REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Trint Ltd'
disclosed a bug submitted by
b'dhakalananda'
b'IDOR in changing shared file name'
22 Jun 2019
b'Slack'
disclosed a bug submitted by
b'freem0'
b'Information leakage and default open port'
22 Jun 2019
b'Rocket.Chat'
disclosed a bug submitted by
b'theappsec'
b'Broken access control on apps '
22 Jun 2019
b'Infogram'
disclosed a bug submitted by
b'theappsec'
b'Stored XSS in infogram.com via language '
22 Jun 2019
b'Khan Academy'
disclosed a bug submitted by
b'rlaneth'
b'Cross-Site Request Forgery (CSRF) vulnerability on API endpoint allows account takeovers'
22 Jun 2019
b'ecobee'
disclosed a bug submitted by
b'prinsfrank'
b'Open API - AWS S3 GET Bucket (List Objects) Version 1'
21 Jun 2019
b'Shopify'
disclosed a bug submitted by
b'tems'
b'DOM XSS via Shopify.API.Modal.initialize'
21 Jun 2019
b'Redtube'
disclosed a bug submitted by
b'tony_tsep'
b'SSRF and local file disclosure by video upload on https://www.redtube.com/upload'
21 Jun 2019
b'SEMrush'
disclosed a bug submitted by
b'r0hack'
b'XSS Reflected on my_report'
21 Jun 2019
b'Nextcloud'
disclosed a bug submitted by
b'francescocar'
b'Vulnerable W3 Total Cache plugin version in use on nextcloud.com'
21 Jun 2019
b'Capital One'
disclosed a bug submitted by
b'linkks'
b' Heartbleed Bug'
19 Jun 2019
b'Capital One'
disclosed a bug submitted by
b'linkks'
b'Apache server-status enabled'
19 Jun 2019
b'Starbucks'
disclosed a bug submitted by
b'd3417_'
b'Blind SQL Injection on starbucks.com.gt and WAF Bypass :*'
19 Jun 2019
b'Collibra'
disclosed a bug submitted by
b'freem0'
b'Access to the database on onboarding.collibra.com'
19 Jun 2019
b'ZEIT'
disclosed a bug submitted by
b'kaunghtetzaw'
b'Open redirect vuln on login'
18 Jun 2019
b'Shopify'
disclosed a bug submitted by
b'h13-'
b'STAFF member with NO Explicit permissions can view `ActivityFeed` via GraphQL'
18 Jun 2019
b'Node.js third-party modules'
disclosed a bug submitted by
b'verichains'
b'[untitled-model] sql injection'
18 Jun 2019
b'VK.com'
disclosed a bug submitted by
b'linkks'
b'CVE-2018-0296'
17 Jun 2019
b'New Relic'
disclosed a bug submitted by
b'jon_bottarini'
b'Giving myself access to NR1 UI / one.newrelic.com without the proper feature flags on my account'
17 Jun 2019
b'ICQ'
disclosed a bug submitted by
b'bigshape'
b"ICQ 10.0.12371 icq: Uri Handler '-testability' URL File Insecure Library Loading Code Execution Vulnerability"
17 Jun 2019
1
...
396
397
398
399
400
...
741
BY DENIS WERNER - @NOBBD -
IMPRESSUM