REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'8x8 Bounty'
disclosed a bug submitted by
b'yassinek3ch'
b'connect.8x8.com: Blind SSRF via /api/v2/chats/image-check allows for Internal Ports scan'
15 May 2023
b'LinkedIn'
disclosed a bug submitted by
b'find_me_here'
b"[ Continuation Report from #1814842 ] Can create articles using other users' NewsLetters"
15 May 2023
b'Nextcloud'
disclosed a bug submitted by
b'lukasreschke'
b'Reflected XSS vulnerability with full CSP bypass in Nextcloud installations using recommended bundle'
15 May 2023
b'GlassWire'
disclosed a bug submitted by
b'chip_sec'
b'Facebook App API credentials leaked in the APK'
12 May 2023
b'WordPress'
disclosed a bug submitted by
b'chip_sec'
b'PII of users can be downloaded from export pages'
12 May 2023
b'HackerOne'
disclosed a bug submitted by
b'iamr0000t'
b'HTML injection in email at https://www.hackerone.com/'
12 May 2023
b'LinkedIn'
disclosed a bug submitted by
b'spaceboy20'
b"Attacker can unpin posts from companies he's not part of."
12 May 2023
b'LinkedIn'
disclosed a bug submitted by
b'find_me_here'
b'Attackers do not need to Pay for a Subscription to get the `Discussion Group URL` in `Paid Learning`'
12 May 2023
b'LinkedIn'
disclosed a bug submitted by
b'encodedguy'
b'Delete any LinkedIn comment on learning API of other users'
12 May 2023
b'U.S. Department of State'
disclosed a bug submitted by
b'doosec101'
b'LDAP anonymous access enabled at certrep.pki.state.gov:389'
11 May 2023
b'IBM'
disclosed a bug submitted by
b'0xpugazh'
b'Moodle XSS on s-immerscio.comprehend.ibm.com'
11 May 2023
b'IBM'
disclosed a bug submitted by
b'gdattacker'
b'Subdomain Takeover Affecting at vex.weather.com'
10 May 2023
b'Mattermost'
disclosed a bug submitted by
b'uchihaluckycs'
b'Reset password link sent over unsecured http protocol'
10 May 2023
b'Brave Software'
disclosed a bug submitted by
b'ameenbasha'
b'download file type warning on Windows does not appear if "ask where to save file before downloading" setting is enabled'
10 May 2023
b'Rocket.Chat'
disclosed a bug submitted by
b'rijalrojan'
b'NoSQL injection in listEmojiCustom method call'
09 May 2023
b'Rocket.Chat'
disclosed a bug submitted by
b'sectex'
b'Cross-Site-Scripting in "Search Messages"'
09 May 2023
b'Rocket.Chat'
disclosed a bug submitted by
b'gronke'
b'Mute User can disclose private channel members to unauthorized users'
09 May 2023
b'Rocket.Chat'
disclosed a bug submitted by
b'vv9k'
b'Maliciously crafted message can cause Rocket.Chat server to stop responding'
09 May 2023
b'Rocket.Chat'
disclosed a bug submitted by
b'gronke'
b'Moving private messages into vision with updateMessage method'
09 May 2023
b'Elastic'
disclosed a bug submitted by
b'lu3ky-13'
b'blind Server-Side Request Forgery (SSRF) allows scanning internal ports'
05 May 2023
1
...
85
86
87
88
89
...
742
BY DENIS WERNER - @NOBBD -
IMPRESSUM