REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Razer'
disclosed a bug submitted by
b't4kemyh4nd'
b'[IDOR] API endpoint leaking sensitive user information'
09 Jan 2020
b'Ian Dunn'
disclosed a bug submitted by
b'bruteforce'
b'Dos https://iandunn.name/ via CVE-2018-6389 exploitation'
09 Jan 2020
b'8x8'
disclosed a bug submitted by
b'kingragnar'
b'Access to ?????????????? due to weak credentials'
08 Jan 2020
b'Dovecot'
disclosed a bug submitted by
b'nick_roessler'
b'Two heap use-after-free errors in IMAP operations'
08 Jan 2020
b'PayPal'
disclosed a bug submitted by
b'alexbirsan'
b"Token leak in security challenge flow allows retrieving victim's PayPal email and plain text password"
08 Jan 2020
b'WordPress'
disclosed a bug submitted by
b'simonscannell'
b'Potential unprivileged Stored XSS through wp_targeted_link_rel'
08 Jan 2020
b'NordVPN'
disclosed a bug submitted by
b'cassiomcampos'
b'DoS of https://nordvpn.com/ via CVE-2018-6389 exploitation'
08 Jan 2020
b'Stripo Inc'
disclosed a bug submitted by
b'jasongardner'
b'Clickjacking on my.stripo.email for MailChimp credentials '
08 Jan 2020
b'Ian Dunn'
disclosed a bug submitted by
b'shrimant_yogi'
b'xmlrpc.php FILE IS enable it can be used for conducting a Bruteforce attack and Denial of Service(DoS)'
07 Jan 2020
b'LifeOmic'
disclosed a bug submitted by
b'base_64'
b'open redirect while login at https://apps.dev.jupiterone.io can leak access code.'
06 Jan 2020
b'LifeOmic'
disclosed a bug submitted by
b'zsbappa'
b'Improper signup & sign-in validation '
06 Jan 2020
b'NordVPN'
disclosed a bug submitted by
b'shardulb_23'
b'xmlrpc.php FILE IS enable it will used for Bruteforce attack and Denial of Service(DoS)'
06 Jan 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'ermilov'
b'[express-laravel-passport] Improper Authentication'
04 Jan 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'ermilov'
b'[atlasboard-atlassian-package] Cross-site Scripting (XSS)'
04 Jan 2020
b'Coda'
disclosed a bug submitted by
b'fisher'
b'Lack or Origin check leads to Cross-Site Websocket Hijacking (CSWSH)'
04 Jan 2020
b'Evernote'
disclosed a bug submitted by
b'renekroka'
b'Reflected + Stored XSS - https://discussion.evernote.com'
03 Jan 2020
b'Intel Corporation'
disclosed a bug submitted by
b'kushal89shah'
b'[FG-VD-19-009] Intel(R) Trace Analyzer and Collector 2019 Memory Corruption Vulnerability Notification'
02 Jan 2020
b'Coda'
disclosed a bug submitted by
b'stefanofinding'
b"Use Github pack with Coda employee github account (search code of Coda's private repositories)"
02 Jan 2020
b'PUBG'
disclosed a bug submitted by
b'renekroka'
b'RXSS to Stored XSS - forums.pubg.com | URL parameter'
02 Jan 2020
b'Rocket.Chat'
disclosed a bug submitted by
b'sectex'
b'XSS (leads to arbitrary file read in Rocket.Chat-Desktop)'
02 Jan 2020
1
...
331
332
333
334
335
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM