REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Tor'
disclosed a bug submitted by
b'soulhunter'
b'Address Bar Spoofing on TOR Browser'
02 Jan 2023
b'Nextcloud'
disclosed a bug submitted by
b'daniel_calvino_sanchez'
b'Guests can continue to receive video streams from call after being removed from a conversation'
31 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'hackeronefour'
b'No password length limit when creating a user as an administrator'
31 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'juliushaertl'
b'Disabled download shares still allow download through preview images'
31 Dec 2022
b'JetBlue'
disclosed a bug submitted by
b'dracoludio'
b'Dom-Based XSS on parameter ?vsid='
30 Dec 2022
b'Twitter'
disclosed a bug submitted by
b'jub0bs'
b"Chained open redirects and use of Ideographic Full Stop defeat Twitter's approach to blocking links"
29 Dec 2022
b'Khan Academy'
disclosed a bug submitted by
b'fdeleite'
b'S3 bucket takeover [learn2.khanacademy.org]'
29 Dec 2022
b'MTN Group'
disclosed a bug submitted by
b'thewikiii'
b'Wordpress users Disclosure [ /wp-json/wp/v2/users/ ] Not Resolved () '
28 Dec 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'jrs53'
b'Leak of sensitive values to Airflow rendered template'
27 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'spaceraccoon'
b'SMTP Command Injection in Appointment Emails via Newlines'
27 Dec 2022
b'curl'
disclosed a bug submitted by
b'bagder'
b'CVE-2022-43552: HTTP Proxy deny use-after-free'
26 Dec 2022
b'Linktree'
disclosed a bug submitted by
b'twelvesix'
b'Account takeover - improper validation of jwt signature (with regards to experiation date claim)'
26 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'tobiaskaminsky'
b'nextcloudcmd incorrectly trusts bad TLS certificates'
25 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'andyscherzinger'
b'Talk Android broadcast receiver is not protected by broadcastPermission allowing malicious apps to communicate'
25 Dec 2022
b'MTN Group'
disclosed a bug submitted by
b'coyemerald'
b'Developer Mistake'
25 Dec 2022
b'MTN Group'
disclosed a bug submitted by
b'coyemerald'
b'Exposure Of Admin Username & Password'
25 Dec 2022
b'MTN Group'
disclosed a bug submitted by
b'netboy'
b'Information Disclosure Leads To User Data Leak'
24 Dec 2022
b'Acronis'
disclosed a bug submitted by
b'melar_dev'
b'mysql credentials exposed on - https://cz.acronis.com/docker-compose.yml'
24 Dec 2022
b'Omise'
disclosed a bug submitted by
b'sim4n6'
b'Secret API Key is logged in cleartext '
23 Dec 2022
b'Khan Academy'
disclosed a bug submitted by
b'moom825'
b'xss due to incorrect handling of postmessages'
23 Dec 2022
1
...
89
90
91
92
93
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM