REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'HackerOne'
disclosed a bug submitted by
b'what94'
b'Reverse Tabnabbing Vulnerability in Outgoing Links'
21 Nov 2017
b'Mail.Ru'
disclosed a bug submitted by
b'lincoln9932'
b'XSS ????? ????????? ??????.'
21 Nov 2017
b'Ubiquiti Networks'
disclosed a bug submitted by
b'kushal89shah'
b'Security: Publicly accessible x.509 Public and Private Key of Ubiquiti Networks.'
20 Nov 2017
b'Mail.Ru'
disclosed a bug submitted by
b'whitesector'
b'reflected XSS on healt.mail.ru'
20 Nov 2017
b'WordPress'
disclosed a bug submitted by
b'skansing'
b'Wordpress 4.7 - CSRF -> HTTP SSRF any private ip:port and basic-auth'
20 Nov 2017
b'Twitter'
disclosed a bug submitted by
b'segumarc'
b'Listing of Amazon S3 Bucket accessible to any amazon authenticated user (metrics.pscp.tv)'
19 Nov 2017
b'WordPress'
disclosed a bug submitted by
b'sikic'
b'Authenticated Cross-site Scripting in Template Name'
18 Nov 2017
b'Slack'
disclosed a bug submitted by
b'kamikaze'
b'Bypass two-factor authentication'
18 Nov 2017
b'Tor'
disclosed a bug submitted by
b'closer'
b'Access to local file system using javascript'
18 Nov 2017
b'HackerOne'
disclosed a bug submitted by
b'ashish_r_padelkar'
b'Pending member invitations are not revoked on program name change'
18 Nov 2017
b'HackerOne'
disclosed a bug submitted by
b'bigbug'
b"GraphQL sessions aren't immediately invalidated when user password is changed"
17 Nov 2017
b'TTS Bug Bounty'
disclosed a bug submitted by
b'muskecan'
b"2FA bypass - confirmation tokens don't expire"
17 Nov 2017
b'TTS Bug Bounty'
disclosed a bug submitted by
b'drough'
b'Error Page Content Spoofing or Text Injection'
17 Nov 2017
b'TTS Bug Bounty'
disclosed a bug submitted by
b'streaak2'
b'CSRF in generating a new Personal Key'
17 Nov 2017
b'Weblate'
disclosed a bug submitted by
b'110110110'
b'Improper validation of unicode characters '
17 Nov 2017
b'Grabtaxi Holdings Pte Ltd'
disclosed a bug submitted by
b'jouko'
b'www.drivegrab.com SQL injection'
17 Nov 2017
b'HackerOne'
disclosed a bug submitted by
b'clarckowen_'
b'Issue with password change in Disabled Account'
16 Nov 2017
b'HackerOne'
disclosed a bug submitted by
b'edio'
b'Additional bypass allows SSRF for internal netblocks'
16 Nov 2017
b'Automattic'
disclosed a bug submitted by
b'dutchgraa'
b'Persistent Cross-Site Scripting in WooCommerce WordPress plugin'
16 Nov 2017
b'WordPress'
disclosed a bug submitted by
b'dutchgraa'
b'WordPress core - Denial of Service via Cross Site Request Forgery'
16 Nov 2017
1
...
491
492
493
494
495
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM