REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
57
b'ooooooo_q'
50
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Zomato'
disclosed a bug submitted by
b'ashoka_rao'
b'Add upto 10K rupees to a wallet by paying an arbitrary amount'
23 Feb 2022
b'TikTok'
disclosed a bug submitted by
b'johnstone'
b'Incorrect authorization to the intelbot service leading to ticket information'
23 Feb 2022
b'GitLab'
disclosed a bug submitted by
b'joaxcar'
b'IDOR in "external status check" API leaks data about any status check on the instance'
22 Feb 2022
b'QIWI'
disclosed a bug submitted by
b'uddeshaya'
b'broken authentication (password reset link not expire after use in https://network.tochka.com/sign-up)'
22 Feb 2022
b'Acronis'
disclosed a bug submitted by
b'lu3ky-13'
b'FULL SSRF '
22 Feb 2022
b'Zomato'
disclosed a bug submitted by
b'ashoka_rao'
b'Claiming the listing of a non-delivery restaurant through OTP manipulation'
22 Feb 2022
b'8x8'
disclosed a bug submitted by
b'adnanmalikinfo'
b' api key exposed in github.com//'
22 Feb 2022
b'Automattic'
disclosed a bug submitted by
b'ajoekerr'
b'De-anonymize anonymous tips through the Tumblr blog network'
21 Feb 2022
b'curl'
disclosed a bug submitted by
b'nsq11'
b' Remote memory disclosure vulnerability in libcurl on 64 Bit Windows'
21 Feb 2022
b'Zomato'
disclosed a bug submitted by
b'codersanjay'
b'Page has a link to google drive which has logos and a few customer phone recordings'
21 Feb 2022
b'Mattermost'
disclosed a bug submitted by
b'rynexxx'
b'Self XSS in Create New Workspace Screen'
20 Feb 2022
b'VK.com'
disclosed a bug submitted by
b'executor'
b' Android'
18 Feb 2022
b'Zenly'
disclosed a bug submitted by
b'mega7'
b'Subdomain Takeover of brand.zen.ly'
17 Feb 2022
b'Courier'
disclosed a bug submitted by
b'musab_alharany'
b'Missing SPF record on trycourier.app'
17 Feb 2022
b'Courier'
disclosed a bug submitted by
b'the_hacker_girl'
b'Broken Authentication Session Token Bug'
16 Feb 2022
b'Showmax'
disclosed a bug submitted by
b'qualin'
b' Cross-origin resource sharing'
15 Feb 2022
b'Nextcloud'
disclosed a bug submitted by
b'ctulhu'
b'When sharing a Deck card in conversation the metaData can be manipulated to open arbitrary URL'
15 Feb 2022
b'Shopify'
disclosed a bug submitted by
b'saurabhsankhwar3'
b'Ability to Disable the Login Attempt of any Shopify Owner for 24 hrs (Zero_Click)'
15 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'shiar'
b'Arbitrary File Read at via filename parameter'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'websecnl'
b'Broken Authentication'
14 Feb 2022
1
...
123
124
125
126
127
...
718
BY DENIS WERNER - @NOBBD -
IMPRESSUM