REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Shopify'
disclosed a bug submitted by
b'jmp_35p'
b'Add new managed stores without permission'
08 Jul 2021
b'Shopify'
disclosed a bug submitted by
b'superbsic'
b'Removing parts of URL from jQuery request exposes links for download of Paid Digital Assets of the most recent Order placed by anyone on the store!'
08 Jul 2021
b'Ruby'
disclosed a bug submitted by
b'chinarulezzz'
b'lib/net/ftp.rb: trusting PASV responses allow client abuse'
08 Jul 2021
b'Ruby'
disclosed a bug submitted by
b'chinarulezzz'
b'imap: StartTLS stripping attack (CVE-2016-0772).'
08 Jul 2021
b'Brave Software'
disclosed a bug submitted by
b'neeythann'
b'DNS Leaks when using any VPN Browser extension with Brave Shield enabled'
08 Jul 2021
b'HackerOne'
disclosed a bug submitted by
b'recon_ninja'
b'New link opening method makes hackerone vulnerable to tabnabbing'
07 Jul 2021
b'HackerOne'
disclosed a bug submitted by
b'whhackersbr'
b'Slack integration setup lacks CSRF protection'
07 Jul 2021
b'LINE'
disclosed a bug submitted by
b'hulkvision_'
b'Theft of arbitrary files in LINE Lite client for Android'
06 Jul 2021
b'QIWI'
disclosed a bug submitted by
b'shell_c0de'
b'[QIWI Wallet] Access to protected app components '
06 Jul 2021
b'New Relic'
disclosed a bug submitted by
b'bbunnny'
b'Verification Link not expiring leading to Account Takeover.'
05 Jul 2021
b'LINE'
disclosed a bug submitted by
b'alexbirsan'
b'Arbitrary Code Execution via npm misconfiguration installing internal libraries from the public registry'
05 Jul 2021
b'Node.js'
disclosed a bug submitted by
b'ericsesterhenn'
b'OOB read in libuv'
05 Jul 2021
b'LINE'
disclosed a bug submitted by
b's5s'
b'Webview in LINE client for iOS will render application/octet-stream files as HTML'
05 Jul 2021
b'New Relic'
disclosed a bug submitted by
b'ashmek'
b'Account takeover by using abandoned email id of victim which has already been changed to new by victim himself on one.newrelic.com'
02 Jul 2021
b'Node.js'
disclosed a bug submitted by
b'deepsurface-robert'
b'Node Installer Local Privilege Escalation '
01 Jul 2021
b'Nextcloud'
disclosed a bug submitted by
b'sjw'
b'Ratelimiting can be bypassed using IPv6 subnets'
01 Jul 2021
b'Glassdoor'
disclosed a bug submitted by
b'l0cpd'
b'Reflected XSS on https://help.glassdoor.com/GD_HC_EmbeddedChatVF'
01 Jul 2021
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'prophet'
b'IDOR while uploading attachments at []'
30 Jun 2021
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'prophet'
b'Reflected XSS at []'
30 Jun 2021
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'biest'
b'Self stored Xss + Login Csrf'
30 Jun 2021
1
...
184
185
186
187
188
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM