REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
63
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'curl'
disclosed a bug submitted by
b'z1andr4g0n'
b'Title: Remote Code Execution (RCE) via Arbitrary Library Loading in `--engine` option'
10 Aug 2025
b'curl'
disclosed a bug submitted by
b'z1andr4g0n'
b'Path Traversal in SFTP QUOTE command leads to Arbitrary File Write and potential RCE'
10 Aug 2025
b'curl'
disclosed a bug submitted by
b'ahmedqc1'
b'Vulnerability Report: Local File Disclosure via file:// Protocol in cURL'
10 Aug 2025
b'curl'
disclosed a bug submitted by
b'geeknik'
b'Heap Buffer Overflow in Curl_memdup0() via CURLOPT_COPYPOSTFIELDS/CURLOPT_POSTFIELDSIZE Mismatch'
09 Aug 2025
b'Nintendo'
disclosed a bug submitted by
b'kinnay'
b'Man-in-the-middle through broken SSL certificate verification'
08 Aug 2025
b'GitHub'
disclosed a bug submitted by
b'ghbountyocto'
b'Sample report: Denial of service '
07 Aug 2025
b'curl'
disclosed a bug submitted by
b'letshack9707'
b'Use After Free (that leads to arbitrary Write for some versions) '
06 Aug 2025
b'WakaTime'
disclosed a bug submitted by
b'zeesozee'
b'Double Clickjacking Attack on WakaTime OAuth Authorization Flow at https://wakatime.com/oauth/authorize'
05 Aug 2025
b'WakaTime'
disclosed a bug submitted by
b'ctrl_cipher'
b'Unauthorized Disclosure of Private Emails via WakaTime Private Leaderboards'
03 Aug 2025
b'curl'
disclosed a bug submitted by
b'kakorrhaphiophobia'
b'Integer Overflow in schannel.c TLS Data Transmission'
02 Aug 2025
b'MetaMask'
disclosed a bug submitted by
b'bug_vs_me'
b'total Failure of password protection while extracting seed phrase! increases attack surface area for scammers'
31 Jul 2025
b'curl'
disclosed a bug submitted by
b'geeknik'
b'Stack use-after-scope in HTTP/3 POST request processing via CURLOPT_POSTFIELDS'
31 Jul 2025
b'Mozilla'
disclosed a bug submitted by
b'yoyomiski'
b'Bypass "No Links" Restriction in Biography via Protocol-Relative URL (//)'
29 Jul 2025
b'Mozilla'
disclosed a bug submitted by
b'trein'
b'Mozilla VPN Clients: RCE via file write and path traversal'
29 Jul 2025
b'curl'
disclosed a bug submitted by
b'nyymi'
b'OpenSSL HTTP/3 bogus CURLINFO_TLS_SSL_PTR'
28 Jul 2025
b'Mars'
disclosed a bug submitted by
b'0xun7h1nk4ble'
b'RXSS on via customerId parameter'
28 Jul 2025
b'Node.js'
disclosed a bug submitted by
b'oblivionsage'
b'Windows Device Names Still Allow Path Traversal in UNC Paths After CVE-2025-27210 Fix'
28 Jul 2025
b'curl'
disclosed a bug submitted by
b'cyph3r_nitro'
b'Vulnerability Report: Public Exposure of Security Audit File'
27 Jul 2025
b'curl'
disclosed a bug submitted by
b'ejejohn'
b'Security check up'
24 Jul 2025
b'curl'
disclosed a bug submitted by
b'catenacyber'
b'Use after free (or assert triggered) with failed allocations in openssl'
24 Jul 2025
1
...
4
5
6
7
8
...
740
BY DENIS WERNER - @NOBBD -
IMPRESSUM