Skip to content

Latest commit

 

History

History
102 lines (101 loc) · 13.7 KB

TOP100UPVOTED.md

File metadata and controls

102 lines (101 loc) · 13.7 KB

Top 100 upvoted reports from HackerOne:

  1. Takeover an account that doesn't have a Shopify ID and more to Shopify - 2904 upvotes, $0
  2. Bypass for #488147 enables stored XSS on https://paypal.com/signin again to PayPal - 2587 upvotes, $20000
  3. Email Confirmation Bypass in myshop.myshopify.com that Leads to Full Privilege Escalation to Any Shop Owner by Taking Advantage of the Shopify SSO to Shopify - 1840 upvotes, $16000
  4. Account takeover via leaked session cookie to HackerOne - 1541 upvotes, $20000
  5. Arbitrary file read via the UploadsRewriter when moving and issue to GitLab - 1451 upvotes, $20000
  6. Token leak in security challenge flow allows retrieving victim's PayPal email and plain text password to PayPal - 1353 upvotes, $15300
  7. RCE on Steam Client via buffer overflow in Server Info to Valve - 1271 upvotes, $0
  8. Potential pre-auth RCE on Twitter VPN to X (Formerly Twitter) - 1190 upvotes, $20160
  9. Github access token exposure to Shopify - 1161 upvotes, $50000
  10. Exposed Kubernetes API - RCE/Exposed Creds to Snapchat - 1134 upvotes, $25000
  11. Confidential data of users and limited metadata of programs and reports accessible via GraphQL to HackerOne - 996 upvotes, $0
  12. Improper Authentication - any user can login as other user with otp/logout & otp/login to Snapchat - 916 upvotes, $0
  13. [Part II] Email Confirmation Bypass in myshop.myshopify.com that Leads to Full Privilege Escalation to Shopify - 877 upvotes, $15000
  14. RCE via npm misconfig -- installing internal libraries from the public registry to PayPal - 849 upvotes, $30000
  15. Mass account takeovers using HTTP Request Smuggling on https://slackb.com/ to steal session cookies to Slack - 835 upvotes, $0
  16. DoS on PayPal via web cache poisoning to PayPal - 820 upvotes, $9700
  17. H1514 Remote Code Execution on kitcrm using bulk customer update of Priority Products to Shopify - 817 upvotes, $0
  18. WannaCrypt “Killswitch” to HackerOne - 801 upvotes, $0
  19. Remote Code Execution on www.semrush.com/my_reports on Logo upload to Semrush - 800 upvotes, $0
  20. Git flag injection - local file overwrite to remote code execution to GitLab - 762 upvotes, $12000
  21. SQL Injection Extracts Starbucks Enterprise Accounting, Financial, Payroll Database to Starbucks - 757 upvotes, $0
  22. Websites Can Run Arbitrary Code on Machines Running the 'PlayStation Now' Application to PlayStation - 754 upvotes, $15000
  23. Subdomain Takeover to Authentication bypass to Roblox - 746 upvotes, $0
  24. Exfiltrate and mutate repository and project data through injected templated service to GitLab - 733 upvotes, $11000
  25. IDOR to add secondary users in www.paypal.com/businessmanage/users/api/v1/users to PayPal - 720 upvotes, $10500
  26. Use-After-Free In IPV6_2292PKTOPTIONS leading To Arbitrary Kernel R/W Primitives to PlayStation - 716 upvotes, $10000
  27. JumpCloud API Key leaked via Open Github Repository. to Starbucks - 715 upvotes, $0
  28. Delete anyone's content spotlight remotely. to Snapchat - 696 upvotes, $15000
  29. SQL injection in https://labs.data.gov/dashboard/datagov/csv_to_json via User-agent to GSA Bounty - 679 upvotes, $0
  30. 🐞 OS Command Injection at https://sea-web.gold.razer.com/lab/ws-lookup via IP parameter to Razer - 676 upvotes, $2000
  31. Webshell via File Upload on ecjobs.starbucks.com.cn to Starbucks - 675 upvotes, $0
  32. Stored XSS on https://paypal.com/signin via cache poisoning to PayPal - 660 upvotes, $18900
  33. My Expense Report resulted in a Server-Side Request Forgery (SSRF) on Lyft to Lyft - 649 upvotes, $0
  34. Reflected XSS on https://www.glassdoor.com/employers/sem-dual-lp/ to Glassdoor - 643 upvotes, $0
  35. Email address of any user can be queried on Report Invitation GraphQL type when username is known to HackerOne - 632 upvotes, $0
  36. Time-Based SQL injection at city-mobil.ru to Mail.ru - 631 upvotes, $15000
  37. Sensitive user information disclosure at bonjour.uber.com/marketplace/_rpc via the 'userUuid' parameter to Uber - 622 upvotes, $0
  38. Getting all the CD keys of any game to Valve - 612 upvotes, $20000
  39. [phpobject in cookie] Remote shell/command execution to Pornhub - 607 upvotes, $20000
  40. Ability to reset password for account to Upserve - 605 upvotes, $0
  41. Stored XSS in Wiki pages to GitLab - 600 upvotes, $0
  42. Stored XSS on imgur profile to Imgur - 592 upvotes, $0
  43. Bypassing Digits origin validation which leads to account takeover to X (Formerly Twitter) - 592 upvotes, $0
  44. SQL injection at https://sea-web.gold.razer.com/ajax-get-status.php via txid parameter to Razer - 580 upvotes, $2000
  45. Github Token Leaked publicly for https://github.sc-corp.net to Snapchat - 572 upvotes, $0
  46. Customer private program can disclose email any users through invited via username to HackerOne - 568 upvotes, $7500
  47. Request smuggling on admin-official.line.me could lead to account takeover to LY Corporation - 556 upvotes, $0
  48. RCE and Complete Server Takeover of http://www.█████.starbucks.com.sg/ to Starbucks - 551 upvotes, $0
  49. Publicly accessible Continuous Integration Tool to Snapchat - 550 upvotes, $0
  50. Stealing Zomato X-Access-Token: in Bulk using HTTP Request Smuggling on api.zomato.com to Zomato - 545 upvotes, $0
  51. The return of the < to Rockstar Games - 543 upvotes, $1000
  52. Privilege Escalation From user to SYSTEM via unauthenticated command execution to Ubiquiti Inc. - 541 upvotes, $0
  53. SSRF in Exchange leads to ROOT access in all instances to Shopify - 540 upvotes, $0
  54. Email Confirmation Bypass in your-store.myshopify.com which leads to privilege escalation to Shopify - 537 upvotes, $0
  55. Local files could be overwritten in GitLab, leading to remote command execution to GitLab - 536 upvotes, $12000
  56. SQL Injection in https://api-my.pay.razer.com/inviteFriend/getInviteHistoryLog to Razer - 528 upvotes, $2000
  57. [Grab Android/iOS] Insecure deeplink leads to sensitive information disclosure to Grab - 525 upvotes, $0
  58. BAD Code ! to Paragon Initiative Enterprises - 522 upvotes, $0
  59. Shopify Stocky App OAuth Misconfiguration to Shopify - 514 upvotes, $0
  60. Password theft login.newrelic.com via Request Smuggling to New Relic - 490 upvotes, $3000
  61. Able to Become Admin for Any LINE Official Account to LY Corporation - 487 upvotes, $4750
  62. Remote Code Execution in Slack desktop apps + bonus to Slack - 486 upvotes, $0
  63. RCE when removing metadata with ExifTool to GitLab - 485 upvotes, $20000
  64. Reflected XSS in OAUTH2 login flow to LY Corporation - 474 upvotes, $1989
  65. SQL injection on contactws.contact-sys.com in TScenObject action ScenObjects leads to remote code execution to QIWI - 473 upvotes, $0
