REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
65
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'InnoGames'
disclosed a bug submitted by
b'batee5a'
b'Unprivileged alliance member is able to recruit new members to his alliance and accepting them (xs1.grepolis.com)'
02 Jun 2020
b'Ubiquiti Inc.'
disclosed a bug submitted by
b'grampae'
b'Reflected XSS in Nanostation Loco M2 - AirOS ver=6.1.7'
01 Jun 2020
b'Helium'
disclosed a bug submitted by
b'kdr9666'
b'Cleartext Transmission of Sensitive Information Leads to administrator access'
30 May 2020
b'GitHub Security Lab'
disclosed a bug submitted by
b'luchua'
b'Java: CWE-532 sensitive info logging'
29 May 2020
b'Lyft'
disclosed a bug submitted by
b'nahamsec'
b'My Expense Report resulted in a Server-Side Request Forgery (SSRF) on Lyft'
29 May 2020
b'Ubiquiti Inc.'
disclosed a bug submitted by
b'jstjohn'
b'Firmware download/install vulnerable to CSRF'
29 May 2020
b'Mail.ru'
disclosed a bug submitted by
b'njgadhiya'
b'Cross-Site Request Forgery (CSRF) in my.games API'
28 May 2020
b'Mail.ru'
disclosed a bug submitted by
b'deadmin'
b'XSS in [community.my.games]'
28 May 2020
b'MariaDB'
disclosed a bug submitted by
b'lixtelnis'
b'Path traversal in command line client'
28 May 2020
b'Mail.ru'
disclosed a bug submitted by
b'zerboa'
b'relap.io CSRF bypass on adding domain to use relap widgets '
28 May 2020
b'Mail.ru'
disclosed a bug submitted by
b'tr3harder'
b'Reflected XSS at city-mobil.ru'
28 May 2020
b'Mail.ru'
disclosed a bug submitted by
b'tr3harder'
b'IDOR of users '
28 May 2020
b'Mail.ru'
disclosed a bug submitted by
b'tr3harder'
b'Account Takeover worki.ru'
28 May 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'0x48piraj'
b'OS Command Injection on Jison [all-parser-ports]'
28 May 2020
b'lemlist'
disclosed a bug submitted by
b'arsene_lupin'
b'SSRF in img.lemlist.com that leads to Localhost Port Scanning'
28 May 2020
b'Helium'
disclosed a bug submitted by
b'azraelsec'
b'Organization Takeover'
27 May 2020
b'Helium'
disclosed a bug submitted by
b'azraelsec'
b'Organization Takeover via invitation API'
27 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'r00tpgp'
b'Previously Compromised PulseSSL VPN Hosts'
27 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'sensoyard'
b'Unrestricted file upload leads to stored xss on https://????????/'
27 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'hunt4p1zza'
b'[Critical] Insufficient Access Control On Registration Page of Webapps Website Allows Privilege Escalation to Administrator '
27 May 2020
1
...
307
308
309
310
311
...
745
BY DENIS WERNER - @NOBBD -
IMPRESSUM