REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
65
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Automattic'
disclosed a bug submitted by
b'sodium_'
b'Authentication bypass on JetPack SSO manager - Allows to access the administration panel of wordpress without user interaction'
28 Dec 2023
b'Khan Academy'
disclosed a bug submitted by
b'grassye'
b'Text Injection/ Content Spoofing on https://cloud.e.khanacademy.org by breaking out of input tag.'
22 Dec 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'aimotonorihito'
b'Possibility of Request smuggling attack'
22 Dec 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'nyymi'
b'curl cookie mixed case PSL bypass'
22 Dec 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'hkario'
b'OpenSSL vulnerable to the Marvin Attack (CVE-2022-4304)'
21 Dec 2023
b'Kubernetes'
disclosed a bug submitted by
b'tomerpeled92'
b'CVE-2023-5528: Insufficient input sanitization in in-tree storage plugin leads to privilege escalation on Windows nodes'
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'fdeleite'
b'RCE in [CVE-2021-26084]'
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'fdeleite'
b'Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464)'
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'fdeleite'
b'RCE on [CVE-2021-26084]'
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'maskedpersian'
b'IDOR to delete profile images in https:'
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'pizzapower'
b'RCE via File Upload with a Null Byte Truncated File Extension at https:///'
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'qu1nten'
b'[] RXSS via "CurrentFolder" parameter'
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'maskedpersian'
b'Default Admin Username and Password on '
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'devdevrl'
b'Unauthorized access to Argo dashboard on '
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'r00tdaddy'
b'Unauthenticated File Read Adobe ColdFusion'
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'0r10nh4ck'
b'Adobe ColdFusion Access Control Bypass - CVE-2023-38205'
21 Dec 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'roland_hack'
b'Elasticsearch is currently open without authentication on https://l'
21 Dec 2023
b'Nextcloud'
disclosed a bug submitted by
b'max_nextcloud'
b'Self XSS when pasting HTML into Text app with Ctrl+Shift+V'
21 Dec 2023
b'Nextcloud'
disclosed a bug submitted by
b'st0nzyy'
b'Admins can change authentication details of user configured external storage'
21 Dec 2023
b'Ruby'
disclosed a bug submitted by
b'z2_'
b"DoS in bigdecimal's sqrt function due to miscalculation of loop iterations"
20 Dec 2023
1
...
64
65
66
67
68
...
747
BY DENIS WERNER - @NOBBD -
IMPRESSUM