REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
65
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Node.js third-party modules'
disclosed a bug submitted by
b'ermilov'
b'[express-laravel-passport] Improper Authentication'
04 Jan 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'ermilov'
b'[atlasboard-atlassian-package] Cross-site Scripting (XSS)'
04 Jan 2020
b'Coda'
disclosed a bug submitted by
b'fisher'
b'Lack or Origin check leads to Cross-Site Websocket Hijacking (CSWSH)'
04 Jan 2020
b'Evernote'
disclosed a bug submitted by
b'renekroka'
b'Reflected + Stored XSS - https://discussion.evernote.com'
03 Jan 2020
b'Intel Corporation'
disclosed a bug submitted by
b'kushal89shah'
b'[FG-VD-19-009] Intel(R) Trace Analyzer and Collector 2019 Memory Corruption Vulnerability Notification'
02 Jan 2020
b'Coda'
disclosed a bug submitted by
b'stefanofinding'
b"Use Github pack with Coda employee github account (search code of Coda's private repositories)"
02 Jan 2020
b'PUBG'
disclosed a bug submitted by
b'renekroka'
b'RXSS to Stored XSS - forums.pubg.com | URL parameter'
02 Jan 2020
b'Rocket.Chat'
disclosed a bug submitted by
b'sectex'
b'XSS (leads to arbitrary file read in Rocket.Chat-Desktop)'
02 Jan 2020
b'Rocket.Chat'
disclosed a bug submitted by
b'ant_pyne'
b'Clickjacking in the admin page'
02 Jan 2020
b'Shopify'
disclosed a bug submitted by
b'jmp_35p'
b'Add store to new partner account without confirming email address.'
02 Jan 2020
b'Mail.ru'
disclosed a bug submitted by
b'flawwan'
b'HTTP-Response-Splitting leads to information disclosure (email, firstname, lastname) at https://tz.mail.ru'
01 Jan 2020
b'Twitter'
disclosed a bug submitted by
b'jaka_tingkir'
b'protected Tweet settings overwritten by other settings'
01 Jan 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'luizviana'
b'[seeftl] Stored XSS when directory listing via filename.'
31 Dec 2019
b'Genasys Technologies'
disclosed a bug submitted by
b'rreiss'
b'Missing redaction on a disclosed report'
31 Dec 2019
b'Node.js third-party modules'
disclosed a bug submitted by
b'ermilov'
b'[webpack-bundle-analyzer] Cross-site Scripting'
30 Dec 2019
b'VK.com'
disclosed a bug submitted by
b'0x3c3e'
b'Clickjacking vkpay'
30 Dec 2019
b'Starbucks'
disclosed a bug submitted by
b'vinothkumar'
b'JumpCloud API Key leaked via Open Github Repository.'
30 Dec 2019
b'Node.js third-party modules'
disclosed a bug submitted by
b'johnssimon007'
b'[fileview] Inadequate Output Encoding and Escaping '
28 Dec 2019
b'Ian Dunn'
disclosed a bug submitted by
b'damn007'
b'Potential Open-Redirection'
27 Dec 2019
b'Stripo Inc'
disclosed a bug submitted by
b'trazer'
b'stripo.email reflected xss'
26 Dec 2019
1
...
347
348
349
350
351
...
745
BY DENIS WERNER - @NOBBD -
IMPRESSUM