REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Recorded Future'
disclosed a bug submitted by
b'subuganz'
b'Storage of old passwords in plain text format'
12 May 2022
b'PlayStation'
disclosed a bug submitted by
b'm00nbsd'
b'Remote kernel heap overflow'
11 May 2022
b'curl'
disclosed a bug submitted by
b'haxatron1'
b'CVE-2022-30115: HSTS bypass via trailing dot'
11 May 2022
b'curl'
disclosed a bug submitted by
b'haxatron1'
b'CVE-2022-27780: percent-encoded path separator in URL host'
11 May 2022
b'Nextcloud'
disclosed a bug submitted by
b'nickvergessen'
b'SQL injextion via vulnerable doctrine/dbal version'
11 May 2022
b'curl'
disclosed a bug submitted by
b'nyymi'
b'CVE-2022-27782: TLS and SSH connection too eager reuse'
11 May 2022
b'Priceline'
disclosed a bug submitted by
b'badca7'
b'Account takeover via Google OneTap'
11 May 2022
b'curl'
disclosed a bug submitted by
b'haxatron1'
b'CVE-2022-27779: cookie for trailing dot TLD'
11 May 2022
b'curl'
disclosed a bug submitted by
b'nyymi'
b'CVE-2022-27778: curl removes wrong file on error'
11 May 2022
b'curl'
disclosed a bug submitted by
b'nyymi'
b'Certificate authentication re-use on redirect'
11 May 2022
b'Alohi'
disclosed a bug submitted by
b'shamim_12__'
b'Misconfigured Rate Limit in Sending Notifications to the Victims Phone Via the Endpoint " /faxes/inbox "'
10 May 2022
b'Phabricator'
disclosed a bug submitted by
b'dyls'
b'Global default settings page is accessible to non-administrators'
09 May 2022
b'Phabricator'
disclosed a bug submitted by
b'dyls'
b'Slowvote and Countdown can cause Denial of Service due to recursive inclusion'
09 May 2022
b'Reddit'
disclosed a bug submitted by
b'abhiramsita'
b'Reflected xss in https://sh.reddit.com'
08 May 2022
b'TikTok'
disclosed a bug submitted by
b's3c'
b'Multiple IDORs in family pairing api'
06 May 2022
b'IBM'
disclosed a bug submitted by
b'asterite'
b'SQL injection in URL path processing on www.ibm.com'
06 May 2022
b'Reddit'
disclosed a bug submitted by
b'bisesh'
b'Able to bypass email verification and change email to any other user email '
06 May 2022
b'Palantir Public'
disclosed a bug submitted by
b'codermak'
b'Github Account Takeover which is used as gradle vcs in "github.com/palantir/gradle-launch-config-plugin"'
05 May 2022
b'TikTok'
disclosed a bug submitted by
b'rioncool22'
b'Clickjacking Vulnerability Can Leads To Delete Developer APP'
04 May 2022
b'TikTok'
disclosed a bug submitted by
b'fr4via'
b'One Click Account Hijacking via Unvalidated Deeplink'
04 May 2022
1
...
131
132
133
134
135
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM