REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'TikTok'
disclosed a bug submitted by
b'gnux'
b'Bypass "Industry Documents" Validation'
29 Oct 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'ryotak'
b'[zenn-cli] Path traversal on Windows allows the attacker to read arbitrary .md files'
29 Oct 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'mik317'
b'[expressjs-ip-control] Whitelist IP bypass leads to authorization bypass and sensitive info disclosure'
29 Oct 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'prathis'
b' [ts-dot-prop] Prototype Pollution'
29 Oct 2020
b'Mail.ru'
disclosed a bug submitted by
b'haxonaut'
b'Multiple SQL Injections and constrained LFI in esk-static.3igames.mail.ru'
29 Oct 2020
b'curl'
disclosed a bug submitted by
b'brumbrum'
b'Parallel upload hangs curl if upload file not found'
29 Oct 2020
b'Ruby'
disclosed a bug submitted by
b'piao'
b'Potential HTTP Request Smuggling in ruby webrick'
29 Oct 2020
b'Tube8'
disclosed a bug submitted by
b'ramsexy'
b'Blind SQL injection in Hall of Fap'
29 Oct 2020
b'Agoric'
disclosed a bug submitted by
b'sickcodes'
b'Stored XSS in agoric-sdk - malicious iframes, malicious svg'
28 Oct 2020
b'Agoric'
disclosed a bug submitted by
b'sickcodes'
b'Improper Input Validation allows an attacker to "double spend" or "respend", violating the integrity of the message command history or causing DoS'
28 Oct 2020
b'Basecamp'
disclosed a bug submitted by
b'hazimaslam'
b'HTTP request smuggling on Basecamp 2 allows web cache poisoning'
28 Oct 2020
b'Basecamp'
disclosed a bug submitted by
b'hazimaslam'
b'Unauthenticated request smuggling on launchpad.37signals.com'
28 Oct 2020
b'Mail.ru'
disclosed a bug submitted by
b'devirok'
b' http://login.aa.mail.ru/logs/'
28 Oct 2020
b'Nextcloud'
disclosed a bug submitted by
b'dschuermann'
b'PIN for passwordless WebAuthn is asked for but not verified'
28 Oct 2020
b'Nextcloud'
disclosed a bug submitted by
b'daniel_calvino_sanchez'
b'The password of a mail share is not hashed if the password is given when the share is created'
28 Oct 2020
b'Nextcloud'
disclosed a bug submitted by
b'lynn-stephenson'
b'Reduced purmations on encryption'
28 Oct 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'd3lla'
b'[gfc] Command Injection via insecure command formatting'
27 Oct 2020
b'Basecamp'
disclosed a bug submitted by
b'enigmaticjohn'
b'Possible DOM XSS on app.hey.com'
27 Oct 2020
b'CS Money'
disclosed a bug submitted by
b'mvm'
b'ReDoS at wiki.cs.money graphQL endpoint (AND probably a kind of command injection)'
27 Oct 2020
b'CS Money'
disclosed a bug submitted by
b'ahmd_halabi'
b'Manipulate Uneditable Messages in Support'
27 Oct 2020
1
...
291
292
293
294
295
...
776
BY DENIS WERNER - @NOBBD -
IMPRESSUM