REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Mail.ru'
disclosed a bug submitted by
b'tr3harder'
b'Reflected XSS at city-mobil.ru'
28 May 2020
b'Mail.ru'
disclosed a bug submitted by
b'tr3harder'
b'IDOR of users '
28 May 2020
b'Mail.ru'
disclosed a bug submitted by
b'tr3harder'
b'Account Takeover worki.ru'
28 May 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'0x48piraj'
b'OS Command Injection on Jison [all-parser-ports]'
28 May 2020
b'lemlist'
disclosed a bug submitted by
b'arsene_lupin'
b'SSRF in img.lemlist.com that leads to Localhost Port Scanning'
28 May 2020
b'Helium'
disclosed a bug submitted by
b'azraelsec'
b'Organization Takeover'
27 May 2020
b'Helium'
disclosed a bug submitted by
b'azraelsec'
b'Organization Takeover via invitation API'
27 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'r00tpgp'
b'Previously Compromised PulseSSL VPN Hosts'
27 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'sensoyard'
b'Unrestricted file upload leads to stored xss on https://????????/'
27 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'hunt4p1zza'
b'[Critical] Insufficient Access Control On Registration Page of Webapps Website Allows Privilege Escalation to Administrator '
27 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'nagli'
b'No Rate Limiting on https://??????/??????????/accounts/password/reset/ endpoint leads to Denial of Service'
27 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'manshum12'
b'Self XSS combine CSRF at https://????????/index.php'
27 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'manshum12'
b'XSS Reflected '
27 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'droop3r'
b'Remote Code Execution through DNN Cookie Deserialization '
27 May 2020
b'Open-Xchange'
disclosed a bug submitted by
b'catenacyber'
b'Missing (or redundant) null check in `dcrypt_openssl_sign`'
27 May 2020
b'Ruby on Rails'
disclosed a bug submitted by
b'mastahyeti'
b'CSRF header is sent to external websites when using data-remote forms'
26 May 2020
b'Ruby on Rails'
disclosed a bug submitted by
b'dylan-ts'
b'Untrusted strings that are cache fetched with raw option are automatically marshal loaded'
26 May 2020
b'Razer'
disclosed a bug submitted by
b's3cr3tsdn'
b'SQL injection at https://sea-web.gold.razer.com/ajax-get-status.php via txid parameter'
26 May 2020
b'Razer'
disclosed a bug submitted by
b'f_m'
b'HTML injection in support.razer.com [IE only]'
26 May 2020
b'Nutanix'
disclosed a bug submitted by
b'zinin'
b'AWS S3 bucket writeable for authenticated AWS users'
26 May 2020
1
...
292
293
294
295
296
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM