REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
56
b'ooooooo_q'
50
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Mars'
disclosed a bug submitted by
b'mo3giza'
b'Response Manipulation lead to bypass verification code while making appointment at `banfield.com`'
30 Aug 2023
b'Mars'
disclosed a bug submitted by
b'ped_baq'
b'Html injection'
30 Aug 2023
b'Mars'
disclosed a bug submitted by
b'ractiurd'
b'Google dork lead to unsubscribe anyone from all Banfield emails'
30 Aug 2023
b'Acronis'
disclosed a bug submitted by
b'cevans_0'
b'Missing brute force protection on login page on www.acronis.com'
30 Aug 2023
b'HackerOne'
disclosed a bug submitted by
b'callmed0_4'
b'IDOR - Delete all Licenses and certifications from users account using CreateOrUpdateHackerCertification GraphQL query'
29 Aug 2023
b'HackerOne'
disclosed a bug submitted by
b'japz'
b'Names not completely redacted despite "Redact the names of the involved users" is selected'
29 Aug 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'shin24'
b'unsanitized input goes to regex function leads to ReDos that make request hangs'
28 Aug 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'yadhukrishnam'
b'HTTP Request Smuggling via Empty headers separated by CR'
28 Aug 2023
b'inDrive'
disclosed a bug submitted by
b'kristoferent'
b'Stored XSS on promo.indrive.com'
28 Aug 2023
b'HackerOne'
disclosed a bug submitted by
b'zerotea'
b'Staff and Triage can modify the initial post of a report, including of already disclosed reports'
28 Aug 2023
b'Automattic'
disclosed a bug submitted by
b'riadalrashed'
b'Entering passwords on the Share Login Page can lead to a brute-force attack'
27 Aug 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'kmhlyxj0'
b'jdbc apache airflow provider code execution vulnerability'
26 Aug 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'kmhlyxj0'
b'odbc apache airflow provider code execution vulnerability'
26 Aug 2023
b'Glassdoor'
disclosed a bug submitted by
b'youstin'
b'Cache Poisoning allows redirection on JS files'
24 Aug 2023
b'LinkedIn'
disclosed a bug submitted by
b'tushar6378'
b'An Attacker Can Flag Draft Job Posts And Can Disclose The Draft Job Posts Details [ Similar to #1581528 Resolved Report]'
24 Aug 2023
b'LinkedIn'
disclosed a bug submitted by
b'find_me_here'
b'Attackers can use TRIAL Premium only by paying **IDR 10,000.00** from the original price of `IDR462,400.00` per month'
24 Aug 2023
b'LinkedIn'
disclosed a bug submitted by
b'tushar6378'
b'A Unverified User Can Post Newsletter (Which Is Not Allowed Through Application UI)'
24 Aug 2023
b'LinkedIn'
disclosed a bug submitted by
b'adilnbabras'
b"IDOR allows an attacker to delete anyone's featured photo."
24 Aug 2023
b'LinkedIn'
disclosed a bug submitted by
b'cybergoddess'
b'Improper access control on Linkedin Page'
24 Aug 2023
b'Uber'
disclosed a bug submitted by
b'lalit2020'
b"Complete Admin account takeover due to PhpDebugBar turned on in Uber's production server"
23 Aug 2023
1
...
47
48
49
50
51
...
717
BY DENIS WERNER - @NOBBD -
IMPRESSUM