering-spam-attack-68b08e36764a"
                 }
              ],
              "Authors": ["Rahul Kankrale (@RahulKankrale)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Mailto injection"],
              "Bounty": "-",
              "PublicationDate": "2018-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — \"I don't need your current password to login into your account\" - How could I completely takeover any user's account in an online classified ads company.",
                    "Link": "https://medium.com/bugbountywriteup/bugbounty-i-dont-need-your-current-password-to-login-into-your-account-how-could-i-e51a945b083d"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2018-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1)",
                    "Link": "https://codeburst.io/hunting-insecure-direct-object-reference-vulnerabilities-for-fun-and-profit-part-1-f338c6a52782"
                 },
                 {
                    "Title": "PART 2",
                    "Link": "https://codeburst.io/hunting-insecure-direct-object-reference-vulnerabilities-for-fun-and-profit-part-2-af832d1c0bb6"
                 }
              ],
              "Authors": ["Mohammed Abdul Raheem (@mohdaltaf163)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "3,000",
              "PublicationDate": "2018-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Internal IPs disclosure",
                    "Link": "http://omespino.com/nokia-internal-ips-disclosure"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Nokia"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2018-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to Bypass XSS Protection on HackerOne’s Private Program",
                    "Link": "https://blog.securitybreached.org/2018/02/02/how-i-was-able-to-bypass-xss-protection-on-hackerones-private-program/"
                 }
              ],
              "Authors": ["Jay Jani (@JayJani007)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Getting access to prompt debug dialog and serialized tool on main website facebook.com",
                    "Link": "http://omespino.com/facebook-bug-bounty-getting-access-to-prompt-debug-dialog-and-serialized-tool-on-main-website-facebook-com/"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure", "Debug mode enabled"],
              "Bounty": "-",
              "PublicationDate": "2018/01/31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to Download Any file from Web server!",
                    "Link": "https://blog.securitybreached.org/2018/01/27/how-i-was-able-to-download-any-file-from-web-server/"
                 }
              ],
              "Authors": ["hammadhassan924"],
              "Programs": ["-"],
              "Bugs": ["XSS", "IDOR"],
              "Bounty": "450",
              "PublicationDate": "2018-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got 22000$ worth ethereum",
                    "Link": "https://web.archive.org/web/20210122102751/https://www.guptashubham.com/how-i-got-22000-worth-ethereum/"
                 }
              ],
              "Authors": ["Shubham Gupta (@hackerspider1)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS"],
              "Bounty": "22,000",
              "PublicationDate": "2018-01-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "JSON CSRF attack on a Social Networking Site[Hackerone Platform]",
                    "Link": "https://medium.com/@pig.wig45/json-csrf-attack-on-a-social-networking-site-hackerone-platform-3d7aed3239b0"
                 }
              ],
              "Authors": ["Sahil Tikoo (@viperbluff)"],
              "Programs": ["Badoo"],
              "Bugs": ["JSON CSRF"],
              "Bounty": "280",
              "PublicationDate": "2018-01-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Here’s how I could’ve ridden for free with Uber",
                    "Link": "https://medium.freecodecamp.org/how-anyone-could-have-used-uber-to-ride-for-free-36cdee5ea854"
                 }
              ],
              "Authors": ["Anand Prakash (@anandpraka_sh)"],
              "Programs": ["Uber"],
              "Bugs": ["Logic flaw"],
              "Bounty": "5,000",
              "PublicationDate": "2018-01-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Full Account Takeover through CORS with connection Sockets",
                    "Link": "https://medium.com/@saamux/full-account-takeover-through-cors-with-connection-sockets-179133384815"
                 }
              ],
              "Authors": ["Samuel (@saamux)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2018-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Yahoo Bug Bounty] Unauthorized Access to Unisphere Management Server Debugging Facility on https://bf1-uaddbcx-002.data.bf1.yahoo.com/Debug/",
                    "Link": "https://web.archive.org/web/20191218054030/https://medium.com/@zk34911/yahoo-bug-bounty-unauthorized-access-to-unisphere-management-server-debugging-facility-on-448aeb6d0c94"
                 }
              ],
              "Authors": ["Peerzada Fawaz Ahmad Qureshi"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Broken authorization"],
              "Bounty": "300",
              "PublicationDate": "2018-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "No RCE? Then SSH to the box!",
                    "Link": "http://blog.jr0ch17.com/2018/No-RCE-then-SSH-to-the-box/"
                 }
              ],
              "Authors": ["Jasmin Laundry (@JR0ch17)"],
              "Programs": ["-"],
              "Bugs": ["LFI", "Path traversal", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2018-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS + Possible Server Side Template Injection in HubSpot CMS ( All Websites Uses HubSpot was affected )",
                    "Link": "https://web.archive.org/web/20201207232241/https://www.mohamedharon.com/2018/01/reflected-xss-possible-server-side.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["HubSpot"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-01-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty @ Linkedln-How I was able to bypass Open Redirection Protection",
                    "Link": "https://medium.com/bugbountywriteup/bugbounty-linkedln-how-i-was-able-to-bypass-open-redirection-protection-2e143eb36941"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["LinkedIn"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2018-01-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Asus Cross Site Scrpting And Directory Listing Vulnerability",
                    "Link": "https://web.archive.org/web/20200926101239/https://medium.com/@adeshkolte/asus-web-application-vulnerabilities-by-adesh-n-kolte-4c14a1bb8739"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["Asus"],
              "Bugs": ["Directory listing", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2018-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "File Disclosure via .DS_Store file (macOS)",
                    "Link": "http://omespino.com/write-up-file-disclosure-via-ds_store-file-macos"
                 }
              ],
              "Authors": ["Omar Espino (@omespino)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Directory listing"],
              "Bounty": "-",
              "PublicationDate": "2018-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Internshala Bug in Internshala Student Partner",
                    "Link": "https://medium.com/@circleninja/internshala-bug-in-internshala-student-partner-33d7b66c1bd5"
                 }
              ],
              "Authors": ["Circle Ninja (@circleninja)"],
              "Programs": ["Internshala"],
              "Bugs": ["Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2018-01-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got $13337 bounty From Google",
                    "Link": "https://twitter.com/kl_sree/status/953999305370607617"
                 }
              ],
              "Authors": ["Sreeram KL (@kl_sree)"],
              "Programs": ["Google"],
              "Bugs": ["Weak credentials"],
              "Bounty": "13,337",
              "PublicationDate": "2018-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected File Download ( RFD ) in www.Google.com",
                    "Link": "https://web.archive.org/web/20201022204145/https://www.mohamedharon.com/2018/01/reflected-file-download-rfd-in.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Google"],
              "Bugs": ["Reflected File Download"],
              "Bounty": "-",
              "PublicationDate": "2018-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My Research on Misconfigured Jenkins Servers",
                    "Link": "https://emtunc.org/blog/01/2018/research-misconfigured-jenkins-servers/"
                 }
              ],
              "Authors": ["Mikail Tunç (@emtunc)"],
              "Programs": ["Google", "Tesco", "Pearson", "News Uk"],
              "Bugs": ["Information disclosure", "Missing authentication", "Exposed Jenkins instance"],
              "Bounty": "-",
              "PublicationDate": "2018-01-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$1800 in less than an hour.",
                    "Link": "http://c0rni3sm.blogspot.com/2018/01/1800-in-less-than-hour.html"
                 }
              ],
              "Authors": ["yappare (@yappare)"],
              "Programs": ["Indeed"],
              "Bugs": ["CSRF", "XSS"],
              "Bounty": "1,800",
              "PublicationDate": "2018-01-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS via AngularJS Template Injection",
                    "Link": "https://blog.ibrahimdraidia.com/xss-via-angularjs-template-injection_hostinger/"
                 }
              ],
              "Authors": ["Taha Ibrahim Draidia"],
              "Programs": ["Hostinger"],
              "Bugs": ["Reflected XSS", "CSTI"],
              "Bounty": "-",
              "PublicationDate": "2018-01-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — AWS S3 added to my “Bucket” list!",
                    "Link": "https://medium.com/bugbountywriteup/bugbounty-aws-s3-added-to-my-bucket-list-f68dd7d0d1ce"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2018-01-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "View the bug subscriptions for any Oculus User",
                    "Link": "https://philippeharewood.com/view-the-bug-subscriptions-for-any-oculus-user/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Facebook accounts using CSRF in Oculus-Facebook integration",
                    "Link": "https://www.josipfranjkovic.com/blog/hacking-facebook-oculus-integration-csrf"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2018-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — How I was able to delete anyone’s account in an Online Car Rental Company",
                    "Link": "https://medium.com/bugbountywriteup/bugbounty-how-i-was-able-to-delete-anyones-account-in-an-online-car-rental-company-8a4022cc611"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Parameter tampering"],
              "Bounty": "-",
              "PublicationDate": "2018-01-14",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Chaining Bugs to Steal Yahoo Contacts!",
                  "Link": "https://corben.io/blog/18-1-11-chaining-yahoo-bugs"
               }
            ],
            "Authors": ["Corben Leo (@hacker_)"],
            "Programs": ["Yahoo! / Verizon Media"],
            "Bugs": ["CORS misconfiguration", "XSS"],
            "Bounty": "-",
            "PublicationDate": "2018-01-11",
            "AddedDate": "2022-11-30"
         },
           {
              "Links": [
                 {
                    "Title": "#BugBounty — How I was able to read chat of users in an Online travel portal",
                    "Link": "https://medium.com/bugbountywriteup/bugbounty-how-i-was-able-to-read-chat-of-users-in-an-online-travel-portal-c55a1787f999"
                 }
              ],
              "Authors": ["Avinash Jain (@logicbomb_1)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2018-01-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE Vulnerabilite in Yahoo Subdomain! ( Yahoo! RCE via Spring Engine SSTI ) By tghawkins",
                    "Link": "https://web.archive.org/web/20200929023045/https://www.mohamedharon.com/2018/01/rce-vulnerabilite-in-yahoo-subdomain.html"
                 }
              ],
              "Authors": ["Mohamed Haron (@m7mdharon)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["RCE"],
              "Bounty": "8,000",
              "PublicationDate": "2018-01-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1)",
                    "Link": "https://blog.securitybreached.org/2018/02/04/hunting-insecure-direct-object-reference-vulnerabilities-for-fun-and-profit-part-1/"
                 }
              ],
              "Authors": ["Mohammed Abdul Raheem (@mohdaltaf163)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "3,000",
              "PublicationDate": "2018-01-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "\"F**k you Thomas\" - ToyTalk bug bounty writeup",
                    "Link": "https://research.digitalinterruption.com/2018/01/04/toytalk-bug-bounty-writeup/"
                 }
              ],
              "Authors": ["Jahmel Harris"],
              "Programs": ["ToyTalk"],
              "Bugs": ["Authentication bypass", "HTML injection"],
              "Bounty": "-",
              "PublicationDate": "2018-01-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Content Injection in DuoLingo’s TinyCards App for Android [CVE-2017-16905]",
                    "Link": "https://wwws.nightwatchcybersecurity.com/2018/01/04/rce-in-duolingos-tinycards-app-for-android-cve-2017-16905/"
                 }
              ],
              "Authors": ["Nightwatch Cybersecurity (@nightwatchcyber)"],
              "Programs": ["DuoLingo"],
              "Bugs": ["Content injection"],
              "Bounty": "-",
              "PublicationDate": "2018-01-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook chat / dashboard content injection",
                    "Link": "https://voidzone.me/facebook-chat-dashboard-content-injection"
                 }
              ],
              "Authors": ["void (@voidz0r)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Content injection"],
              "Bounty": "-",
              "PublicationDate": "2018-01-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing internal API to achieve IDOR in New Relic",
                    "Link": "https://www.jonbottarini.com/2018/01/02/abusing-internal-api-to-achieve-idor-in-new-relic/"
                 }
              ],
              "Authors": ["Jon Bottarini (@jon_bottarini)"],
              "Programs": ["New Relic"],
              "Bugs": ["IDOR"],
              "Bounty": "1,000",
              "PublicationDate": "2018-01-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing $10,000 Yahoo Cookies!",
                    "Link": "https://blog.witcoat.com/2018/05/30/stealing-10000-yahoo-cookies/"
                 }
              ],
              "Authors": ["Tabahi (@_tabahi)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "10,000",
              "PublicationDate": "2017-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found SSRF on TheFacebook.com",
                    "Link": "https://w00troot.blogspot.com/2017/12/how-i-found-ssrf-on-thefacebookcom.html"
                 }
              ],
              "Authors": ["Thunder"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Jumping to the hell with 10 attempts to bypass devil's WAF",
                    "Link": "https://medium.com/bugbountywriteup/jumping-to-the-hell-with-10-attempts-to-bypass-devils-waf-4275bfe679dd"
                 }
              ],
              "Authors": ["Ak1T4 (@akita_zen)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft SharePoint's 'Follow' Feature XSS (CVE-2017–8514) -Adesh Kolte",
                    "Link": "https://web.archive.org/web/20200920204426/https://medium.com/@adeshkolte/microsoft-sharepoints-follow-feature-xss-cve-2017-8514-adesh-kolte-d78d701cd064"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Takeover Due to Misconfigured Login with Facebook/Google",
                    "Link": "https://bhavukjain.com/blog/2017/12/20/facebook-google-login-misconfig/"
                 }
              ],
              "Authors": ["Bhavuk Jain (@bhavukjain1)"],
              "Programs": ["Google", "Meta / Facebook"],
              "Bugs": ["Account takeover", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2017-12-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "P4 to P2 - The story of one blind SSRF",
                    "Link": "https://mike-n1.github.io/SSRF_P4toP2"
                 }
              ],
              "Authors": ["Mikhail Klyuchnikov (@__Mn1__)"],
              "Programs": ["-"],
              "Bugs": ["Blind SSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-12-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Unrestricted File Upload to RCE | Bug Bounty POC",
                    "Link": "https://blog.securitybreached.org/2017/12/19/unrestricted-file-upload-to-rce-bug-bounty-poc/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2017-12-19",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "LFI to 10 servers pwn",
                  "Link": "https://nirmaldahal.com.np/posts/2017/12/lfi-to-10-servers-pwn/"
               }
            ],
            "Authors": ["Nirmal Dahal (@TheNittam)"],
            "Programs": ["-"],
            "Bugs": ["LFI", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2017-12-19",
            "AddedDate": "2022-09-15"
         },
         {
            "Links": [
               {
                  "Title": "Hacking the Hackers: Leveraging an SSRF in HackerTarget",
                  "Link": "https://corben.io/blog/17-12-17-hackertarget"
               }
            ],
            "Authors": ["Corben Leo (@hacker_)"],
            "Programs": ["HackerTarget"],
            "Bugs": ["SSRF"],
            "Bounty": "-",
            "PublicationDate": "2017-12-17",
            "AddedDate": "2023-05-22"
         },
         {
              "Links": [
                 {
                    "Title": "Don't Trust the Host Header for Sending Password Reset Emails",
                    "Link": "https://lightningsecurity.io/blog/host-header-injection/"
                 }
              ],
              "Authors": ["Jack Cable (@jackhcable)"],
              "Programs": ["Mavenlink"],
              "Bugs": ["Password reset", "Account takeover"],
              "Bounty": "1,500",
              "PublicationDate": "2017-12-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to takeover Facebook account",
                    "Link": "https://blog.securitybreached.org/2017/12/10/how-i-was-able-to-takeover-facebook-account-bug-bounty-poc/"
                 }
              ],
              "Authors": ["Ameer Hamza"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2017-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Using App Ads Helper as an Analytic User",
                    "Link": "https://medium.com/@joshuaregio/using-app-ads-helper-as-an-analytic-user-e751fcf9c594"
                 }
              ],
              "Authors": ["Joshua Regio"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "500",
              "PublicationDate": "2017-12-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty: Fastmail",
                    "Link": "https://medium.com/bugbountywriteup/bug-bounty-fastmail-feeda67905f5"
                 }
              ],
              "Authors": ["Brian Hyde (@0xHyde)"],
              "Programs": ["Fastmail"],
              "Bugs": ["Blind SSRF", "Blind XXE"],
              "Bounty": "3,000",
              "PublicationDate": "2017-12-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Was Able To See The Bounty Balance Of Any Bug Bounty Program In HackerOne",
                    "Link": "https://medium.com/secjuice/how-i-was-able-to-view-exact-bounty-balance-of-any-bug-bounty-program-in-hackerone-f0e18e4206d5"
                 }
              ],
              "Authors": ["Cj Legacion (@LegacionCj)"],
              "Programs": ["HackerOne"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2017-12-06",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Multiple Plone Cross-Site Scripting Vulnerabilities",
                  "Link": "https://www.fortinet.com/blog/threat-research/multiple-plone-cross-site-scripting-vulnerabilities"
               }
            ],
            "Authors": ["Zhouyuan Yang"],
            "Programs": ["Plone"],
            "Bugs": ["XSS", "CSRF"],
            "Bounty": "-",
            "PublicationDate": "2017-12-05",
            "AddedDate": "2022-09-15"
         },
           {
              "Links": [
                 {
                    "Title": "Getting a RCE — CTF Way",
                    "Link": "https://medium.com/@uranium238/getting-a-rce-ctf-way-2fd612fb643f"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2017-12-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DEV XSS Protection bypass made my quickest bounty ever!!",
                    "Link": "https://medium.com/@Skylinearafat/xss-protection-bypass-made-my-quickest-bounty-ever-f4fd970c9116"
                 }
              ],
              "Authors": ["Yeasir Arafat"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "150",
              "PublicationDate": "2017-12-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "LFI to Command Execution: Deutche Telekom Bug Bounty",
                    "Link": "https://medium.com/@maxon3/lfi-to-command-execution-deutche-telekom-bug-bounty-6fe0de7df7a6"
                 }
              ],
              "Authors": ["Daniel Maksimovic"],
              "Programs": ["Deutche Telekom"],
              "Bugs": ["LFI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2017-11-30",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "SQL Injection in rog.asus.com",
                  "Link": "https://corben.io/blog/17-11-30-asus-sqli"
               }
            ],
            "Authors": ["Corben Leo (@hacker_)"],
            "Programs": ["Asus"],
            "Bugs": ["SQL injection", "Security code review"],
            "Bounty": "-",
            "PublicationDate": "2017-11-30",
