REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Mars'
disclosed a bug submitted by
b'0xs4m'
b"IDOR ' can add animal to other account ' at https://www.miroyalcanin.cl/"
22 Jun 2023
b'Node.js'
disclosed a bug submitted by
b'tniessen'
b'OpenSSL engines can be used to bypass and/or disable the permission model'
22 Jun 2023
b'Nextcloud'
disclosed a bug submitted by
b'akshayravic09yc47'
b'Open redirect on "Unsupported browser" warning'
22 Jun 2023
b'Nextcloud'
disclosed a bug submitted by
b'rullzer'
b'End-to-end encrypted file-drops can be made inaccessible'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'HTML injection in title of reader view'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'Universal XSS through FIDO U2F register from subframe'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'Phishing/Malware site blocking on Brave iOS can be bypassed with trailing dot in hostname'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'Onion-Location header allows to open arbitrary URLs including chrome:'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'XSS on Brave Today through custom RSS feed'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'New XSS vector in ReaderMode with %READER-TITLE-NONCE%'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'Universal XSS with Playlist feature'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'XSS on internal: privileged origin through reader mode'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'Security token and handler name leak from window.braveBlockRequests'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'Persistent user tracking is possible using window.caches, by avoiding Brave Shields'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'UI spoofing by showing sms:/tel: dialog on another website'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'Brave Shield for iOS is weak against IDN homograph attacks'
22 Jun 2023
b'Brave Software'
disclosed a bug submitted by
b'nishimunea'
b'Brave News feeds can open arbitrary chrome: URLs'
22 Jun 2023
b'IBM'
disclosed a bug submitted by
b'ro0od'
b'response manipulation leads to bypass in register at employee website than 0 click account takeover'
21 Jun 2023
b'LinkedIn'
disclosed a bug submitted by
b'headhunter'
b'See whos interested in working for your company - security issue'
21 Jun 2023
b'Node.js'
disclosed a bug submitted by
b'yadhukrishnam'
b'HTTP Request Smuggling via Empty headers separated by CR'
20 Jun 2023
1
...
62
63
64
65
66
...
724
BY DENIS WERNER - @NOBBD -
IMPRESSUM