REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'IBM'
disclosed a bug submitted by
b'thesanjok'
b'Public Jenkins instance with /script enabled'
11 Mar 2022
b'Reddit'
disclosed a bug submitted by
b'ahacker1'
b'XSS via Mod Log Removed Posts'
10 Mar 2022
b'8x8'
disclosed a bug submitted by
b'ig420_vrush'
b'Open Redirect on https://.8x8.com/login?nextPage=%2F'
10 Mar 2022
b'curl'
disclosed a bug submitted by
b'shobhit2401200'
b'Use of Unsafe function || Strcpy'
09 Mar 2022
b'curl'
disclosed a bug submitted by
b'eliasknudsen'
b'Binary output bypass'
09 Mar 2022
b'curl'
disclosed a bug submitted by
b'luminixaaron'
b'Occasional use-after-free in multi_done() libcurl-7.81.0'
09 Mar 2022
b'Krisp'
disclosed a bug submitted by
b'mrirfan__07'
b'Error Page Content Spoofing or Text Injection'
09 Mar 2022
b'Krisp'
disclosed a bug submitted by
b'blackxxhat'
b'Unsubscripe linkes leaked'
09 Mar 2022
b'Equifax'
disclosed a bug submitted by
b'miguel_santareno'
b'RXSS on https://equifax.gr8people.com on Password Reset page in the username parameter'
09 Mar 2022
b'FetLife'
disclosed a bug submitted by
b'trieulieuf9'
b'Race condition in endpoint POST fetlife.com/users/invitation, allow attacker to generate unlimited invites'
09 Mar 2022
b'Nextcloud'
disclosed a bug submitted by
b'fancycode'
b'High memory usage for generating preview of broken image'
09 Mar 2022
b'Stripe'
disclosed a bug submitted by
b'bubbounty'
b'GRAPHQL cross-tenant IDOR giving write access thought the operation UpdateAtlasApplicationPerson'
08 Mar 2022
b'Nextcloud'
disclosed a bug submitted by
b'ctulhu'
b'objectId in share location can be set to open arbitrary URL or Deeplinks'
08 Mar 2022
b'MTN Group'
disclosed a bug submitted by
b'pudsec'
b'PHP Info Exposing Secrets at https://radio.mtn.bj/info'
08 Mar 2022
b'Glassdoor'
disclosed a bug submitted by
b'bombon'
b'Web Cache Poisoning leads to Stored XSS '
07 Mar 2022
b'Mail.ru'
disclosed a bug submitted by
b'mainteemoforfun'
b'unclaimed subdomain special.rkeeper.ru to takeover from tilda.cc'
05 Mar 2022
b'Lark Technologies'
disclosed a bug submitted by
b'aishkendle'
b'Normal User is able to EXPORT Feature Usage Statistics'
04 Mar 2022
b'Omise'
disclosed a bug submitted by
b'sachinrajput'
b'Brute force attack of current password on login page by bypassing account limit using IP rotator(https://dashboard.omise.co/signin)'
04 Mar 2022
b'Uber'
disclosed a bug submitted by
b'johnzilla313'
b'Uber Test Report 20220301'
03 Mar 2022
b'Ruby on Rails'
disclosed a bug submitted by
b'nagli'
b'Subdomain Takeover at https://new.rubyonrails.org/'
03 Mar 2022
1
...
142
143
144
145
146
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM