REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
81
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Kaspersky'
disclosed a bug submitted by
b'golim'
b'Several domains on kaspersky.com are vulnerable to Web Cache Deception attack'
20 May 2021
b'U.S. General Services Administration'
disclosed a bug submitted by
b'rajeshpatil'
b'Weak password policy leading to exposure of administrator account access'
20 May 2021
b'QIWI'
disclosed a bug submitted by
b'sniper302'
b'Account takeover just through csrf in https://booking.qiwi.kz/profile'
20 May 2021
b'Lark Technologies'
disclosed a bug submitted by
b'imran_nisar'
b'Improper Access Control on Lark Footer Feature'
18 May 2021
b'Rocket.Chat'
disclosed a bug submitted by
b'sonarsource'
b'Pre-Auth Blind NoSQL Injection leading to Remote Code Execution'
18 May 2021
b'UPchieve'
disclosed a bug submitted by
b'shoaib_18'
b"No Valid SPF Records/don't have DMARC record"
18 May 2021
b'Twitter'
disclosed a bug submitted by
b'iambouali'
b'Bypass t.co link shortener in Twitter direct messages'
18 May 2021
b'CS Money'
disclosed a bug submitted by
b'gatolouco'
b'Previously created sessions continue being valid after MFA activation'
18 May 2021
b'WordPress'
disclosed a bug submitted by
b'sonarsource'
b'Authenticated XXE'
18 May 2021
b'Starbucks'
disclosed a bug submitted by
b'elber'
b'Japan - CSRF in webapp.starbucks.co.jp with user interaction could leak an access token if the user was not using Chrome'
18 May 2021
b'Valve'
disclosed a bug submitted by
b'simonscannell'
b'CS:GO Server -> Client RCE through OOB access in CSVCMsg_SplitScreen + Info leak in HTTP download'
17 May 2021
b'WordPress'
disclosed a bug submitted by
b'hoangkien1020'
b'Privilege Escalation via REST API to Administrator leads to RCE'
17 May 2021
b'Informatica'
disclosed a bug submitted by
b'rawezh_ali'
b'Cross site scripting '
17 May 2021
b'UPchieve'
disclosed a bug submitted by
b'mr-zero'
b'User enumeration through forget password'
16 May 2021
b'Sifchain'
disclosed a bug submitted by
b'b29z'
b'Open S3 Bucket | information leakage'
15 May 2021
b'Sifchain'
disclosed a bug submitted by
b'bringing2021'
b'Information Disclosure on https://rpc.sifchain.finance/'
15 May 2021
b'Uber'
disclosed a bug submitted by
b'beezlewaxin'
b'private passenger information is exposed to the Uber Driver app during ride dispatch ("Ping") events'
14 May 2021
b'UPchieve'
disclosed a bug submitted by
b'zero_or_1'
b'Zero click account Takeover due to Api misconfiguration '
14 May 2021
b'UPchieve'
disclosed a bug submitted by
b'saajanbhujel'
b'Full account takeover of any user through reset password'
14 May 2021
b'GitLab'
disclosed a bug submitted by
b'vakzz'
b'RCE when removing metadata with ExifTool'
14 May 2021
1
...
189
190
191
192
193
...
731
BY DENIS WERNER - @NOBBD -
IMPRESSUM