REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Mail.ru'
disclosed a bug submitted by
b'chernobog'
b'CSRF on draft message creation in tel.mail.ru'
01 Sep 2019
b'Mail.ru'
disclosed a bug submitted by
b'pikky'
b'Stored XSS'
01 Sep 2019
b'Nextcloud'
disclosed a bug submitted by
b'xatom'
b'Passwords being stored as plain text in logging'
31 Aug 2019
b'Nextcloud'
disclosed a bug submitted by
b'chernobyl'
b'User Editable nextcloud Wiki pages of Public Repositories'
31 Aug 2019
b'GitLab'
disclosed a bug submitted by
b'mario-areias'
b'Persistent XSS via e-mail when creating merge requests'
30 Aug 2019
b'GitLab'
disclosed a bug submitted by
b'ngalog'
b'Bypass Email Verification -- Able to Access Internal Gitlab Services that use Login with Gitlab and Perform Check on email domain'
30 Aug 2019
b'GitLab'
disclosed a bug submitted by
b'jobert'
b"GitLab's GitHub integration is vulnerable to SSRF vulnerability"
30 Aug 2019
b'Imgur'
disclosed a bug submitted by
b'hogarth45'
b'CSRF leads to a stored self xss'
30 Aug 2019
b'New Relic'
disclosed a bug submitted by
b'albinowax'
b'Password theft login.newrelic.com via Request Smuggling'
30 Aug 2019
b'Nextcloud'
disclosed a bug submitted by
b'jelle293'
b'Missing DNSSEC'
29 Aug 2019
b'Nextcloud'
disclosed a bug submitted by
b'freddyb'
b'Reflected XSS / Markup Injection in `index.php/svg/core/logo/logo` parameter `color`'
29 Aug 2019
b'Phabricator'
disclosed a bug submitted by
b'ranjit_p'
b'IDOR bug to See hidden slowvote of any user even when you dont have access right'
29 Aug 2019
b'WordPress'
disclosed a bug submitted by
b'ashketchum'
b'Parameter tampering : Price Manipulation of Products'
29 Aug 2019
b'Ruby'
disclosed a bug submitted by
b'kyoshida'
b'OS Command Injection via egrep in Rake::FileList'
29 Aug 2019
b'Shipt'
disclosed a bug submitted by
b'streaak'
b'Slack token leaking in stackoverflow and devtimes '
29 Aug 2019
b'Kaspersky'
disclosed a bug submitted by
b'palant'
b'Certificate warnings and similar UI elements are susceptible to clickjacking'
28 Aug 2019
b'Kaspersky'
disclosed a bug submitted by
b'palant'
b'Opening up a Universal XSS vulnerability in Microsoft Edge'
28 Aug 2019
b'GitLab'
disclosed a bug submitted by
b'uzsunny'
b'Access Projects And create projects in gitlab pre production server'
28 Aug 2019
b'Starbucks'
disclosed a bug submitted by
b'parzel'
b'Subdomain takeover of datacafe-cert.starbucks.com'
28 Aug 2019
b'WordPress'
disclosed a bug submitted by
b'foobar7'
b'Reflected XSS: Taxonomy Converter via tax parameter'
28 Aug 2019
1
...
406
407
408
409
410
...
766
BY DENIS WERNER - @NOBBD -
IMPRESSUM