REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
65
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Uber'
disclosed a bug submitted by
b'gamer7112'
b'Reflected XSS on https://www.uber.com'
24 Feb 2021
b'Uber'
disclosed a bug submitted by
b'molejarka'
b'[experience.uber.com] Node.js source code disclosure & anonymous access to internal Uber documents, templates and tools'
23 Feb 2021
b'Uber'
disclosed a bug submitted by
b'cablej'
b'[manage.jumpbikes.com] Blind XSS on Jump admin panel via user name'
23 Feb 2021
b'Rockstar Games'
disclosed a bug submitted by
b'bugstar'
b'RDR2 game service method allows adding any player to a new Posse without consent'
23 Feb 2021
b'Node.js'
disclosed a bug submitted by
b'v6ak'
b'DNS rebinding in --inspect (insufficient fix of CVE-2018-7160)'
23 Feb 2021
b'Acronis'
disclosed a bug submitted by
b'theevilbit'
b'Acronis True Image Local Privilege Escalation via insecure folder permissions'
23 Feb 2021
b'Acronis'
disclosed a bug submitted by
b'theevilbit'
b'True Image 2021 - LPE via XPC service communication'
23 Feb 2021
b'Lark Technologies'
disclosed a bug submitted by
b'imran_nisar'
b'Stored XSS in Satisfaction Surveys via "Ask Reason for Dissatisfaction" option'
23 Feb 2021
b'Valve'
disclosed a bug submitted by
b'fe7ch'
b'[CS 1.6] Map cycle abuse allows arbitrary file read/write'
22 Feb 2021
b'Keybase'
disclosed a bug submitted by
b'johnjhacking'
b'Keybase /AppData/Local/Keybase/uploadtemps folder stores pasted photos'
22 Feb 2021
b'Zomato'
disclosed a bug submitted by
b'hoteyes'
b'SQL Injection in www.hyperpure.com'
22 Feb 2021
b'Basecamp'
disclosed a bug submitted by
b'aisforarray'
b'DNS Setup allows sending mail on behalf of other customers'
21 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'n19ht-d3v1l'
b'subdomain Takeover'
21 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'n19ht-d3v1l'
b'Subdomain Takeover'
21 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'schutzx0r'
b'CSRF in updating username https://pw.mail.ru/'
21 Feb 2021
b'Lark Technologies'
disclosed a bug submitted by
b'imran_nisar'
b"Stored xss in larksuite internal helpdesk and other user's helpdesk."
19 Feb 2021
b'Nextcloud'
disclosed a bug submitted by
b'verg'
b'Stored XSS in markdown file with Nextcloud Talk using Internet Explorer'
19 Feb 2021
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'nidens'
b' IDOR leads to disclosure of PHI/PII'
18 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'0ang3el'
b'Stored XSS in calendar via UID parameter'
18 Feb 2021
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'un4gi'
b'Password Cracking - Weak Password Used to Secure Containing a Plaintext Password'
18 Feb 2021
1
...
227
228
229
230
231
...
746
BY DENIS WERNER - @NOBBD -
IMPRESSUM