HackerOne Bug Bounty Disclosure: csrf-to-delete-accounts-[htus]bynightm4re
Programme HackerOne U.S. Dept Of Defense U.S. Dept Of Defense Submitted by nightm4re nightm4re Report CSRF to delete accounts Full...
Programme HackerOne U.S. Dept Of Defense U.S. Dept Of Defense Submitted by nightm4re nightm4re Report CSRF to delete accounts Full...
Programme HackerOne WordPress WordPress Submitted by chip_sec chip_sec Report PII of users can be downloaded from export pages Full Report...
Programme HackerOne HackerOne HackerOne Submitted by iamr0000t iamr0000t Report HTML injection in email at https://www.hackerone.com/ Full Report A considerable...
Programme HackerOne GlassWire GlassWire Submitted by chip_sec chip_sec Report Facebook App API credentials leaked in the APK Full Report ...
Programme HackerOne LinkedIn LinkedIn Submitted by encodedguy encodedguy Report Delete any LinkedIn comment on learning API of other users Full...
Programme HackerOne LinkedIn LinkedIn Submitted by spaceboy20 spaceboy20 Report Attacker can unpin posts from companies he's not part of. Full...
Programme HackerOne LinkedIn LinkedIn Submitted by find_me_here find_me_here Report Attackers do not need to Pay for a Subscription to get...
Programme HackerOne IBM IBM Submitted by 0xpugazh 0xpugazh Report Moodle XSS on s-immerscio.comprehend.ibm.com Full Report A considerable amount of...
The below information is fully automated and the information is captured from the BugCrowd Disclosure website. The information was correct...
Programme HackerOne Mattermost Mattermost Submitted by uchihaluckycs uchihaluckycs Report Reset password link sent over unsecured http protocol Full Report ...
Programme HackerOne Brave Software Brave Software Submitted by ameenbasha ameenbasha Report download file type warning on Windows does not appear...
Programme HackerOne IBM IBM Submitted by gdattacker gdattacker Report Subdomain Takeover Affecting at vex.weather.com Full Report A considerable amount...
The below information is fully automated and the information is captured from the BugCrowd Disclosure website. The information was correct...
Programme HackerOne Elastic Elastic Submitted by lu3ky-13 lu3ky-13 Report blind Server-Side Request Forgery (SSRF) allows scanning internal ports Full Report...
Programme HackerOne Nextcloud Nextcloud Submitted by juliushaertl juliushaertl Report Hide download previews are accessible without a watermark Full Report ...
Programme HackerOne Nextcloud Nextcloud Submitted by meinereiner meinereiner Report App pin of the Android app can be bypassed via 3rdparty...
Programme HackerOne Ruby Ruby Submitted by leixiao leixiao Report Header CRLF Injection in Ruby Net::HTTP Full Report A considerable...
Programme HackerOne Nextcloud Nextcloud Submitted by nickvergessen nickvergessen Report Potential directory traversal in OC\Files\Node\Folder::getFullPath Full Report A considerable amount...
Programme HackerOne Nextcloud Nextcloud Submitted by juliushaertl juliushaertl Report Document content of files can be obtained through Collabora for files...
Programme HackerOne TD Bank TD Bank Submitted by def1ant def1ant Report Reflected XSS on marketsandresearch.td.com Full Report A considerable...
Programme HackerOne HackerOne HackerOne Submitted by datph4m datph4m Report Insecure Direct Object Reference (IDOR) - Delete Campaigns Full Report ...
Programme HackerOne Fastly VDP Fastly VDP Submitted by rubayet_hassan rubayet_hassan Report Unauthenticated cache purging Full Report A considerable amount...
Programme HackerOne Fastly VDP Fastly VDP Submitted by xerhakhd xerhakhd Report Cache purge requests are not authenticated Full Report ...
Programme HackerOne Nextcloud Nextcloud Submitted by brthnc brthnc Report Reference fetch can saturate the server bandwidth for 10 seconds Full...