REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Passit'
disclosed a bug submitted by
b'exception'
b'X-Content-Type-Options has not been set at app.passit.io'
24 Jul 2018
b'WordPress'
disclosed a bug submitted by
b'arunthelegion'
b'xss - reflected'
24 Jul 2018
b'Starbucks'
disclosed a bug submitted by
b'txt3rob'
b'svcardproxydevus.starbucks.com Subdomain take over'
23 Jul 2018
b'Starbucks'
disclosed a bug submitted by
b'blurbdust'
b'Subdomain takeover on svcgatewaydevus.starbucks.com and svcgatewayloadus.starbucks.com'
23 Jul 2018
b'Starbucks'
disclosed a bug submitted by
b'qwacsawd'
b"Able to reset other user's password in https://card.starbucks.com.sg/"
23 Jul 2018
b'HackerOne'
disclosed a bug submitted by
b'tisisire'
b'Information leakage - Private reports cached by Google '
23 Jul 2018
b'WordPress'
disclosed a bug submitted by
b'mopman'
b'XSS on support.wordcamp.org in ajax-quote.php'
23 Jul 2018
b'WordPress'
disclosed a bug submitted by
b'sameerphad72'
b'Open API For Username enumeration'
23 Jul 2018
b'Vanilla'
disclosed a bug submitted by
b'geekboy'
b'Overwrite Drafts of Everyone '
23 Jul 2018
b'Vanilla'
disclosed a bug submitted by
b'geekboy'
b'Accessing Private Files Shared in message of other users'
23 Jul 2018
b'Open-Xchange'
disclosed a bug submitted by
b'mishre'
b'Blind XXE via Powerpoint files'
23 Jul 2018
b'Razer US'
disclosed a bug submitted by
b'achapman'
b'Razer Synapse 3 Local Privilege Escalation'
23 Jul 2018
b'Tor'
disclosed a bug submitted by
b'rbcafe'
b'Expose relay IP in the debug (The source is different from the rendering)'
21 Jul 2018
b'Nextcloud'
disclosed a bug submitted by
b'noumar'
b'OAuth2 Access Token and App Password Security Vulnerability'
21 Jul 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'n1__'
b'[markdown-pdf] Local file reading'
20 Jul 2018
b'Starbucks'
disclosed a bug submitted by
b'qwacsawd'
b'Able to purchase a gift card with any amount'
20 Jul 2018
b'New Relic'
disclosed a bug submitted by
b'ldionmarcil'
b'Stored XSS in Brower `name` field reflected in two pages'
20 Jul 2018
b'HackerOne'
disclosed a bug submitted by
b'kapytein'
b'Team object exposes amount of participants in a private program'
20 Jul 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'szkrstf'
b'[ponse] Path traversal in ponse module allows to read any file on server'
20 Jul 2018
b'Valve'
disclosed a bug submitted by
b'chippy'
b'Malformed .BSP Access Violation in CS:GO can lead to Remote Code Execution'
19 Jul 2018
1
...
448
449
450
451
452
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM