REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Uber'
disclosed a bug submitted by
b'mustafa_farrag'
b'Golang expvar Information Disclosure'
24 Aug 2022
b'Node.js'
disclosed a bug submitted by
b'nagaro'
b'Off-by-slash vulnerability in nodejs.org and iojs.org'
24 Aug 2022
b'Invision Power Services, Inc.'
disclosed a bug submitted by
b'fthacker101'
b'support.invisionpower.com takeover the subdomain with Zendesk'
24 Aug 2022
b'Automattic'
disclosed a bug submitted by
b'sawrav-chowdhury'
b'XSS and HTML Injection on the pressable.com search box'
23 Aug 2022
b'MTN Group'
disclosed a bug submitted by
b'error201'
b'Blind SSRF External Interaction on https://mtngbissau.com/'
21 Aug 2022
b'Monero'
disclosed a bug submitted by
b'xfang'
b'RPC call crashes node'
20 Aug 2022
b'TikTok'
disclosed a bug submitted by
b'sinayeganeh'
b'Stored XSS on TikTok Ads'
19 Aug 2022
b'GitHub'
disclosed a bug submitted by
b'jupenur'
b'Delimiter injection in GitHub Actions core.exportVariable'
18 Aug 2022
b'Hyperledger'
disclosed a bug submitted by
b'bhaskar_ram'
b'Cross Site Scripting Vulnerability in fabric-sdk-py source code '
17 Aug 2022
b'TikTok'
disclosed a bug submitted by
b'aidilarf_2000'
b'IDOR on TikTok Seller'
16 Aug 2022
b'TikTok'
disclosed a bug submitted by
b's3c'
b'CSRF Account Takeover'
16 Aug 2022
b'Semrush'
disclosed a bug submitted by
b'a_d_a_m'
b"IDOR allowing to read another user's token on the Social Media Ads service"
16 Aug 2022
b'Kubernetes'
disclosed a bug submitted by
b'amlweems'
b'Ingress-nginx annotation injection allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces'
13 Aug 2022
b'Showmax'
disclosed a bug submitted by
b'miron666'
b'Reflected XSS at https://stories.showmax.com/wp-content/themes/theme-internal_ss/blocks/ajax/a.php via `ss_country_filter` param'
12 Aug 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b's1r1u5'
b'Disabling context isolation, nodeIntegrationInSubFrames using an unauthorised frame.'
11 Aug 2022
b'Shopify'
disclosed a bug submitted by
b'0x50d'
b'Admin panel Exposure without credential at https://plus-website.shopifycloud.com/admin.php'
11 Aug 2022
b'Top Echelon Software'
disclosed a bug submitted by
b'hammodmt'
b'Wordpress Users Disclosure (/wp-json/wp/v2/users/) '
11 Aug 2022
b'Hyperledger'
disclosed a bug submitted by
b'bhaskar_ram'
b'fix(security):Path Traversal Bug'
11 Aug 2022
b'Top Echelon Software'
disclosed a bug submitted by
b'sohelahmed786'
b'Disable xmlrpc.php file'
11 Aug 2022
b'PortSwigger Web Security'
disclosed a bug submitted by
b'mr_vrush'
b'Redirection in Repeater & Intruder Tab'
11 Aug 2022
1
...
120
121
122
123
124
...
742
BY DENIS WERNER - @NOBBD -
IMPRESSUM