REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
67
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Mail.ru'
disclosed a bug submitted by
b'kassih'
b'Cross-site Scripting (XSS) - Stored in ru.mail.mailapp'
19 Jul 2019
b'GitLab'
disclosed a bug submitted by
b'nyangawa'
b'Persistent XSS in Note objects'
19 Jul 2019
b'WordPress'
disclosed a bug submitted by
b'mygf'
b'Stored XSS Vulnerability'
18 Jul 2019
b'ExpressionEngine'
disclosed a bug submitted by
b'winst0n13'
b'Open Redirect in comment section'
18 Jul 2019
b'Imgur'
disclosed a bug submitted by
b'rioncool22'
b'BUG XSS IN "ADD IMAGES"'
18 Jul 2019
b'Maximum'
disclosed a bug submitted by
b'sicarius'
b"Developper's websites are easily accessibles leading to massive information disclosure"
18 Jul 2019
b'Chainlink'
disclosed a bug submitted by
b'danangtriatmaja'
b'No Valid SPF Records.'
18 Jul 2019
b'Semmle'
disclosed a bug submitted by
b'zealsham'
b'Server side includes in https://lgtm-com.pentesting.semmle.net/internal_api/v0.2/savePublicInformation leads to 500 server error and D-DOS'
18 Jul 2019
b'Mail.ru'
disclosed a bug submitted by
b'ruvlol'
b'LRF on shared.mail.ru due to "markdown" plugin'
18 Jul 2019
b'Mail.ru'
disclosed a bug submitted by
b'ruvlol'
b'Open Selenoid instance at 188.93.63.186 leads to LFR/SSRF.'
18 Jul 2019
b'Uber'
disclosed a bug submitted by
b'eequalsmc2'
b'Lack of proper paymentProfileUUID validation allows any number of free rides without any outstanding balance'
18 Jul 2019
b'Chainlink'
disclosed a bug submitted by
b'jaisharma'
b'Testnet address being sent in cleartext as http://rinkeby.chain.link/ is missing SSL certificate'
17 Jul 2019
b'Vanilla'
disclosed a bug submitted by
b'klmunday'
b'Stored XSS in Rich editor via Embed datetime'
17 Jul 2019
b'Vanilla'
disclosed a bug submitted by
b'klmunday'
b'Stored XSS in Profile Comments'
17 Jul 2019
b'Vanilla'
disclosed a bug submitted by
b'klmunday'
b'Stored XSS in embedded posts containing images'
17 Jul 2019
b'Vanilla'
disclosed a bug submitted by
b'klmunday'
b'Hidden Stored XSS in nested post embeds'
17 Jul 2019
b'GitLab'
disclosed a bug submitted by
b'nyangawa'
b'Local files could be overwritten in GitLab, leading to remote command execution'
17 Jul 2019
b'Maximum'
disclosed a bug submitted by
b'sicarius'
b'Wrong link on corne.maximum.nl'
16 Jul 2019
b'Ian Dunn'
disclosed a bug submitted by
b'littlegeek'
b'xmlrpc.php FILE IS enable on Main website'
16 Jul 2019
b'Grammarly'
disclosed a bug submitted by
b'metnew'
b'`socket` command allows sending data over WebSockets to arbitrary origins from Grammarly Extension'
15 Jul 2019
1
...
405
406
407
408
409
...
757
BY DENIS WERNER - @NOBBD -
IMPRESSUM