Top 100 paid reports from HackerOne:
- Github access token exposure to Shopify - $50000, 1239 upvotes
- [Pre-Submission][H1-4420-2019] API access to Phabricator on code.uberinternal.com from leaked certificate in git repo to Uber - $39999, 362 upvotes
- Незащищённый экземпляр Zeppelin to Mail.ru - $35000, 169 upvotes
- Remote Command Execution via Github import to GitLab - $33510, 314 upvotes
- RCE via the DecompressedArchiveSizeValidator and Project BulkImports (behind feature flag) to GitLab - $33510, 310 upvotes
- RCE via npm misconfig -- installing internal libraries from the public registry to PayPal - $30000, 869 upvotes
- Arbitrary file read via the bulk imports UploadsPipeline to GitLab - $29000, 303 upvotes
- Exposed Kubernetes API - RCE/Exposed Creds to Snapchat - $25000, 1144 upvotes
- Server Side Request Forgery (SSRF) via Analytics Reports to HackerOne - $25000, 461 upvotes
- SQL Injection in report_xml.php through countryFilter[] parameter to Valve - $25000, 375 upvotes
- SAML Signature verification bypass allows logging into any user (with specific conditions) to GitHub - $25000, 170 upvotes
- RepositoryPipeline allows importing of local git repos to GitLab - $22300, 65 upvotes
- access list owner can escalate his role to the highest roles to Teleport - $21000, 255 upvotes
- Potential pre-auth RCE on Twitter VPN to X (Formerly Twitter) - $20160, 1202 upvotes
- Bypass for #488147 enables stored XSS on https://paypal.com/signin again to PayPal - $20000, 2612 upvotes
- Account takeover via leaked session cookie to HackerOne - $20000, 1565 upvotes
- Arbitrary file read via the UploadsRewriter when moving and issue to GitLab - $20000, 1461 upvotes
- Getting all the CD keys of any game to Valve - $20000, 619 upvotes
- [phpobject in cookie] Remote shell/command execution to Pornhub - $20000, 607 upvotes
- RCE when removing metadata with ExifTool to GitLab - $20000, 486 upvotes
- RCE via unsafe inline Kramdown options when rendering certain Wiki pages to GitLab - $20000, 415 upvotes
- bd-j exploit chain to PlayStation - $20000, 266 upvotes
- Steal private objects of other projects via project import to GitLab - $20000, 228 upvotes
- Github Apps can use Scoped-User-To-Server Tokens to Obtain Full Access to User's Projects in Project V2 GraphQL api to GitHub - $20000, 189 upvotes
- Private objects exposed through project import to GitLab - $20000, 113 upvotes
- Stored XSS on https://paypal.com/signin via cache poisoning to PayPal - $18900, 665 upvotes
- Oracle Webcenter Sites administrative and hi-privilege access available directly from the internet (/cs/Satellite) to LocalTapiola - $18000, 264 upvotes
- Struct type confusion RCE to shopify-scripts - $18000, 9 upvotes
- Full Response SSRF via Google Drive to Dropbox - $17576, 302 upvotes
- Stored XSS in markdown via the DesignReferenceFilter to GitLab - $16000, 289 upvotes
- Arbitrary file read during project import to GitLab - $16000, 183 upvotes
- Token leak in security challenge flow allows retrieving victim's PayPal email and plain text password to PayPal - $15300, 1366 upvotes
- Ability to bypass partner email confirmation to take over any store given an employee email to Shopify - $15250, 240 upvotes
- Websites Can Run Arbitrary Code on Machines Running the 'PlayStation Now' Application to PlayStation - $15000, 759 upvotes
- Delete anyone's content spotlight remotely. to Snapchat - $15000, 720 upvotes
- Time-Based SQL injection at city-mobil.ru to Mail.ru - $15000, 631 upvotes
- Open prod Jenkins instance to Snapchat - $15000, 428 upvotes
- file read on MCS servers via supplying a QCOW2 image with external backing file to Mail.ru - $15000, 222 upvotes
- Incorrect authorization to the intelbot service leading to ticket information to TikTok - $15000, 205 upvotes
- [mcs.mail.ru] Пользователь с ролью наблюдателя может создавать ключи доступа для очереди сообщений (sqs.mcs.mail.ru) to Mail.ru - $15000, 147 upvotes
- Leaked JFrog Artifactory username and password exposed on GitHub - https://snapchat.jfrog.io to Snapchat - $15000, 126 upvotes
- Stored XSS via Kroki diagram to GitLab - $13950, 276 upvotes
- Stored XSS in Notes (with CSP bypass for gitlab.com) to GitLab - $13950, 149 upvotes
- New /add_contacts /remove_contacts quick commands susseptible to XSS from Customer Contact firstname/lastname fields to GitLab - $13950, 85 upvotes
- XSS in ZenTao integration affecting self hosted instances without strict CSP to GitLab - $13950, 75 upvotes
- Mass Accounts Takeover Without any user Interaction at https://app.taxjar.com/ to Stripe - $13000, 180 upvotes
- IDOR - Delete all Licenses and certifications from users account using CreateOrUpdateHackerCertification GraphQL query to HackerOne - $12500, 313 upvotes
- An attacker can archive and unarchive any structured scope object on HackerOne to HackerOne - $12500, 312 upvotes
- Internal attachments can be exported via "Export as .zip" feature to HackerOne - $12500, 258 upvotes
- View Titles of Private Reports with pending email invitation to HackerOne - $12500, 227 upvotes
- Spring Actuator endpoints publicly available and broken authentication to LY Corporation - $12500, 226 upvotes
- Remote vulnerabilities in spp to PlayStation - $12500, 164 upvotes
- Git flag injection - local file overwrite to remote code execution to GitLab - $12000, 763 upvotes