            "AddedDate": "2023-05-22"
         },
         {
            "Links": [
               {
                  "Title": "Tricky CORS Bypass in Yahoo! View",
                  "Link": "https://corben.io/blog/17-11-27-tricky-CORS"
               }
            ],
            "Authors": ["Corben Leo (@hacker_)"],
            "Programs": ["Yahoo! / Verizon Media"],
            "Bugs": ["CORS misconfiguration"],
            "Bounty": "500",
            "PublicationDate": "2017-11-27",
            "AddedDate": "2023-05-22"
         },
         {
              "Links": [
                 {
                    "Title": "Image removal vulnerability in Facebook polling feature",
                    "Link": "https://blog.darabi.me/2017/11/image-removal-vulnerability-in-facebook.html"
                 }
              ],
              "Authors": ["Pouya Darabi (@Pouyadarabi)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "10,000",
              "PublicationDate": "2017-11-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of bypassing Referer Header to make open redirect",
                    "Link": "https://medium.com/@malcolmx0x/story-of-bypassing-referer-header-to-make-open-redirect-94f938b9d032"
                 }
              ],
              "Authors": ["Mohammed Eldeeb (@malcolmx0x)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2017-11-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Taking note: XSS to RCE in the Simplenote Electron client",
                    "Link": "https://ysx.me.uk/taking-note-xss-to-rce-in-the-simplenote-electron-client/"
                 }
              ],
              "Authors": ["Yasin Soliman (@SecurityYasin)"],
              "Programs": ["Automattic"],
              "Bugs": ["XSS", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2017-11-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "UBER Wildcard Subdomain Takeover | BugBounty POC",
                    "Link": "https://blog.securitybreached.org/2017/11/20/uber-wildcard-subdomain-takeover"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["Uber"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2017-11-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Amazon Bypass Open Redirect",
                    "Link": "https://medium.com/@honcbb/amazon-bypass-open-redirect-12609c879dff"
                 }
              ],
              "Authors": ["Honc (@honcbb)"],
              "Programs": ["Amazon"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2017-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "VMware Official VCDX Reflected XSS",
                    "Link": "https://medium.com/@honcbb/vmware-official-vcdx-reflected-xss-90e69a3c35e1"
                 }
              ],
              "Authors": ["Honc (@honcbb)"],
              "Programs": ["VMware"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-11-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Account Take Over Vulnerability in Google acquisition [Famebit]",
                    "Link": "https://medium.com/bugbountywriteup/account-take-over-vulnerability-in-google-acquisition-famebit-e93b1a0a7af9"
                 }
              ],
              "Authors": ["Hassan Khan Yusufzai"],
              "Programs": ["Google"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-11-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Transforming a Domain into the Matrix (an open redirect story)",
                    "Link": "https://medium.com/bugbountywriteup/transforming-a-domain-into-the-matrix-an-open-redirect-story-4bd87c3a8caa"
                 }
              ],
              "Authors": ["Ak1T4 (@akita_zen)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2017-11-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "JWT Refresh Token Manipulation",
                    "Link": "https://emtunc.org/blog/11/2017/jwt-refresh-token-manipulation/"
                 }
              ],
              "Authors": ["Mikail Tunç (@emtunc)"],
              "Programs": ["-"],
              "Bugs": ["JWT", "Authentication bypass", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2017-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL in everywhere.",
                    "Link": "https://medium.com/@agrawalsmart7/sql-is-every-where-5cba6ae9480a"
                 }
              ],
              "Authors": ["Utkarsh Agrawal (@agrawalsmart7)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2017-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Why I walked away from $30,000 of DJI bounty money",
                    "Link": "http://www.digitalmunition.com/WhyIWalkedFrom3k.pdf"
                 }
              ],
              "Authors": ["Kevin Finisterre (@d0tslash)"],
              "Programs": ["DJI"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2017-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Crossdomain Policy and Hit Hundreds of Top Alexa Sites",
                    "Link": "https://medium.com/bugbountywriteup/bypassing-crossdomain-policy-and-hit-hundreds-of-top-alexa-sites-af1944f6bbf5"
                 }
              ],
              "Authors": ["Ak1T4 (@akita_zen)"],
              "Programs": ["-"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How signing up for an account with an @company.com email can have unexpected results",
                    "Link": "https://zseano.medium.com/how-signing-up-for-an-account-with-an-company-com-email-can-have-unexpected-results-7f1b700976f5"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://blog.bugbountyhunter.com/company-account-unexpected/"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2017-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Pwned a company using IDOR & Blind XSS",
                    "Link": "https://www.ansariosama.com/2017/11/how-i-pwned-company-using-idor-blind-xss.html"
                 }
              ],
              "Authors": ["Osama Ansari (@AnsariOsama10)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From Recon to DOM-Based XSS",
                    "Link": "https://medium.com/@abdelfattahibrahim/from-recon-to-dom-based-xss-f279602a14cf"
                 }
              ],
              "Authors": ["Abdelfattah Ibrahim"],
              "Programs": ["-"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-11-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing bitcoin wallet backups from blockchain.info",
                    "Link": "http://blog.shashank.co/2017/11/stealing-bitcoin-wallet-backups-from.html"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["Blockchain.info"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,600",
              "PublicationDate": "2017-11-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to delete all company progress by one \"rm\" command in AWS s3 Buckets",
                    "Link": "https://medium.com/@valeriyshevchenko/how-to-delete-all-company-progress-by-one-rm-command-in-aws-s3-bucket-df9c44727d7b"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["-"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2017-11-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Local File Read via XSS in Dynamically Generated PDF",
                    "Link": "http://www.noob.ninja/2017/11/local-file-read-via-xss-in-dynamically.html"
                 }
              ],
              "Authors": ["Rahul Maini (@iamnoooob)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2017-11-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From SSRF to Local File Disclosure",
                    "Link": "https://medium.com/@tungpun/from-ssrf-to-local-file-disclosure-58962cdc589f"
                 }
              ],
              "Authors": ["Tung Pun"],
              "Programs": ["-"],
              "Bugs": ["SSRF", "Local file disclosure (LFD)"],
              "Bounty": "-",
              "PublicationDate": "2017-11-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Get your Microsoft account hijacked by simply clicking connect button -Adesh Kolte",
                    "Link": "https://web.archive.org/web/20200825165420/https://medium.com/@adeshkolte/get-your-microsoft-account-hijacked-by-simply-clicking-connect-button-adesh-kolte-cc0b335b0221"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-11-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Intel Vulnerabilities-Adesh Kolte",
                    "Link": "https://web.archive.org/web/20201013141953/https://medium.com/@adeshkolte/multiple-intel-vulnerabilities-adesh-kolte-9f74372db34c"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["Intel"],
              "Bugs": ["Open redirect", "Directory listing"],
              "Bounty": "-",
              "PublicationDate": "2017-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Non-persistent XSS at Microsoft -Adesh Kolte",
                    "Link": "https://web.archive.org/web/20200819161548/https://medium.com/@adeshkolte/non-persistent-xss-at-microsoft-adesh-kolte-ad36b1b4a325"
                 }
              ],
              "Authors": ["Adesh Nandkishor kolte (@AdeshKolte)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CRLF injection in blockchain.info",
                    "Link": "http://blog.shashank.co/2017/11/crlf-injection-in-bockchaininfo.html"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["Blockchain.info"],
              "Bugs": ["CRLF injection"],
              "Bounty": "1,600",
              "PublicationDate": "2017-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accessing Localhost via Vhost",
                    "Link": "https://blog.securitybreached.org/2017/11/04/access-localhost-via-virtual-host-virtual-host-enumeration/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["-"],
              "Bugs": ["vHost misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2017-11-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Senstive Information Leak Lead To join any Organisation",
                    "Link": "https://medium.com/bugbountywriteup/senstive-information-disclose-lead-to-join-any-organisation-40ab549011"
                 }
              ],
              "Authors": ["Shivbihari Pandey (@ninja_pandit_)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2017-11-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "App Maker and Colaboratory: a stored Google XSS double-bill",
                    "Link": "https://ysx.me.uk/app-maker-and-colaboratory-a-stored-google-xss-double-bill/"
                 }
              ],
              "Authors": ["Yasin Soliman (@SecurityYasin)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-11-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked Google’s bug tracking system itself for $15,600 in bounties",
                    "Link": "https://medium.freecodecamp.org/messing-with-the-google-buganizer-system-for-15-600-in-bounties-58f86cc9f9a5"
                 }
              ],
              "Authors": ["Alex Birsan (@alxbrsn)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "15,600",
              "PublicationDate": "2017-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing new Claps feature in Medium",
                    "Link": "https://medium.com/bugbountywriteup/abusing-new-claps-feature-in-medium-6bd8757a64a4"
                 }
              ],
              "Authors": ["Sai Krishna Kothapalli (@kmskrishna)"],
              "Programs": ["Medium"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2017-10-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Slack SAML authentication bypass",
                    "Link": "https://blog.intothesymmetry.com/2017/10/slack-saml-authentication-bypass.html"
                 }
              ],
              "Authors": ["Antonio Sanso (@asanso)"],
              "Programs": ["Slack"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "3,000",
              "PublicationDate": "2017-10-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i found an SSRF in Yahoo! Guesthouse (Recon Wins)",
                    "Link": "https://medium.com/@th3g3nt3l/how-i-found-an-ssrf-in-yahoo-guesthouse-recon-wins-8722672e41d4"
                 }
              ],
              "Authors": ["Th3G3nt3lman (@Th3G3nt3lman)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-10-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Taking over every Ad on OLX (automated), an IDOR story",
                    "Link": "https://kciredor.com/taking-over-every-ad-on-olx-automated-an-idor-story.html"
                 }
              ],
              "Authors": ["Roderick Schaefer (@kciredor_)"],
              "Programs": ["OLX"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2017-10-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sensitive data exposure by requesting a resource with a different content type",
                    "Link": "https://medium.com/@yogendra_h1/sensitive-data-exposure-by-requesting-a-resource-with-a-different-content-type-27412a9d6e2f"
                 }
              ],
              "Authors": ["Yogendra Jaiswal (@vulnh0lic)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2017-10-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked all the [REDACT] Agents accounts",
                    "Link": "https://medium.com/@neerajedwards/how-i-hacked-all-the-redact-agents-accounts-ec165b7c514a"
                 }
              ],
              "Authors": ["Neeraj Sonaniya (@neeraj_sonaniya)"],
              "Programs": ["-"],
              "Bugs": ["Default credentials"],
              "Bounty": "100",
              "PublicationDate": "2017-10-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reading Internal Files using SSRF vulnerability",
                    "Link": "https://medium.com/@neerajedwards/reading-internal-files-using-ssrf-vulnerability-703c5706eefb"
                 }
              ],
              "Authors": ["Neeraj Sonaniya (@neeraj_sonaniya)"],
              "Programs": ["-"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-10-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM XSS – auth.uber.com",
                    "Link": "https://web.archive.org/web/20180704183048/http://stamone-bug-bounty.blogspot.com/2017/10/dom-xss-auth_14.html"
                 }
              ],
              "Authors": ["StamOne_"],
              "Programs": ["Uber"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-10-14",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Adobe ColdFusion Deserialization RCE (CVE-2017-11283, CVE-2017-11284)",
                  "Link": "https://nickbloor.co.uk/2017/10/13/adobe-coldfusion-deserialization-rce-cve-2017-11283-cve-2017-11238/"
               }
            ],
            "Authors": ["Nicky Bloor (@NickstaDB)"],
            "Programs": ["Adobe (ColdFusion)"],
            "Bugs": ["Insecure deserialization", "RCE", "Security code review", "Java RMI"],
            "Bounty": "-",
            "PublicationDate": "2017-10-13",
            "AddedDate": "2024-02-06"
         },
           {
            "Links": [
               {
                  "Title": "How I was Able to see someone’s all private files with a single file share link through Atom feed & Never Give Up #togetherwehitharder HackerOne",
                  "Link": "https://medium.com/bugbountywriteup/how-i-was-able-to-see-someones-all-private-files-with-a-single-file-share-link-through-atom-feed-7cde46d7e84d"
               }
            ],
            "Authors": ["Yogendra Jaiswal (@vulnh0lic)"],
            "Programs": ["-"],
            "Bugs": ["Information disclosure"],
            "Bounty": "-",
            "PublicationDate": "2017-10-13",
            "AddedDate": "2022-09-15"
         },
           {
            "Links": [
               {
                  "Title": "Uber Bug Bounty: Gaining Access To An Internal Chat System",
                  "Link": "https://mishresec.wordpress.com/2017/10/13/uber-bug-bounty-gaining-access-to-an-internal-chat-system/"
               }
            ],
            "Authors": ["Michael Reizelman"],
            "Programs": ["Uber"],
            "Bugs": ["SAML", "Authentication bypass"],
            "Bounty": "8,500",
            "PublicationDate": "2017-10-13",
            "AddedDate": "2024-02-01"
         },
         {
            "Links": [
               {
                  "Title": "Yahoo Bug Bounty: Chaining 3 Minor Issues To Takeover Flickr Accounts",
                  "Link": "https://mishresec.wordpress.com/2017/10/13/yahoo-bug-bounty-chaining-3-minor-issues-to-takeover-flickr-accounts/"
               }
            ],
            "Authors": ["Michael Reizelman"],
            "Programs": ["Yahoo! / Verizon Media"],
            "Bugs": ["Authentication bypass", "Account takeover"],
            "Bounty": "7,000",
            "PublicationDate": "2017-10-13",
            "AddedDate": "2024-02-01"
         },
         {
            "Links": [
               {
                  "Title": "Yahoo Bug Bounty: Exploiting OAuth Misconfiguration To Takeover Flickr Accounts",
                  "Link": "https://mishresec.wordpress.com/2017/10/12/yahoo-bug-bounty-exploiting-oauth-misconfiguration-to-takeover-flickr-accounts/"
               }
            ],
            "Authors": ["Michael Reizelman"],
            "Programs": ["Yahoo! / Verizon Media"],
            "Bugs": ["OAuth", "Account takeover"],
            "Bounty": "4,000",
            "PublicationDate": "2017-10-12",
            "AddedDate": "2024-02-01"
         },
           {
              "Links": [
                 {
                    "Title": "Leaking Amazon.com CSRF Tokens Using Service Worker API",
                    "Link": "https://ahussam.me/Amazon-leaking-csrf-token-using-service-worker/"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["Amazon"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-10-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bugcrowd’s Domain & Subdomain Takeover vulnerability!",
                    "Link": "https://blog.securitybreached.org/2017/10/10/bugcrowds-domain-subdomain-takeover-vulnerability"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["Bugcrowd"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "600",
              "PublicationDate": "2017-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Insecure Cross Origin Resource Sharing ( CORS ) | api.artsy.net",
                    "Link": "https://blog.securitybreached.org/2017/10/10/exploiting-insecure-cross-origin-resource-sharing-cors-api-artsy-net"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["Artsy"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2017-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Subdomain Takeover Through Expired Cloudfront Distribution | live.lamborghini.co",
                    "Link": "https://blog.securitybreached.org/2017/10/10/subdomain-takeover-lamborghini-hacked/"
                 }
              ],
              "Authors": ["Muhammad Khizer Javed (@khizer_javed47)"],
              "Programs": ["Lamborghini"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2017-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook GraphQL CSRF",
                    "Link": "https://philippeharewood.com/facebook-graphql-csrf/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "7,500",
              "PublicationDate": "2017-10-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Was Able To View Private Tweets Of Any Private Twitter Account",
                    "Link": "https://medium.com/secjuice/how-i-was-able-to-view-private-tweets-of-any-private-twitter-account-86a9d2640ded"
                 }
              ],
              "Authors": ["Cj Legacion (@LegacionCj)"],
              "Programs": ["Twitter"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2017-10-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could have mass uploaded from every Flickr account!",
                    "Link": "https://ret2got.wordpress.com/2017/10/05/how-i-could-have-mass-uploaded-from-every-flickr-account/"
                 }
              ],
              "Authors": ["Jazzy (@ret2got)"],
              "Programs": ["Flickr"],
              "Bugs": ["Bruteforce"],
              "Bounty": "4,000",
              "PublicationDate": "2017-10-05",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Craft CMS – Why case matters",
                  "Link": "https://markus-krell.de/craft-cms-why-case-matters/"
               }
            ],
            "Authors": ["Markus Krell (@MarkusKrell)"],
            "Programs": ["Craft CMS"],
            "Bugs": ["Reflected XSS", "Content injection"],
            "Bounty": "-",
            "PublicationDate": "2017-10-01",
            "AddedDate": "2022-10-24"
         },
           {
              "Links": [
                 {
                    "Title": "Device Authorization Bypass!",
                    "Link": "https://medium.com/bugbountywriteup/device-authorization-bypass-aa508c9193ed"
                 }
              ],
              "Authors": ["Hassan Khan Yusufzai"],
              "Programs": ["-"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2017-09-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Filter Bypass to Reflected XSS on https://finance.yahoo.com (mobile version)",
                    "Link": "https://medium.com/@saamux/filter-bypass-to-reflected-xss-on-https-finance-yahoo-com-mobile-version-22b854327b27"
                 }
              ],
              "Authors": ["Samuel (@saamux)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "900$ XSS in yahoo ( Recon Wins )",
                    "Link": "https://medium.com/bugbountywriteup/900-xss-in-yahoo-recon-wins-65ee6d4bfcbd"
                 }
              ],
              "Authors": ["Th3G3nt3lman (@Th3G3nt3lman)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["XSS"],
              "Bounty": "900",
              "PublicationDate": "2017-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i bypassed Practo’s firewall and triggered a XSS.",
                    "Link": "https://medium.com/bugbountywriteup/how-i-bypassed-practos-firewall-and-triggered-a-xss-b30164a8f1dc"
                 }
              ],
              "Authors": ["Vipin Chaudhary (@vipinxsec)"],
              "Programs": ["Practo"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-09-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR – Execute JavaScript into anyone account",
                    "Link": "https://guptashubham.com/idor-execute-javascript-into-anyone-account/"
                 }
              ],
              "Authors": ["Shubham Gupta (@hackerspider1)"],
              "Programs": ["Terapeak"],
              "Bugs": ["IDOR", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS to Full Information disclosure",
                    "Link": "https://guptashubham.com/stored-xss-to-full-information-disclosure"
                 }
              ],
              "Authors": ["Shubham Gupta (@hackerspider1)"],
              "Programs": ["Terapeak"],
              "Bugs": ["Stored XSS"],
              "Bounty": "750",
              "PublicationDate": "2017-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Luminate Internal Privilege Escalation — Admin to Owner",
                    "Link": "https://medium.com/@rojanrijal/luminate-internal-privilege-escalation-admin-to-owner-2ca28e575985"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2017-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "This domain is my domain — G Suite A record vulnerability",
                    "Link": "https://medium.com/@rojanrijal/this-domain-is-my-domain-g-suite-a-record-vulnerability-b447a90a8de7"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Google", "Uber"],
              "Bugs": ["Domain takeover"],
              "Bounty": "-",
              "PublicationDate": "2017-09-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "All About Hackerone Private Program Terapeak",
                    "Link": "https://guptashubham.com/all-about-hackerone-private-program-terapeak/"
                 }
              ],
              "Authors": ["Shubham Gupta (@hackerspider1)"],
              "Programs": ["Terapeak"],
              "Bugs": ["IDOR", "Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-09-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple vulnerabilities in Oracle EBS",
                    "Link": "https://guptashubham.com/multiple-vulnerabilities-in-oracle-ebs/"
                 }
              ],
              "Authors": ["Shubham Gupta (@hackerspider1)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection", "XXE", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "First bounty, time to step up my game",
                    "Link": "https://kciredor.com/first-bounty-time-to-step-up-my-game.html"
                 }
              ],
              "Authors": ["Roderick Schaefer (@kciredor_)"],
              "Programs": ["-"],
              "Bugs": ["Same Origin Method Execution"],
              "Bounty": "-",
              "PublicationDate": "2017-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting a Single Request for Multiple Vulnerabilities",
                    "Link": "https://www.ansariosama.com/2017/09/exploiting-single-request-for-multiple.html"
                 }
              ],
              "Authors": ["Osama Ansari (@AnsariOsama10)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "Reflected XSS", "SSRF", "OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2017-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Story of a Parameter Specific XSS!",
                    "Link": "http://www.noob.ninja/2017/09/story-of-parameter-specific-xss.html"
                 }
              ],
              "Authors": ["Rahul Maini (@iamnoooob)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-09-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chaining Self XSS with UI Redressing is Leading to Session Hijacking (PWN users like a boss)",
                    "Link": "https://medium.com/bugbountywriteup/chaining-self-xss-with-ui-redressing-is-leading-to-session-hijacking-pwn-users-like-a-boss-efb46249cd14"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["-"],
              "Bugs": ["Self-XSS", "Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2017-09-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS] with arbitrary cookie installation",
                    "Link": "https://medium.com/@arbazhussain/stored-xss-with-arbitrary-cookie-installation-567931433c7f"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-09-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "URL Whitelist Bypass - Accounts Google (accounts.google.com) - VRP",
                    "Link": "http://manuel-sousa.blogspot.com/2017/09/url-whitelist-bypass-accounts-google.html"
                 }
              ],
              "Authors": ["Manuel Sousa (@manuelvsousa)"],
              "Programs": ["Google"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2017-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked hundreds of companies through their helpdesk",
                    "Link": "https://medium.com/intigriti/how-i-hacked-hundreds-of-companies-through-their-helpdesk-b7680ddc2d4c"
                 }
              ],
              "Authors": ["Inti De Ceukelaire (@securinti)"],
              "Programs": ["GitLab", "Slack", "Yammer", "Kayako", "Zendesk"],
              "Bugs": ["Ticket Trick", "Logic flaw"],
              "Bounty": "5,000",
              "PublicationDate": "2017-09-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Facebook Profile Picture Guard Security.",
                    "Link": "https://hackernoon.com/bypassing-facebook-profile-picture-guard-security-f0676550f089"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2017-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Phishing with history.back() open redirect",
                    "Link": "https://medium.com/@0xHyde/exploiting-history-back-3ec789c124dd"
                 }
              ],
              "Authors": ["Brian Hyde (@0xHyde)"],
              "Programs": ["-"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2017-09-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflective XSS and Open Redirect on Indeed.com subdomain",
                    "Link": "https://medium.com/@SyntaxError4/reflective-xss-and-open-redirect-on-indeed-com-subdomain-b4ab40e40c83"
                 }
              ],
              "Authors": ["Syntax Error (@SYNTAXERRORBA)"],
              "Programs": ["Indeed"],
              "Bugs": ["Reflected XSS", "Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2017-09-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found Reflective XSS in Yahoo Subdomain",
                    "Link": "https://medium.com/@SyntaxError4/how-i-found-reflective-xss-in-yahoo-subdomain-3ad4831b386e"
                 }
              ],
              "Authors": ["Syntax Error (@SYNTAXERRORBA)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-09-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR on HackerOne Hacker Review “What Program Say”",
                    "Link": "https://medium.com/japzdivino/idor-on-hackerone-hacker-review-what-program-say-885ce3989a6f"
                 }
              ],
              "Authors": ["Japz Divino (@japzdivino)"],
              "Programs": ["HackerOne"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2017-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Don’t just alert(1) , Because XSS is for fun…!!",
                    "Link": "https://medium.com/@armaanpathan/dont-just-alert-1-because-xss-is-for-fun-f88cfb88d5b9"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["Optimizely"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "My write up about UBER Cross-site scripting by help of KNOXSS",
                    "Link": "https://medium.com/@Alra3ees/my-write-up-about-uber-cross-site-scripting-by-help-of-knoxss-b1b56f8d090"
                 }
              ],
              "Authors": ["Emad Shanab (@Alra3ees)"],
              "Programs": ["Uber"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "500",
              "PublicationDate": "2017-09-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing 0Auth Token (MITM)",
                    "Link": "https://medium.com/@arbazhussain/stealing-0auth-token-mitm-3eeab46e96cf"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["OAuth"],
              "Bounty": "-",
              "PublicationDate": "2017-09-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS in Yahoo!",
                    "Link": "https://medium.com/@TheShahzada/reflected-xss-in-yahoo-6e2b6b177448"
                 }
              ],
              "Authors": ["Shahzada AL Shahriar Khan (@TheShahzada)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "700",
              "PublicationDate": "2017-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Uber XSS via Cookie",
                    "Link": "http://zhchbin.github.io/2017/08/30/Uber-XSS-via-Cookie/"
                 }
              ],
              "Authors": ["Chaobin Zhang"],
              "Programs": ["Uber"],
              "Bugs": ["XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2017-08-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Luminate Store Basics defacement and potential takeover",
                    "Link": "https://medium.com/@rojanrijal/luminate-store-basics-defacement-and-potential-takeover-3b53d1e45b4f"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["CSRF", "Session management issue"],
              "Bounty": "-",
              "PublicationDate": "2017-08-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Developer Luminate IDOR",
                    "Link": "https://medium.com/@rojanrijal/developer-luminate-idor-42bd0d98e0c"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2017-08-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Improper Storage of Private Project’s Files",
                    "Link": "https://medium.com/@arbazhussain/improper-storage-of-protected-projects-files-9ece8e9a4743"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2017-08-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Rate Limit Protection by spoofing originating IP",
                    "Link": "https://medium.com/@arbazhussain/bypassing-rate-limit-protection-by-spoofing-originating-ip-ff06adf34157"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["Bruteforce"],
              "Bounty": "-",
              "PublicationDate": "2017-08-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Upgrade from LFI to RCE via PHP Sessions",
                    "Link": "https://web.archive.org/web/20220818204507/https://www.rcesecurity.com/2017/08/from-lfi-to-rce-via-php-sessions/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["-"],
              "Bugs": ["LFI", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2017-08-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pre-domain wildcard CORS Exploitation",
                    "Link": "https://medium.com/bugbountywriteup/pre-domain-wildcard-cors-exploitation-2d6ac1d4bd30"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "1,000",
              "PublicationDate": "2017-08-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook stories disclose Facebook friend list",
                    "Link": "https://philippeharewood.com/facebook-stories-disclose-facebook-friend-list/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2017-08-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Secure Your Jenkins Instance Or Hackers Will Force You To! (Snapchat’s $5,000 Vulnerability)",
                    "Link": "https://nahamsec.com/posts/secure-your-jenkins-instance-or-hackers-will-force-you-to-snapchats-5000-vulnerability"
                 }
              ],
              "Authors": ["Ben Sadeghipour (@nahamsec)"],
              "Programs": ["Snapchat"],
              "Bugs": ["RCE", "LFI", "Exposed Jenkins instance"],
              "Bounty": "5,000",
              "PublicationDate": "2017-08-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Password Not Provided - Compromising Any Flurry User's Account [Yahoo Bug Bounty]",
                    "Link": "https://lightningsecurity.io/blog/password-not-provided/"
                 }
              ],
              "Authors": ["Jack Cable (@jackhcable)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Broken authentication", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2017-08-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Accidentally typo to bypass administration access",
                    "Link": "http://c0rni3sm.blogspot.com/2017/08/accidentally-typo-to-bypass.html"
                 }
              ],
              "Authors": ["yappare (@yappare)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2017-08-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected XSS on www.yahoo.com",
                    "Link": "https://medium.com/@saamux/reflected-xss-on-www-yahoo-com-9b1857cecb8c"
                 }
              ],
              "Authors": ["Samuel (@saamux)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Chain the vulnerabilities and take your report impact on the moon (CSRF to HTML INJECTION which results OPEN REDIRECT and could steal USER CREDENTIALS)",
                    "Link": "https://medium.com/@armaanpathan/chain-the-vulnerabilities-and-take-your-report-impact-on-the-moon-csrf-to-html-injection-which-608fa6e74236"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["Legal Robot"],
              "Bugs": ["CSRF", "HTML injection"],
              "Bounty": "40",
              "PublicationDate": "2017-08-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Insecure Direct Object Reference In Facebook Events",
                    "Link": "https://medium.com/@armaanpathan/idor-was-leading-to-privilege-escalation-and-violating-the-facebook-policy-355c67c654e6"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "2,000",
              "PublicationDate": "2017-08-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Getting access to 25k employees details",
                    "Link": "https://medium.com/securityescape/getting-access-to-25k-employees-details-c085d18b73f0"
                 }
              ],
              "Authors": ["Sahil Ahamad (@ehsahil)"],
              "Programs": ["-"],
              "Bugs": ["Exposed registration page"],
              "Bounty": "2,500",
              "PublicationDate": "2017-08-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "$10k host header",
                    "Link": "https://web.archive.org/web/20200411123311/https://sites.google.com/site/testsitehacking/10k-host-header"
                 }
              ],
              "Authors": ["Ezequiel Pereira (@epereiralopez)"],
              "Programs": ["Google"],
              "Bugs": ["Broken authorization"],
              "Bounty": "10,000",
              "PublicationDate": "2017-08-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to confirm a Google user’s specific email address (Bug Bounty Submission)",
                    "Link": "http://www.tomanthony.co.uk/blog/confirm-google-users-email/"
                 }
              ],
              "Authors": ["Tom Anthony (@TomAnthonySEO)"],
              "Programs": ["Google"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2017-08-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Because of wrong Content-type Header",
                    "Link": "https://bugbaba.blogspot.com/2017/08/xss-because-of-wrong-content-type-header.html"
                 }
              ],
              "Authors": ["Noman Shaikh (@nomanali181)"],
              "Programs": ["Internshala"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-08-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business Logic Vulnerabilities Series: How I became invisible and immune to blocking on Instagram!",
                    "Link": "https://www.seekurity.com/blog/general/business-logic-vulnerabilities-series-how-i-became-invisible-and-immune-to-blocking-on-instagram/"
                 }
              ],
              "Authors": ["Ali Kabeel"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2017-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i found massive information disclosure of 1500 famous people",
                    "Link": "https://medium.com/@valeriyshevchenko/massive-information-disclosure-of-1500-famous-people-b1b950fa657"
                 }
              ],
              "Authors": ["Valeriy Shevchenko (@Krevetk0Valeriy)"],
              "Programs": ["-"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2017-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Referer Based XSS",
                    "Link": "https://medium.com/@arbazhussain/referer-based-xss-52aeff7b09e7"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE!",
                    "Link": "https://blog.orange.tw/2017/07/how-i-chained-4-vulnerabilities-on.html"
                 }
              ],
              "Authors": ["Orange Tsai (@orange_8361)"],
              "Programs": ["GitHub"],
              "Bugs": ["SSRF", "RCE", "CRLF injection", "Insecure deserialization"],
              "Bounty": "12,500",
              "PublicationDate": "2017-07-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cracking the lens: targeting HTTP's hidden attack-surface",
                    "Link": "https://portswigger.net/research/cracking-the-lens-targeting-https-hidden-attack-surface"
                 }
              ],
              "Authors": ["James Kettle (@albinowax)"],
              "Programs": ["Yahoo! / Verizon Media", "BT", "New Relic"],
              "Bugs": ["Reflected XSS", "SSRF"],
              "Bounty": "33,000",
              "PublicationDate": "2017-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How we invented the Tesla DOM DOOM XSS",
                    "Link": "https://labs.detectify.com/2017/07/27/how-we-invented-the-tesla-dom-doom-xss/"
                 }
              ],
              "Authors": ["Detectify Labs"],
              "Programs": ["Tesla"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-07-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Disabling New Emails From Facebook Without Email Owner Interaction",
                    "Link": "https://medium.com/@zahidali_93675/disabling-new-emails-from-facebook-without-email-owner-interaction-11c979778a68"
                 }
              ],
              "Authors": ["Zahid Ali"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2017-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Rolling around and Bypassing Facebook’s Linkshim protection on iOS",
                    "Link": "https://www.seekurity.com/blog/general/rolling-around-and-bypassing-facebook-linkshim-protection-on-ios"
                 }
              ],
              "Authors": ["Seif Elsallamy (@seifelsallamy)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2017-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS on Rockstar Game",
                    "Link": "https://medium.com/@arbazhussain/stored-xss-on-rockstar-game-c008ec18d071"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["Rockstar Games"],
              "Bugs": ["XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2017-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "pen Redirect In Flock | My First Swag pack",
                    "Link": "https://bugbaba.blogspot.com/2017/07/open-redirect-in-flock-my-first-swag.html"
                 }
              ],
              "Authors": ["Noman Shaikh (@nomanali181)"],
              "Programs": ["Flock"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2017-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "May the Shells be with You - A Star Wars RCE Adventure!",
                    "Link": "https://blog.zsec.uk/rce-starwars/"
                 }
              ],
              "Authors": ["Andy Gill (@ZephrFish)"],
              "Programs": ["-"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2017-07-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How i was able to bypass strong xss protection in well known website. (imgur.com)",
                    "Link": "https://medium.com/bugbountywriteup/how-i-was-able-to-bypass-strong-xss-protection-in-well-known-website-imgur-com-8a247c527975"
                 }
              ],
              "Authors": ["Armaan Pathan (@armaancrockroax)"],
              "Programs": ["Imgur"],
              "Bugs": ["XSS"],
              "Bounty": "250",
              "PublicationDate": "2017-07-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Missing Authorization check in Facebook Pages Manager",
                    "Link": "https://medium.com/@arbazhussain/missing-authorization-check-in-facebook-pages-manager-9f7bd879ff33"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "1,000",
              "PublicationDate": "2017-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Race Condition bypassing team limit",
                    "Link": "https://medium.com/@arbazhussain/race-condition-bypassing-team-limit-b162e777ca3b"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["Race condition"],
              "Bounty": "-",
              "PublicationDate": "2017-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Self XSS to Good XSS Clickjacking",
                    "Link": "https://medium.com/@arbazhussain/self-xss-to-good-xss-clickjacking-6db43b44777e"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "Clickjacking"],
              "Bounty": "300",
              "PublicationDate": "2017-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Business Logic Vulnerabilities Series: A brief on Abusing Invitation Systems",
                    "Link": "https://www.seekurity.com/blog/general/business-logic-vulnerabilities-series-a-brief-on-abusing-invitation-systems/"
                 }
              ],
              "Authors": ["Ali Kabeel"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2017-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "That Escalated Quickly : From partial CSRF to reflected XSS to complete CSRF to Stored XSS",
                    "Link": "https://medium.com/@ciph3r7r0ll/that-escalated-quickly-from-partial-csrf-to-reflected-xss-to-complete-csrf-to-stored-xss-6ba8103069c2"
                 }
              ],
              "Authors": ["Mandeep Jadon (@1337tr0lls)"],
              "Programs": ["-"],
              "Bugs": ["CSRF", "Reflected XSS", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Xss using dynamically generated js file",
                    "Link": "https://medium.com/@arbazhussain/xss-using-dynamically-generated-js-file-a7a10d05ff08"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["XSS"],
              "Bounty": "150",
              "PublicationDate": "2017-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Exploiting Misconfigured CORS on popular BTC Site",
                    "Link": "https://medium.com/@arbazhussain/exploiting-misconfigured-cors-on-popular-btc-site-2aedfff906f6"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2017-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing Access Token of One-drive Integration By Chaining CSRF Vulnerability",
                    "Link": "https://medium.com/@arbazhussain/stealing-access-token-of-one-drive-integration-by-chaining-csrf-vulnerability-779f999624a7"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR While Connecting Social Account in Hackster.io",
                    "Link": "https://medium.com/@arbazhussain/idor-while-connecting-social-account-in-hackster-io-2296b316b7a7"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["Hackster.io"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2017-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ctrl+c & ctrl+v to Steal SESSIONID",
                    "Link": "https://medium.com/@arbazhussain/ctrl-d5ffc7b0640e"
                 }
              ],
              "Authors": ["Arbaz Hussain (@ArbazKiraak)"],
              "Programs": ["-"],
              "Bugs": ["Clickjacking"],
              "Bounty": "100",
              "PublicationDate": "2017-07-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How to find internal subdomains? YQL, Yahoo! and bug bounty.",
                    "Link": "https://hackernoon.com/how-to-find-internal-subdomains-yql-yahoo-and-bug-bounty-d7730b374d77"
                 }
              ],
              "Authors": ["Wojciech"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2017-07-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hey UserID x, what’s your secret token? Broken API enables me to leak/modify any users personal information",
                    "Link": "https://zseano.medium.com/fun-with-mobile-apps-broken-api-leads-to-leak-of-millions-of-personal-information-e7eb0b9dcce7"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://blog.bugbountyhunter.com/user-id-leak/"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["IDOR", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2017-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fabric.io API permission apocalypse – Privilege Escalations",
                    "Link": "https://wesecureapp.com/blog/fabric-io-api-permission-apocalypse-privilege-escalations"
                 }
              ],
              "Authors": ["WeSecureApp (@wesecureapp)"],
              "Programs": ["Twitter"],
              "Bugs": ["Broken authorization", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2017-07-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How we tookover shopify accounts with one single click",
                    "Link": "https://wesecureapp.com/blog/how-we-tookover-shopify-accounts-with-one-single-click"
                 }
              ],
              "Authors": ["WeSecureApp (@wesecureapp)"],
              "Programs": ["Shopify"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-07-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS by tossing cookies",
                    "Link": "https://wesecureapp.com/blog/xss-by-tossing-cookies/"
                 }
              ],
              "Authors": ["WeSecureApp (@wesecureapp)"],
              "Programs": ["Microsoft", "Twitter"],
              "Bugs": ["XSS", "Cookie tossing"],
              "Bounty": "-",
              "PublicationDate": "2017-07-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How a simple IDOR become a $4K User Impersonation vulnerability",
                    "Link": "https://shahmeeramir.com/how-a-simple-idor-become-a-4k-user-impersonation-vulnerability-705291b55c0d"
                 }
              ],
              "Authors": ["Shahmeer Amir (@Shahmeer_Amir)"],
              "Programs": ["-"],
              "Bugs": ["IDOR"],
              "Bounty": "4,250",
              "PublicationDate": "2017-07-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Coinbase AngularJS DOM XSS via Kiteworks",
                    "Link": "https://web.archive.org/web/20180827025910/http://www.paulosyibelo.com/2017/07/coinbase-angularjs-dom-xss-via-kiteworks.html"
                 }
              ],
              "Authors": ["Paulos Yibelo (@PaulosYibelo)"],
              "Programs": ["Coinbase"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-07-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Medium Content Spoofing Leads to XSS",
                    "Link": "https://ahussam.me/Medium-content-spoofing-xss"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["Medium"],
              "Bugs": ["Content spoofing", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-07-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Managed Apps and Music: a tale of two XSSes in Google Play",
                    "Link": "https://ysx.me.uk/managed-apps-and-music-a-tale-of-two-xsses-in-google-play/"
                 }
              ],
              "Authors": ["Yasin Soliman (@SecurityYasin)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WhatsApp — DoS Vulnerability In iOS & Android",
                    "Link": "https://infosecwriteups.com/whatsapp-dos-vulnerability-in-ios-android-d896f76d3253"
                 }
              ],
              "Authors": ["Vishnuraj"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS"],
              "Bounty": "-",
              "PublicationDate": "2017-07-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Making an XSS triggered by CSP bypass on Twitter.",
                    "Link": "https://web.archive.org/web/20190718104640/https://medium.com/@tbmnull/making-an-xss-triggered-by-csp-bypass-on-twitter-561f107be3e5"
                 }
              ],
              "Authors": ["tbmnull"],
              "Programs": ["Twitter"],
              "Bugs": ["XSS", "CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2017-07-06",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Stored XSS in Bandcamp",
                  "Link": "https://corben.io/blog/17-06-30-bandcamp-xss"
               }
            ],
            "Authors": ["Corben Leo (@hacker_)"],
            "Programs": ["Bandcamp"],
            "Bugs": ["Stored XSS"],
            "Bounty": "500",
            "PublicationDate": "2017-06-30",
            "AddedDate": "2023-05-22"
         },
           {
              "Links": [
                 {
                    "Title": "OpenProject Session Management Security Vulnerability aka CVE-2017-11667",
                    "Link": "https://www.seekurity.com/blog/general/openproject-session-management-security-vulnerability/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["OpenProject"],
              "Bugs": ["Session management issue"],
              "Bounty": "-",
              "PublicationDate": "2017-06-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Posting on groups as people whenever their email was known by an attacker",
                    "Link": "https://medium.com/@zahidali_93675/posting-on-groups-as-people-whenever-their-email-was-known-by-an-attacker-9dc8d7baf970"
                 }
              ],
              "Authors": ["Zahid Ali"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "7,500",
              "PublicationDate": "2017-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Escalating XSS in PhantomJS Image Rendering to SSRF/Local-File Read",
                    "Link": "https://buer.haus/2017/06/29/escalating-xss-in-phantomjs-image-rendering-to-ssrflocal-file-read/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "SSRF", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2017-06-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2017-10711: Reflected XSS vulnerability in SimpleRisk – Open Source Risk Management System",
                    "Link": "https://www.seekurity.com/blog/general/reflected-xss-vulnerability-in-simplerisk"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["SimpleRisk"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Road to (unauthenticated) recovery: downloading GitHub SSO bypass codes",
                    "Link": "https://ysx.me.uk/road-to-unauthenticated-recovery-downloading-github-saml-codes/"
                 }
              ],
              "Authors": ["Yasin Soliman (@SecurityYasin)"],
              "Programs": ["GitHub"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2017-06-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authentication bypass on Uber’s Single Sign-On via subdomain takeover",
                    "Link": "https://www.arneswinnen.net/2017/06/authentication-bypass-on-ubers-sso-via-subdomain-takeover/"
                 }
              ],
              "Authors": ["Arne Swinnen (@ArneSwinnen)"],
              "Programs": ["Uber"],
              "Bugs": ["Subdomain takeover", "Authentication bypass"],
              "Bounty": "4,500",
              "PublicationDate": "2017-06-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in the heart of the Russian email provider giant (Mail.ru)",
                    "Link": "https://www.seekurity.com/blog/general/stored-xss-in-the-heart-of-the-russian-email-provider-giant-mail-ru/"
                 }
              ],
              "Authors": ["Seif Elsallamy (@seifelsallamy)"],
              "Programs": ["Mail.ru"],
              "Bugs": ["Stored XSS"],
              "Bounty": "600",
              "PublicationDate": "2017-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Yahoo Small Business (Luminate) and the Not-So-Secret Keys",
                    "Link": "https://dos.sh/blog/2017/6/21/yahoo-small-business-luminate-and-the-not-so-secret-keys"
                 }
              ],
              "Authors": ["Tommy DeVoss / dawgyg (@thedawgyg)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Blind SSRF"],
              "Bounty": "9,000",
              "PublicationDate": "2017-06-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Built An XSS Worm On Atmail",
                    "Link": "https://www.bishopfox.com/blog/2017/06/how-i-built-an-xss-worm-on-atmail/"
                 }
              ],
              "Authors": ["Jake Miller"],
              "Programs": ["Atmail"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-06-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authentication bypass on Airbnb via OAuth tokens theft",
                    "Link": "https://www.arneswinnen.net/2017/06/authentication-bypass-on-airbnb-via-oauth-tokens-theft/"
                 }
              ],
              "Authors": ["Arne Swinnen (@ArneSwinnen)"],
              "Programs": ["Airbnb"],
              "Bugs": ["OAuth", "Login CSRF", "Open redirect", "Authentication bypass"],
              "Bounty": "5,000",
              "PublicationDate": "2017-06-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked 23.900.000 tumblr domains at once :)",
                    "Link": "https://web.archive.org/web/20170620023433/https://medium.com/@know.0nix/how-i-hack-23-900-000-tumblr-domains-at-once-341edad6e7cc"
                 }
              ],
              "Authors": ["Ak1T4 (@akita_zen)"],
              "Programs": ["Automattic"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2017-06-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS on Bugcrowd and so many other website’s main Domain",
                    "Link": "https://blog.witcoat.com/2018/05/30/xss-on-bugcrowd-and-so-many-other-websites-main-domain/"
                 }
              ],
              "Authors": ["Bull (@v0sx9b)"],
              "Programs": ["Bugcrowd"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "600",
              "PublicationDate": "2017-06-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerability in Metasploit Project aka CVE-2017-5244",
                    "Link": "https://www.seekurity.com/blog/general/metasploit-web-project-kill-all-running-tasks-csrf-cve-2017-5244/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Rapid7"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-06-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Godaddy XSS affects parked domains redirector/processor!",
                    "Link": "https://www.seekurity.com/blog/write-ups/godaddy-xss-affects-parked-domains-redirector-processor"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["GoDaddy"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Let’s steal some tokens!",
                    "Link": "https://www.seekurity.com/blog/general/lets-steal-some-tokens"
                 }
              ],
              "Authors": ["Mahmoud Gamal (@Zombiehelp54)"],
              "Programs": ["Google", "Shopify"],
              "Bugs": ["CSRF", "XSS", "Account takeover"],
              "Bounty": "1,000",
              "PublicationDate": "2017-06-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WhatsApp — Dos Vulnerability In iOS & Android",
                    "Link": "https://medium.com/bugbountywriteup/whatsapp-dos-vulnerability-in-ios-android-d896f76d3253"
                 }
              ],
              "Authors": ["Vishnu Prasad P G (@vishnuprasadnta)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["DoS"],
              "Bounty": "500",
              "PublicationDate": "2017-06-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From JS to another JS files lead to authentication bypass",
                    "Link": "http://c0rni3sm.blogspot.com/2017/06/from-js-to-another-js-files-lead-to.html"
                 }
              ],
              "Authors": ["yappare (@yappare)"],
              "Programs": ["-"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2017-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got 5500$ from Yahoo for RCE",
                    "Link": "https://medium.com/bugbountywriteup/how-i-got-5500-from-yahoo-for-rce-92fffb7145e6"
                 }
              ],
              "Authors": ["Th3G3nt3lman (@Th3G3nt3lman)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["RCE"],
              "Bounty": "5,500",
              "PublicationDate": "2017-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Django Privilege Escalation – Zero To Superuser",
                    "Link": "https://seanmelia.files.wordpress.com/2017/06/django-privilege-escalation-e28093-zero-to-superuser.pdf"
                 }
              ],
              "Authors": ["Sean Melia (@seanmeals)"],
              "Programs": ["-"],
              "Bugs": ["Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2017-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS, CSRF And Clickjacking Vulnerabilities in Opera",
                    "Link": "https://www.rafaybaloch.com/2017/06/stored-xss-csrf-and-clickjacking.html"
                 }
              ],
              "Authors": ["Rafay Baloch (@rafaybaloch)"],
              "Programs": ["Opera"],
              "Bugs": ["Stored XSS", "CSRF", "Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2017-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Tale Of Another SOP Bypass In Android Browser < 4.4",
                    "Link": "https://www.rafaybaloch.com/2017/06/a-tale-of-another-sop-bypass-in-android.html"
                 }
              ],
              "Authors": ["Rafay Baloch (@rafaybaloch)"],
              "Programs": ["Google"],
              "Bugs": ["SOP bypass"],
              "Bounty": "-",
              "PublicationDate": "2017-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Android Browser Same Origin Policy Bypass < 4.4 - CVE-2014-6041",
                    "Link": "https://www.rafaybaloch.com/2017/06/android-browser-same-origin-policy.html"
                 }
              ],
              "Authors": ["Rafay Baloch (@rafaybaloch)"],
              "Programs": ["Google"],
              "Bugs": ["SOP bypass"],
              "Bounty": "-",
              "PublicationDate": "2017-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM Based XSS In Microsoft",
                    "Link": "https://www.rafaybaloch.com/2017/06/dom-based-xss-in-microsoft.html"
                 }
              ],
              "Authors": ["Rafay Baloch (@rafaybaloch)"],
              "Programs": ["Microsoft"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Paypal Mobile Verification And Payment Restrictions Bypass",
                    "Link": "https://www.rafaybaloch.com/2017/06/paypal-mobile-verification-and-payment.html"
                 }
              ],
              "Authors": ["Rafay Baloch (@rafaybaloch)"],
              "Programs": ["Paypal"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2017-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Nokia Asha Series Lock Screen Bypass",
                    "Link": "https://www.rafaybaloch.com/2017/06/nokia-asha-series-lock-screen-bypass.html"
                 }
              ],
              "Authors": ["Hammad Shamsi (@HammadShamsii)"],
              "Programs": ["Nokia"],
              "Bugs": ["Authentication bypass", "Lock screen bypass"],
              "Bounty": "-",
              "PublicationDate": "2017-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Android Browser All Versions - Address Bar Spoofing Vulnerability - CVE-2015-3830",
                    "Link": "https://www.rafaybaloch.com/2017/06/android-browser-all-versions-address.html"
                 }
              ],
              "Authors": ["Rafay Baloch (@rafaybaloch)"],
              "Programs": ["Google"],
              "Bugs": ["Address Bar Spoofing"],
              "Bounty": "-",
              "PublicationDate": "2017-06-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS on Google{5.000$}-Google Vulnerability Reward Program (VRP)",
                    "Link": "https://blog.fraktal.fi/comparing-cloud-wafs-in-2024-61b689b1b0e1"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2017-05-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Pivoting from blind SSRF to RCE with HashiCorp Consul",
                    "Link": "http://www.kernelpicnic.net/2017/05/29/Pivoting-from-blind-SSRF-to-RCE-with-Hashicorp-Consul.html"
                 }
              ],
              "Authors": ["Peter Adkins (@darkarnium)"],
              "Programs": ["-"],
              "Bugs": ["Blind XSS", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2017-05-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A pair of Plotly bugs: Stored XSS and AWS Metadata SSRF",
                    "Link": "https://ysx.me.uk/a-pair-of-plotly-bugs-stored-xss-and-aws-metadata-ssrf/"
                 }
              ],
              "Authors": ["Yasin Soliman (@SecurityYasin)"],
              "Programs": ["Plotly"],
              "Bugs": ["Stored XSS", "SSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-05-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking the NHS for Fun and No Profit",
                    "Link": "https://medium.com/@nmalcolm/hacking-the-nhs-for-fun-and-no-profit-90931029dcb4"
                 }
              ],
              "Authors": ["Nathan (@NathOnSecurity)"],
              "Programs": ["NHS"],
              "Bugs": ["SQL injection", "LFI"],
              "Bounty": "-",
              "PublicationDate": "2017-05-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One Cloud-based Local File Inclusion = Many Companies affected",
                    "Link": "http://panchocosil.blogspot.com/2017/05/one-cloud-based-local-file-inclusion.html"
                 }
              ],
              "Authors": ["Francisco Correa (@panchocosil)"],
              "Programs": ["Oracle", "Meta / Facebook", "LinkedIn", "Dropbox"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2017-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Find Mingle Suggestions for any Facebook User (Revisited)",
                    "Link": "https://philippeharewood.com/find-mingle-suggestions-for-any-facebook-user-revisited/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2017-05-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "I got emails — G Suite Vulnerability",
                    "Link": "https://medium.com/@rojanrijal/i-got-emails-g-suite-vulnerability-917e1f6a91f6"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Google", "Yelp", "Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2017-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tales of SugarCRM Security Horrors",
                    "Link": "http://karmainsecurity.com/tales-of-sugarcrm-security-horrors"
                 }
              ],
              "Authors": ["Egidio Romano / EgiX"],
              "Programs": ["SugarCRM"],
              "Bugs": ["PHP object injection", "SQL injection", "Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2017/04/23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AWS S3 bucket misconfiguration - Paytm",
                    "Link": "https://web.archive.org/web/20190506160222/https://tutorgeeks.blogspot.com/2017/04/aws-s3-bucket-misconfiguration.html"
                 }
              ],
              "Authors": ["Tutorgeeks (@tutorgeeks)"],
              "Programs": ["Paytm"],
              "Bugs": ["AWS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2017/04/18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Inspect Element leads to Stripe Account Lockout Authentication Bypass",
                    "Link": "https://www.jonbottarini.com/2017/04/03/inspect-element-leads-to-stripe-account-lockout-authentication-bypass/"
                 }
              ],
              "Authors": ["Jon Bottarini (@jon_bottarini)"],
              "Programs": ["Stripe"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "500",
              "PublicationDate": "2017/04/03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Airbnb – Web to App Phone Notification IDOR to view Everyone’s Airbnb Messages",
                    "Link": "https://buer.haus/2017/03/31/airbnb-web-to-app-phone-notification-idor-to-view-everyones-airbnb-messages/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)", "Ben Sadeghipour (@nahamsec)"],
              "Programs": ["Airbnb"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2017-03-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hundreds of hundreds sub-secdomains hack3d! (including Hacker0ne)",
                    "Link": "https://medium.com/bugbountywriteup/hundreds-of-hundreds-subdomains-hack3d-including-hacker0ne-ad3acd1c0a44"
                 }
              ],
              "Authors": ["Ak1T4 (@akita_zen)"],
              "Programs": ["HackerOne"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "1,000",
              "PublicationDate": "2017-03-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Critical information disclosure on Wappalyzer.com",
