REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
57
b'ooooooo_q'
50
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'GitHub Security Lab'
disclosed a bug submitted by
b'jessforfun'
b'[Java]: CWE-601 Spring url redirection detect'
21 May 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'luchua'
b'[Java] CWE-094: Jython code injection'
21 May 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'luchua'
b'[Java] CWE-094: Rhino code injection'
21 May 2021
b'Kaspersky'
disclosed a bug submitted by
b'golim'
b'Several domains on kaspersky.com are vulnerable to Web Cache Deception attack'
20 May 2021
b'U.S. General Services Administration'
disclosed a bug submitted by
b'rajeshpatil'
b'Weak password policy leading to exposure of administrator account access'
20 May 2021
b'QIWI'
disclosed a bug submitted by
b'sniper302'
b'Account takeover just through csrf in https://booking.qiwi.kz/profile'
20 May 2021
b'Lark Technologies'
disclosed a bug submitted by
b'imran_nisar'
b'Improper Access Control on Lark Footer Feature'
18 May 2021
b'Rocket.Chat'
disclosed a bug submitted by
b'sonarsource'
b'Pre-Auth Blind NoSQL Injection leading to Remote Code Execution'
18 May 2021
b'UPchieve'
disclosed a bug submitted by
b'shoaib_18'
b"No Valid SPF Records/don't have DMARC record"
18 May 2021
b'Twitter'
disclosed a bug submitted by
b'iambouali'
b'Bypass t.co link shortener in Twitter direct messages'
18 May 2021
b'CS Money'
disclosed a bug submitted by
b'gatolouco'
b'Previously created sessions continue being valid after MFA activation'
18 May 2021
b'WordPress'
disclosed a bug submitted by
b'sonarsource'
b'Authenticated XXE'
18 May 2021
b'Starbucks'
disclosed a bug submitted by
b'elber'
b'Japan - CSRF in webapp.starbucks.co.jp with user interaction could leak an access token if the user was not using Chrome'
18 May 2021
b'Valve'
disclosed a bug submitted by
b'simonscannell'
b'CS:GO Server -> Client RCE through OOB access in CSVCMsg_SplitScreen + Info leak in HTTP download'
17 May 2021
b'WordPress'
disclosed a bug submitted by
b'hoangkien1020'
b'Privilege Escalation via REST API to Administrator leads to RCE'
17 May 2021
b'Informatica'
disclosed a bug submitted by
b'rawezh_ali'
b'Cross site scripting '
17 May 2021
b'UPchieve'
disclosed a bug submitted by
b'mr-zero'
b'User enumeration through forget password'
16 May 2021
b'Sifchain'
disclosed a bug submitted by
b'b29z'
b'Open S3 Bucket | information leakage'
15 May 2021
b'Sifchain'
disclosed a bug submitted by
b'bringing2021'
b'Information Disclosure on https://rpc.sifchain.finance/'
15 May 2021
b'Uber'
disclosed a bug submitted by
b'beezlewaxin'
b'private passenger information is exposed to the Uber Driver app during ride dispatch ("Ping") events'
14 May 2021
1
...
176
177
178
179
180
...
718
BY DENIS WERNER - @NOBBD -
IMPRESSUM