REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Hyperledger'
disclosed a bug submitted by
b'mik-patient'
b'CVE-2017-5929: Hyperledger - Arbitrary Deserialization of Untrusted Data '
18 Oct 2022
b'Shopify'
disclosed a bug submitted by
b'noblesix'
b'XSS in www.shopify.com/markets?utm_source='
18 Oct 2022
b'MTN Group'
disclosed a bug submitted by
b'mr_sparrow'
b'Otp bypass in verifying nin'
17 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'0x1int'
b'Host Header Injection on https:////Account/ForgotPassword'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'0xd0ff9'
b'Unauthenticated SQL Injection at [HtUS]'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'sudi'
b'.git folder exposed [HtUS]'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'shreky'
b'Unauthenticated PII leak on verified/requested to be verified profiles on /app/org/{id}/profile/{id}/version/{id} [HtUS]'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'ludv1k'
b'Authentication bypass leads to Information Disclosure at U.S Air Force "https://"'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'720922'
b'SSRF to read AWS metaData at https:/// [HtUS]'
14 Oct 2022
b'8x8'
disclosed a bug submitted by
b'testingforbugs'
b'Subdomain Takeover at http://.get8x8.com/'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'ibrahim0936356'
b"Found Origin IP's Lead To Access "
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'g4mb4'
b'Broken access discloses users and PII at https:// [HtUS]'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'sudi'
b'Local file read at https:/// [HtUS]'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'jr0ch17'
b'[hta3] Chain of ESI Injection & Reflected XSS leading to Account Takeover on []'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'jr0ch17'
b'[HTA2] Receiving access request on @wearehackerone.com email address'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'0x1int'
b'Blind SSRF via image upload URL downloader on https:/// '
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'snifyak'
b'Account Takeover and Information update due to cross site request forgery via POST /registration/my-account.cfm'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'0x1int'
b'IDOR leaking PII data via VendorId parameter'
14 Oct 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'nightm4re'
b'Account takeover on [HtUS]'
14 Oct 2022
b'Shopify'
disclosed a bug submitted by
b'hazemhussien99'
b'Self XSS in https://linkpop.com/dashboard/admin'
13 Oct 2022
1
...
107
108
109
110
111
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM