REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'LinkedIn'
disclosed a bug submitted by
b'vampirex'
b'HTTP Request Smuggling (CL.0) leads to mass redirect users to attacker server without user interaction'
25 Sep 2023
b'LinkedIn'
disclosed a bug submitted by
b'headhunter'
b'Access to resumes applied through LinkedIn Jobs'
22 Sep 2023
b'Nord Security'
disclosed a bug submitted by
b'yozzo_'
b'Email verification bypass for manual connection setup service credentials'
22 Sep 2023
b'Slack'
disclosed a bug submitted by
b'd3f4u17'
b'Hashed data exposure via WebSockets to Workspace Members'
21 Sep 2023
b'Basecamp'
disclosed a bug submitted by
b'neex'
b'AWS keys and user cookie leakage via uninitialized memory leak in outdated librsvg version in Basecamp'
21 Sep 2023
b'Mozilla Critical Services'
disclosed a bug submitted by
b'anish_kosaraju'
b'If rate limit is hit, IP address is leaked to anyone who tries to login'
20 Sep 2023
b'curl'
disclosed a bug submitted by
b's0urc3_'
b'NULL Pointer dereference in idn.c'
20 Sep 2023
b'Mozilla Critical Services'
disclosed a bug submitted by
b'r3dpars3c'
b'Stored Xss on bugzilla.mozilla.org via comment edit feature from non-admin to admin.'
20 Sep 2023
b'Mozilla Core Services'
disclosed a bug submitted by
b'lamscun'
b'IDOR - send a message on behalf of other user '
20 Sep 2023
b'X (Formerly Twitter)'
disclosed a bug submitted by
b'greytesla'
b"Improper santization of edit in list feature at twitter leads to delete any twitter user's list cover photo."
18 Sep 2023
b'X (Formerly Twitter)'
disclosed a bug submitted by
b'mirhat'
b'Twitter Subscriptions Information Disclosure'
18 Sep 2023
b'Cosmos'
disclosed a bug submitted by
b'strikeout'
b'Circuit Breaker Authorization Issue'
18 Sep 2023
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'suzuka'
b'Permanent CASB Integration Takeover due to Improper Access Controls+Confused Deputy Problem'
18 Sep 2023
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'imtheking'
b'2FA BYPASS'
18 Sep 2023
b'Invision Power Services, Inc.'
disclosed a bug submitted by
b'mpiosik'
b'XSS with Visual Language Editor tags'
17 Sep 2023
b'8x8'
disclosed a bug submitted by
b'imranhudaa'
b'Unprotected Atlantis Server at https://132.226..'
15 Sep 2023
b'RubyGems'
disclosed a bug submitted by
b'ooooooo_q'
b'Possibility to guess email address from gravatar image URL'
14 Sep 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'kietna20'
b'Apache Airflow path traversal by authenticated user'
14 Sep 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'wct'
b"Potential NULL dereference in libssh's sftp server"
14 Sep 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'hungtd'
b'Regular Expression Denial of Service (ReDoS) Vulnerability before 2.6.3'
14 Sep 2023
1
...
65
66
67
68
69
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM