Daily Bug Bounty Writeups by @Piyush Kumawat
This repository contains Bug Bounty writeups
-
💯May 21, 2026 - I Found a Prompt Injection Vulnerability in DeepHat - And They Never Responded
-
💯May 21, 2026 - How an Android App’s Misconfigured Firebase Database Exposed Sensitive Data
-
💯May 21, 2026 - How a College Website’s REST API Exposed Its Entire Attack Surface — User Enumeration…
-
💯May 21, 2026 - Cryptographic Failures — The #4 Vulnerability on the Web
-
💯May 21, 2026 - The AI Flood That’s Killing Bug Bounty — And the Hidden Reason Nobody Is Talking About By Adil Ali
-
💯May 21, 2026 - From Org Switcher to Org Takeover: An IDOR Story
-
💯May 21, 2026 - How a Simple URL Parameter Exposed Hidden Database Records
-
💯May 20, 2026 - I Broke Into a GraphQL API Using a File Nobody Reads ️♂️
-
💯May 20, 2026 - One Request, Two Parameters, Zero Validation
-
💯May 20, 2026 - Password Reset Tokens in URLs: A Small Mistake That Can Lead to Account Takeover