REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
65
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'LINE'
disclosed a bug submitted by
b'kazan71p'
b'Spring Actuator endpoints publicly available and broken authentication'
06 Aug 2020
b'8x8'
disclosed a bug submitted by
b'wisp'
b'Send Phishing/Spam email from support@sameroom.io to any email address.'
05 Aug 2020
b'Rockset'
disclosed a bug submitted by
b'thatquasar'
b'S3 bucket data at http://rockset-support.s3-us-west-2.amazonaws.com/ reveals user addresses based on latitudes and longitudes.'
05 Aug 2020
b'Nextcloud'
disclosed a bug submitted by
b'l00ph0le'
b'Arbitrary code execution in desktop client via OpenSSL config'
05 Aug 2020
b'Nextcloud'
disclosed a bug submitted by
b'yzy9951'
b'XSS in image metadata field'
05 Aug 2020
b'concrete5'
disclosed a bug submitted by
b'thiennv'
b'Time-base SQL Injection in Search Users'
05 Aug 2020
b'GitLab'
disclosed a bug submitted by
b'yvvdwf'
b'Stored XSS in blob viewer'
04 Aug 2020
b'LINE'
disclosed a bug submitted by
b'kazan71p'
b'Spring Actuator endpoints publicly available, leading to account takeover'
04 Aug 2020
b'Twitter'
disclosed a bug submitted by
b'ryotak'
b'Private list members disclosure via GraphQL'
04 Aug 2020
b'GitLab'
disclosed a bug submitted by
b'semsem123'
b'Unrestricted file upload leads to Stored XSS'
03 Aug 2020
b'LINE'
disclosed a bug submitted by
b'j0eii'
b'Insufficient access control on all BCRM instances leading to the ability to create admin accounts using the API'
03 Aug 2020
b'Mail.ru'
disclosed a bug submitted by
b'kursadalsan'
b'Open Redirect at "city-mobil.ru"'
03 Aug 2020
b'Mail.ru'
disclosed a bug submitted by
b'aslanemre'
b'xss while uploading a file'
03 Aug 2020
b'Mail.ru'
disclosed a bug submitted by
b'pisarenko'
b'xss on [storehouse5.ucs.ru]'
03 Aug 2020
b'Mail.ru'
disclosed a bug submitted by
b'mehulpanchal007'
b'Reflected XSS in "keywords" parameter at "https://sbermarket.ru/metro/search"'
03 Aug 2020
b'Mail.ru'
disclosed a bug submitted by
b'weev3kyaw'
b'Account takeover through password reset in cups.mail.ru'
03 Aug 2020
b'Mail.ru'
disclosed a bug submitted by
b'shuraros'
b'relap.io IDOR'
03 Aug 2020
b'Nextcloud'
disclosed a bug submitted by
b'pshknst'
b'Anonymous file drop page ignores user profile visibility restrictions'
03 Aug 2020
b'Facebook'
disclosed a bug submitted by
b'yashrs'
b'Facebook - Reputation Sync For #267890541047618'
02 Aug 2020
b'LINE'
disclosed a bug submitted by
b'ledz1996'
b'Get-based SSRF limited to HTTP protocol on https://resizer.line-apps.com/form'
02 Aug 2020
1
...
286
287
288
289
290
...
745
BY DENIS WERNER - @NOBBD -
IMPRESSUM