REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'GitHub Security Lab'
disclosed a bug submitted by
b'zelibob'
b'[golang] Division by zero query'
17 Feb 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'someonenobbd'
b'[JavaScript]: add query for Express-HBS LFR'
17 Feb 2021
b'Automattic'
disclosed a bug submitted by
b'ucuping'
b'Stored XSS in wordpress.com'
17 Feb 2021
b'Automattic'
disclosed a bug submitted by
b'h_-_cker'
b'Non-changing "_idnonce" value leads to CSRF on accounts at https://intensedebate.com for account takeover'
17 Feb 2021
b'QIWI'
disclosed a bug submitted by
b'timyun'
b'PIN OK attack'
17 Feb 2021
b'Acronis'
disclosed a bug submitted by
b'savik'
b'CVE-2020-6287 https://redapi2.acronis.com'
16 Feb 2021
b'Ruby on Rails'
disclosed a bug submitted by
b'ooooooo_q'
b'Server-side template injection at ujs test server'
16 Feb 2021
b'Acronis'
disclosed a bug submitted by
b'stealthy'
b'Administrative access to development deployment of web service due to auto-filled credentials'
16 Feb 2021
b'Acronis'
disclosed a bug submitted by
b'ganofins'
b'Found multiple SAP NetWeaver vulnerable services'
16 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'organdonor'
b"Possible access to the car's photo and registration by its ID on [fleet.city-mobil.ru]"
16 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'organdonor'
b'Disclosure of the account email by phone number on [corporate.city-mobil.ru]'
16 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'organdonor'
b'HTML injection in an email [delivery.city-mobil.ru]'
16 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'kwel'
b' [mcs.mail.ru]'
15 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'kwel'
b"Partner's manager can access statistics of all drivers [city-mobil.ru/taxiserv]"
15 Feb 2021
b'TikTok'
disclosed a bug submitted by
b'ach'
b'External SSRF and Local File Read via video upload due to vulnerable FFmpeg HLS processing'
15 Feb 2021
b'GitLab'
disclosed a bug submitted by
b'anshraj_srivastava'
b'Remote hacker can download all the files of master branch in public projects where everything is members only.'
15 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'r0hack'
b'Account TakeOver at kvartira.city-mobil.ru'
15 Feb 2021
b'8x8'
disclosed a bug submitted by
b'melbadry9'
b'DNS Misconfiguration (Subdomain Takeover) .wavecell.com'
15 Feb 2021
b'Automattic'
disclosed a bug submitted by
b'sodium_'
b'Stored XSS in Intense Debate comment system'
14 Feb 2021
b'Nextcloud'
disclosed a bug submitted by
b'sanmue'
b'External Storage - WebDAV - New user has access to storage from deleted user (same user-ID)'
14 Feb 2021
1
...
221
222
223
224
225
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM