REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'LinkedIn'
disclosed a bug submitted by
b'nagu123'
b'HTML Injection in LinkedIn Premium Support Chat'
07 May 2025
b'Dust'
disclosed a bug submitted by
b'yoyomiski'
b'BAC Bypass chatbot restrictions via unauthorized mention injection'
06 May 2025
b'curl'
disclosed a bug submitted by
b'evilginx'
b'HTTP/3 Stream Dependency Cycle Exploit'
04 May 2025
b'RubyGems'
disclosed a bug submitted by
b'jagat-singh'
b'`/names.nsf` and all `/names*` files route to public API on rubygems.org'
03 May 2025
b'Fastly VDP'
disclosed a bug submitted by
b'hasn0x'
b'Open Redirect on https://api.fastly.com/'
02 May 2025
b'IBM'
disclosed a bug submitted by
b'muhammadwaseem3'
b'Middleware Authentication Bypass on IBM Portal'
02 May 2025
b'Dust'
disclosed a bug submitted by
b'sjalu'
b'Stored XSS in File Upload Leads to Privilege Escalation and Full Workspace Takeover'
02 May 2025
b'WakaTime'
disclosed a bug submitted by
b'ctrl_cipher'
b'Session Replay Attack Allows Authentication Bypass via Captured Login Responses Allowing Bypass of 429 Too many attempts for Multiple Failed Logins'
01 May 2025
b'Dust'
disclosed a bug submitted by
b'yoyomiski'
b'Privilege Persistence via Cloned Agent'
30 Apr 2025
b'curl'
disclosed a bug submitted by
b'tannicarcher'
b'Double Free Vulnerability in `libcurl` Cookie Management (`cookie.c`)'
29 Apr 2025
b'curl'
disclosed a bug submitted by
b'tannicarcher'
b'Use of a Broken or Risky Cryptographic Algorithm (CWE-327) in libcurl'
29 Apr 2025
b'IBM'
disclosed a bug submitted by
b'thpless'
b'Information disclosure on IBM training service endpoint'
29 Apr 2025
b'Dust'
disclosed a bug submitted by
b'pent0ss'
b'Improper Session Invalidation Auto Sign-In Without Credentials After Logout (Affects Chrome & Firefox)'
29 Apr 2025
b'WakaTime'
disclosed a bug submitted by
b'ctrl_cipher'
b'Broken Access Control Exposes Email Verification Status and Privacy Settings via API Endpoint'
29 Apr 2025
b'Dust'
disclosed a bug submitted by
b'0xsom3a'
b'Privilege Escalation leads to Unauthorized Access to Private Conversations By any Regular user [Read , Edit and Delete]'
29 Apr 2025
b'Dust'
disclosed a bug submitted by
b'qatada'
b'User Limit Bypass via Pending Invitations in Workspace System'
29 Apr 2025
b'Dust'
disclosed a bug submitted by
b'0xsom3a'
b'Race Condition in Folder Creation Allows Bypassing Folder Limit'
29 Apr 2025
b'Internet Bug Bounty'
disclosed a bug submitted by
b'tyage'
b'Possible Sensitive Session Information Leak in Active Storage'
27 Apr 2025
b'Internet Bug Bounty'
disclosed a bug submitted by
b'l33thaxor'
b'CVE-2024-43398: DoS vulnerability in REXML'
27 Apr 2025
b'curl'
disclosed a bug submitted by
b'bsr13'
b'Heapbased buffer overflow in curl -K <config_file> allows arbitrary write .'
27 Apr 2025
1
...
10
11
12
13
14
...
737
BY DENIS WERNER - @NOBBD -
IMPRESSUM