Skip to main content

Security

2023

Full Passcode bypass on Nextcloud App iOS
·1 min· 0 · 0
Nextcloud bugbounty CVE-2023-28647
Ability to read any emails through IDOR on Nextcloud Mail
·1 min· 0 · 0
Nextcloud bugbounty CVE-2023-25160
Messages can still be seen on conversation after expiring when cron is misconfigured
·1 min· 0 · 0
Nextcloud bugbounty CVE-2023-26041
Ability to control the filename when uploading a logo or favicon on theming
·1 min· 0 · 0
Nextcloud bugbounty CVE-2023-28833
Passcode bypass on Talk Android app
·1 min· 0 · 0
Nextcloud bugbounty CVE-2023-22473

2022

File and Chat disclosure by calling the device while its in locked state
·1 min· 0 · 0
Nextcloud bugbounty CVE-2021-41181
Nextcloud Talk ObjectId in share location can be set to open arbitrary URL or Deeplinks
·1 min· 0 · 0
Nextcloud bugbounty CVE-2021-41180

2021

Sophos Secure Workspace App Password Bypass using Race Condition
·2 mins· 0 · 0
Sophos bugbounty race condition Sophos Secure Workspace CVE-2021-36808

2020

Breaking the Doors: Paypal 2-Factor Bypass
·1 min· 0 · 0
Paypal bugbounty Two Factor Authentication Bypass Paypal 2FA Bypass
404 Not Found: Vulnerability Disclosure in the Philippines
·3 mins· 0 · 0
Opinion Vulnerability Disclosure Philippines
CVE-2020-12832
·1 min· 0 · 0
Wordpress CVE-2020-12832 Path Traversal
Non-Verified User can Submit Report,View Disclosed Reports | Secuna bug bounty
·2 mins· 0 · 0
Secuna bugbounty

2019

Exposed S3 Credentials of QuadX
·2 mins· 0 · 0
quadx vdp hardcoded credentials
Rootcon CTF 2019 | Kahl Dereta Write Up
·1 min· 0 · 0
rootcon Capture The Flag
Insufficient Rate Limitting on Facebook Fundraisers
·1 min· 0 · 0
facebook bugbounty Insufficient Rate Limit
CVE-2019-5450
·1 min· 0 · 0
Nextcloud android bbp
CVE-2018-19937
·1 min· 0 · 0
vlc ios vdp