                    "Link": "https://www.nc-lp.com/blog/critical-information-disclosure-on-wappalyzer-com"
                 }
              ],
              "Authors": ["Davide Tampellini (@tampe125)"],
              "Programs": ["Wappalyzer"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2017-03-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Near universal XSS in McAfee Web Gateway",
                    "Link": "https://blog.ettic.ca/near-universal-xss-in-mcafee-web-gateway-cf8dfcbc8fc3"
                 }
              ],
              "Authors": ["Olivier Arteau"],
              "Programs": ["McAfee"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-03-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Penetrating PornHub – XSS vulns galore (plus a cool shirt!)",
                    "Link": "https://www.jonbottarini.com/2017/03/16/penetrating-pornhub-xss-vulns-galore-plus-a-cool-shirt"
                 }
              ],
              "Authors": ["Jon Bottarini (@jon_bottarini)"],
              "Programs": ["PornHub"],
              "Bugs": ["XSS"],
              "Bounty": "250",
              "PublicationDate": "2017-03-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Safe Links in Exchange Online Advanced Threat Protection",
                    "Link": "https://emtunc.org/blog/03/2017/bypassing-safe-links-exchange-online-advanced-threat-protection/"
                 }
              ],
              "Authors": ["Mikail Tunç (@emtunc)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2017-03-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Airbnb – Ruby on Rails String Interpolation led to Remote Code Execution",
                    "Link": "https://buer.haus/2017/03/13/airbnb-ruby-on-rails-string-interpolation-led-to-remote-code-execution/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)", "Ben Sadeghipour (@nahamsec)"],
              "Programs": ["Airbnb"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2017-03-13",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Remote Code Execution in AT&T",
                  "Link": "https://corben.io/blog/17-3-10-att-rce"
               }
            ],
            "Authors": ["Corben Leo (@hacker_)"],
            "Programs": ["AT&T"],
            "Bugs": ["RCE", "SSTI", "Components with known vulnerabilities"],
            "Bounty": "-",
            "PublicationDate": "2017-03-10",
            "AddedDate": "2023-05-22"
         },
           {
              "Links": [
                 {
                    "Title": "How I found a $5,000 Google Maps XSS (by fiddling with Protobuf)",
                    "Link": "https://medium.com/@marin_m/how-i-found-a-5-000-google-maps-xss-by-fiddling-with-protobuf-963ee0d9caff"
                 }
              ],
              "Authors": ["Marin Moulinier"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2017-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Airbnb – Chaining Third-Party Open Redirect into Server-Side Request Forgery (SSRF) via LivePerson Chat",
                    "Link": "https://buer.haus/2017/03/09/airbnb-chaining-third-party-open-redirect-into-server-side-request-forgery-ssrf-via-liveperson-chat/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)", "Ben Sadeghipour (@nahamsec)"],
              "Programs": ["Airbnb"],
              "Bugs": ["Open redirect", "SSRF", "Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2017-03-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities",
                    "Link": "https://buer.haus/2017/03/08/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-vulnerabilities/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)", "Ben Sadeghipour (@nahamsec)"],
              "Programs": ["Airbnb"],
              "Bugs": ["XSS", "CSP bypass"],
              "Bounty": "-",
              "PublicationDate": "2017-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Ok Google, Give Me All Your Internal DNS Information!",
                    "Link": "https://www.rcesecurity.com/2017/03/ok-google-give-me-all-your-internal-dns-information/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["Google"],
              "Bugs": ["SSRF"],
              "Bounty": "-",
              "PublicationDate": "2017-03-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token",
                    "Link": "https://labs.detectify.com/2017/02/28/hacking-slack-using-postmessage-and-websocket-reconnect-to-steal-your-precious-token/"
                 }
              ],
              "Authors": ["Frans Rosén (@fransrosen)"],
              "Programs": ["Slack"],
              "Bugs": ["postMessage", "Violation of secure design principles"],
              "Bounty": "3,000",
              "PublicationDate": "2017-02-28",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Time-based Blind SQLi on news.starbucks.com",
                  "Link": "https://timeofcheck.com/time-based-blind-sqli-on-news-starbucks-com/"
               }
            ],
            "Authors": ["toctou"],
            "Programs": ["Starbucks"],
            "Bugs": ["Blind SQL injection"],
            "Bounty": "-",
            "PublicationDate": "2017-02-26",
            "AddedDate": "2023-01-02"
         },
           {
              "Links": [
                 {
                    "Title": "One company: 262 bugs, 100% acceptance, 2.57 priority, millions of user details saved.",
                    "Link": "https://medium.com/@sean.roesner/one-company-262-bugs-100-acceptance-2-57-priority-300million-user-details-saved-dd88ecb10f6f"
                 },
                 {
                    "Title": "Alternative link",
                    "Link": "https://blog.bugbountyhunter.com/one-company-262-bugs/"
                 }
              ],
              "Authors": ["Zseano (@zseano)"],
              "Programs": ["-"],
              "Bugs": ["Stored XSS", "Blind XSS", "CSRF", "Account takeover", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2017-02-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got your phone number through Facebook",
                    "Link": "https://medium.com/intigriti/how-i-got-your-phone-number-through-facebook-223b769cccf1"
                 }
              ],
              "Authors": ["Inti De Ceukelaire (@securinti)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2017-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Practical Exploitation of Error Based Sql Injection",
                    "Link": "https://eslam.io/posts/practical-exploitation-of-error-based-sql-injection"
                 }
              ],
              "Authors": ["Eslam Salem (@net_code)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2017-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I bypassed State Bank of India OTP.",
                    "Link": "https://hackernoon.com/how-i-bypassed-state-bank-of-india-otp-f145469a9f1d"
                 }
              ],
              "Authors": ["Neeraj Sonaniya (@neeraj_sonaniya)"],
              "Programs": ["State Bank of India"],
              "Bugs": ["OTP bypass"],
              "Bounty": "-",
              "PublicationDate": "2017-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to remove your Instagram Phone number",
                    "Link": "https://medium.com/bugbountywriteup/how-i-was-able-to-remove-your-instagram-phone-number-d346515e79c3"
                 }
              ],
              "Authors": ["Neeraj Sonaniya (@neeraj_sonaniya)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Bruteforce"],
              "Bounty": "1,000",
              "PublicationDate": "2017-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "From RSS to XXE: feed parsing on Hootsuite",
                    "Link": "https://ysx.me.uk/from-rss-to-xxe-feed-parsing-on-hootsuite/"
                 }
              ],
              "Authors": ["Yasin Soliman (@SecurityYasin)"],
              "Programs": ["Hootsuite"],
              "Bugs": ["XSS", "XXE"],
              "Bounty": "-",
              "PublicationDate": "2017-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL injection in an UPDATE query - a bug bounty story!",
                    "Link": "http://mahmoudsec.blogspot.com/2017/02/sql-injection-in-update-query-bug.html"
                 }
              ],
              "Authors": ["Mahmoud Gamal (@Zombiehelp54)"],
              "Programs": ["-"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2017-02-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Lightweight markup: a trio of persistent XSS in GitLab",
                    "Link": "https://ysx.me.uk/lightweight-markup-a-trio-of-persistent-xss-in-gitlab/"
                 }
              ],
              "Authors": ["Yasin Soliman (@SecurityYasin)"],
              "Programs": ["GitLab"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2017-02-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vulnerabilities in Facebook Login Approval Form",
                    "Link": "https://medium.com/@zahidali_93675/vulnerabilities-in-facebook-login-approval-form-dfa5fce92023"
                 }
              ],
              "Authors": ["Zahid Ali"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "2,250",
              "PublicationDate": "2017-02-14",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Account Recovery Form (CONFLICTING)",
                    "Link": "https://medium.com/@zahidali_93675/conflict-account-recovery-form-in-facebook-2b6e7d203cfd"
                 }
              ],
              "Authors": ["Zahid Ali"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "1,000",
              "PublicationDate": "2017-02-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassed Facebook Phone Number Security",
                    "Link": "https://medium.com/@zahidali_93675/bypassed-facebook-phone-number-security-9e2d34dc063b"
                 }
              ],
              "Authors": ["Zahid Ali"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw", "Information disclosure"],
              "Bounty": "3,000",
              "PublicationDate": "2017-02-10",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Type Juggling and PHP Object Injection, and SQLi, Oh My!",
                  "Link": "https://foxglovesecurity.com/2017/02/07/type-juggling-and-php-object-injection-and-sqli-oh-my/"
               }
            ],
            "Authors": ["Justin Kennedy (@jstnkndy)"],
            "Programs": ["-"],
            "Bugs": ["Type juggling", "PHP object injection", "Insecure deserialization", "SQL injection"],
            "Bounty": "-",
            "PublicationDate": "2017-02-07",
            "AddedDate": "2022-11-11"
         },
           {
              "Links": [
                 {
                    "Title": "Facebook Groups Hack",
                    "Link": "https://medium.com/@zahidali_93675/hijack-facebook-groups-721c08526326"
                 }
              ],
              "Authors": ["Zahid Ali"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Logic flaw"],
              "Bounty": "3,000",
              "PublicationDate": "2017-02-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cross Site Request Forgery in Facebook",
                    "Link": "https://medium.com/@zahidali_93675/cross-site-request-forgery-in-facebook-86087201d8c"
                 }
              ],
              "Authors": ["Zahid Ali"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "1,000",
              "PublicationDate": "2017-02-04",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Spring Boot RCE",
                  "Link": "https://web.archive.org/web/20170206221502/https://deadpool.sh/2017/RCE-Springs/"
               }
            ],
            "Authors": ["Tushar (@0xdeadpool)"],
            "Programs": ["-"],
            "Bugs": ["RCE", "SpEL injection", "Spring Boot"],
            "Bounty": "-",
            "PublicationDate": "2017-02-02",
            "AddedDate": "2022-12-09"
         },
           {
              "Links": [
                 {
                    "Title": "I got emails - G Suite Vulnerability",
                    "Link": "https://web.archive.org/web/20200822111544/https://whitehatnepal.tumblr.com/post/156707088037/i-got-emails-g-suite-vulnerability"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Google", "Meta / Facebook", "Yelp"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2017-02-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could have compromised any account on one of the biggest startup based in California",
                    "Link": "https://medium.com/@prateek_0490/how-i-could-have-compromised-any-account-on-one-of-the-biggest-startup-based-in-california-3ebc8c6844b5"
                 }
              ],
              "Authors": ["Prateek Tiwari (@prateek_0490)"],
              "Programs": ["-"],
              "Bugs": ["Account takeover", "IDOR", "Password reset"],
              "Bounty": "-",
              "PublicationDate": "2017-01-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "0day writeup: XXE in uber.com",
                    "Link": "https://httpsonly.blogspot.com/2017/01/0day-writeup-xxe-in-ubercom.html"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["Uber"],
              "Bugs": ["XXE"],
              "Bounty": "9,000",
              "PublicationDate": "2017-01-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I could have Hacked IIT Guwahati’s website",
                    "Link": "https://medium.com/bugbountywriteup/how-i-could-have-hacked-iit-guwahatis-website-52dff319b056"
                 }
              ],
              "Authors": ["Sai Krishna Kothapalli (@kmskrishna)"],
              "Programs": ["IIT Guwahati"],
              "Bugs": ["Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2017-01-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing passwords from McDonald's users",
                    "Link": "https://tij.me/blog/stealing-passwords-from-mcdonalds-users/"
                 }
              ],
              "Authors": ["Tijme Gommers (@tijme)"],
              "Programs": ["McDonalds"],
              "Bugs": ["Reflected XSS", "AngularJS sandbox bypass"],
              "Bounty": "-",
              "PublicationDate": "2017-01-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Cross-site-scripting on one of the largest Dutch franchisors",
                    "Link": "https://tij.me/blog/xss-on-hema-one-of-the-largest-dutch-franchisors/"
                 }
              ],
              "Authors": ["Tijme Gommers (@tijme)"],
              "Programs": ["Hema"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-12-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "IDOR in Facebook's Acquisition (Parse)",
                    "Link": "http://www.pranav-venkat.com/2016/12/idor-in-facebooks-acquisition-parse.html"
                 }
              ],
              "Authors": ["Venkatesh Sivakumar (@pranavvenkats)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2016-12-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability in AWS, Google Cloud, Rackspace and Digital Ocean",
                    "Link": "https://thehackerblog.com/the-orphaned-internet-taking-over-120k-domains-via-a-dns-vulnerability-in-aws-google-cloud-rackspace-and-digital-ocean/index.html"
                 }
              ],
              "Authors": ["Matthew Bryant (@IAmMandatory)"],
              "Programs": ["Google", "Amazon", "Rackspace", "DigitalOcean"],
              "Bugs": ["Domain takeover"],
              "Bounty": "1,337",
              "PublicationDate": "2016-12-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Atom.io Misconfiguration Allowed Code Execution on Untrusted Networks",
                    "Link": "https://evilpacket.net/2016/atom-io-misconfiguration-allowed-code-execution-on-untrusted-networks/"
                 }
              ],
              "Authors": ["Adam Baldwin (@adam_baldwin)"],
              "Programs": ["GitHub"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2016-11-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Authentication bypass on Ubiquity’s Single Sign-On via subdomain takeover",
                    "Link": "https://www.arneswinnen.net/2016/11/authentication-bypass-on-sso-ubnt-com-via-subdomain-takeover-of-ping-ubnt-com/"
                 }
              ],
              "Authors": ["Arne Swinnen (@ArneSwinnen)"],
              "Programs": ["Ubiquity Networks"],
              "Bugs": ["Subdomain takeover", "Authentication bypass"],
              "Bounty": "500",
              "PublicationDate": "2016-11-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Ebay XSS Protection to launch XSS by Nirmal Dahal",
                    "Link": "https://medium.com/pentesternepal/bypassing-ebay-xss-protection-8cf73466ba0f"
                 }
              ],
              "Authors": ["Nirmal Dahal (@TheNittam)"],
              "Programs": ["Ebay"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-11-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Svg XSS in Unifi v5.0.2",
                    "Link": "https://guptashubham.com/svg-xss-in-unifi-v5-0-2/"
                 }
              ],
              "Authors": ["Shubham Gupta (@hackerspider1)"],
              "Programs": ["Ubiquity Networks"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-11-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stored XSS in UniFi v4.8.12 Controller",
                    "Link": "https://guptashubham.com/stored-xss-in-unifi-v4-8-12-controller/"
                 }
              ],
              "Authors": ["Shubham Gupta (@hackerspider1)"],
              "Programs": ["Ubiquity Networks"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-11-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Backslash Powered Scanning: hunting unknown vulnerability classes",
                    "Link": "https://portswigger.net/research/backslash-powered-scanning-hunting-unknown-vulnerability-classes"
                 }
              ],
              "Authors": ["James Kettle (@albinowax)"],
              "Programs": ["-"],
              "Bugs": ["-"],
              "Bounty": "-",
              "PublicationDate": "2016-11-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Rewriting a photo not owned by the session user in Moments App (Revisited)",
                    "Link": "https://philippeharewood.com/rewriting-a-photo-not-owned-by-the-session-user-in-moments-app-revisited/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2016-10-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leak Private Videos [Vimeo Bug Bounty]",
                    "Link": "https://ahussam.me/leak-private-videos-vimeo/"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["Vimeo"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2016-10-23",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Hacking JasperReports – The Hidden Shell Feature",
                  "Link": "https://foxglovesecurity.com/2016/10/14/hacking-jasperreports-the-hidden-shell-feature/"
               }
            ],
            "Authors": ["Steve Breen (@breenmachine)"],
            "Programs": ["-"],
            "Bugs": ["RCE"],
            "Bounty": "-",
            "PublicationDate": "2016-10-14",
            "AddedDate": "2022-11-25"
         },
           {
              "Links": [
                 {
                    "Title": "Exploiting CORS misconfigurations for Bitcoins and bounties",
                    "Link": "https://portswigger.net/research/exploiting-cors-misconfigurations-for-bitcoins-and-bounties"
                 }
              ],
              "Authors": ["James Kettle (@albinowax)"],
              "Programs": ["-"],
              "Bugs": ["CORS misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2016-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Parameter pollution bug at twitter",
                    "Link": "https://blog.mert.ninja/twitter-hpp-vulnerability/"
                 }
              ],
              "Authors": ["Mert (@mertistaken)"],
              "Programs": ["Twitter"],
              "Bugs": ["HTTP parameter pollution"],
              "Bounty": "-",
              "PublicationDate": "2016-10-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open Redirect Scanner with Uber.com",
                    "Link": "https://medium.com/bugbountywriteup/open-redirect-scanner-c72cd60d0bf"
                 }
              ],
              "Authors": ["Ak1T4 (@akita_zen)"],
              "Programs": ["Uber"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2016-10-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Command Injection Without Spaces",
                    "Link": "https://www.betterhacker.com/2016/10/command-injection-without-spaces.html"
                 }
              ],
              "Authors": ["Fyoorer (@ƒyoorer)"],
              "Programs": ["-"],
              "Bugs": ["OS command injection"],
              "Bounty": "-",
              "PublicationDate": "2016-10-02",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "gif it time it'll come to you - Finding More Holes in The Hub",
                    "Link": "https://blog.zsec.uk/gif-time-pornhub/"
                 }
              ],
              "Authors": ["Andy Gill (@ZephrFish)"],
              "Programs": ["PornHub"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-10-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS Vulnerability in Twitter [https://twitter.com] (Write Up)",
                    "Link": "https://blog.evanricafort.com/2016/09/xss-vulnerability-in-twitter.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Twitter"],
              "Bugs": ["XSS"],
              "Bounty": "280",
              "PublicationDate": "2016-09-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Persisting on Pornhub",
                    "Link": "https://blog.zsec.uk/persisting-pornhub/"
                 }
              ],
              "Authors": ["Andy Gill (@ZephrFish)"],
              "Programs": ["PornHub"],
              "Bugs": ["Stored XSS"],
              "Bounty": "1,500",
              "PublicationDate": "2016-09-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Link Injection Manipulation at admin.google.com",
                    "Link": "https://medium.com/@know.0nix/link-injection-manipulation-at-admin-google-com-6da3b15a2854"
                 }
              ],
              "Authors": ["Ak1T4 (@akita_zen)"],
              "Programs": ["Google"],
              "Bugs": ["Hyperlink injection"],
