REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Mail.ru'
disclosed a bug submitted by
b'cutoffurmind'
b'mailer.i.bizml.ru viber service preprod information disclosure'
13 Aug 2021
b'Mail.ru'
disclosed a bug submitted by
b'cutoffurmind'
b'uchi.ru check_lessons Blind SQL Injection'
13 Aug 2021
b'Mail.ru'
disclosed a bug submitted by
b'act1on3'
b'[http://kiwi.youdrive.today/] Information disclosure via Kiwi TCMS vulnerability'
13 Aug 2021
b'Uber'
disclosed a bug submitted by
b'pmnh'
b"Chain of vulnerabilities in Uber for Business Vouchers program allows for attacker to perform arbitrary charges to victim's U4B payment account"
12 Aug 2021
b'Snapchat'
disclosed a bug submitted by
b'kiyell'
b'Leaked JFrog Artifactory username and password exposed on GitHub - https://snapchat.jfrog.io'
12 Aug 2021
b'Snapchat'
disclosed a bug submitted by
b'damian89'
b'Client IP Spoofing using "X-Forwarded-For: 127.0.0.1" on "studio-app.snapchat.com" exposing bucket details'
12 Aug 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'someonenobbd'
b'[C#]: HttpOnly and Secure Cookies for .NET Core and .NET'
12 Aug 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'artem'
b'Java: Timing attacks while comparing results of cryptographic operations'
12 Aug 2021
b'UPchieve'
disclosed a bug submitted by
b'scianto05'
b'Business logic error'
11 Aug 2021
b'Nextcloud'
disclosed a bug submitted by
b'rtod'
b'Add to your nextcloud endpoint is not properly protected'
11 Aug 2021
b'Nextcloud'
disclosed a bug submitted by
b'lukasreschkenc'
b'Text app leaks file path of shared files'
11 Aug 2021
b'Nextcloud'
disclosed a bug submitted by
b'lukasreschkenc'
b'ApiService#fetch serves content as text/html and inline Content-Disposition'
11 Aug 2021
b'Nextcloud'
disclosed a bug submitted by
b'foobar7'
b'Bypass of privacy filter / tracking pixel blocker'
11 Aug 2021
b'Nextcloud'
disclosed a bug submitted by
b'rtod'
b'public webdav endpoint not bruteforce protected'
11 Aug 2021
b'Nextcloud'
disclosed a bug submitted by
b'rtod'
b'index.php/apps/files_sharing/shareinfo endpoint is not properly protected'
11 Aug 2021
b'Nextcloud'
disclosed a bug submitted by
b'foobar7'
b'Download of file with arbitrary extension via injection into attachment header'
11 Aug 2021
b'Nextcloud'
disclosed a bug submitted by
b'lukasreschkenc'
b'Ratelimits do not apply to OCS DataResponse'
11 Aug 2021
b'Valve'
disclosed a bug submitted by
b'drbrix'
b'Modify in-flight data to payment provider Smart2Pay'
10 Aug 2021
b'Acronis'
disclosed a bug submitted by
b'aapo'
b'Acronis True Image 2021 (windows) does not validate server hostname on a login TLS connection'
10 Aug 2021
b'UPchieve'
disclosed a bug submitted by
b'n1had'
b'Password reset token leak on third party website via Referer header'
10 Aug 2021
1
...
169
170
171
172
173
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM