REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'curl'
disclosed a bug submitted by
b'd4d'
b'Abusing URL Parsers by long schema name'
08 Jan 2021
b'curl'
disclosed a bug submitted by
b'bagder'
b'CVE-2020-8285: FTP wildcard stack overflow'
08 Jan 2021
b'Kubernetes'
disclosed a bug submitted by
b'rhynorater'
b'Blind SSRF on velodrome.canary.k8s.io'
07 Jan 2021
b'Logitech'
disclosed a bug submitted by
b'hammodmt'
b'Host Header injection in oslo.io (using X-Forwarded-For header) leading to email spoofing'
07 Jan 2021
b'Kubernetes'
disclosed a bug submitted by
b'jsafrane'
b'csi-snapshot-controller crashes when processing VolumeSnapshot with non-existing PVC'
07 Jan 2021
b'Kubernetes'
disclosed a bug submitted by
b'flag_c0'
b'exposed Git Repo at http://api.e2e-kops-aws-canary.test-cncf-aws.canary.k8s.io/.git/'
07 Jan 2021
b'Kubernetes'
disclosed a bug submitted by
b'flag_c0'
b'Unsecured Grafana instance on https://monitoring.prow-canary.k8s.io/dashboards'
07 Jan 2021
b'Kubernetes'
disclosed a bug submitted by
b'riramar'
b'Plaintext storage of a password on kubernetes release bucket'
07 Jan 2021
b'Node.js'
disclosed a bug submitted by
b'piao'
b'Potential HTTP Request Smuggling in nodejs'
07 Jan 2021
b'Mail.ru'
disclosed a bug submitted by
b'steal_wart'
b'Django Debug=True Leaks admin email addresss and serval system information '
07 Jan 2021
b'Doppler'
disclosed a bug submitted by
b'bugera'
b'No rate limit into email change leads to email notification boombing to its victim.'
06 Jan 2021
b'Doppler'
disclosed a bug submitted by
b'bugera'
b'Access page must be reloaded to perform multiple requests'
06 Jan 2021
b'Logitech'
disclosed a bug submitted by
b'c0nquer0r'
b'One Click Account takeover using Ouath CSRF bypass by adding Null byte %00 in state parameter on www.streamlabs.com'
06 Jan 2021
b'Kartpay'
disclosed a bug submitted by
b'ph4n745m'
b'Being able to change account contents even after password change'
06 Jan 2021
b'Logitech'
disclosed a bug submitted by
b'optional'
b'Stored XSS on oslo.io in notifications via project name change'
05 Jan 2021
b'GitHub Security Lab'
disclosed a bug submitted by
b'someonenobbd'
b'[Java] CWE-555: Query to detect password in Java EE configuration files'
05 Jan 2021
b'Open-Xchange'
disclosed a bug submitted by
b'rumata'
b'A specially crafted message sent to the local delivery agent (LMTP) causes the LMTP child process to issue a panic (call i_panic)'
05 Jan 2021
b'Stripo Inc'
disclosed a bug submitted by
b'ofjaaaah'
b'No rate limiting - Create data'
05 Jan 2021
b'Stripo Inc'
disclosed a bug submitted by
b'ofjaaaah'
b'No rate limiting - Create Plug-ins'
05 Jan 2021
b'Node.js'
disclosed a bug submitted by
b'fwilhelm'
b'Node.js: use-after-free in TLSWrap'
05 Jan 2021
1
...
238
239
240
241
242
...
741
BY DENIS WERNER - @NOBBD -
IMPRESSUM