              "Bounty": "-",
              "PublicationDate": "2016-09-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Vine Re-auth Bypass [Twitter Bug Bounty]",
                    "Link": "https://ahussam.me/Vine-Reauth-Bypass"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["Twitter"],
              "Bugs": ["Broken authentication"],
              "Bounty": "420",
              "PublicationDate": "2016-09-21",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "CSRF in partners.facebook.com",
                  "Link": "https://github.com/cymtrick/lol/blob/d17ed765129b26a1bf8060757e5aebd4e237c908/_posts/2016-09-20-Facebook-partners-CSRF.md"
               }
            ],
            "Authors": ["Prashanth Varma (@cymtrick)"],
            "Programs": ["Meta / Facebook"],
            "Bugs": ["CSRF"],
            "Bounty": "5,000",
            "PublicationDate": "2016-09-20",
            "AddedDate": "2022-10-28"
         },
           {
              "Links": [
                 {
                    "Title": "Bug Bounty : Account Takeover Vulnerability POC",
                    "Link": "http://blog.rakeshmane.com/2016/09/bug-bounty-account-takeover.html"
                 }
              ],
              "Authors": ["Rakesh Mane (@RakeshMane10)"],
              "Programs": ["-"],
              "Bugs": ["OAuth", "Account takeover", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-09-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I snooped into your private Slack messages [Slack Bug bounty worth $2,500]",
                    "Link": "https://web.archive.org/web/20200817171403/https://whitehatnepal.tumblr.com/post/150381068912/how-i-snooped-into-your-private-slack-messages"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Slack"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "2,500",
              "PublicationDate": "2016-09-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Decoding a $😱,000.00 htpasswd bounty",
                    "Link": "https://wss.sh/en/blog/bugbounty-decoding-a-😱-00000-htpasswd-bounty/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["-"],
              "Bugs": [".htpasswd misconfiguration"],
              "Bounty": "-",
              "PublicationDate": "2016-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Internet Explorer has a URL problem",
                    "Link": "https://web.archive.org/web/20220401221504/https://blog.innerht.ml/internet-explorer-has-a-url-problem/"
                 }
              ],
              "Authors": ["File Descriptor (@filedescriptor)"],
              "Programs": ["GitHub", "Google"],
              "Bugs": ["OAuth", "RPO", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-09-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reading Uber’s Internal Emails [Uber Bug Bounty report worth $10,000]",
                    "Link": "https://web.archive.org/web/20200822010745/https://whitehatnepal.tumblr.com/post/149985438982/reading-ubers-internal-emails-uber-bug-bounty"
                 }
              ],
              "Authors": ["Rojan Rijal (@uraniumhacker)"],
              "Programs": ["Uber"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "10,000",
              "PublicationDate": "2016-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RCE In AddThis",
                    "Link": "https://web.archive.org/web/20200811013300/https://whitehatnepal.tumblr.com/post/149933960267/rce-in-addthis"
                 }
              ],
              "Authors": ["whitehatnepal"],
              "Programs": ["AddThis"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2016-09-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PornHub: Email Confirmation Bypass",
                    "Link": "https://web.archive.org/web/20200819161533/https://whitehatnepal.tumblr.com/post/149937173467/pornhub-email-confirmation-bypass"
                 }
              ],
              "Authors": ["Vaxo Dai (@___0x00)"],
              "Programs": ["PornHub"],
              "Bugs": ["Email verification bypass"],
              "Bounty": "-",
              "PublicationDate": "2016-09-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Turning Self-XSS into Good XSS v2: Challenge Completed but Not Rewarded",
                    "Link": "https://httpsonly.blogspot.com/2016/08/turning-self-xss-into-good-xss-v2.html"
                 }
              ],
              "Authors": ["-"],
              "Programs": ["Uber"],
              "Bugs": ["XSS"],
              "Bounty": "1,000",
              "PublicationDate": "2016-08-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Floating Domains – Taking Over 20K DigitalOcean Domains via a Lax Domain Import System",
                    "Link": "https://thehackerblog.com/floating-domains-taking-over-20k-digitalocean-domains-via-a-lax-domain-import-system/"
                 }
              ],
              "Authors": ["Matthew Bryant (@IAmMandatory)"],
              "Programs": ["DigitalOcean"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2016-08-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[demo.paypal.com] Node.js code injection (RCE)",
                    "Link": "http://artsploit.blogspot.com/"
                 }
              ],
              "Authors": ["Michael Stepankin (@artsploit)"],
              "Programs": ["Paypal"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2016-08-19",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Samsung Galaxy Apps MiTM vulnerabilities",
                  "Link": "https://www.evilsocket.net/2016/08/17/Samsung-Galaxy-Apps-MITM-Vulnerabilities/"
               }
            ],
            "Authors": ["Simone Margaritelli (@evilsocket)"],
            "Programs": ["Samsung"],
            "Bugs": ["MiTM", "Android"],
            "Bounty": "-",
            "PublicationDate": "2016-08-17",
            "AddedDate": "2022-10-21"
         },
           {
              "Links": [
                 {
                    "Title": "Swf XSS (Dom Based Xss)",
                    "Link": "https://guptashubham.com/swf-xss-dom-based-xss/"
                 }
              ],
              "Authors": ["Shubham Gupta (@hackerspider1)"],
              "Programs": ["Ubiquity Networks"],
              "Bugs": ["Flash XSS", "DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Xss filter bypass in Yahoo dev.flurry.com",
                    "Link": "https://guptashubham.com/xss-filter-bypass-in-yahoo-dev-flurry-com/"
                 }
              ],
              "Authors": ["Shubham Gupta (@hackerspider1)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS on Flickr",
                    "Link": "https://guptashubham.com/xss-on-flickr/"
                 }
              ],
              "Authors": ["Shubham Gupta (@hackerspider1)"],
              "Programs": ["Flickr"],
              "Bugs": ["XSS"],
              "Bounty": "400",
              "PublicationDate": "2016-07-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CSV Injection -> Meterpreter on Pornhub",
                    "Link": "https://blog.zsec.uk/csvhub/"
                 }
              ],
              "Authors": ["Andy Gill (@ZephrFish)"],
              "Programs": ["PornHub"],
              "Bugs": ["CSV injection"],
              "Bounty": "500",
              "PublicationDate": "2016-07-29",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Messenger.com Site-Wide CSRF",
                    "Link": "https://whitton.io/articles/messenger-site-wide-csrf/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2016-07-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "BMW Vulnerabilities – Hijack Cars ConnectedDrive™ Service!",
                    "Link": "https://www.seekurity.com/blog/general/bmw-vulnerabilities-hijack-cars-connecteddrive-service/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["BMW"],
              "Bugs": ["Clickjacking", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2016-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Remote Code Execution (RCE) on Microsoft's 'signout.live.com'",
                    "Link": "http://www.kernelpicnic.net/2016/07/24/Microsoft-signout.live.com-Remote-Code-Execution-Write-Up.html"
                 }
              ],
              "Authors": ["Peter Adkins (@darkarnium)"],
              "Programs": ["Microsoft"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2016-07-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How we broke PHP, hacked Pornhub and earned $20,000",
                    "Link": "https://web.archive.org/web/20220709205125/https://www.evonide.com/how-we-broke-php-hacked-pornhub-and-earned-20000-dollar/"
                 }
              ],
              "Authors": ["Ruslan Habalov (@evonide)", "cutz", "Dario Weißer (@haxonaut)"],
              "Programs": ["PornHub"],
              "Bugs": ["RCE", "Memory corruption", "Use-After-Free"],
              "Bounty": "20,000",
              "PublicationDate": "2016-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Twitter's Vine Source code dump - $10080",
                    "Link": "https://avicoder.me/2016/07/22/Twitter-Vine-Source-code-dump/"
                 }
              ],
              "Authors": ["avicoder (@avicoder)"],
              "Programs": ["Twitter"],
              "Bugs": ["Source code disclosure", "Information disclosure"],
              "Bounty": "10,080",
              "PublicationDate": "2016-07-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind XSS in Spotify's Salesforce Integration",
                    "Link": "https://mhmdiaa.com/blog/spotify-blind-xss/"
                 }
              ],
              "Authors": ["Mohammed Diaa (@mhmdiaa)"],
              "Programs": ["Spotify"],
              "Bugs": ["Blind XSS", "Salesforce"],
              "Bounty": "-",
              "PublicationDate": "2016-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing Facebook access_tokens using CSRF in device login flow",
                    "Link": "https://www.josipfranjkovic.com/blog/hacking-facebook-csrf-device-login-flow"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF", "OAuth", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2016-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Could Steal Money from Instagram, Google and Microsoft",
                    "Link": "https://www.arneswinnen.net/2016/07/how-i-could-steal-money-from-instagram-google-and-microsoft/"
                 }
              ],
              "Authors": ["Arne Swinnen (@ArneSwinnen)"],
              "Programs": ["Google", "Microsoft", "Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "2,500",
              "PublicationDate": "2016-07-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Race conditions on the web",
                    "Link": "https://www.josipfranjkovic.com/blog/race-conditions-on-web"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Cobalt.io", "Meta / Facebook", "MEGA", "Keybase"],
              "Bugs": ["Race condition"],
              "Bounty": "8,450",
              "PublicationDate": "2016-07-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "TopCoder.com Vulnerabilities – A tail of site-wide bugs leads to accounts compromise & payments hijacking",
                    "Link": "https://www.seekurity.com/blog/general/topcoder-vulnerabilities-a-tail-of-site-wide-bugs-leads-to-accounts-compromise-payments-hijacking/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Topcoder.com"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "-",
              "PublicationDate": "2016-06-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Uber Hacking: How we found out who you are, where you are and where you went",
                    "Link": "https://medium.com/@r0t1v/uber-hacking-how-we-found-out-who-you-are-where-you-are-and-where-you-went-1e0769674535"
                 }
              ],
              "Authors": ["Vitor “r0t” Oliveira (@r0t1v)"],
              "Programs": ["Uber"],
              "Bugs": ["Bruteforce", "Information disclosure", "Logic flaw", "IDOR"],
              "Bounty": "18,000",
              "PublicationDate": "2016-06-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Medium Full Account Takeover By One Click",
                    "Link": "https://ahussam.me/Medium-full-account-takeover/"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["Medium"],
              "Bugs": ["XSS"],
              "Bounty": "100",
              "PublicationDate": "2016-06-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Critical LinkedIn vulnerability proactively resolved by Wallarm (XXE in application server)",
                    "Link": "https://lab.wallarm.com/critical-linkedin-vulnerability-proactively-resolved-by-wallarm-xxe-in-application-server-239bba28e415"
                 }
              ],
              "Authors": ["Wallarm (@Wallarm)"],
              "Programs": ["LinkedIn"],
              "Bugs": ["XXE"],
              "Bounty": "-",
              "PublicationDate": "2016-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Two vulnerabilities makes an Exploit!! (XSS and CSRF in Bing)",
                    "Link": "https://medium.com/bugbountywriteup/two-vulnerabilities-makes-an-exploit-xss-and-csrf-in-bing-cd4269da7b69"
                 }
              ],
              "Authors": ["Sai Krishna Kothapalli (@kmskrishna)"],
              "Programs": ["Microsoft"],
              "Bugs": ["XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2016-06-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Why you shouldn’t share links on Facebook",
                    "Link": "https://medium.com/intigriti/why-you-shouldnt-share-links-on-facebook-f317ba4aa58b"
                 }
              ],
              "Authors": ["Inti De Ceukelaire (@securinti)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2016-06-09",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Popping the Pornhub Cherry",
                    "Link": "https://blog.zsec.uk/pwning-pornhub"
                 }
              ],
              "Authors": ["Andy Gill (@ZephrFish)"],
              "Programs": ["PornHub"],
              "Bugs": ["Information disclosure"],
              "Bounty": "2,500",
              "PublicationDate": "2016-06-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "RunKeeper Stored XSS Vulnerability – Where worms are able to run too!",
                    "Link": "https://www.seekurity.com/blog/general/runkeeper-stores-xss-vulnerability/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["RunKeeper"],
              "Bugs": ["Stored XSS", "CSRF"],
              "Bounty": "-",
              "PublicationDate": "2016-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "InstaBrute: Two Ways to Brute-force Instagram Account Credentials",
                    "Link": "https://www.arneswinnen.net/2016/05/instabrute-two-ways-to-brute-force-instagram-account-credentials/"
                 }
              ],
              "Authors": ["Arne Swinnen (@ArneSwinnen)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Bruteforce", "Username enumeration"],
              "Bounty": "5,000",
              "PublicationDate": "2016-05-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Microsoft Yammer Clickjacking – Exploiting HTML5 Security Features",
                    "Link": "https://www.seekurity.com/blog/general/microsoft-yammer-clickjacking-exploiting-html5-security-features"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Microsoft"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2016-05-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "When your privacy disclosure is a “feature” not a “bug” – Badoo & HotorNot failure!",
                    "Link": "https://www.seekurity.com/blog/general/badoo-hotornot-privacy-disclosure-feature-not-a-bug"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Badoo", "Hot Or Not"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2016-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Sleeping stored Google XSS Awakens a $5000 Bounty",
                    "Link": "https://wss.sh/en/blog/bugbounty-sleeping-stored-google-xss-awakens-a-5000-bounty/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2016-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I bypassed Facebook CSRF once again!",
                    "Link": "https://blog.darabi.me/2016/05/how-i-bypassed-facebook-csrf-in-2016.html"
                 }
              ],
              "Authors": ["Pouya Darabi (@Pouyadarabi)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "7,500",
              "PublicationDate": "2016-05-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Vulnerability – a \"Cute Bug\" that reveals the \"likes\" of deleted posts regardless of their privacy settings",
                    "Link": "https://www.seekurity.com/blog/general/facebook-vulnerability-a-cute-bug-that-reveals-the-likes-of-deleted-posts-regardless-of-their-privacy-settings/"
                 }
              ],
              "Authors": ["Mohamed Aty (@m_aty)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2016-05-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Fiverr.com Full Accounts Takeover – A Vulnerability Puts $50 Million Company At Risk",
                    "Link": "https://www.seekurity.com/blog/general/fiverr-com-full-accounts-takeover-vulnerability/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Fiverr"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2016-05-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "FirefoxOS Find My Device Service Clickjacking Bug results in Changing PINs, Wiping and Locking Phones!",
                    "Link": "https://www.seekurity.com/blog/general/firefox-find-my-device-service-clickjacking/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Mozilla"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2016-05-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Poisoning the Well – Compromising GoDaddy Customer Support With Blind XSS",
                    "Link": "https://thehackerblog.com/poisoning-the-well-compromising-godaddy-customer-support-with-blind-xss/index.html"
                 }
              ],
              "Authors": ["Matthew Bryant (@IAmMandatory)"],
              "Programs": ["GoDaddy"],
              "Bugs": ["Blind XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-05-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook movies recommendation vulnerability – A bug capable of erasing all your important notifications!",
                    "Link": "https://www.seekurity.com/blog/general/facebook-movies-recommendation-bug/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "DoS"],
              "Bounty": "-",
              "PublicationDate": "2016-05-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "WhatsApp Clickjacking Vulnerability – Yet another web client failure!",
                    "Link": "https://www.seekurity.com/blog/general/whatsapp-clickjacking-vulnerability-yet-another-web-client-failure"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2016-05-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Official Telegram Web Client ClickJacking Vulnerability – When crypto is strong and client is weak",
                    "Link": "https://www.seekurity.com/blog/general/telegram-web-client-clickjacking-vulnerability/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Telegram"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2016-04-28",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook ClickJacking – How we put a new dress on Facebook UI",
                    "Link": "https://www.seekurity.com/blog/write-ups/facebook-clickjacking-how-we-put-a-new-dress-on-facebook-ui/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2016-04-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ESEA Server-Side Request Forgery and Querying AWS Meta Data",
                    "Link": "https://buer.haus/2016/04/18/esea-server-side-request-forgery-and-querying-aws-meta-data/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)"],
              "Programs": ["ESEA"],
              "Bugs": ["SSRF"],
              "Bounty": "1,000",
              "PublicationDate": "2016-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Yahoo Login Protection Seal – Stored CSS Injection",
                    "Link": "https://buer.haus/2016/04/18/yahoo-login-protection-seal-stored-css-injection/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["CSS injection"],
              "Bounty": "-",
              "PublicationDate": "2016-04-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Invitees Email Address Disclosure",
                    "Link": "https://medium.com/@albeckshahar/facebook-invitees-email-address-disclosure-25059ae93725"
                 }
              ],
              "Authors": ["Shahar Albeck"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2016-04-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Obtaining Login Tokens for an Outlook, Office or Azure Account",
                    "Link": "https://whitton.io/articles/obtaining-tokens-outlook-office-azure-account/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Microsoft"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2016-04-03",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Watch Paint Dry: How I got a game on the Steam Store without anyone from Valve ever looking at it.",
                  "Link": "https://medium.com/swlh/watch-paint-dry-how-i-got-a-game-on-the-steam-store-without-anyone-from-valve-ever-looking-at-it-2e476858c753"
               }
            ],
            "Authors": ["Ruby Nealon (@_ruby)"],
            "Programs": ["Valve"],
            "Bugs": ["Broken authorization", "Logic flaw"],
            "Bounty": "-",
            "PublicationDate": "2016-03-29",
            "AddedDate": "2022-10-28"
         },
           {
              "Links": [
                 {
                    "Title": "How I Could Compromise 4% (Locked) Instagram Accounts",
                    "Link": "https://www.arneswinnen.net/2016/03/how-i-could-compromise-4-locked-instagram-accounts"
                 }
              ],
              "Authors": ["Arne Swinnen (@ArneSwinnen)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR", "DoS", "Broken authorization"],
              "Bounty": "5,000",
              "PublicationDate": "2016-03-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Uber Bug Bounty: Turning Self-XSS into Good-XSS",
