REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Moneybird'
disclosed a bug submitted by
b't3chnophil3'
b'IDOR in https://moneybird.com/user/accountant_company/edit(change company name)'
21 Sep 2021
b'Moneybird'
disclosed a bug submitted by
b'bugera'
b'Open Redirect through POST Request in OAuth'
21 Sep 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'someonenobbd'
b'ihsinme: Add query for CWE-758 Reliance on Undefined, Unspecified, or Implementation-Defined Behavior'
20 Sep 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'vovohelo'
b'New experimental query: Clipboard-based XSS'
20 Sep 2021
b'HackerOne'
disclosed a bug submitted by
b'frozensolid'
b'Hacker can bypass minimum bounty amount restrictions in "invitation preferences" setting via UpdateInvitationPreferencesMutation GraphQL operation'
20 Sep 2021
b'XVIDEOS'
disclosed a bug submitted by
b'alone_test'
b'Text injection or content spoofing on forbiden page'
19 Sep 2021
b'Basecamp'
disclosed a bug submitted by
b'nagli'
b'Subdomain Takeover due to NS records at us-east4.37signals.com'
17 Sep 2021
b'Zomato'
disclosed a bug submitted by
b'ian'
b'Subdomain takeover of fr1.vpn.zomans.com'
17 Sep 2021
b'Mattermost'
disclosed a bug submitted by
b'akashhamal0x01'
b'Account takeover due to misconfiguration'
17 Sep 2021
b'Topcoder'
disclosed a bug submitted by
b'3viltwin'
b'SSRF to AWS file read'
16 Sep 2021
b'Courier'
disclosed a bug submitted by
b'bugera'
b'Session Fixiation allow attacker to create new evil workspace without being logged in [ Insecure Session management ]'
16 Sep 2021
b'Courier'
disclosed a bug submitted by
b'bugera'
b'[3] Bypassing IP Based Rate Limit Blocking leads to rate limit bypass in Courier Login Panel'
16 Sep 2021
b'Zivver'
disclosed a bug submitted by
b'dhirenkumar8280'
b'Bypassing Rate limit for forgot password by using different ip addresses'
15 Sep 2021
b'curl'
disclosed a bug submitted by
b'z2_'
b'CVE-2021-22945: UAF and double-free in MQTT sending'
15 Sep 2021
b'GitLab'
disclosed a bug submitted by
b'joaxcar'
b'Stored XSS in main page of a project caused by arbitrary script payload in group "Default initial branch name"'
15 Sep 2021
b'Revive Adserver'
disclosed a bug submitted by
b'418sec'
b'Use of a Broken or Risky Cryptographic Algorithm'
15 Sep 2021
b'LINE'
disclosed a bug submitted by
b'reinforchu'
b'Webview address bar spoofing in LINE client for iOS'
15 Sep 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'luchua'
b'[Java] CWE-079: Query to detect XSS with JavaServer Faces (JSF)'
15 Sep 2021
b'Flickr'
disclosed a bug submitted by
b'asad0x01_'
b'CSRF in Account Deletion feature (https://www.flickr.com/account/delete)'
14 Sep 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'someonenobbd'
b'[Java]: Add XXE sinks'
14 Sep 2021
1
...
169
170
171
172
173
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM