REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
56
b'ooooooo_q'
50
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'motu-vai'
b'Enable 2Fa verification without verifying email leads account takeover'
31 Aug 2022
b'curl'
disclosed a bug submitted by
b'haxatron1'
b'CVE-2022-35252: control code in cookie denial of service'
31 Aug 2022
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'lohigowda'
b'Blind SSRF on platform.dash.cloudflare.com Due to Sentry misconfiguration'
31 Aug 2022
b'TikTok'
disclosed a bug submitted by
b'fransrosen'
b"TikTok's pixel/sdk.js leaks current URL from websites using postMessage"
30 Aug 2022
b'Palo Alto Software'
disclosed a bug submitted by
b'zer0code'
b'weak protection against brute-forcing on login api leads to account takeover '
29 Aug 2022
b'LinkedIn'
disclosed a bug submitted by
b'naaash'
b'Privilege Escalation - "Analyst" Role Can View Email Domains of a Company - [GET /voyager/api/voyagerOrganizationDashEmailDomainMappings]'
26 Aug 2022
b'GitLab'
disclosed a bug submitted by
b'mega7'
b'Unauthorized access'
25 Aug 2022
b'Stripo Inc'
disclosed a bug submitted by
b'deb0con'
b'Non-revoked API Key Information disclosure via Stripo_report()'
25 Aug 2022
b'MTN Group'
disclosed a bug submitted by
b'theranger'
b'Default Login Credentials on https://broadbandmaps.mtn.com.gh/ '
25 Aug 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'albinowax'
b'Pause-based desync in Apache HTTPD'
25 Aug 2022
b'Nord Security'
disclosed a bug submitted by
b'bashketchum'
b'NordVPN Linux Client - Unsafe service file permissions leads to Local Privilege Escalation'
24 Aug 2022
b'Sony'
disclosed a bug submitted by
b'leo_rac'
b'Reflected XSS on pages.email.sel.sony.com/page.aspx via jobid parameter'
24 Aug 2022
b'Uber'
disclosed a bug submitted by
b'mustafa_farrag'
b'Golang expvar Information Disclosure'
24 Aug 2022
b'Node.js'
disclosed a bug submitted by
b'nagaro'
b'Off-by-slash vulnerability in nodejs.org and iojs.org'
24 Aug 2022
b'Invision Power Services, Inc.'
disclosed a bug submitted by
b'fthacker101'
b'support.invisionpower.com takeover the subdomain with Zendesk'
24 Aug 2022
b'Automattic'
disclosed a bug submitted by
b'sawrav-chowdhury'
b'XSS and HTML Injection on the pressable.com search box'
23 Aug 2022
b'MTN Group'
disclosed a bug submitted by
b'error201'
b'Blind SSRF External Interaction on https://mtngbissau.com/'
21 Aug 2022
b'Monero'
disclosed a bug submitted by
b'xfang'
b'RPC call crashes node'
20 Aug 2022
b'TikTok'
disclosed a bug submitted by
b'sinayeganeh'
b'Stored XSS on TikTok Ads'
19 Aug 2022
b'GitHub'
disclosed a bug submitted by
b'jupenur'
b'Delimiter injection in GitHub Actions core.exportVariable'
18 Aug 2022
1
...
95
96
97
98
99
...
717
BY DENIS WERNER - @NOBBD -
IMPRESSUM