REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Nextcloud'
disclosed a bug submitted by
b'yzy9951'
b'Reflected XSS when renaming a file with a vulnerable name which results in an error'
01 Mar 2021
b'Nextcloud'
disclosed a bug submitted by
b'alacn1'
b'External storage app saves password for all users in the database'
01 Mar 2021
b'Xiaomi'
disclosed a bug submitted by
b'l1ack3d'
b'CORS Misconfiguration, could lead to disclosure of users information'
01 Mar 2021
b'Xiaomi'
disclosed a bug submitted by
b'cujanovic'
b'DOM-based XSS in d.miwifi.com on IE 11'
01 Mar 2021
b'Mail.ru'
disclosed a bug submitted by
b'tofla'
b'Reflected XSS https://tracker.my.com'
28 Feb 2021
b'8x8'
disclosed a bug submitted by
b'melbadry9'
b'DNS Misconfiguration (Subdomain Takeover) .staging..8x8.com'
28 Feb 2021
b'Lark Technologies'
disclosed a bug submitted by
b'w2w'
b"Improper generating of access link at go.larksuite.com leads to access to other organizations/users' private data"
27 Feb 2021
b'Dropbox'
disclosed a bug submitted by
b'h4x0r_dz'
b'User has Sender permission can Get Team information '
26 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'alexeysergeevich'
b'capsula.mail.ru - reflected xss'
26 Feb 2021
b'Lark Technologies'
disclosed a bug submitted by
b'imran_nisar'
b'Stealing app credentials by reflected xss on Lark Suite'
26 Feb 2021
b'Uber'
disclosed a bug submitted by
b'apolo2'
b'Thumbor misconfiguration at blogapi.uber.com can lead to DoS'
25 Feb 2021
b'Uber'
disclosed a bug submitted by
b'mariogomez1'
b'stack trace exposed on https://receipts.uber.com/'
25 Feb 2021
b'Uber'
disclosed a bug submitted by
b'corb3nik'
b'[First 30] Stored XSS on login.uber.com/oauth/v2/authorize via redirect_uri parameter'
25 Feb 2021
b'Uber'
disclosed a bug submitted by
b'corb3nik'
b'Stored XSS on auth.uber.com/oauth/v2/authorize via redirect_uri parameter leads to Account Takeover'
25 Feb 2021
b'Uber'
disclosed a bug submitted by
b'healdb'
b'Outdated Wordpress installation and plugins at www.uberxgermany.com create CSRF and XSS vulnerabilities'
25 Feb 2021
b'Uber'
disclosed a bug submitted by
b'tomnomnom'
b'[Pre-Submission][H1-4420-2019] API access to Phabricator on code.uberinternal.com from leaked certificate in git repo'
25 Feb 2021
b'Uber'
disclosed a bug submitted by
b'fawazxq'
b'Disclosure of Co-Rider user (Uber-pooling) profile picture at Amazon AWS Cloudfront within HTTP RESPONSE '
25 Feb 2021
b'Uber'
disclosed a bug submitted by
b'phwd'
b'Listing of email addresses of whitelisted business users visible at business.uber.com'
25 Feb 2021
b'Uber'
disclosed a bug submitted by
b'rijalrojan'
b'Uber employees are sharing information on productforums.google.com'
25 Feb 2021
b'Uber'
disclosed a bug submitted by
b'0xd0m7'
b'[usuppliers.uber.com] - Server Side Request Forgery via XXE OOB'
25 Feb 2021
1
...
221
222
223
224
225
...
741
BY DENIS WERNER - @NOBBD -
IMPRESSUM