REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Logitech'
disclosed a bug submitted by
b'c0nquer0r'
b'One Click Account takeover using Ouath CSRF bypass by adding Null byte %00 in state parameter on www.streamlabs.com'
06 Jan 2021
b'Kartpay'
disclosed a bug submitted by
b'ph4n745m'
b'Being able to change account contents even after password change'
06 Jan 2021
b'Logitech'
disclosed a bug submitted by
b'optional'
b'Stored XSS on oslo.io in notifications via project name change'
05 Jan 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'someonenobbd'
b'[Java] CWE-555: Query to detect password in Java EE configuration files'
05 Jan 2021
b'Open-Xchange'
disclosed a bug submitted by
b'rumata'
b'A specially crafted message sent to the local delivery agent (LMTP) causes the LMTP child process to issue a panic (call i_panic)'
05 Jan 2021
b'Stripo Inc'
disclosed a bug submitted by
b'ofjaaaah'
b'No rate limiting - Create data'
05 Jan 2021
b'Stripo Inc'
disclosed a bug submitted by
b'ofjaaaah'
b'No rate limiting - Create Plug-ins'
05 Jan 2021
b'Node.js'
disclosed a bug submitted by
b'fwilhelm'
b'Node.js: use-after-free in TLSWrap'
05 Jan 2021
b'Doppler'
disclosed a bug submitted by
b'ibrahimauwal'
b'email spoofing on doppler.team'
04 Jan 2021
b'Open-Xchange'
disclosed a bug submitted by
b'catenacyber'
b'Incomplete fix for CVE-2020-12673 : Specially crafted NTML message leads to buffer over read'
04 Jan 2021
b'Open-Xchange'
disclosed a bug submitted by
b'catenacyber'
b'Buffer overread off by one in `rpa_read_buffer`, incomplete fix for CVE-2020-12674'
04 Jan 2021
b'Twitter'
disclosed a bug submitted by
b'ryotak'
b'Read-only application can publish/delete fleets'
04 Jan 2021
b'New Relic'
disclosed a bug submitted by
b'batuhan'
b'Sending thousands of notifications with single request'
04 Jan 2021
b'ImpressCMS'
disclosed a bug submitted by
b'ex1st4nc3_'
b'Other misconfiguration on Slack Server'
04 Jan 2021
b'Lark Technologies'
disclosed a bug submitted by
b'susant_wagle123'
b'Hyper Link Injection while signup '
03 Jan 2021
b'Omise'
disclosed a bug submitted by
b'tw4v3sx'
b'bypassing MessageToSeller length limit at link.omise.co leads to the seller not been able to check any transaction details , refund or open a dispute.'
02 Jan 2021
b'curl'
disclosed a bug submitted by
b'cjun'
b'Integer overflows in tool_operate.c at line 1541'
01 Jan 2021
b'Rocket.Chat'
disclosed a bug submitted by
b'fabianfreyer'
b'XSS leads to RCE on the RocketChat desktop client.'
01 Jan 2021
b'Automattic'
disclosed a bug submitted by
b'fuzzme'
b'[intensedebate.com] SQL Injection Time Based on /changeReplaceOpt.php'
01 Jan 2021
b'Automattic'
disclosed a bug submitted by
b'fuzzme'
b'[intensedebate.com] SQL Injection Time Based On /js/commentAction/'
01 Jan 2021
1
...
235
236
237
238
239
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM