REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Nintendo'
disclosed a bug submitted by
b'roccodev'
b'[Xenoblade Chronicles X: Definitive Edition] Unrestricted RPCs allow DoS and writing arbitrary flags remotely'
15 May 2025
b'Nintendo'
disclosed a bug submitted by
b'roccodev'
b'[Xenoblade Chronicles X: Definitive Edition] Improper validation of names allows injecting formatting tags and bypassing profanity filter'
15 May 2025
b'Node.js'
disclosed a bug submitted by
b'tniessen'
b'Improper error handling in async cryptographic operations crashes process'
14 May 2025
b'WakaTime'
disclosed a bug submitted by
b'atasec'
b'user api key leaked'
13 May 2025
b'Mozilla'
disclosed a bug submitted by
b'samirsec0x01'
b'Netlify Authentication Token Exposed in Public Mozilla CI Logs'
13 May 2025
b'Mars'
disclosed a bug submitted by
b'reinhardtthe'
b'insecure deserilize object leads to RCE On Sitecore (CVE--27218)'
12 May 2025
b'Mars'
disclosed a bug submitted by
b'bughunter0x7'
b'Users Data Exposure via Insecure Endpoint'
12 May 2025
b'Mars'
disclosed a bug submitted by
b'imeng'
b'debug.log leaked []'
12 May 2025
b'Mars'
disclosed a bug submitted by
b'thpless'
b'massive PII leakage for '
12 May 2025
b'Mars'
disclosed a bug submitted by
b'bughunter0x7'
b'change part of personal information all users'
12 May 2025
b'curl'
disclosed a bug submitted by
b'antypanty'
b'Memory Leak'
10 May 2025
b'Automattic'
disclosed a bug submitted by
b'root_geek280'
b'Race condition on add 1 free domain'
09 May 2025
b'XVIDEOS'
disclosed a bug submitted by
b'samtime'
b'Enable 2FA without verifying the email'
09 May 2025
b'HackerOne'
disclosed a bug submitted by
b'light3r'
b'Ability to access policy and updates for unauthorized program'
08 May 2025
b'curl'
disclosed a bug submitted by
b'oblivionsage'
b'CRLF Injection in `--proxy-header` allows extra HTTP headers (CWE-93)'
08 May 2025
b'Khan Academy'
disclosed a bug submitted by
b'firec4t'
b'Unauthorized Account Access via Leaked Credentials in URL Format (Account Takeover )'
07 May 2025
b'IBM'
disclosed a bug submitted by
b'0x4bdo'
b'Path Traversal Vulnerability found on IBM Cloud'
07 May 2025
b'LinkedIn'
disclosed a bug submitted by
b'nagu123'
b'HTML Injection in LinkedIn Premium Support Chat'
07 May 2025
b'Dust'
disclosed a bug submitted by
b'yoyomiski'
b'BAC Bypass chatbot restrictions via unauthorized mention injection'
06 May 2025
1
2
3
...
727
BY DENIS WERNER - @NOBBD -
IMPRESSUM