REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'homosec'
b'XSS on https:/// via parameter'
07 Apr 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'whoisbinit'
b'Open Akamai ARL XSS at '
07 Apr 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'whoisbinit'
b'Bypassing CORS Misconfiguration Leads to Sensitive Exposure at https:///'
07 Apr 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'drauschkolb'
b'XSS Reflected - '
07 Apr 2022
b'Rockstar Games'
disclosed a bug submitted by
b'toxiqcitee'
b'Uninstalling Rockstar Games Launcher for Windows (64-bit), then reinstalling keeps you logged in without authentication'
07 Apr 2022
b'Zomato'
disclosed a bug submitted by
b'schutzx0r'
b'Attacker shall recieve order updates on whatsapp for users who have activated whatsapp notification'
06 Apr 2022
b'Palantir Public'
disclosed a bug submitted by
b'haxor31337'
b'SQL Injection at https://files.palantir.com/ due to CVE-2021-38159'
05 Apr 2022
b'HackerOne'
disclosed a bug submitted by
b'bigbug'
b'Private invitation links/tokens leak to third-party analytics site'
05 Apr 2022
b'Krisp'
disclosed a bug submitted by
b'alp'
b'[api.krisp.ai] Race condition on /v2/seats endpoint allows bypassing the original seat limit'
04 Apr 2022
b'Kubernetes'
disclosed a bug submitted by
b'0xlegendkiller'
b'Broken Domain Link Takeover from kubernetes.io docs'
03 Apr 2022
b'Stripe'
disclosed a bug submitted by
b'd_sharad'
b'CSRF token validation system is disabled on Stripe Dashboard'
02 Apr 2022
b'Slack'
disclosed a bug submitted by
b'kadusantiago'
b'Workspace configuration metadata disclosure'
01 Apr 2022
b'Sifchain'
disclosed a bug submitted by
b'hrdfrdh'
b'Subdomain Takeover on proxies.sifchain.finance pointing to vercel'
01 Apr 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'happyhacking123'
b'CVE-2022-24288: Apache Airflow: TWO RCEs in example DAGs'
01 Apr 2022
b'TikTok'
disclosed a bug submitted by
b'arifmkhls'
b'Information Leakage via TikTok Ads Web Cache Deception'
31 Mar 2022
b'GitLab'
disclosed a bug submitted by
b'joaxcar'
b'Stored XSS in merge request creation page through payload in approval rule name'
31 Mar 2022
b'Judge.me '
disclosed a bug submitted by
b'glister'
b'IDOR: leak buyer info & Publish/Hide foreign comments'
31 Mar 2022
b'Judge.me '
disclosed a bug submitted by
b'glister'
b'Stored XSS in Question edit from product name'
31 Mar 2022
b'Judge.me '
disclosed a bug submitted by
b'glister'
b'stored XSS on AliExpress Review Importer/Products when delete product'
31 Mar 2022
b'Judge.me '
disclosed a bug submitted by
b'glister'
b'Stored XSS in Question edit for product name (bypass #1416672)'
31 Mar 2022
1
...
137
138
139
140
141
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM