REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
57
b'ooooooo_q'
50
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Mail.ru'
disclosed a bug submitted by
b'rivalsec'
b' photo-test.gb.ru ()'
22 Dec 2021
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'xko2x'
b'Rxss on via logout?service=javascript:alert(1)'
22 Dec 2021
b'Acronis'
disclosed a bug submitted by
b'darkdream'
b'admin password disclosure via log file '
21 Dec 2021
b'Judge.me '
disclosed a bug submitted by
b'bhishma14'
b'Log4j RCE on https://judge.me/reviews'
21 Dec 2021
b'Azbuka Vkusa'
disclosed a bug submitted by
b'wocat'
b'Unauthorized access to choice.av.ru control panel'
19 Dec 2021
b'Azbuka Vkusa'
disclosed a bug submitted by
b'zophi'
b'Open redirect (DOM-based) on av.ru via "return_url" parameter (Login form)'
19 Dec 2021
b'RubyGems'
disclosed a bug submitted by
b'akincibor'
b'Dependency repository hijacking aka Repo Jacking from GitHub repo rubygems/bundler-site & rubygems/bundler.github.io + bundler.io docs'
19 Dec 2021
b'ImpressCMS'
disclosed a bug submitted by
b'tehwinsam'
b'Stored XSS on 1.4.0'
18 Dec 2021
b'MTN Group'
disclosed a bug submitted by
b'ibrahimatix_'
b'HTML injection in email content during registration via FirstName/LastName parameter'
18 Dec 2021
b'Flickr'
disclosed a bug submitted by
b'lauritz'
b'Flickr Account Takeover using AWS Cognito API'
18 Dec 2021
b'Judge.me '
disclosed a bug submitted by
b'0xteles'
b'html injection at judge.me'
17 Dec 2021
b'Informatica'
disclosed a bug submitted by
b'jak0_'
b'Reflected Cross-Site Scripting/HTML Injection'
17 Dec 2021
b'Kubernetes'
disclosed a bug submitted by
b'codermak'
b'Google storage bucket takeover which is used to load JS file in dashboard.html in "github.com/kubernetes/release" which can lead to XSS'
16 Dec 2021
b'Showmax'
disclosed a bug submitted by
b'ibrahimatix_'
b'Race Condition Vulnerability when creating profiles'
16 Dec 2021
b'FetLife'
disclosed a bug submitted by
b'trieulieuf9'
b'Able to access private picture/video/writing when requesting for their JSON response'
16 Dec 2021
b'Kubernetes'
disclosed a bug submitted by
b'codermak'
b'Broken Link Takeover from kubernetes.io docs'
16 Dec 2021
b'Kubernetes'
disclosed a bug submitted by
b'codermak'
b'Broken Github Link Used in deployment docs of "github.com/kubernetes/kompose"'
16 Dec 2021
b'Reddit'
disclosed a bug submitted by
b'bombon'
b'Weak rate limit could lead to ATO due to weak password protection mechanisms'
15 Dec 2021
b'Reddit'
disclosed a bug submitted by
b'cracker922'
b'No rate limit on password reset leads to email enumeration at gateway-production.dubsmash.com '
15 Dec 2021
b'VK.com'
disclosed a bug submitted by
b'executor'
b' '
15 Dec 2021
1
...
132
133
134
135
136
...
718
BY DENIS WERNER - @NOBBD -
IMPRESSUM