REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Courier'
disclosed a bug submitted by
b'everybodyhurts'
b'[OPEN S3 BUCKET] All uploaded files are public. '
01 Apr 2021
b'Khan Academy'
disclosed a bug submitted by
b'4z1zu'
b"Khan Academy ClickJacking to Steal Users's Credintials"
31 Mar 2021
b'Nextcloud'
disclosed a bug submitted by
b'supr4s'
b'HTML Injection on "polls" app - comments section (possibly XSS)'
31 Mar 2021
b'Kaspersky'
disclosed a bug submitted by
b'abbadeed'
b'A vulnerability in KAVKIS 2020 products family allows full disabling of protection'
31 Mar 2021
b'Rocket.Chat'
disclosed a bug submitted by
b'sectex'
b'Account takeover via XSS'
31 Mar 2021
b'QIWI'
disclosed a bug submitted by
b'okradze'
b'crlf injection https://bug.qiwi.com'
31 Mar 2021
b'QIWI'
disclosed a bug submitted by
b'okradze'
b'mysql.initial.sql file is accessable for everyone'
31 Mar 2021
b'pixiv'
disclosed a bug submitted by
b'noxx'
b'Reset any password'
31 Mar 2021
b'Hyperledger'
disclosed a bug submitted by
b'swang1994'
b'Vulnerability in Private Data Endorsement Policy Management in Hyperledger Fabric 2.0'
30 Mar 2021
b'Hyperledger'
disclosed a bug submitted by
b'swang1994'
b'The payload Field of Transactions in a Block Reveals the Private Data to All Peers '
30 Mar 2021
b'Hyperledger'
disclosed a bug submitted by
b'swang1994'
b'Vulnerabilities in Endorsement Mechanism of Private Data Related Transactions in Hyperledger Fabric 2.0'
30 Mar 2021
b'Uber'
disclosed a bug submitted by
b'healdb'
b'Chained vulnerabilities create DOS attack against users on desafio5estrelas.com'
30 Mar 2021
b'Uber'
disclosed a bug submitted by
b'healdb'
b'Cleartext password exposure allows access to the desafio5estrelas.com admin panel'
30 Mar 2021
b'CS Money'
disclosed a bug submitted by
b'sawmj'
b'Origin IP found, Cloudflare bypassed'
30 Mar 2021
b'Acronis'
disclosed a bug submitted by
b'atikna'
b'Account Confirmation bypass leads to acess some fucntionality '
30 Mar 2021
b'PlayStation'
disclosed a bug submitted by
b'pwrofwon'
b'Unrestricted access to quiesce functionality in dss.api.playstation.com REST API leads to unavailability of application'
30 Mar 2021
b'PlayStation'
disclosed a bug submitted by
b'vakzz'
b'Reflected XSS on transact.playstation.com using postMessage from the opening window'
30 Mar 2021
b'PlayStation'
disclosed a bug submitted by
b'bugdiscloseguys'
b'SSRF chained to hit internal host leading to another SSRF which allows to read internal images.'
30 Mar 2021
b'Uber'
disclosed a bug submitted by
b'm4ll0x0k'
b'Critical Information disclosure of rtapi token for any user via https://video-support-staging.uber.com/video/api/getPopulousUser'
29 Mar 2021
b'Uber'
disclosed a bug submitted by
b'healdb'
b'SQLI on desafio5estrelas.com '
29 Mar 2021
1
...
212
213
214
215
216
...
742
BY DENIS WERNER - @NOBBD -
IMPRESSUM