REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Acronis'
disclosed a bug submitted by
b'mega7'
b'Self XSS in attachments name'
31 May 2022
b'Alohi'
disclosed a bug submitted by
b'darkknight4688'
b'Users who are restricted to use the application because of a "Waiting List" are able to get access to the Beta Application by bypassing the waitlist'
30 May 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'piao'
b'CVE-2022-28738: Double free in Regexp compilation'
28 May 2022
b'Nextcloud'
disclosed a bug submitted by
b'david_h1'
b'Control character filtering misses leading and trailing whitespace in file and folder names'
27 May 2022
b'Nextcloud'
disclosed a bug submitted by
b'qj_test'
b'Notification implicit PendingIntent in com.nextcloud.client allows to access contacts'
27 May 2022
b'Uber'
disclosed a bug submitted by
b'ian'
b'Full read SSRF in flyte-poc-us-east4.uberinternal.com'
26 May 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'ashutosh7'
b'[Urgent] Critical Vulnerability [RCE] on vulnerable to Remote Code Execution by exploiting MS15-034, CVE-2015-1635'
26 May 2022
b'U.S. General Services Administration'
disclosed a bug submitted by
b'hollaatm3'
b'Read Other Users Reports Through Cloning'
26 May 2022
b'HackerOne'
disclosed a bug submitted by
b'bugra'
b'Blind XSS in app.pullrequest.com/ via /reviews/ratings/{uuid}'
25 May 2022
b'GitLab'
disclosed a bug submitted by
b'joaxcar'
b'Stored XSS in Notes (with CSP bypass for gitlab.com)'
25 May 2022
b'Judge.me '
disclosed a bug submitted by
b'caue'
b'Email templates XSS by filterXSS bypass'
25 May 2022
b'Flickr'
disclosed a bug submitted by
b'ian'
b'Critical broken cookie signing on dagobah.flickr.com '
24 May 2022
b'EXNESS'
disclosed a bug submitted by
b'nearsecurity'
b'[com.exness.android.pa Android] Universal XSS in webview. Lead to steal user cookies'
24 May 2022
b'Omise'
disclosed a bug submitted by
b'oblivionlight'
b'Cross-site scripting on dashboard2.omise.co'
24 May 2022
b'Flickr'
disclosed a bug submitted by
b'xlord91'
b'Open redirect bypass'
23 May 2022
b'Flickr'
disclosed a bug submitted by
b'keer0k'
b'Stored XSS in photos_user_map.gne'
23 May 2022
b'GitHub Security Lab'
disclosed a bug submitted by
b'farid_hunter'
b'[python]: Zip Slip Vulnerability'
23 May 2022
b'GitHub Security Lab'
disclosed a bug submitted by
b'someonenobbd'
b'[Java]: Flow sources and steps for JMS and RabbitMQ'
23 May 2022
b'Evernote'
disclosed a bug submitted by
b'cyberworlcload'
b'Email Verification Bypass by bruteforcing when setting up 2FA'
22 May 2022
b'Rocket.Chat'
disclosed a bug submitted by
b'samuelsiv'
b'Possible Domain Takeover on AWS Instance.'
22 May 2022
1
...
128
129
130
131
132
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM