REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'U.S. Department of State'
disclosed a bug submitted by
b'doosec101'
b'LDAP anonymous access enabled at certrep.pki.state.gov:389'
11 May 2023
b'IBM'
disclosed a bug submitted by
b'0xpugazh'
b'Moodle XSS on s-immerscio.comprehend.ibm.com'
11 May 2023
b'IBM'
disclosed a bug submitted by
b'gdattacker'
b'Subdomain Takeover Affecting at vex.weather.com'
10 May 2023
b'Mattermost'
disclosed a bug submitted by
b'uchihaluckycs'
b'Reset password link sent over unsecured http protocol'
10 May 2023
b'Brave Software'
disclosed a bug submitted by
b'ameenbasha'
b'download file type warning on Windows does not appear if "ask where to save file before downloading" setting is enabled'
10 May 2023
b'Rocket.Chat'
disclosed a bug submitted by
b'rijalrojan'
b'NoSQL injection in listEmojiCustom method call'
09 May 2023
b'Rocket.Chat'
disclosed a bug submitted by
b'sectex'
b'Cross-Site-Scripting in "Search Messages"'
09 May 2023
b'Rocket.Chat'
disclosed a bug submitted by
b'gronke'
b'Mute User can disclose private channel members to unauthorized users'
09 May 2023
b'Rocket.Chat'
disclosed a bug submitted by
b'vv9k'
b'Maliciously crafted message can cause Rocket.Chat server to stop responding'
09 May 2023
b'Rocket.Chat'
disclosed a bug submitted by
b'gronke'
b'Moving private messages into vision with updateMessage method'
09 May 2023
b'Elastic'
disclosed a bug submitted by
b'lu3ky-13'
b'blind Server-Side Request Forgery (SSRF) allows scanning internal ports'
05 May 2023
b'Expedia Group Bug Bounty'
disclosed a bug submitted by
b'bombon'
b'Reflected XSS Via origCity Parameter (UPPER Case + WAF Protection Bypass)'
04 May 2023
b'Nextcloud'
disclosed a bug submitted by
b'meinereiner'
b'App pin of the Android app can be bypassed via 3rdparty apps generating deep links'
04 May 2023
b'Nextcloud'
disclosed a bug submitted by
b'nickvergessen'
b'Potential directory traversal in OC\\Files\\Node\\Folder::getFullPath'
04 May 2023
b'Nextcloud'
disclosed a bug submitted by
b'juliushaertl'
b'Document content of files can be obtained through Collabora for files of other users'
04 May 2023
b'Nextcloud'
disclosed a bug submitted by
b'juliushaertl'
b'Hide download previews are accessible without a watermark'
04 May 2023
b'Ruby'
disclosed a bug submitted by
b'leixiao'
b'Header CRLF Injection in Ruby Net::HTTP'
04 May 2023
b'HackerOne'
disclosed a bug submitted by
b'datph4m'
b'Insecure Direct Object Reference (IDOR) - Delete Campaigns '
03 May 2023
b'TD Bank'
disclosed a bug submitted by
b'def1ant'
b'Reflected XSS on marketsandresearch.td.com'
03 May 2023
b'Stripe'
disclosed a bug submitted by
b'saajanbhujel'
b'Possible XSS vulnerability without a content security bypass'
01 May 2023
1
...
73
74
75
76
77
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM