REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'TikTok'
disclosed a bug submitted by
b'mrhavit'
b'IDOR for changing privacy settings on any memories'
27 Jan 2023
b'TikTok'
disclosed a bug submitted by
b's3c'
b'XSS at TikTok Ads Endpoint'
27 Jan 2023
b'EXNESS'
disclosed a bug submitted by
b'siddharthamx'
b'Verification process done using different documents without corresponding to user information / User information can be changed after verification'
27 Jan 2023
b'8x8'
disclosed a bug submitted by
b'xdopa'
b'wavecell.com: Broken Link Hijacking / Instagram Takeover @'
27 Jan 2023
b'TikTok'
disclosed a bug submitted by
b'mrhavit'
b'Any user can vote on `Friend Only` video pull'
27 Jan 2023
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b"Github Apps can use Scoped-User-To-Server Tokens to Obtain Full Access to User's Projects in Project V2 GraphQL api"
26 Jan 2023
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'albertspedersen'
b'Using special IPv4-mapped IPv6 addresses to bypass local IP ban'
24 Jan 2023
b'Linktree'
disclosed a bug submitted by
b'0xshdax'
b'[song.link] Open Redirect'
23 Jan 2023
b'Slack'
disclosed a bug submitted by
b'pisarenko'
b'XSS on link and window.opener '
23 Jan 2023
b'LocalTapiola'
disclosed a bug submitted by
b'voiddy'
b'Cookie exfiltration through XSS on the main search request of www.lahitapiola.fi'
19 Jan 2023
b'Yelp'
disclosed a bug submitted by
b'rac_fckscty'
b'PURGE is not authenticated'
19 Jan 2023
b'KAYAK'
disclosed a bug submitted by
b'retr02332'
b'1 click Account takeover via deeplink in [com.kayak.android]'
19 Jan 2023
b'HackerOne'
disclosed a bug submitted by
b'reigertje'
b'Private information exposed through GraphQL search endpoints aggregates'
19 Jan 2023
b'Adobe'
disclosed a bug submitted by
b'dreamer_eh'
b'HTML INJECTION on https://adobedocs.github.io/JourneyAPI/ due to outdated SWAGGER UI'
17 Jan 2023
b'Adobe'
disclosed a bug submitted by
b'dreamer_eh'
b'DOM XSS at `https://adobedocs.github.io/indesign-api-docs/?configUrl={site}` due to outdated Swagger UI'
17 Jan 2023
b'ownCloud'
disclosed a bug submitted by
b'atorralba'
b'GitHub Security Lab (GHSL) Vulnerability Report: Insufficient path validation in ReceiveExternalFilesActivity.java (GHSL-2022-060)'
16 Jan 2023
b'Mattermost'
disclosed a bug submitted by
b'annonmous'
b'Uninstalling Mattermost Launcher for Windows (64-bit), then reinstalling keeps you logged in without authentication'
14 Jan 2023
b'Yelp'
disclosed a bug submitted by
b'ethack1886'
b'Robots.txt file with potentially sensitive content.'
13 Jan 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'berserkbd47'
b'Critical sensitive information Disclosure. [HtUS]'
13 Jan 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'berserkbd47'
b'Wordpress Takeover using setup configuration at http://.edu [HtUS]'
13 Jan 2023
1
...
86
87
88
89
90
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM