REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Stripe'
disclosed a bug submitted by
b'mr_asg'
b'Unauthorized Canceling/Unsubscribe TaxJar account & Payment information DIsclosure'
20 Dec 2022
b'Stripe'
disclosed a bug submitted by
b'mr_asg'
b'[Broken Access Control ] Unauthorized Linking accounts & Linked Accounts info DIsclosure'
20 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'errorx404'
b'Missing length validation of user displayname allows to generate an SQL error'
20 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'lauritz'
b'[user_oidc] Stored XSS via Authorization Endpoint - Safari-Only'
18 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'lauritz'
b'[user_oidc] Unencrypted Communications'
18 Dec 2022
b'Khan Academy'
disclosed a bug submitted by
b'shuvam321'
b'Email Verification Bypass Allows Users to Add & verify Any Email As Guardians Email '
17 Dec 2022
b'Sony'
disclosed a bug submitted by
b'n0x496n'
b'LFI at http://www.'
16 Dec 2022
b'Consensys'
disclosed a bug submitted by
b'krrish_hackk'
b'Sub-Domain Takeover at http://www.codefi.consensys.net/'
16 Dec 2022
b'Automattic'
disclosed a bug submitted by
b'aaroncarson'
b'Akismet API keys are exposed by authentication method'
16 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'0x3bdo'
b'Exposed Log File Lead to Full Internal path disclosure at [https://nextcloud.com/wp-content/debug.log] '
15 Dec 2022
b'MTN Group'
disclosed a bug submitted by
b'jimmisimon'
b'Firebase credentials leak'
15 Dec 2022
b'Nintendo'
disclosed a bug submitted by
b'rambo6glaz'
b'[MK8DX] Improper verification of Competition creation allows to create "Official" competitions'
15 Dec 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'ooooooo_q'
b'ReDoS (Rails::Html::PermitScrubber.scrub_attribute)'
14 Dec 2022
b'Ruby on Rails'
disclosed a bug submitted by
b'0b5cur17y'
b'Rails::Html::SafeListSanitizer vulnerable to XSS when certain tags are allowed (math+style || svg+style)'
14 Dec 2022
b'Ruby on Rails'
disclosed a bug submitted by
b'0b5cur17y'
b'Incomplete fix for CVE-2022-32209 (XSS in Rails::Html::Sanitizer under certain configurations)'
14 Dec 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'theinternetofdefcon_'
b'Electron CVE-2022-35954 Delimiter Injection Vulnerability in exportVariable'
14 Dec 2022
b'Ruby'
disclosed a bug submitted by
b'djspinmonkey'
b'Attacker can smuggle a malicious domain in a URI object.'
13 Dec 2022
b'GitHub'
disclosed a bug submitted by
b'legit-security'
b'DoS via markdown API from unauthenticated user'
13 Dec 2022
b'Twitter'
disclosed a bug submitted by
b'jub0bs'
b'Link-shortener bypass (regression on fix for #1032610)'
12 Dec 2022
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'mattipv4'
b'cd=false (DNSSEC) not respected in DNS over HTTPS JSON requests'
12 Dec 2022
1
...
99
100
101
102
103
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM