Telegram Web Link
[doc.rt.informaticacloud.com] Reflected XSS via Stack Strace

πŸ‘‰ https://hackerone.com/reports/232320

πŸ”Ή Severity: High
πŸ”Ή Reported To: Informatica
πŸ”Ή Reported By: #bigbear_
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 23, 2022, 11:03am (UTC)
CVE-2022-27781: CERTINFO never-ending busy-loop

πŸ‘‰ https://hackerone.com/reports/1606039

πŸ”Ή Severity: Low | πŸ’° 480 USD
πŸ”Ή Reported To: Internet Bug Bounty
πŸ”Ή Reported By: #sybr
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 24, 2022, 7:31pm (UTC)
Node.js - DLL Hijacking on Windows

πŸ‘‰ https://hackerone.com/reports/1636566

πŸ”Ή Severity: High | πŸ’° 3,000 USD
πŸ”Ή Reported To: Internet Bug Bounty
πŸ”Ή Reported By: #yakirka
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 25, 2022, 6:30pm (UTC)
Race condition in faucet when using starport

πŸ‘‰ https://hackerone.com/reports/1438052

πŸ”Ή Severity: Critical | πŸ’° 5,000 USD
πŸ”Ή Reported To: Cosmos
πŸ”Ή Reported By: #cyberboy
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 26, 2022, 5:47pm (UTC)
HTML Injection via Email Share

πŸ‘‰ https://hackerone.com/reports/1490311

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: TikTok
πŸ”Ή Reported By: #lu3ky-13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 27, 2022, 1:46am (UTC)
Off-by-slash vulnerability in nodejs.org and iojs.org

πŸ‘‰ https://hackerone.com/reports/1650273

πŸ”Ή Severity: Medium | πŸ’° 1,200 USD
πŸ”Ή Reported To: Internet Bug Bounty
πŸ”Ή Reported By: #nagaro
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 28, 2022, 8:25am (UTC)
Acronis True Image Local Privilege Escalation Due To Race Condition In Application Verification

πŸ‘‰ https://hackerone.com/reports/1251464

πŸ”Ή Severity: High | πŸ’° 250 USD
πŸ”Ή Reported To: Acronis
πŸ”Ή Reported By: #vkas-afk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 28, 2022, 10:32am (UTC)
Hijack all emails sent to any domain that uses Cloudflare Email Forwarding

πŸ‘‰ https://hackerone.com/reports/1419341

πŸ”Ή Severity: Critical | πŸ’° 6,000 USD
πŸ”Ή Reported To: Cloudflare Public Bug Bounty
πŸ”Ή Reported By: #albertspedersen
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 28, 2022, 4:35pm (UTC)
πŸ”₯2
Twitter Account hijack through broken link in https://runpanther.io

πŸ‘‰ https://hackerone.com/reports/1607429

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Panther Labs
πŸ”Ή Reported By: #prakash142
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 28, 2022, 4:57pm (UTC)
Channel statistics up-to-date

πŸ₯‡Total awarded amount - πŸ’°2,994,628
πŸ₯ˆTotal bug reports - 3,350
πŸ₯‰Total reporters - 1,654

Reports counts by severity rating:

πŸ”΅ medium - 1333
🟠 high - 689
🟒 low - 659
πŸ”΄ critical - 359
🟀 none - 310

Top 10 participants by vulnerabilities found:

#skavans < 34 < πŸ’°68,911
#nyymi < 33 < πŸ’°21,320
#rtod < 33 < πŸ’°11,200
#jon_bottarini < 32 < πŸ’°36,773
#nagli < 31 < πŸ’°4,961
#luchua < 26 < πŸ’°47,700
#executor < 23 < πŸ’°9,100
#ihsinme < 22 < πŸ’°25,650
#lu3ky-13 < 21 < πŸ’°4,048
#d3lla < 20 < πŸ’°9,900

Top 10 teams by resolved reports:

Mail.ru > 305 > πŸ’°314,033
U.S. Dept Of Defense > 290 > πŸ’°8,000
GitHub Security Lab > 158 > πŸ’°203,750
Shopify > 139 > πŸ’°256,050
Nextcloud > 128 > πŸ’°20,575
GitLab > 97 > πŸ’°405,160
curl > 87 > πŸ’°16,700
New Relic > 82 > πŸ’°104,490
Acronis > 80 > πŸ’°12,837
HackerOne > 68 > πŸ’°63,501
πŸ‘6πŸ‘2πŸ”₯1
HTML Injection via TikTok Ads Email Share

πŸ‘‰ https://hackerone.com/reports/1376990

πŸ”Ή Severity: Medium | πŸ’° 1,000 USD
πŸ”Ή Reported To: TikTok
πŸ”Ή Reported By: #lu3ky-13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 28, 2022, 10:08pm (UTC)
@nextcloud/logger NPM package brings vulnerable ansi-regex version

πŸ‘‰ https://hackerone.com/reports/1607601

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #ro0telqayser
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2022, 10:18am (UTC)
Send Fax from Anyone's HelloFax Account Due to Misconfigured Email Validation

πŸ‘‰ https://hackerone.com/reports/1428385

πŸ”Ή Severity: High | πŸ’° 4,913 USD
πŸ”Ή Reported To: Dropbox
πŸ”Ή Reported By: #sayaanalam
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2022, 5:18pm (UTC)
Possible to make restricted files public on Phabricator via Diffusion

πŸ‘‰ https://hackerone.com/reports/1560717

πŸ”Ή Severity: No Rating | πŸ’° 2,000 USD
πŸ”Ή Reported To: Phabricator
πŸ”Ή Reported By: #dyls
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2022, 10:37pm (UTC)
Open redirection at https://smartreports.mtncameroon.net

πŸ‘‰ https://hackerone.com/reports/1530396

πŸ”Ή Severity: Low
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #vulnera
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2022, 1:38am (UTC)
Corsa Site Scripting Vulnerability (XSS)

πŸ‘‰ https://hackerone.com/reports/1650210

πŸ”Ή Severity: High
πŸ”Ή Reported To: Hyperledger
πŸ”Ή Reported By: #bhaskar_ram
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: July 30, 2022, 2:37pm (UTC)
Open S3 Bucket Accessible by any Aws User

πŸ‘‰ https://hackerone.com/reports/1654145

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: GoCD
πŸ”Ή Reported By: #khalidou
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 31, 2022, 3:02am (UTC)
Race condition on https://judge.me/people

πŸ‘‰ https://hackerone.com/reports/1566017

πŸ”Ή Severity: Low | πŸ’° 250 USD
πŸ”Ή Reported To: Judge.me
πŸ”Ή Reported By: #netboom
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 1, 2022, 5:28am (UTC)
πŸ‘1
Insecure use of shell.openExternal() in Rocket.Chat Desktop App leading to RCE

πŸ‘‰ https://hackerone.com/reports/924151

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Rocket.Chat
πŸ”Ή Reported By: #baltpeter
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 1, 2022, 10:17am (UTC)
delete the subaccount from the user id

πŸ‘‰ https://hackerone.com/reports/1646340

πŸ”Ή Severity: Medium | πŸ’° 700 USD
πŸ”Ή Reported To: Showmax
πŸ”Ή Reported By: #qualwin38000
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 1, 2022, 1:05pm (UTC)
2025/10/26 13:41:04
Back to Top
HTML Embed Code: