REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Azbuka Vkusa'
disclosed a bug submitted by
b'zophi'
b'Open redirect (DOM-based) on av.ru via "return_url" parameter (Login form)'
19 Dec 2021
b'RubyGems'
disclosed a bug submitted by
b'akincibor'
b'Dependency repository hijacking aka Repo Jacking from GitHub repo rubygems/bundler-site & rubygems/bundler.github.io + bundler.io docs'
19 Dec 2021
b'ImpressCMS'
disclosed a bug submitted by
b'tehwinsam'
b'Stored XSS on 1.4.0'
18 Dec 2021
b'MTN Group'
disclosed a bug submitted by
b'ibrahimatix_'
b'HTML injection in email content during registration via FirstName/LastName parameter'
18 Dec 2021
b'Flickr'
disclosed a bug submitted by
b'lauritz'
b'Flickr Account Takeover using AWS Cognito API'
18 Dec 2021
b'Judge.me '
disclosed a bug submitted by
b'0xteles'
b'html injection at judge.me'
17 Dec 2021
b'Informatica'
disclosed a bug submitted by
b'jak0_'
b'Reflected Cross-Site Scripting/HTML Injection'
17 Dec 2021
b'Kubernetes'
disclosed a bug submitted by
b'codermak'
b'Google storage bucket takeover which is used to load JS file in dashboard.html in "github.com/kubernetes/release" which can lead to XSS'
16 Dec 2021
b'Showmax'
disclosed a bug submitted by
b'ibrahimatix_'
b'Race Condition Vulnerability when creating profiles'
16 Dec 2021
b'FetLife'
disclosed a bug submitted by
b'trieulieuf9'
b'Able to access private picture/video/writing when requesting for their JSON response'
16 Dec 2021
b'Kubernetes'
disclosed a bug submitted by
b'codermak'
b'Broken Link Takeover from kubernetes.io docs'
16 Dec 2021
b'Kubernetes'
disclosed a bug submitted by
b'codermak'
b'Broken Github Link Used in deployment docs of "github.com/kubernetes/kompose"'
16 Dec 2021
b'Reddit'
disclosed a bug submitted by
b'bombon'
b'Weak rate limit could lead to ATO due to weak password protection mechanisms'
15 Dec 2021
b'Reddit'
disclosed a bug submitted by
b'cracker922'
b'No rate limit on password reset leads to email enumeration at gateway-production.dubsmash.com '
15 Dec 2021
b'VK.com'
disclosed a bug submitted by
b'executor'
b' '
15 Dec 2021
b'Mail.ru'
disclosed a bug submitted by
b'seifelsallamy'
b'reflected xss in e.mail.ru'
15 Dec 2021
b'Aiven Ltd'
disclosed a bug submitted by
b'j0v'
b'Zero day path traversal vulnerability in Grafana 8.x allows unauthenticated arbitrary local file read'
14 Dec 2021
b'Proctorio'
disclosed a bug submitted by
b'sector7-nl'
b'Universal Cross-Site Scripting vulnerability'
14 Dec 2021
b'Reddit'
disclosed a bug submitted by
b'asce21'
b'[dubsmash] Username and password bruteforce'
13 Dec 2021
b'Reddit'
disclosed a bug submitted by
b'nexus2k'
b'com.reddit.frontpage vulernable to Task Hijacking (aka StrandHogg Attack)'
13 Dec 2021
1
...
156
157
158
159
160
...
742
BY DENIS WERNER - @NOBBD -
IMPRESSUM