REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
57
b'ooooooo_q'
50
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Zomato'
disclosed a bug submitted by
b'shell_c0de'
b'[Zomato for Business Android] Vulnerability in exported activity WebView'
23 Sep 2021
b'Zomato'
disclosed a bug submitted by
b'shell_c0de'
b'[Zomato Order] Insecure deeplink leads to sensitive information disclosure'
23 Sep 2021
b'Concrete CMS'
disclosed a bug submitted by
b'pabl00nicarres'
b'Fetching the update json scheme from concrete5 over HTTP leads to remote code execution'
22 Sep 2021
b'HackerOne'
disclosed a bug submitted by
b'muon4'
b"User's who are banned from program can still be invited to the new reports as collaborators"
22 Sep 2021
b'HackerOne'
disclosed a bug submitted by
b'muon4'
b'Temporary banned user (from platform) is able to make submissions via embedded submission forms'
22 Sep 2021
b'HackerOne'
disclosed a bug submitted by
b'muon4'
b'CSV injection in the credentials export'
22 Sep 2021
b'HackerOne'
disclosed a bug submitted by
b'muon4'
b'Used email confirmation link reveals the email address which is tied to it'
22 Sep 2021
b'HackerOne'
disclosed a bug submitted by
b'muon4'
b'Race condition allows to send multiple times feedback for the hacker'
22 Sep 2021
b'Engel & V\xc3\xb6lkers Technology GmbH'
disclosed a bug submitted by
b'chaitanya_024'
b'HTML Injection in Email'
22 Sep 2021
b'Brave Software'
disclosed a bug submitted by
b'kkarfalcon'
b'Information disclosure'
21 Sep 2021
b'Valve'
disclosed a bug submitted by
b'hydraskyteam'
b"Privilege Escalation vulnerability in steam's Remote Play feature leads to arbitrary kernel-mode driver installation"
21 Sep 2021
b'Valve'
disclosed a bug submitted by
b'bugstar'
b'Big Picture web browser leaks login cookies and discloses sensitive information (may lead to account takeover)'
21 Sep 2021
b'Valve'
disclosed a bug submitted by
b'njbooher'
b'Access to microtransaction sales data for lots of apps from 2014 to present at /valvefinance/sanity/'
21 Sep 2021
b'Moneybird'
disclosed a bug submitted by
b't3chnophil3'
b'IDOR in https://moneybird.com/user/accountant_company/edit(change company name)'
21 Sep 2021
b'Moneybird'
disclosed a bug submitted by
b'bugera'
b'Open Redirect through POST Request in OAuth'
21 Sep 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'someonenobbd'
b'ihsinme: Add query for CWE-758 Reliance on Undefined, Unspecified, or Implementation-Defined Behavior'
20 Sep 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'vovohelo'
b'New experimental query: Clipboard-based XSS'
20 Sep 2021
b'HackerOne'
disclosed a bug submitted by
b'frozensolid'
b'Hacker can bypass minimum bounty amount restrictions in "invitation preferences" setting via UpdateInvitationPreferencesMutation GraphQL operation'
20 Sep 2021
b'XVIDEOS'
disclosed a bug submitted by
b'alone_test'
b'Text injection or content spoofing on forbiden page'
19 Sep 2021
b'Basecamp'
disclosed a bug submitted by
b'nagli'
b'Subdomain Takeover due to NS records at us-east4.37signals.com'
17 Sep 2021
1
...
148
149
150
151
152
...
718
BY DENIS WERNER - @NOBBD -
IMPRESSUM