REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Nextcloud'
disclosed a bug submitted by
b'ibrahim71192'
b'A vulnerability classified as critical has been found in gsi-openssh-server 7.9p1 on Fedora (Connectivity Software) on server (http://95.217.64.181:22'
10 Dec 2022
b'Kubernetes'
disclosed a bug submitted by
b'weinongw'
b'SSRF vulnerability can be exploited when a hijacked aggregated api server such as metrics-server returns 30X'
10 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'mik-patient'
b'[nextcloud/server] Moment.js vulnerable to Inefficient Regular Expression Complexity'
09 Dec 2022
b'Rocket.Chat'
disclosed a bug submitted by
b'sectex'
b'Insecure use of shell.openExternal() leads to RCE in Rocket.Chat-Desktop'
08 Dec 2022
b'Sony'
disclosed a bug submitted by
b'splint3rsec'
b'SQL Injection on []'
07 Dec 2022
b'Node.js'
disclosed a bug submitted by
b'haxatron1'
b'DNS rebinding in --inspect via invalid octal IP address'
07 Dec 2022
b'LinkedIn'
disclosed a bug submitted by
b'headhunter'
b'Unauthorized access to resumes stored on LinkedIn'
07 Dec 2022
b'TikTok'
disclosed a bug submitted by
b'imran_nisar'
b'Ability to change permissions across seller platform'
06 Dec 2022
b'8x8'
disclosed a bug submitted by
b'shuvam321'
b'Unprotected Atlantis Server at https://152.70..'
06 Dec 2022
b'Linktree'
disclosed a bug submitted by
b'jagata'
b'XSS in linktr.ee - on link thumbnail adding'
06 Dec 2022
b'EXNESS'
disclosed a bug submitted by
b'ashwarya'
b'IDOR in Stats API Endpoint Allows Viewing Equity or Net Profit of Any MT Account '
05 Dec 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'kurohiro'
b'CVE-2022-35260: .netrc parser out-of-bounds access'
03 Dec 2022
b'Shopify'
disclosed a bug submitted by
b'ian'
b'Exposed Cortex API at https://cortex-ingest.shopifycloud.com/'
02 Dec 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'robbotic'
b'POST following PUT confusion'
02 Dec 2022
b'Acronis'
disclosed a bug submitted by
b'mooimacow'
b'XSS in Acronis Cloud Manager Admin Portal'
02 Dec 2022
b'MTN Group'
disclosed a bug submitted by
b'roland_hack'
b'Authentication bypass in https://nin.mtn.ng'
02 Dec 2022
b'Shopify'
disclosed a bug submitted by
b'ashketchum'
b'Stored XSS in /admin/product and /admin/collections'
01 Dec 2022
b'Shopify'
disclosed a bug submitted by
b'attackerbhai'
b'Disconnecting an external login provider does not revoke session'
01 Dec 2022
b'Shopify'
disclosed a bug submitted by
b'bored-engineer'
b'Read/Write arbitrary (non-HttpOnly) cookies on checkout pages via GoogleAnalyticsAdditionalScripts postMessage handler'
01 Dec 2022
b'Shopify'
disclosed a bug submitted by
b'm7mdharoun'
b'Subdomain Takeover at course.oberlo.com'
01 Dec 2022
1
...
100
101
102
103
104
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM