REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
57
b'ooooooo_q'
50
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Kubernetes'
disclosed a bug submitted by
b'flag_c0'
b'exposed Git Repo at http://api.e2e-kops-aws-canary.test-cncf-aws.canary.k8s.io/.git/'
07 Jan 2021
b'Kubernetes'
disclosed a bug submitted by
b'flag_c0'
b'Unsecured Grafana instance on https://monitoring.prow-canary.k8s.io/dashboards'
07 Jan 2021
b'Kubernetes'
disclosed a bug submitted by
b'riramar'
b'Plaintext storage of a password on kubernetes release bucket'
07 Jan 2021
b'Node.js'
disclosed a bug submitted by
b'piao'
b'Potential HTTP Request Smuggling in nodejs'
07 Jan 2021
b'Mail.ru'
disclosed a bug submitted by
b'steal_wart'
b'Django Debug=True Leaks admin email addresss and serval system information '
07 Jan 2021
b'Doppler'
disclosed a bug submitted by
b'bugera'
b'No rate limit into email change leads to email notification boombing to its victim.'
06 Jan 2021
b'Doppler'
disclosed a bug submitted by
b'bugera'
b'Access page must be reloaded to perform multiple requests'
06 Jan 2021
b'Logitech'
disclosed a bug submitted by
b'c0nquer0r'
b'One Click Account takeover using Ouath CSRF bypass by adding Null byte %00 in state parameter on www.streamlabs.com'
06 Jan 2021
b'Kartpay'
disclosed a bug submitted by
b'ph4n745m'
b'Being able to change account contents even after password change'
06 Jan 2021
b'Logitech'
disclosed a bug submitted by
b'optional'
b'Stored XSS on oslo.io in notifications via project name change'
05 Jan 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'someonenobbd'
b'[Java] CWE-555: Query to detect password in Java EE configuration files'
05 Jan 2021
b'Open-Xchange'
disclosed a bug submitted by
b'rumata'
b'A specially crafted message sent to the local delivery agent (LMTP) causes the LMTP child process to issue a panic (call i_panic)'
05 Jan 2021
b'Stripo Inc'
disclosed a bug submitted by
b'ofjaaaah'
b'No rate limiting - Create data'
05 Jan 2021
b'Stripo Inc'
disclosed a bug submitted by
b'ofjaaaah'
b'No rate limiting - Create Plug-ins'
05 Jan 2021
b'Node.js'
disclosed a bug submitted by
b'fwilhelm'
b'Node.js: use-after-free in TLSWrap'
05 Jan 2021
b'Doppler'
disclosed a bug submitted by
b'ibrahimauwal'
b'email spoofing on doppler.team'
04 Jan 2021
b'Open-Xchange'
disclosed a bug submitted by
b'catenacyber'
b'Incomplete fix for CVE-2020-12673 : Specially crafted NTML message leads to buffer over read'
04 Jan 2021
b'Open-Xchange'
disclosed a bug submitted by
b'catenacyber'
b'Buffer overread off by one in `rpa_read_buffer`, incomplete fix for CVE-2020-12674'
04 Jan 2021
b'Twitter'
disclosed a bug submitted by
b'ryotak'
b'Read-only application can publish/delete fleets'
04 Jan 2021
b'New Relic'
disclosed a bug submitted by
b'batuhan'
b'Sending thousands of notifications with single request'
04 Jan 2021
1
...
215
216
217
218
219
...
718
BY DENIS WERNER - @NOBBD -
IMPRESSUM