REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Shopify'
disclosed a bug submitted by
b'kannthu'
b'XSS at jamfpro.shopifycloud.com'
02 Feb 2023
b'Judge.me '
disclosed a bug submitted by
b'penguinshelp'
b'Self-XSS due to image URL can be eploited via XSSJacking techniques in review email'
01 Feb 2023
b'Judge.me '
disclosed a bug submitted by
b'criptex'
b'HTML INJECTION (STORED)'
01 Feb 2023
b'Judge.me '
disclosed a bug submitted by
b'penguinshelp'
b'Improper Access Control in Ali Express Importer'
01 Feb 2023
b'Judge.me '
disclosed a bug submitted by
b'vj1naruto'
b'Stored XSS in Public Profile Reviews'
01 Feb 2023
b'Shopify'
disclosed a bug submitted by
b'irisrumtub'
b'Stored XSS in SVG file as data: url'
31 Jan 2023
b'JetBlue'
disclosed a bug submitted by
b'mmdz'
b'Open Redirect at blueonboardingqa1.jetblue.com'
29 Jan 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'haqpl'
b'Rails ActionView sanitize helper bypass leading to XSS using SVG tag.'
29 Jan 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'theinternetofdefcon_'
b'[U.S. Air Force] Information disclosure due unauthenticated access to APIs and system browser functions'
27 Jan 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'alishah'
b'Reflected XSS on .mil'
27 Jan 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'maskedpersian'
b'reflected xss in www..gov'
27 Jan 2023
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'notajax'
b'XSS on ( .gov ) Via URL path'
27 Jan 2023
b'TikTok'
disclosed a bug submitted by
b'mrhavit'
b'IDOR for changing privacy settings on any memories'
27 Jan 2023
b'TikTok'
disclosed a bug submitted by
b's3c'
b'XSS at TikTok Ads Endpoint'
27 Jan 2023
b'EXNESS'
disclosed a bug submitted by
b'siddharthamx'
b'Verification process done using different documents without corresponding to user information / User information can be changed after verification'
27 Jan 2023
b'8x8'
disclosed a bug submitted by
b'xdopa'
b'wavecell.com: Broken Link Hijacking / Instagram Takeover @'
27 Jan 2023
b'TikTok'
disclosed a bug submitted by
b'mrhavit'
b'Any user can vote on `Friend Only` video pull'
27 Jan 2023
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b"Github Apps can use Scoped-User-To-Server Tokens to Obtain Full Access to User's Projects in Project V2 GraphQL api"
26 Jan 2023
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'albertspedersen'
b'Using special IPv4-mapped IPv6 addresses to bypass local IP ban'
24 Jan 2023
b'Linktree'
disclosed a bug submitted by
b'0xshdax'
b'[song.link] Open Redirect'
23 Jan 2023
1
...
94
95
96
97
98
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM