REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
65
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'curl'
disclosed a bug submitted by
b'sy2n0'
b'Denial of Service (DoS) vulnerability in dedotdotify() URL path normalization'
13 Dec 2025
b'curl'
disclosed a bug submitted by
b'mlgzackfly'
b'Buffer Overflow in cURL Internal printf Function'
12 Dec 2025
b'curl'
disclosed a bug submitted by
b'kelsier'
b'Terminal Output Not Great'
11 Dec 2025
b'curl'
disclosed a bug submitted by
b'4bccc'
b'Certificate Hostname Validation Bypass via Leading Dot in Hostname'
09 Dec 2025
b'curl'
disclosed a bug submitted by
b'lm3alm'
b'Stack Buffer Overflow in cURL wolfSSL Backend (lib/vtls/wolfssl.c)'
09 Dec 2025
b'curl'
disclosed a bug submitted by
b'nyymi'
b'curl built with GnuTLS backend defaults to weak crypto parameters'
08 Dec 2025
b'Enjin'
disclosed a bug submitted by
b'pwnie'
b'Unauthenticated GraphQL access by prepending __schema to private operations'
05 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'aptroom'
b'Stored XSS Vulnerability via SVG File'
05 Dec 2025
b'curl'
disclosed a bug submitted by
b'rootx1337'
b'Title: Use-After-Free in cURL Test Suite via Improper Cleanup of Global Handle'
05 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'klipz'
b'admin_audit does not log actions on files in a group folder'
05 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'daroo'
b'Deck app allowed user with "Can share" permission to modify permissions of other non-owners'
05 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'daroo'
b'Calendar app allowed booking appointments without the generated token'
05 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'daroo'
b'Calendar attachments of local files are offered to downloaded'
05 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'daroo'
b'Missing ownership check in Tables app allows moving columns into tables of other users'
05 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'daroo'
b'Tables app allowed users to view columns metadata information of any table'
05 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'daroo'
b'Participants were able to blindly delete poll drafts of other users by ID'
05 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'0x0doteth'
b'Approval app allows users to request approval for other users file '
05 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'0x0doteth'
b' Nextcloud Tables v1 Share Enumeration Without Authorization (Regression of CVE-2024-52507)'
05 Dec 2025
b'curl'
disclosed a bug submitted by
b'anonymous_237'
b'SMTP Protocol Injection via CRLF in CURLOPT_MAIL_FROM leading to Email Spoofing'
04 Dec 2025
1
2
3
...
745
BY DENIS WERNER - @NOBBD -
IMPRESSUM