REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Internet Bug Bounty'
disclosed a bug submitted by
b'haxatron1'
b'(CVE-2023-32004) Permission model bypass by specifying a path traversal sequence in a Buffer'
07 Oct 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'tniessen'
b'OpenSSL engines can be used to bypass and/or disable the Node.js permission model'
07 Oct 2023
b'WordPress'
disclosed a bug submitted by
b'tanvir0x'
b'Previously created sessions continue being valid after 2FA activation'
07 Oct 2023
b'HackerOne'
disclosed a bug submitted by
b'imranhudaa'
b'Draft report exposure via slack alerting system for programs'
06 Oct 2023
b'LinkedIn'
disclosed a bug submitted by
b'mainteemoforfun'
b'[ADMIN FEATURE ACCESS] Knowing The Competitors analytics of any company '
05 Oct 2023
b'Informatica'
disclosed a bug submitted by
b'mtk0308'
b'[mysupport.informatica.com] - reflected XSS'
05 Oct 2023
b'Mozilla Core Services'
disclosed a bug submitted by
b'd0xing'
b'Subdomain takeover of eideticker.mozilla.org'
04 Oct 2023
b'Mozilla Core Services'
disclosed a bug submitted by
b'd0xing'
b'Subdomain takeover of google-cdn-delivery.dev.mozaws.net'
04 Oct 2023
b'inDrive'
disclosed a bug submitted by
b'h1xploit'
b'Bypassing Garbage Collection with Uppercase Endpoint'
04 Oct 2023
b'LY Corporation'
disclosed a bug submitted by
b'tosun'
b'Reflected XSS in OAUTH2 login flow (https://access.line.me)'
04 Oct 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'mattaustin'
b'CVE-2023-30587 Process-based permissions can be bypassed with the "inspector" module.'
30 Sep 2023
b'LinkedIn'
disclosed a bug submitted by
b'find_me_here'
b'Attackers can create unlimited jobs by paying a low price `( Rp. 10,000 )` from the original lowest price of around **Rp 93,151**'
29 Sep 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'unexpectedbuffercon_'
b'[] Information disclosure due unauthenticated access to APIs and system browser functions'
29 Sep 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'xandsz'
b'authentication bypass'
29 Sep 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'testingforbugs'
b'Reflected XSS at https:///'
29 Sep 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'unexpectedbuffercon_'
b'[] Reflected XSS via Keycloak on '
29 Sep 2023
b'Mattermost'
disclosed a bug submitted by
b'zerodivisi0n'
b'Reflected XSS in OAuth complete endpoints'
28 Sep 2023
b'Liberapay'
disclosed a bug submitted by
b'ma_hunter'
b' Twitter account hijack @Costalfy'
27 Sep 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'selmelc'
b'[curl] CVE-2023-38039: HTTP header allocation DOS'
27 Sep 2023
b'Mozilla Core Services'
disclosed a bug submitted by
b'mikey96'
b'Subdomain Takeover on mozaws.net'
27 Sep 2023
1
...
55
56
57
58
59
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM