REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'sp1d3rs'
68
b'someonenobbd'
62
b'nyymi'
53
b'jon_bottarini'
49
b'haxta4ok00'
48
b'netfuzzer'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'ownCloud'
disclosed a bug submitted by
b'paulos_'
b'Config'
11 Oct 2015
b'ownCloud'
disclosed a bug submitted by
b'suhas_gaikwad'
b'apps.owncloud.com: Mixed Active Scripting Issue '
11 Oct 2015
b'ownCloud'
disclosed a bug submitted by
b'avicoder'
b'Webview Vulnerablity [OwnCloudAndroid Application] '
11 Oct 2015
b'Sandbox Escape'
disclosed a bug submitted by
b'ashutoshmehra'
b'Internet Explorer Enhanced Protected Mode sandbox escape via a broker vulnerability'
09 Oct 2015
b'Sandbox Escape'
disclosed a bug submitted by
b'yopwn'
b'Microsoft Internet Explorer ActiveX Broker Allows EPM Bypass'
09 Oct 2015
b'ownCloud'
disclosed a bug submitted by
b'paresh_parmar'
b'demo.owncloud.org: HTTP compression is enabled potentially leading to BREACH attack'
09 Oct 2015
b'Shopify'
disclosed a bug submitted by
b'reeth'
b'The POS Firmware is leaking the root Password which can be used for unauthorized access to the device.'
09 Oct 2015
b'Udemy'
disclosed a bug submitted by
b'adrianbelen'
b'XSS on https://www.udemy.com/asset/export.html'
08 Oct 2015
b'Shopify'
disclosed a bug submitted by
b'pouya'
b'unauthorized access to all customers first and last name '
06 Oct 2015
b'Shopify'
disclosed a bug submitted by
b'dhaval'
b'Open Redirect after login at http://ecommerce.shopify.com'
05 Oct 2015
b'Shopify'
disclosed a bug submitted by
b'pouya'
b'customers password hash leak!!!!'
05 Oct 2015
b'Twitter'
disclosed a bug submitted by
b'wesecureapp'
b"Insecure Direct Object Reference - access to other user/group DM's"
03 Oct 2015
b'Shopify'
disclosed a bug submitted by
b'satishb3'
b'Shop admin can change external login services'
02 Oct 2015
b'Anghami'
disclosed a bug submitted by
b'aaj__'
b'[https://www.anghami.com/updatemailinfo/] Sql Injection'
02 Oct 2015
b'Anghami'
disclosed a bug submitted by
b'egyxos'
b'[CRITICAL] Login To Any Account Linked With Google+ With Email Only'
02 Oct 2015
b'Hired'
disclosed a bug submitted by
b'mohammedalsaggaf'
b'URGENT - Subdomain Takeover on be.hired.com. due to unclaimed domain pointing to Heroku.com'
01 Oct 2015
b'Phabricator'
disclosed a bug submitted by
b'superkritisch'
b"Multiple so called 'type juggling' attacks. Most notably PhabricatorUser::validateCSRFToken() is 'bypassable' in certain cases."
01 Oct 2015
b'Zaption'
disclosed a bug submitted by
b'psychomantis'
b'CSV Excel Macro Injection in Export Response'
01 Oct 2015
b'Hired'
disclosed a bug submitted by
b'yujitounai'
b'Stored XSS in Company Name'
30 Sep 2015
b'Shopify'
disclosed a bug submitted by
b'acid_creative'
b'Passwords Returned in Later Responses.'
30 Sep 2015
1
...
615
616
617
618
619
...
680
BY DENIS WERNER - @NOBBD -
IMPRESSUM