  66. profile-picture name parameter with large value lead to DoS for other users and programs on the platform to HackerOne - 464 upvotes, $0
  67. XSS in steam react chat client to Valve - 463 upvotes, $7500
  68. Steal ALL collateral during liquidation by exploiting lack of validation in flip.kick to BlockDev Sp. Z o.o - 461 upvotes, $0
  69. One-click account hijack for anyone using Apple sign-in with Reddit, due to response-type switch + leaking href to XSS on www.redditmedia.com to Reddit - 456 upvotes, $0
  70. How the Bug stole hacking to HackerOne - 455 upvotes, $0
  71. Cross-Site-Scripting on www.tiktok.com and m.tiktok.com leading to Data Exfiltration to TikTok - 452 upvotes, $0
  72. Access to multiple production Grafana dashboards to Snapchat - 448 upvotes, $10000
  73. XSS vulnerable parameter in a location hash to Slack - 443 upvotes, $0
  74. Project Template functionality can be used to copy private project data, such as repository, confidential issues, snippets, and merge requests to GitLab - 439 upvotes, $12000
  75. Blind SQL Injection to InnoGames - 432 upvotes, $2000
  76. CRLF injection to X (Formerly Twitter) - 429 upvotes, $0
  77. Server Side Request Forgery (SSRF) via Analytics Reports to HackerOne - 426 upvotes, $25000
  78. Open prod Jenkins instance to Snapchat - 425 upvotes, $15000
  79. Blind XSS on image upload to CS Money - 420 upvotes, $1000
  80. RCE via unsafe inline Kramdown options when rendering certain Wiki pages to GitLab - 414 upvotes, $20000
  81. June 2022 Incident Report to HackerOne - 412 upvotes, $0
  82. touch.mail.ru / e.mail.ru memory content disclosure to Mail.ru - 409 upvotes, $10000
  83. Remote code execution on Basecamp.com to Basecamp - 409 upvotes, $5000
  84. Panorama UI XSS leads to Remote Code Execution via Kick/Disconnect Message to Valve - 408 upvotes, $0
  85. Modify in-flight data to payment provider Smart2Pay to Valve - 405 upvotes, $7500
  86. Chained Bugs to Leak Victim's Uber's FB Oauth Token to Uber - 404 upvotes, $7500
  87. Unrestricted file upload on [ambassador.mail.ru] to Mail.ru - 404 upvotes, $3000
  88. Flickr Account Takeover using AWS Cognito API to Flickr - 403 upvotes, $0
  89. H1514 Server Side Template Injection in Return Magic email templates? to Shopify - 401 upvotes, $0
  90. gitlab-workhorse bypass in Gitlab::Middleware::Multipart allowing files in allowed_paths to be read to GitLab - 400 upvotes, $10000
  91. Reset password link sent over unsecured http protocol to Mattermost - 400 upvotes, $750
  92. Stored XSS Vulnerability to WordPress - 397 upvotes, $0
  93. Read-only application can publish/delete fleets to X (Formerly Twitter) - 395 upvotes, $0
  94. Employee's GitHub Token Found In Travis CI Build Logs to Grammarly - 394 upvotes, $5000
  95. Account Takeover worki.ru to Mail.ru - 391 upvotes, $1700
  96. An attacker can can view any hacker email via /SaveCollaboratorsMutation operation name to HackerOne - 391 upvotes, $0
  97. Denial of service to WP-JSON API by cache poisoning the CORS allow origin header to Automattic - 389 upvotes, $0
  98. Server-Side Request Forgery using Javascript allows to exfill data from Google Metadata to Snapchat - 388 upvotes, $0
  99. Full account takeover to Reverb.com - 387 upvotes, $0
  100. CVE-2019-5765: 1-click HackerOne account takeover on all Android devices to Chrome - 374 upvotes, $0