REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Rockstar Games'
disclosed a bug submitted by
b'osama-hamad'
b'Open Redirection effects autodiscover.rockstargames.com'
03 Feb 2025
b'MTN Group'
disclosed a bug submitted by
b'aliyueka'
b'Improper Access Controls(Admin Path)'
31 Jan 2025
b'MTN Group'
disclosed a bug submitted by
b'aliyueka'
b'Broken Access Control(Horizontal Privilege Escalation).'
31 Jan 2025
b'MTN Group'
disclosed a bug submitted by
b'aliyueka'
b'Insecure direct Object Reference(Horizontal Escalation)'
31 Jan 2025
b'Yelp'
disclosed a bug submitted by
b'no-need'
b'Unauthorized Reservation Cancellation Through IDOR Vulnerability'
29 Jan 2025
b'Yelp'
disclosed a bug submitted by
b'vijaysimha-reddy'
b'Privilege Escalation - A Non Owner User Who Does not Have access to the user management can invite other users to the restaurant page'
29 Jan 2025
b'Adobe'
disclosed a bug submitted by
b'titanrain'
b'Registration Information Leakage '
29 Jan 2025
b'Cognizant'
disclosed a bug submitted by
b'hellicopter'
b'Disclosure of the valid Cognizant credentials at the Postman collection'
29 Jan 2025
b'Yelp'
disclosed a bug submitted by
b'vijaysimha-reddy'
b'Privilege Escalation - A Low Privilege User who does not have access to the user management module can remove the owner of the business account'
28 Jan 2025
b'Node.js'
disclosed a bug submitted by
b'taise'
b'Path traversal by drive name in Windows environment'
27 Jan 2025
b'TikTok'
disclosed a bug submitted by
b'datph4m'
b'Unauthorized Access to TikTok Account [Private Videos] via API Endpoint'
24 Jan 2025
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'0xrasputin'
b'Public google drive link Exposes Military Orders Containing PII (Name, SSN etc..) and Operational Details'
24 Jan 2025
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'hxhbrofessor'
b'Exposure of Private Personal Information to an Unauthorized Actor - PII and soldier data (mos, schools, and speciality training)'
24 Jan 2025
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'iamunixtz'
b'Boolen Based Blind Sql Injection Via User Agent in .mil'
24 Jan 2025
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'leofmlopes'
b'Time-based blind SQL injection'
24 Jan 2025
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'thpless'
b'XSS vulnerability found in javascript code of https://.mil'
24 Jan 2025
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'thpless'
b'XSS found in https://www..mil'
24 Jan 2025
b'XVIDEOS'
disclosed a bug submitted by
b'chse_'
b'Stored XSS via SMTP Error Message'
24 Jan 2025
b'IBM'
disclosed a bug submitted by
b'youssifs7'
b'POST based Cross-Site Scripting on IBM research endpoint'
23 Jan 2025
b'Node.js'
disclosed a bug submitted by
b'parrot409'
b'Usage of unsafe random function in undici for choosing boundary'
23 Jan 2025
1
...
22
23
24
25
26
...
742
BY DENIS WERNER - @NOBBD -
IMPRESSUM