REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
56
b'ooooooo_q'
50
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'albertspedersen'
b'Using special IPv4-mapped IPv6 addresses to bypass local IP ban'
24 Jan 2023
b'Linktree'
disclosed a bug submitted by
b'0xshdax'
b'[song.link] Open Redirect'
23 Jan 2023
b'Slack'
disclosed a bug submitted by
b'pisarenko'
b'XSS on link and window.opener '
23 Jan 2023
b'LocalTapiola'
disclosed a bug submitted by
b'voiddy'
b'Cookie exfiltration through XSS on the main search request of www.lahitapiola.fi'
19 Jan 2023
b'Yelp'
disclosed a bug submitted by
b'rac_fckscty'
b'PURGE is not authenticated'
19 Jan 2023
b'KAYAK'
disclosed a bug submitted by
b'retr02332'
b'1 click Account takeover via deeplink in [com.kayak.android]'
19 Jan 2023
b'HackerOne'
disclosed a bug submitted by
b'reigertje'
b'Private information exposed through GraphQL search endpoints aggregates'
19 Jan 2023
b'Adobe'
disclosed a bug submitted by
b'dreamer_eh'
b'HTML INJECTION on https://adobedocs.github.io/JourneyAPI/ due to outdated SWAGGER UI'
17 Jan 2023
b'Adobe'
disclosed a bug submitted by
b'dreamer_eh'
b'DOM XSS at `https://adobedocs.github.io/indesign-api-docs/?configUrl={site}` due to outdated Swagger UI'
17 Jan 2023
b'ownCloud'
disclosed a bug submitted by
b'atorralba'
b'GitHub Security Lab (GHSL) Vulnerability Report: Insufficient path validation in ReceiveExternalFilesActivity.java (GHSL-2022-060)'
16 Jan 2023
b'Mattermost'
disclosed a bug submitted by
b'annonmous'
b'Uninstalling Mattermost Launcher for Windows (64-bit), then reinstalling keeps you logged in without authentication'
14 Jan 2023
b'Yelp'
disclosed a bug submitted by
b'ethack1886'
b'Robots.txt file with potentially sensitive content.'
13 Jan 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'berserkbd47'
b'Critical sensitive information Disclosure. [HtUS]'
13 Jan 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'berserkbd47'
b'Wordpress Takeover using setup configuration at http://.edu [HtUS]'
13 Jan 2023
b'GitHub'
disclosed a bug submitted by
b'vaib25vicky'
b'Github app Privilege Escalation to Administrator/Owner of the Organization '
13 Jan 2023
b'Nextcloud'
disclosed a bug submitted by
b'systemkeeper'
b'Reference caching can leak data to unauthorized users'
13 Jan 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'zeyu2001'
b'DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices)'
12 Jan 2023
b'Hiro'
disclosed a bug submitted by
b'bug_vs_me'
b'Security Issue into Wallet lock protection '
11 Jan 2023
b'Nextcloud'
disclosed a bug submitted by
b'lukasreschke'
b'CSRF vulnerability in Nextcloud Desktop Client 3.6.1 on Windows when clicking malicious link '
11 Jan 2023
b'Node.js'
disclosed a bug submitted by
b'algisec1337'
b'Take over subdomain undici.nodejs.org.cdn.cloudflare.net'
11 Jan 2023
1
...
74
75
76
77
78
...
717
BY DENIS WERNER - @NOBBD -
IMPRESSUM