- Local files could be overwritten in GitLab, leading to remote command execution to GitLab - $12000, 537 upvotes
- Project Template functionality can be used to copy private project data, such as repository, confidential issues, snippets, and merge requests to GitLab - $12000, 441 upvotes
- JSON serialization of any Project model results in all Runner tokens being exposed through Quick Actions to GitLab - $12000, 354 upvotes
- Path traversal, to RCE to GitLab - $12000, 136 upvotes
- Account Takeover via Authentication Bypass in TikTok Account Recovery to TikTok - $12000, 123 upvotes
- Path traversal in Nuget Package Registry to GitLab - $12000, 84 upvotes
- WG call injection in /economy/contextcommand to Valve - $12000, 43 upvotes
- Arbitrary Code Execution via npm misconfiguration – installing internal libraries from the public registry to LY Corporation - $11500, 278 upvotes
- Shell command injection in https://partner.steamgames.com/apps/communityitems/ via file extension of item_image_small and item_image_large to Valve - $11500, 50 upvotes
- Exfiltrate and mutate repository and project data through injected templated service to GitLab - $11000, 736 upvotes
- IDOR to add secondary users in www.paypal.com/businessmanage/users/api/v1/users to PayPal - $10500, 732 upvotes
- Ability to DOS any organization's SSO and open up the door to account takeovers to Grammarly - $10500, 230 upvotes
- Use-After-Free In IPV6_2292PKTOPTIONS leading To Arbitrary Kernel R/W Primitives to PlayStation - $10000, 724 upvotes
- Access to multiple production Grafana dashboards to Snapchat - $10000, 452 upvotes
- touch.mail.ru / e.mail.ru memory content disclosure to Mail.ru - $10000, 409 upvotes
- gitlab-workhorse bypass in Gitlab::Middleware::Multipart allowing files in
allowed_paths
to be read to GitLab - $10000, 402 upvotes - SQL injection at fleet.city-mobil.ru to Mail.ru - $10000, 372 upvotes
- RCE on shared.mail.ru due to "widget" plugin to Mail.ru - $10000, 359 upvotes
- SSRF on project import via the remote_attachment_url on a Note to GitLab - $10000, 345 upvotes
- Partial disclosure of report activity through new "Export as .zip" feature to HackerOne - $10000, 342 upvotes
- Double Payout via PayPal to Coinbase - $10000, 297 upvotes
- SOCK_RAW sockets reachable from Webkit process allows triggering double free in IP6_EXTHDR_CHECK to PlayStation - $10000, 285 upvotes
- Deserialization of untrusted data at https://www.redtube.com/media/hls?s=data to Pornhub - $10000, 271 upvotes
- size_t-to-int vulnerability in exFAT leads to memory corruption via malformed USB flash drives to PlayStation - $10000, 267 upvotes
- Malformed NAV file leads to buffer overflow and code execution in Left4Dead2.exe to Valve - $10000, 264 upvotes
- Information Disclosure in /skills call to HackerOne - $10000, 260 upvotes
- Publicly exposed SVN repository, ht.pornhub.com to Pornhub - $10000, 211 upvotes
- Hacker can bypass 2FA requirement and reporter blacklist through embedded submission form to HackerOne - $10000, 192 upvotes
- read new emails from any inbox IOS APP in notification center to Mail.ru - $10000, 186 upvotes
- Authentication bypass on gist.github.com through SSH Certificates to GitHub - $10000, 167 upvotes
- CSRF protection bypass in GitHub Enterprise management console to GitHub - $10000, 143 upvotes
- Use-after-free in setsockopt IPV6_2292PKTOPTIONS (CVE-2020-7457) to PlayStation - $10000, 131 upvotes
- uber.com may RCE by Flask Jinja2 Template Injection to Uber - $10000, 113 upvotes
- Using gossip to drain miner wallets to Zilliqa - $10000, 111 upvotes
- Management Console Editor Privilege Escalation to Root SSH Access in GitHub Enterprise Server via RCE in ghe-update-check to GitHub - $10000, 77 upvotes
- Management Console Editor Privilege Escalation to Root SSH Access in GitHub Enterprise Server via nomad template injection and audit-forward to GitHub - $10000, 73 upvotes
- Privilege Escalation to Root SSH Access via Pre-Receive Hook Environment in GitHub Enterprise Server to GitHub - $10000, 66 upvotes
- Management Console Editor Privilege Escalation to Root SSH Access in GitHub Enterprise Server via nomad template injection to GitHub - $10000, 56 upvotes
- Management Console Editor Privilege Escalation to Root SSH Access in GitHub Enterprise Server via RCE in syslog-ng to GitHub - $10000, 55 upvotes
- OneLogin authentication bypass on WordPress sites to Uber - $10000, 53 upvotes
- Shell command injection in https://partner.steamgames.com/bundles/savestore/ via overwriting asset_path_identifier to Valve - $10000, 43 upvotes
- Management Console Editor Privilege Escalation to Root SSH Access in GitHub Enterprise Server via RCE in collectd to GitHub - $10000, 39 upvotes
- Management Console Editor Privilege Escalation to Root SSH Access in GitHub Enterprise Server via RCE in actions-console to GitHub - $10000, 38 upvotes
- Invalid handling of zero-length heredoc identifiers leads to infinite loop in the sandbox to shopify-scripts - $10000, 23 upvotes
- Crash: Overwriting NoMethodError with a builtin class crashes/corrupts memory to shopify-scripts - $10000, 20 upvotes
- RCE hazard in reporting (via Chromium) to Elastic - $10000, 20 upvotes
- Segfault and/or potential unwanted (byte)code execution with "break" and "||=" inside a loop to shopify-scripts - $10000, 13 upvotes