REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
57
b'ooooooo_q'
50
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'websecnl'
b'IDOR'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'pll25'
b'CUI Labelled document out in the open'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'dreyand72'
b'EC2 subdomain takeover at http:///'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'rozerx00'
b'XSS trigger via HTML Iframe injection in ( https:// ) due to unfiltered HTML tags'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'pelegn'
b'Reflected XSS at https:// via "" parameter'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'pelegn'
b'Reflected XSS at https:// via "" parameter'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'pelegn'
b'Reflected XSS at https:/// via "" parameter'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'pelegn'
b'Reflected XSS at https:/// via "" parameter'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'pelegn'
b'Reflected XSS at https:/// via "" parameter'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'fiveguyslover'
b'(CORS) Cross-origin resource sharing misconfiguration on https://'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'pirateducky'
b'default creds on https://'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'takester'
b'Unauthorized access to PII leads to MASS account Takeover'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'iam_a_jinchuriki'
b'RXSS ON https://'
14 Feb 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'ghostxsec'
b'[CVE-2020-3452] Unauthenticated file read in Cisco ASA'
14 Feb 2022
b'UPchieve'
disclosed a bug submitted by
b'zeyu2001'
b'Widespread CSRF on authenticated POST endpoints'
13 Feb 2022
b'Shopify'
disclosed a bug submitted by
b'hogarth45'
b'[h1-2102] Break permissions waterfall'
12 Feb 2022
b'Twitter'
disclosed a bug submitted by
b'iambouali'
b"Blind XSS on Twitter's internal Jira panel at allows exfiltration of hackers reports and other sensitive data"
12 Feb 2022
b'Twitter'
disclosed a bug submitted by
b'zhirinovskiy'
b'Discoverability by phone number/email restriction bypass'
11 Feb 2022
b'FetLife'
disclosed a bug submitted by
b'trieulieuf9'
b'Able to detect if a user is FetLife supporter although this user hides their support badge in fetlife.com/conversations/{id} JSON response'
11 Feb 2022
b'Nextcloud'
disclosed a bug submitted by
b'technorat'
b'Information Exposure Through Directory Listing vulnerability'
11 Feb 2022
1
...
124
125
126
127
128
...
718
BY DENIS WERNER - @NOBBD -
IMPRESSUM