                    "Link": "https://whitton.io/articles/uber-turning-self-xss-into-good-xss/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Uber"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-03-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Command injection which got me \"6000$\" from #Google",
                    "Link": "http://www.pranav-venkat.com/2016/03/command-injection-which-got-me-6000.html"
                 }
              ],
              "Authors": ["Venkatesh Sivakumar (@pranavvenkats)"],
              "Programs": ["Google"],
              "Bugs": ["OS command injection"],
              "Bounty": "6000",
              "PublicationDate": "2016-03-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL Injection On MEGA.NZ",
                    "Link": "https://nareshlamgade.com.np/2016/03/sql-injection-on-mega/"
                 }
              ],
              "Authors": ["Naresh LamGade (@nlamgade)"],
              "Programs": ["MEGA"],
              "Bugs": ["SQL injection"],
              "Bounty": "400",
              "PublicationDate": "2016-03-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Magento eCommerce For Fun And 17.000 USD",
                    "Link": "http://karmainsecurity.com/hacking-magento-ecommerce-for-fun-and-17000-usd"
                 }
              ],
              "Authors": ["Egidio Romano / EgiX"],
              "Programs": ["Adobe"],
              "Bugs": ["Information disclosure", "LFI", "RFI"],
              "Bounty": "17000",
              "PublicationDate": "2016-03-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Ubiquiti Bug Bounty: UniFi v3.2.10 Generic CSRF Protection Bypass",
                    "Link": "https://www.rcesecurity.com/2016/02/ubiquiti-bug-bounty-unifi-v3-2-10-generic-csrf-protection-bypass/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["Ubiquity Networks"],
              "Bugs": ["CSRF"],
              "Bounty": "500",
              "PublicationDate": "2016-02-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Hacked [Oculus] OAuth +Ebay +IBM",
                    "Link": "https://ahussam.me/how-i-hacked-oculus-oauth-ebay-ibm/"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["Meta / Facebook", "Ebay", "IBM", "AnswerHub"],
              "Bugs": ["Unrestricted file upload", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-02-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Hilarious ESET Broken Authentication Vulnerability (one click free purchase)",
                    "Link": "https://www.seekurity.com/blog/write-ups/eset-broken-authentication-vulnerability/"
                 }
              ],
              "Authors": ["Mohamed A. Baset"],
              "Programs": ["ESET"],
              "Bugs": ["Broken authentication", "SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2016-02-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I got access to millions of [redacted] accounts",
                    "Link": "https://bitquark.co.uk/blog/2016/02/09/how_i_got_access_to_millions_of_redacted_accounts"
                 }
              ],
              "Authors": ["Bitquark (@bitquark)"],
              "Programs": ["-"],
              "Bugs": ["RFI"],
              "Bounty": "-",
              "PublicationDate": "2016-02-09",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Deserialization in Perl v5.8",
                  "Link": "https://www.agarri.fr/blog/archives/2016/02/06/deserialization_in_perl_v5_8/index.html"
               }
            ],
            "Authors": ["Nicolas Grégoire (@Agarri_FR)"],
            "Programs": ["-"],
            "Bugs": ["Insecure deserialization", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2016-02-06",
            "AddedDate": "2024-02-06"
         },
           {
              "Links": [
                 {
                    "Title": "XSS without HTML: Client-Side Template Injection with AngularJS",
                    "Link": "https://portswigger.net/research/xss-without-html-client-side-template-injection-with-angularjs"
                 }
              ],
              "Authors": ["Gareth Heyes (@garethheyes)"],
              "Programs": ["Google"],
              "Bugs": ["CSTI", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "An XSS on Facebook via PNGs & Wonky Content Types",
                    "Link": "https://whitton.io/articles/xss-on-facebook-via-png-content-types"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2016-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[manager.paypal.com] Remote Code Execution Vulnerability",
                    "Link": "http://artsploit.blogspot.com/2016/01/paypal-rce.html"
                 }
              ],
              "Authors": ["Michael Stepankin (@artsploit)"],
              "Programs": ["Paypal"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2016-01-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Broken Access Control in bingmapsportal !!!",
                    "Link": "https://medium.com/bugbountywriteup/broken-access-control-in-bingmapsportal-a012bffd2c43"
                 }
              ],
              "Authors": ["Sai Krishna Kothapalli (@kmskrishna)"],
              "Programs": ["Microsoft"],
              "Bugs": ["Broken Access Control"],
              "Bounty": "-",
              "PublicationDate": "2016-01-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Leaking API keys in Bing Maps Portal",
                    "Link": "https://medium.com/bugbountywriteup/how-i-got-listed-in-microsoft-hall-of-fame-8f96ca4535c2"
                 }
              ],
              "Authors": ["Sai Krishna Kothapalli (@kmskrishna)"],
              "Programs": ["Microsoft"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2015-12-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Instagram's Million Dollar Bug",
                    "Link": "http://exfiltrated.com/research-Instagram-RCE.php"
                 }
              ],
              "Authors": ["Wesley Wineberg"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["RCE"],
              "Bounty": "2,500",
              "PublicationDate": "2015-12-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Local File XSS Vulnerability in Wordpress.com (Write Up)",
                    "Link": "https://web.archive.org/web/20210511011807/https://blog.evanricafort.com/2015/12/local-file-xss-vulnerability-in.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["WordPress"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2015-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Arbitary File Upload Vulnerability in Google Nest (Write Up)",
                    "Link": "https://blog.evanricafort.com/2015/12/arbitary-file-upload-vulnerability-in.html"
                 }
              ],
              "Authors": ["Evan Ricafort (@evanricafort)"],
              "Programs": ["Google"],
              "Bugs": ["Unrestricted file upload", "Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2015-12-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How To Hack PayU – And Buy 10x More For The Same Price",
                    "Link": "https://web.archive.org/web/20180322133921/http://codel10n.com/how-to-hack-payu-buy-10x-more-same-price/"
                 }
              ],
              "Authors": ["Rick Harris (@codel10n)"],
              "Programs": ["PayU"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2015-12-18",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "AMF parsing and XXE",
                  "Link": "https://www.agarri.fr/blog/archives/2015/12/17/amf_parsing_and_xxe/index.html"
               }
            ],
            "Authors": ["Nicolas Grégoire (@Agarri_FR)"],
            "Programs": ["BlazeDS", "PyAMF"],
            "Bugs": ["XXE"],
            "Bounty": "-",
            "PublicationDate": "2015-11-16",
            "AddedDate": "2024-02-06"
         },
           {
              "Links": [
                 {
                    "Title": "Cloudflare WAF XSS",
                    "Link": "https://ahussam.me/Cloudflare-xss/"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["Cloudflare"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2015-11-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS to RCE in Atlassian Hipchat",
                    "Link": "https://maustin.net/2015/11/12/hipchat_rce.html"
                 }
              ],
              "Authors": ["Matt Austin (@mattaustin)"],
              "Programs": ["Atlassian"],
              "Bugs": ["XSS", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2015-11-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Open Redirect in Linkedin and Yahoo",
                    "Link": "https://medium.com/@r0t1v/open-redirect-in-linkedin-and-yahoo-a3ffd2a9cc48"
                 }
              ],
              "Authors": ["Vitor “r0t” Oliveira (@r0t1v)"],
              "Programs": ["LinkedIn", "Yahoo! / Verizon Media"],
              "Bugs": ["Open redirect"],
              "Bounty": "-",
              "PublicationDate": "2015-09-24",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS vulnerability in Google image search",
                    "Link": "http://mahmoudsec.blogspot.com/2015/09/how-i-found-xss-vulnerability-in-google.html"
                 }
              ],
              "Authors": ["Mahmoud Gamal (@Zombiehelp54)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2015-09-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS to RCE in ...",
                    "Link": "https://matatall.com/xss/rce/bugbounty/2015/09/08/xss-to-rce.html"
                 }
              ],
              "Authors": ["Neil Hakuna Matatall (@ndm)"],
              "Programs": ["-"],
              "Bugs": ["XSS", "RCE"],
              "Bounty": "-",
              "PublicationDate": "2015-09-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "CVE-2014-7216: A Journey Through Yahoo’s Bug Bounty Program",
                    "Link": "https://www.rcesecurity.com/2015/09/cve-2014-7216-a-journey-through-yahoos-bug-bounty-program/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Buffer Overflow", "Memory corruption"],
              "Bounty": "-",
              "PublicationDate": "2015-09-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hacking Facebook Pages",
                    "Link": "https://thezerohack.com/hacking-facebook-pages"
                 }
              ],
              "Authors": ["Laxman Muthiyah (@LaxmanMuthiyah)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Privilege escalation", "Broken Access Control"],
              "Bounty": "2,500",
              "PublicationDate": "2015-08-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "One Payload to XSS Them All!",
                    "Link": "https://ahussam.me/One-payload-to-xss-them/"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["Adobe"],
              "Bugs": ["Flash XSS"],
              "Bounty": "-",
              "PublicationDate": "2015-08-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Blind SQL Inejction [Hootsuite]",
                    "Link": "https://ahussam.me/Blind-sqli-Hootsuite/"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["Hootsuite"],
              "Bugs": ["Blind SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2015-08-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypassing Google Authentication on Periscope's Administration Panel",
                    "Link": "https://whitton.io/articles/bypassing-google-authentication-on-periscopes-admin-panel/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Google"],
              "Bugs": ["Authentication bypass"],
              "Bounty": "-",
              "PublicationDate": "2015-07-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The easiest bug bounties I have ever won",
                    "Link": "https://josipfranjkovic.blogspot.com/2015/07/the-easiest-bug-bounties-i-have-ever-won.html"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2015-07-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "[Responsible disclosure] How I could have hacked 62.5 million Zomato Users",
                    "Link": "https://web.archive.org/web/20200313201545/http://www.anandpraka.sh/2015/06/how-i-hacked-zomatocom-to-see-data-of.html"
                 }
              ],
              "Authors": ["Anand Prakash (@anandpraka_sh)"],
              "Programs": ["Zomato"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2015-06-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Bypass ad account roles vulnerability 2015",
                    "Link": "https://blog.darabi.me/2015/03/facebook-bypass-ads-account-roles.html"
                 }
              ],
              "Authors": ["Pouya Darabi (@Pouyadarabi)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "8,000",
              "PublicationDate": "2015-05-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Race conditions on Facebook, DigitalOcean and others (fixed)",
                    "Link": "https://josipfranjkovic.blogspot.com/2015/04/race-conditions-on-facebook.html"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook", "DigitalOcean", "LastPass"],
              "Bugs": ["Race condition"],
              "Bounty": "-",
              "PublicationDate": "2015-04-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I bypassed Facebook CSRF Protection",
                    "Link": "https://blog.darabi.me/2015/04/bypass-facebook-csrf.html"
                 }
              ],
              "Authors": ["Pouya Darabi (@Pouyadarabi)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "15,000",
              "PublicationDate": "2015-09-04",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Telegram App Store Secret-Chat Messages in Plain-Text Database",
                    "Link": "https://blog.zimperium.com/telegram-hack/"
                 }
              ],
              "Authors": ["Jon Paterson (@shellprompt)"],
              "Programs": ["Telegram"],
              "Bugs": ["Privacy issue", "Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2015-02-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Neglected DNS records exploited to takeover subdomains",
                    "Link": "https://web.archive.org/web/20210423154459/https://yassineaboukir.com/blog/neglected-dns-records-exploited-to-takeover-subdomains/"
                 }
              ],
              "Authors": ["Yassine Aboukir (@Yassineaboukir)"],
              "Programs": ["Heroku"],
              "Bugs": ["Subdomain takeover"],
              "Bounty": "-",
              "PublicationDate": "2015-02-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google.com – Mobile Feedback URL Redirect Regex/Validation Flaw",
                    "Link": "https://buer.haus/2015/02/03/google-com-mobile-feedback-url-redirect-regexvalidation-flaw/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)"],
              "Programs": ["Google"],
              "Bugs": ["Open redirect"],
              "Bounty": "500",
              "PublicationDate": "2015-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Flickr API Explorer – Force users to execute any API request.",
                    "Link": "https://buer.haus/2015/02/03/flickr-api-explorer-force-users-to-execute-any-api-request/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)"],
              "Programs": ["Flickr"],
              "Bugs": ["CSRF"],
              "Bounty": "100",
              "PublicationDate": "2015-02-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "admin.google.com Reflected Cross-Site Scripting (XSS)",
                    "Link": "https://buer.haus/2015/01/21/admin-google-com-reflected-cross-site-scripting-xss/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)"],
              "Programs": ["Google"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2015-01-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "vimeo IDOR ( buying pro membership & ondemand videos for 0.1$ )",
                    "Link": "http://nbsriharsha.blogspot.com/2015/01/vimeo-buying-pro-membership-ondemand.html"
                 }
              ],
              "Authors": ["N B Sri Harsha (@nbsriharsha)"],
              "Programs": ["Vimeo"],
              "Bugs": ["IDOR"],
              "Bounty": "-",
              "PublicationDate": "2015-01-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Yahoo – Root Access SQL Injection – tw.yahoo.com",
                    "Link": "https://buer.haus/2015/01/15/yahoo-root-access-sql-injection-tw-yahoo-com/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2015-01-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Papyal XML Upload Cross Site Scripting Vulnerability",
                    "Link": "https://wss.sh/en/blog/bugbounty-papyal-xml-upload-cross-site-scripting-vulnerability/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["Paypal"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2015-01-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I discovered a 1000$ open redirect in Facebook",
                    "Link": "https://www.yassineaboukir.com/blog/how-I-discovered-a-1000$-open-redirect-in-facebook/"
                 }
              ],
              "Authors": ["Yassine Aboukir (@Yassineaboukir)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "1,000",
              "PublicationDate": "2014-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected Cross Site Scripting at Paypal.com",
                    "Link": "https://wss.sh/en/blog/bugbounty-reflected-cross-site-scripting-at-paypal-com/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["Paypal"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2014-12-15",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Malicious redirect on mailroom.prezi.com",
                    "Link": "https://wss.sh/en/blog/bugbounty-malicious-redirect-on-mailroom-prezi-com/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["Prezi"],
              "Bugs": ["Open redirect"],
              "Bounty": "500",
              "PublicationDate": "2014-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "AliExpress XSS vulnerability - take over any seller account",
                    "Link": "https://quitten.github.io/Aliexpress/"
                 }
              ],
              "Authors": ["Barak Tawily (@quitten11)"],
              "Programs": ["Alibaba"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2014-12-10",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reading local files from Facebook's server (fixed)",
                    "Link": "https://josipfranjkovic.blogspot.com/2014/12/reading-local-files-from-facebooks.html"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["LFI", "Unrestricted file upload"],
              "Bounty": "-",
              "PublicationDate": "2014-12-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Bug Bounty: Nice Catch on Google Cloud Platform Live",
                    "Link": "https://www.rcesecurity.com/2014/11/google-bug-bounty-nice-catch-on-google-cloud-platform-live"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["Google"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2014-11-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Reflected Cross Site Scripting BillMeLater",
                    "Link": "https://wss.sh/en/blog/bugbounty-reflected-cross-site-scripting-billmelater/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["BillMeLater"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2014-11-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Paypal stored XSS + Security bypass",
                    "Link": "https://wss.sh/en/blog/bugbounty-paypal-stored-xss-security-bypass/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["Paypal"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2014-11-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Paypal DOM XSS main domain",
                    "Link": "https://blog.it-securityguard.com/bugbounty-paypal-dom-xss-main-domain/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["Paypal"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2014-11-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "The 5000$ Google XSS",
                    "Link": "https://wss.sh/en/blog/bugbounty-the-5000-google-xss/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "5,000",
              "PublicationDate": "2014-10-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook Bug Bounty: secondary damage (revisited) why I really like reporting to Facebook too :)",
                    "Link": "https://philippeharewood.com/facebook-bug-bounty-secondary-damage-revisited-why-i-really-like-reporting-to-facebook-too/"
                 }
              ],
              "Authors": ["Philippe Harewood (@phwd)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2014-10-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Yahoo phpinfo.php disclosure",
                    "Link": "https://wss.sh/en/blog/bugbounty-yahoo-phpinfo-php-disclosure-2/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["Yahoo! / Verizon Media"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2014-10-16",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Bypassing blacklists based on IPy",
                  "Link": "https://www.agarri.fr/blog/archives/2014/10/15/bypassing_blacklists_based_on_ipy/index.html"
               }
            ],
            "Authors": ["Nicolas Grégoire (@Agarri_FR)"],
            "Programs": ["Prezi", "autocracy (python-ipy)"],
            "Bugs": ["IP address validation bypass"],
            "Bounty": "500",
            "PublicationDate": "2014-10-15",
            "AddedDate": "2024-02-06"
         },
           {
            "Links": [
               {
                  "Title": "Trying to hack Redis via HTTP requests",
                  "Link": "https://www.agarri.fr/blog/archives/2014/09/11/trying_to_hack_redis_via_http_requests/index.html"
               }
            ],
            "Authors": ["Nicolas Grégoire (@Agarri_FR)"],
            "Programs": ["Meta / Facebook"],
            "Bugs": ["SSRF", "CRLF injection", "RCE"],
            "Bounty": "20,000",
            "PublicationDate": "2014-09-11",
            "AddedDate": "2024-02-06"
         },
           {
              "Links": [
                 {
                    "Title": "Step-by-step: exploiting SQL injection(s) in Oculus' website.",
                    "Link": "https://josipfranjkovic.blogspot.com/2014/09/step-by-step-exploiting-sql-injection.html"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2014-09-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Popping a shell on the Oculus developer portal",
