REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Sony'
disclosed a bug submitted by
b'splint3rsec'
b'SQL Injection on []'
07 Dec 2022
b'Node.js'
disclosed a bug submitted by
b'haxatron1'
b'DNS rebinding in --inspect via invalid octal IP address'
07 Dec 2022
b'LinkedIn'
disclosed a bug submitted by
b'headhunter'
b'Unauthorized access to resumes stored on LinkedIn'
07 Dec 2022
b'TikTok'
disclosed a bug submitted by
b'imran_nisar'
b'Ability to change permissions across seller platform'
06 Dec 2022
b'8x8'
disclosed a bug submitted by
b'shuvam321'
b'Unprotected Atlantis Server at https://152.70..'
06 Dec 2022
b'Linktree'
disclosed a bug submitted by
b'jagata'
b'XSS in linktr.ee - on link thumbnail adding'
06 Dec 2022
b'EXNESS'
disclosed a bug submitted by
b'ashwarya'
b'IDOR in Stats API Endpoint Allows Viewing Equity or Net Profit of Any MT Account '
05 Dec 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'kurohiro'
b'CVE-2022-35260: .netrc parser out-of-bounds access'
03 Dec 2022
b'Shopify'
disclosed a bug submitted by
b'ian'
b'Exposed Cortex API at https://cortex-ingest.shopifycloud.com/'
02 Dec 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'robbotic'
b'POST following PUT confusion'
02 Dec 2022
b'Acronis'
disclosed a bug submitted by
b'mooimacow'
b'XSS in Acronis Cloud Manager Admin Portal'
02 Dec 2022
b'MTN Group'
disclosed a bug submitted by
b'roland_hack'
b'Authentication bypass in https://nin.mtn.ng'
02 Dec 2022
b'Shopify'
disclosed a bug submitted by
b'ashketchum'
b'Stored XSS in /admin/product and /admin/collections'
01 Dec 2022
b'Shopify'
disclosed a bug submitted by
b'attackerbhai'
b'Disconnecting an external login provider does not revoke session'
01 Dec 2022
b'Shopify'
disclosed a bug submitted by
b'bored-engineer'
b'Read/Write arbitrary (non-HttpOnly) cookies on checkout pages via GoogleAnalyticsAdditionalScripts postMessage handler'
01 Dec 2022
b'Shopify'
disclosed a bug submitted by
b'm7mdharoun'
b'Subdomain Takeover at course.oberlo.com'
01 Dec 2022
b'MTN Group'
disclosed a bug submitted by
b'wallotry'
b'Remove Every User, Admin, And Owner Out Of Their Teams on developers.mtn.com via IDOR + Information Disclosure'
01 Dec 2022
b'MTN Group'
disclosed a bug submitted by
b'coyemerald'
b'Unprotected Direct Object Reference'
01 Dec 2022
b'MTN Group'
disclosed a bug submitted by
b'shuvam321'
b'Firebase Database Takeover in https://pulseradio.mtn.co.ug/'
01 Dec 2022
b'Nextcloud'
disclosed a bug submitted by
b'errorx404'
b'Calendar name length not validated before writing to database'
01 Dec 2022
1
...
104
105
106
107
108
...
742
BY DENIS WERNER - @NOBBD -
IMPRESSUM