REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Dust'
disclosed a bug submitted by
b'0xsom3a'
b'Privilege Escalation in Edit and Create Secret Endpoints Leads to Unauthorized Secret Modification'
24 Apr 2025
b'AWS VDP'
disclosed a bug submitted by
b'nick_frichette_dd'
b'Non-Production API Endpoints for the ssm Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration'
24 Apr 2025
b'Cosmos'
disclosed a bug submitted by
b'vakzz'
b'Groups module can halt chain when handling a proposal with malicious group weights '
23 Apr 2025
b'Dust'
disclosed a bug submitted by
b'qatada'
b'UI flaw allows unauthorized users to add documents to restricted folders'
23 Apr 2025
b'Dust'
disclosed a bug submitted by
b'mous_haxk'
b'Unauthorized Table Creation by Member'
23 Apr 2025
b'Monero'
disclosed a bug submitted by
b'boog900'
b'Transactions in invalid blocks are kept in tx-pool without undergoing certain checks.'
23 Apr 2025
b'Monero'
disclosed a bug submitted by
b'boog900'
b'A peer can remotely fill the pending block queue to an extremely high size, with blocks that will never leave the queue.'
23 Apr 2025
b'Monero'
disclosed a bug submitted by
b'sagewilder2022'
b'Remote memory exhaustion in Epee RPC stack under zero Receive Window'
23 Apr 2025
b'Monero'
disclosed a bug submitted by
b'asurar0'
b'Spamming highly nested JSON RPC requests cause node to disconnect from p2p network'
23 Apr 2025
b'PlayStation'
disclosed a bug submitted by
b'theflow0'
b'sys_fsc2h_ctrl kernel stack free'
18 Apr 2025
b'Autodesk'
disclosed a bug submitted by
b'ahmednasr1'
b'Reflected XSS Vulnerability in SVG File at area-resources-stg.autodesk.com'
17 Apr 2025
b'WakaTime'
disclosed a bug submitted by
b'0x_matrix'
b'Leaked credentials ( emails and passwords , etc...)'
16 Apr 2025
b'Shopify'
disclosed a bug submitted by
b'raymond_lind'
b'Reflected XSS In Marketing Reports Page On *.myshopify.com/admin'
15 Apr 2025
b'Monero'
disclosed a bug submitted by
b'padillac'
b'low-level p2p ping + tcp flooding leads to a remote crash in monerod'
14 Apr 2025
b'WakaTime'
disclosed a bug submitted by
b'parthabishwas'
b'Login Information and Credentials Have Been Leaked on wakatime.com'
13 Apr 2025
b'1Password - Enterprise Password Manager'
disclosed a bug submitted by
b'stomper4'
b'#**CSV Injection in shared passwords leads to complete Private Vault Exfiltration**'
12 Apr 2025
b'Lichess'
disclosed a bug submitted by
b'ryomenshuvro'
b'Direct IP Access to Website'
11 Apr 2025
b'Ruby on Rails'
disclosed a bug submitted by
b'leonsirio'
b'1-Click Cross-Site Scripting via Custom Configuration in SafeListSanitizer'
09 Apr 2025
b'AWS VDP'
disclosed a bug submitted by
b'nick_frichette_dd'
b'(Part 2) Non-Production API Endpoints for the Datazone Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration'
08 Apr 2025
1
2
3
...
725
BY DENIS WERNER - @NOBBD -
IMPRESSUM