REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
57
b'ooooooo_q'
50
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'8x8'
disclosed a bug submitted by
b'remonsec'
b'F5 BIG-IP TMUI RCE - CVE-2020-5902 (.packet8.net)'
25 Mar 2022
b'Dragon'
disclosed a bug submitted by
b'engr-naseem1'
b'Business Logic Flaw in the subscription of the app'
25 Mar 2022
b'Kubernetes'
disclosed a bug submitted by
b'0xlegendkiller'
b'Broken link hijacking in https://kubernetes-csi.github.io/docs/drivers.html?highlight=chubaofs#production-drivers'
25 Mar 2022
b'TikTok'
disclosed a bug submitted by
b'bushidobrown200'
b'Impersonation of tiktok account via Broken Link in TikTok Newsroom'
24 Mar 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'hkratz'
b'Time-of-check to time-of-use vulnerability in the std::fs::remove_dir_all() function of the Rust standard library'
24 Mar 2022
b'Basecamp'
disclosed a bug submitted by
b'fuzzsqlb0f'
b'Improper Authentication via previous backup code login'
24 Mar 2022
b'Stripe'
disclosed a bug submitted by
b'gregxsunday'
b'Bypassing domain deny_list rule in Smokescreen via trailing dot leads to SSRF'
23 Mar 2022
b'pixiv'
disclosed a bug submitted by
b'aidilarf_2000'
b'XSS Reflected at https://sketch.pixiv.net/ Via `next_url`'
23 Mar 2022
b'ImpressCMS'
disclosed a bug submitted by
b'egix'
b'Incorrect Authorization Checks in /include/findusers.php'
22 Mar 2022
b'ImpressCMS'
disclosed a bug submitted by
b'egix'
b'Arbitrary File Deletion via Path Traversal in image-edit.php'
22 Mar 2022
b'ImpressCMS'
disclosed a bug submitted by
b'egix'
b'Potential Authentication Bypass through "autologin" feature'
22 Mar 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'addisoncrump'
b'Regexes with large repetitions on empty sub-expressions take a very long time to parse'
22 Mar 2022
b'Omise'
disclosed a bug submitted by
b'sim4n6'
b"The endpoint '/test/webhooks' is vulnerable to DNS Rebinding"
22 Mar 2022
b'Omise'
disclosed a bug submitted by
b'sim4n6'
b'Race condition on action: Invite members to a team'
22 Mar 2022
b'Khan Academy'
disclosed a bug submitted by
b'sim4n6'
b'The endpoint /api/internal/graphql/requestAuthEmail on Khanacademy.or is vulnerable to Race Condition Attack.'
22 Mar 2022
b'Lyst'
disclosed a bug submitted by
b'deksterh1'
b'Web Cache poisoning attack leads to User information Disclosure and more'
22 Mar 2022
b'Lyst'
disclosed a bug submitted by
b'mandark'
b'[https:///]&&[https:///] Open Redirection'
22 Mar 2022
b'Mattermost'
disclosed a bug submitted by
b'rynexxx'
b'html injection via invite members can be leads account takeover '
22 Mar 2022
b'Adobe'
disclosed a bug submitted by
b'sheikhrishad0'
b'Log4j Java RCE in [beta.dev.adobeconnect.com]'
21 Mar 2022
b'GitLab'
disclosed a bug submitted by
b'vakzz'
b'Arbitrary file read via the bulk imports UploadsPipeline'
21 Mar 2022
1
...
119
120
121
122
123
...
718
BY DENIS WERNER - @NOBBD -
IMPRESSUM