                    "Link": "https://bitquark.co.uk/blog/2014/08/31/popping_a_shell_on_the_oculus_developer_portal"
                 }
              ],
              "Authors": ["Bitquark (@bitquark)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["SQL injection", "CSRF", "RCE", "IDOR"],
              "Bounty": "30,000",
              "PublicationDate": "2014-08-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Flickr XSRF to Change Photo Details",
                    "Link": "https://ahussam.me/Flickr-CSRF/"
                 }
              ],
              "Authors": ["Abdullah Hussam (@Abdulahhusam)"],
              "Programs": ["Flickr"],
              "Bugs": ["XSRF"],
              "Bounty": "-",
              "PublicationDate": "2014-08-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook – Stored Cross-Site Scripting (XSS) – Badges",
                    "Link": "https://buer.haus/2014/06/16/facebook-stored-cross-site-scripting-xss-badges/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Stored XSS"],
              "Bounty": "-",
              "PublicationDate": "2014-06-16",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "ebay bug bounty",
                    "Link": "https://thehackerblog.com/ebay-mobile-reflected-xss-disclosure-writeup/index.html"
                 }
              ],
              "Authors": ["Matthew Bryant (@IAmMandatory)"],
              "Programs": ["Ebay"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "-",
              "PublicationDate": "2014-06-06",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Prezi (map.prezi.com) Path Traversal",
                    "Link": "https://wss.sh/en/blog/bug-bounty-prezi-map-prezi-com-path-traversal/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["Prezi"],
              "Bugs": ["Path traversal"],
              "Bounty": "1,000",
              "PublicationDate": "2014-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Docs 'ClickJacking' (Information Disclosure)",
                    "Link": "https://maustin.net/google_docs"
                 }
              ],
              "Authors": ["Matt Austin (@mattaustin)"],
              "Programs": ["Google"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2014-05-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Magix Bug Bounty: magix.com (RCE, SQLi) and xara.com (LFI, XSS)",
                    "Link": "https://www.rcesecurity.com/2014/04/magix-bug-bounty-magix-com-rce-sqli-and-xara-com-lfi-xss/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["Magix"],
              "Bugs": ["RCE", "SQL injection", "LFI", "XSS"],
              "Bounty": "-",
              "PublicationDate": "2014-04-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "A Tale of 7 Vulnerabilities",
                    "Link": "https://wss.sh/en/blog/a-tale-of-7-vulnerabilities-paypal-bug-bounty/"
                 }
              ],
              "Authors": ["Patrik Fehrenbach (@ITSecurityguard)"],
              "Programs": ["Paypal"],
              "Bugs": ["Stored XSS", "Reflected XSS", "Default credentials", "Privilege escalation"],
              "Bounty": "-",
              "PublicationDate": "2014-04-20",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook – Send Notifications to any User Exploit",
                    "Link": "https://buer.haus/2014/04/07/facebook-send-notifications-to-any-user-exploit/"
                 }
              ],
              "Authors": ["Brett Buerhaus (@bbuerhaus)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Logic flaw"],
              "Bounty": "-",
              "PublicationDate": "2014-04-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Exploit – Steal Account Login Email Addresses",
                    "Link": "http://www.tomanthony.co.uk/blog/google-exploit-steal-login-email-addresses/"
                 }
              ],
              "Authors": ["Tom Anthony (@TomAnthonySEO)"],
              "Programs": ["Google"],
              "Bugs": ["Information disclosure"],
              "Bounty": "1,337",
              "PublicationDate": "2014-03-08",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Tesla Motors blind SQL injection",
                    "Link": "https://bitquark.co.uk/blog/2014/02/23/tesla_motors_blind_sql_injection"
                 }
              ],
              "Authors": ["Bitquark (@bitquark)"],
              "Programs": ["Tesla"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2014-02-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "GitHub RCE Writeup",
                    "Link": "https://0day.click/recipe/2014-02-22-github/"
                 }
              ],
              "Authors": ["joernchen (@joernchen)"],
              "Programs": ["GitHub"],
              "Bugs": ["RCE"],
              "Bounty": "-",
              "PublicationDate": "2014-02-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I was able to track the location of any Tinder user.",
                    "Link": "https://blog.includesecurity.com/2014/02/how-i-was-able-to-track-the-location-of-any-tinder-user/"
                 }
              ],
              "Authors": ["Max Veytsman (@mveytsman)"],
              "Programs": ["Tinder"],
              "Bugs": ["Information disclosure"],
              "Bounty": "-",
              "PublicationDate": "2014-02-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I hacked Github again.",
                    "Link": "http://homakov.blogspot.com/2014/02/how-i-hacked-github-again.html"
                 }
              ],
              "Authors": ["Egor Homakov (@homakov)"],
              "Programs": ["GitHub"],
              "Bugs": ["Open redirect", "Account takeover", "Information disclosure"],
              "Bounty": "4,000",
              "PublicationDate": "2014-02-07",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google Sites: A Tale of Five Vulnerabilities",
                    "Link": "https://bitquark.co.uk/blog/2013/12/30/google_sites_a_tale_of_five_vulnerabilities"
                 }
              ],
              "Authors": ["Bitquark (@bitquark)"],
              "Programs": ["Google"],
              "Bugs": ["XSS", "LFI", "HTML injection"],
              "Bounty": "13,034.80",
              "PublicationDate": "2013-12-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Waze arbitrary file upload",
                    "Link": "http://blog.shashank.co/2013/12/waze-arbitrary-file-upload.html"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["Google (Waze)"],
              "Bugs": ["Unrestricted file upload", "XSS"],
              "Bounty": "100",
              "PublicationDate": "2013-12-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Imgur xss",
                    "Link": "http://blog.shashank.co/2013/12/imgur-xss.html"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["Imgur"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-12-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Flickr XSS (Stored / DOM XSS)",
                    "Link": "https://maustin.net/articles/2013-12/flickr_xss"
                 }
              ],
              "Authors": ["Matt Austin (@mattaustin)"],
              "Programs": ["Flickr"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-12-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Abusing CORS for an XSS on Flickr",
                    "Link": "https://whitton.io/articles/abusing-cors-for-an-xss-on-flickr/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Flickr"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-12-12",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Heroku Directory Transversal",
                    "Link": "http://blog.shashank.co/2013/12/heroku-directory-transversal.html"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["Heroku"],
              "Bugs": ["Path traversal"],
              "Bounty": "-",
              "PublicationDate": "2013-12-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "XSS - Google Groups (groups.google.com) - Vulnerability Reward Program",
                    "Link": "http://manuel-sousa.blogspot.com/2013/11/xss-google-groups-groupsgooglecom.html"
                 }
              ],
              "Authors": ["Manuel Sousa (@manuelvsousa)"],
              "Programs": ["Google"],
              "Bugs": ["Reflected XSS"],
              "Bounty": "3,133.7",
              "PublicationDate": "2013-11-30",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Compromising an unreachable Solr server with CVE-2013-6397",
                  "Link": "https://www.agarri.fr/blog/archives/2013/11/27/compromising_an_unreachable_solr_server_with_cve-2013-6397/index.html"
               }
            ],
            "Authors": ["Nicolas Grégoire (@Agarri_FR)"],
            "Programs": ["Apache Solr"],
            "Bugs": ["XXE", "Path traversal", "XSLT injection", "RCE"],
            "Bounty": "-",
            "PublicationDate": "2013-11-27",
            "AddedDate": "2024-02-06"
         },
           {
              "Links": [
                 {
                    "Title": "Oracle xss",
                    "Link": "http://blog.shashank.co/2013/11/oracle-xss.html"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["Oracle"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-11-17",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Instagram's One-Click Privacy Switch",
                    "Link": "https://whitton.io/articles/instagrams-one-click-privacy-switch/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2013-10-31",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Nokia email app pwnage",
                    "Link": "http://blog.shashank.co/2013/10/nokia-email-app-pwnage.html"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["Nokia"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "LFI in Nokia maps",
                    "Link": "http://blog.shashank.co/2013/10/lfi-in-nokia-maps.html"
                 }
              ],
              "Authors": ["Shashank (@cyberboyIndia)"],
              "Programs": ["Nokia"],
              "Bugs": ["LFI"],
              "Bounty": "-",
              "PublicationDate": "2013-10-22",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook bug bounty: secondary damage (one report that leads to more bugs), fairness, and why I really like reporting to Facebook",
                    "Link": "https://josipfranjkovic.blogspot.com/2013/11/facebook-bug-bounty-secondary-damage.html"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF"],
              "Bounty": "-",
              "PublicationDate": "2013-10-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Content Types and XSS: Facebook Studio",
                    "Link": "https://whitton.io/articles/content-types-and-xss-facebook-studio/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-10-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Facebook CSRF leading to full account takeover (fixed)",
                    "Link": "https://www.josipfranjkovic.com/blog/facebook-csrf-full-account-takeover"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF", "Account takeover"],
              "Bounty": "8,450",
              "PublicationDate": "2013-10-18",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PayPal Bug Bounty: PayPaltech.com E-Mail Injection",
                    "Link": "https://www.rcesecurity.com/2013/09/paypal-bug-bounty-paypaltech-com-e-mail-injection/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["Paypal"],
              "Bugs": ["Email injection"],
              "Bounty": "-",
              "PublicationDate": "2013-09-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Removing Covers Images on Friendship Pages, on Facebook",
                    "Link": "https://whitton.io/articles/removing-covers-images-on-friendship-pages-on-facebook/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2013-09-25",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Delete any Photo from Facebook by Exploiting Support Dashboard - $12,500 Bug",
                    "Link": "https://arulkumar.in/delete-any-photo-from-facebook-by-exploiting-support-dashboard"
                 }
              ],
              "Authors": ["Arul Kumar (@ArulVaiyapuri)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["IDOR"],
              "Bounty": "12,500",
              "PublicationDate": "2013-09-01",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Multiple Open URL Redirection Vulnerability on Facebook worth $1500",
                    "Link": "https://arulkumar.in/multiple-open-url-redirection-vulnerability-in-facebook-worth-1500/"
                 }
              ],
              "Authors": ["Arul Kumar (@ArulVaiyapuri)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Open redirect"],
              "Bounty": "1,500",
              "PublicationDate": "2022-08-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "SQL injections in Nokia sites.",
                    "Link": "https://josipfranjkovic.blogspot.com/2013/07/sql-injections-in-nokia-sites.html"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Nokia"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2013-07-30",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I found my way into Instagram's Ganglia, and a bug with Facebook likes.",
                    "Link": "https://josipfranjkovic.blogspot.com/2013/07/how-i-found-my-way-into-instagrams.html"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Reflected XSS", "IDOR"],
              "Bounty": "-",
              "PublicationDate": "2013-07-23",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Admob creative image cross-site scripting vulnerability",
                    "Link": "https://bitquark.co.uk/blog/2013/07/19/admob_creative_image_xss"
                 }
              ],
              "Authors": ["Bitquark (@bitquark)"],
              "Programs": ["Google"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-07-19",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Amazon packaging feedback cross-site scripting vulnerability",
                    "Link": "https://bitquark.co.uk/blog/2013/07/03/amazon_packaging_feedback_xss"
                 }
              ],
              "Authors": ["Bitquark (@bitquark)"],
              "Programs": ["Amazon"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-07-03",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Hijacking a Facebook Account with SMS",
                    "Link": "https://whitton.io/articles/hijacking-a-facebook-account-with-sms/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["Broken authorization", "Account takeover"],
              "Bounty": "20,000",
              "PublicationDate": "2013-06-26",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Overwriting Banner Images on Etsy",
                    "Link": "https://whitton.io/articles/overwriting-banner-images-on-etsy/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Etsy"],
              "Bugs": ["Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2013-05-21",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "PayPal Bug Bounty: PayPaltech.com XSS",
                    "Link": "https://www.rcesecurity.com/2013/04/paypal-bug-bounty-paypaltech-com-xss/"
                 }
              ],
              "Authors": ["Julien Ahrens (@MrTuxracer)"],
              "Programs": ["Paypal"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Stealing Facebook Access Tokens with a Double Submit",
                    "Link": "https://whitton.io/articles/stealing-facebook-access-tokens-with-a-double-submit/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Meta / Facebook"],
              "Bugs": ["CSRF", "OAuth"],
              "Bounty": "-",
              "PublicationDate": "2013-04-13",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "How I Rewarded with USD?K Just With a Simple Search Form",
                    "Link": "http://c0rni3sm.blogspot.com/2013/04/how-i-rewarded-with-usdk-just-with.html"
                 }
              ],
              "Authors": ["yappare (@yappare)"],
              "Programs": ["Paypal"],
              "Bugs": ["SQL injection"],
              "Bounty": "-",
              "PublicationDate": "2013-04-11",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "DOM Based XSS In AVG",
                    "Link": "http://www.rafayhackingarticles.net/2013/02/dom-based-xss-in-avg.html"
                 }
              ],
              "Authors": ["Rafay Baloch (@rafaybaloch)", "David Vieira-Kurz (@secalert)"],
              "Programs": ["AVG"],
              "Bugs": ["DOM XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-02-26",
              "AddedDate": "2022-09-15"
           },
           {
            "Links": [
               {
                  "Title": "Mutation-based fuzzing of XSLT engines",
                  "Link": "https://www.agarri.fr/blog/archives/2013/02/25/mutation-based_fuzzing_of_xslt_engines/index.html"
               }
            ],
            "Authors": ["Nicolas Grégoire (@Agarri_FR)"],
            "Programs": ["Intel", "Mozilla (Firefox)", "Adobe (Reader)", "libxslt", "Microsoft (MSXML)", "Google (Chrome & Chromium)"],
            "Bugs": ["Memory corruption", "Fuzzing", "Heap buffer overflow", "Use-After-Free", "NULL pointer dereference", "Out-of-bounds Read"],
            "Bounty": "-",
            "PublicationDate": "2013-02-25",
            "AddedDate": "2024-02-06"
         },
           {
              "Links": [
                 {
                    "Title": "Framing, Part 1: Click-Jacking Etsy",
                    "Link": "https://whitton.io/archive/framing-part-1-click-jacking-etsy"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Etsy"],
              "Bugs": ["Clickjacking"],
              "Bounty": "-",
              "PublicationDate": "2013-02-05",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Persistent XSS on myworld.ebay.com",
                    "Link": "https://whitton.io/archive/persistent-xss-on-myworld-ebay-com/"
                 }
              ],
              "Authors": ["Jack Whitton (@fin1te)"],
              "Programs": ["Ebay"],
              "Bugs": ["XSS"],
              "Bounty": "-",
              "PublicationDate": "2013-01-27",
              "AddedDate": "2022-09-15"
           },
           {
              "Links": [
                 {
                    "Title": "Google.com cross site scripting and privilege escalation in Consumer Surveys",
                    "Link": "https://josipfranjkovic.blogspot.com/2013/01/googlecom-cross-site-scripting-and.html"
                 }
              ],
              "Authors": ["Josip Franjkovic (@josipfranjkovic)"],
              "Programs": ["Google"],
              "Bugs": ["Stored XSS", "Broken authorization"],
              "Bounty": "-",
              "PublicationDate": "2013-01-03",
              "AddedDate": "2022-09-15"
           },
           {
          "Links": [
            {
               "Title": "My Experience with the PayPal Bug Bounty Programme",
               "Link": "https://whitton.io/archive/my-experience-with-the-paypal-bug-bounty-programme/"
            }
           ],
          "Authors": ["Jack Whitton (@fin1te)"],
          "Programs": ["Paypal"],
          "Bugs": ["CSRF"],
          "Bounty": "750",
          "PublicationDate": "2012-10-12",
          "AddedDate": "2022-09-15"
         },
         {
            "Links": [
              {
                 "Title": "All your PostgreSQL databases are belong to us",
                 "Link": "https://www.agarri.fr/blog/archives/2012/08/28/all_your_postgresql_databases_are_belong_to_us/index.html"
              }
             ],
            "Authors": ["Nicolas Grégoire (@Agarri_FR)"],
            "Programs": ["PostgreSQL", "libxslt"],
            "Bugs": ["XXE", "Privilege escalation"],
            "Bounty": "-",
            "PublicationDate": "2012-08-28",
            "AddedDate": "2024-02-06"
           },
         {
            "Links": [
              {
                 "Title": "SVG files and Java code execution",
                 "Link": "https://www.agarri.fr/blog/archives/2012/05/11/svg_files_and_java_code_execution/index.html"
              }
             ],
            "Authors": ["Nicolas Grégoire (@Agarri_FR)"],
            "Programs": ["Apache Batik"],
            "Bugs": ["Arbitrary code execution"],
            "Bounty": "-",
            "PublicationDate": "2012-05-11",
            "AddedDate": "2024-02-06"
           },
         {
            "Links": [
              {
                 "Title": "Compromising HP SAN appliances",
                 "Link": "https://www.agarri.fr/blog/archives/2012/02/17/compromising_hp_san_appliances/index.html"
              }
             ],
            "Authors": ["Nicolas Grégoire (@Agarri_FR)"],
            "Programs": ["HP"],
            "Bugs": ["Hardcoded credentials", "Reverse engineering", "Buffer Overflow"],
            "Bounty": "-",
            "PublicationDate": "2012-02-17",
            "AddedDate": "2024-02-06"
           },
         {
          "Links": [
            {
               "Title": "Facebook FBML DOM Traversal (Information Disclosure)",
               "Link": "https://maustin.net/articles/2011-08/FBML_dom_traversal"
            }
           ],
          "Authors": ["Matt Austin (@mattaustin)"],
          "Programs": ["Meta / Facebook"],
          "Bugs": ["Information disclosure"],
          "Bounty": "-",
          "PublicationDate": "2011-08-23",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Hacking Facebook with FBML and DOM",
               "Link": "https://maustin.net/articles/2010-07/facebook_fbml_xss"
            }
           ],
          "Authors": ["Matt Austin (@mattaustin)"],
          "Programs": ["Meta / Facebook"],
          "Bugs": ["XSS"],
          "Bounty": "-",
          "PublicationDate": "2010-07-18",
          "AddedDate": "2022-09-15"
         },
         {
          "Links": [
            {
               "Title": "Facebook XSS via Cross-Origin Resource Sharing",
               "Link": "https://maustin.net/articles/2010-07/facebook_html5"
            }
           ],
          "Authors": ["Matt Austin (@mattaustin)"],
          "Programs": ["Meta / Facebook"],
          "Bugs": ["XSS"],
          "Bounty": "-",
          "PublicationDate": "2010-07-06",
          "AddedDate": "2022-09-15"
        }
        
   ]
}


