REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
67
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'curl'
disclosed a bug submitted by
b'lg_oled77c5pua'
b'HSTS accepted from HTTP origin behind HTTPS proxy'
17 Mar 2026
b'curl'
disclosed a bug submitted by
b'am-perip'
b'Unescaped username in SASL DIGEST-MD5 response allows injection'
17 Mar 2026
b'LinkedIn'
disclosed a bug submitted by
b'dphoeniixx'
b'Session Cookie Leakage via Static Header Field in WebViewerFragment'
17 Mar 2026
b'Lovable VDP'
disclosed a bug submitted by
b'ziadmomen'
b'Business Logic Bypass Allows Setting Read Access Role Without Pro Plan Subscription'
16 Mar 2026
b'curl'
disclosed a bug submitted by
b'tavro'
b'SMB READ_ANDX DataOffset not validated'
16 Mar 2026
b'Basecamp'
disclosed a bug submitted by
b'perxibes'
b'Unauthenticated access to private files on app.fizzy.do via Active Storage URLs leads to information disclosure'
16 Mar 2026
b'Consensys'
disclosed a bug submitted by
b'aszx87410'
b'Authorization Bypass in Starknet Snap via enableAuthorize parameter leads to unauthorized transaction signing'
13 Mar 2026
b'IBM'
disclosed a bug submitted by
b'cr3ckerxploit'
b'SQL Injection vulnerability found on ibm.com endpoint'
12 Mar 2026
b'curl'
disclosed a bug submitted by
b'henriqueg'
b'Curl_compareheader() fails to match multi-value HTTP headers'
12 Mar 2026
b'curl'
disclosed a bug submitted by
b'otiscui'
b'urlapi: off-by-one in custom scheme validation skips last character'
12 Mar 2026
b'Lovable VDP'
disclosed a bug submitted by
b'marioniangi'
b'Bypass of Open Redirect Fix on lovable.dev via /..// Path Traversal in redirect parameter'
12 Mar 2026
b'curl'
disclosed a bug submitted by
b'm777m0'
b'NULL Pointer Dereference (DoS) in libcurl SFTP QUOTE command parsing due to missing return statement'
11 Mar 2026
b'curl'
disclosed a bug submitted by
b'rat5ak'
b'CVE-2026-3805: use after free in SMB connection reuse'
11 Mar 2026
b'curl'
disclosed a bug submitted by
b'nobcoder'
b'CVE-2026-3784: wrong proxy connection reuse with credentials'
11 Mar 2026
b'curl'
disclosed a bug submitted by
b'spectreglobalsec'
b'CVE-2026-3783: token leak with redirect and netrc'
11 Mar 2026
b'curl'
disclosed a bug submitted by
b'sabari_n'
b'Connection Reuse Ignores OAuth Bearer Token Mismatch'
10 Mar 2026
b'curl'
disclosed a bug submitted by
b'sabari_n'
b'CURLOPT_UNRESTRICTED_AUTH Dangerous Default Documentation Gap'
10 Mar 2026
b'AWS VDP'
disclosed a bug submitted by
b'locus-x64'
b'Arbitrary Code Execution via Scanner Bypass in **aws-diagram-mcp-server** `exec()` Namespace'
09 Mar 2026
b'Lovable VDP'
disclosed a bug submitted by
b'hossam25'
b'Users can change project visibility which requires high subscription by just changing request body'
09 Mar 2026
b'curl'
disclosed a bug submitted by
b'brewm4ster'
b'LM Challenge-Response Hash Always Sent in SMB Authentication'
09 Mar 2026
1
2
3
4
...
756
BY DENIS WERNER - @NOBBD -
IMPRESSUM