Host Header Injection Attack - www.xnxx.com
π https://hackerone.com/reports/1630073
πΉ Severity: No Rating
πΉ Reported To: XVIDEOS
πΉ Reported By: #cyber_anon
πΉ State: βͺοΈ Informative
πΉ Disclosed: November 8, 2022, 7:25pm (UTC)
π https://hackerone.com/reports/1630073
πΉ Severity: No Rating
πΉ Reported To: XVIDEOS
πΉ Reported By: #cyber_anon
πΉ State: βͺοΈ Informative
πΉ Disclosed: November 8, 2022, 7:25pm (UTC)
api keys leaked
π https://hackerone.com/reports/1762927
πΉ Severity: Medium
πΉ Reported To: Reddit
πΉ Reported By: #saibalajis6
πΉ State: βͺοΈ Informative
πΉ Disclosed: November 10, 2022, 2:40pm (UTC)
π https://hackerone.com/reports/1762927
πΉ Severity: Medium
πΉ Reported To: Reddit
πΉ Reported By: #saibalajis6
πΉ State: βͺοΈ Informative
πΉ Disclosed: November 10, 2022, 2:40pm (UTC)
sensitive data exposure
π https://hackerone.com/reports/1716249
πΉ Severity: High
πΉ Reported To: Reddit
πΉ Reported By: #saibalajis6
πΉ State: π΄ N/A
πΉ Disclosed: November 10, 2022, 2:41pm (UTC)
π https://hackerone.com/reports/1716249
πΉ Severity: High
πΉ Reported To: Reddit
πΉ Reported By: #saibalajis6
πΉ State: π΄ N/A
πΉ Disclosed: November 10, 2022, 2:41pm (UTC)
Business Suite "Get Leads" Resulting in Revealing User Email & Phone
π https://hackerone.com/reports/1744194
πΉ Severity: High | π° 5,500 USD
πΉ Reported To: TikTok
πΉ Reported By: #datph4m
πΉ State: π’ Resolved
πΉ Disclosed: November 10, 2022, 11:41pm (UTC)
π https://hackerone.com/reports/1744194
πΉ Severity: High | π° 5,500 USD
πΉ Reported To: TikTok
πΉ Reported By: #datph4m
πΉ State: π’ Resolved
πΉ Disclosed: November 10, 2022, 11:41pm (UTC)
Subdomain Takeover on delivey.yelp.com
π https://hackerone.com/reports/1715538
πΉ Severity: Low
πΉ Reported To: Yelp
πΉ Reported By: #racersaravanaa05
πΉ State: π΄ N/A
πΉ Disclosed: November 12, 2022, 3:49pm (UTC)
π https://hackerone.com/reports/1715538
πΉ Severity: Low
πΉ Reported To: Yelp
πΉ Reported By: #racersaravanaa05
πΉ State: π΄ N/A
πΉ Disclosed: November 12, 2022, 3:49pm (UTC)
Subdomain takeover at https://test.www.midigator.com
π https://hackerone.com/reports/1718371
πΉ Severity: High
πΉ Reported To: Equifax
πΉ Reported By: #valluvarsploit_h1
πΉ State: π’ Resolved
πΉ Disclosed: November 12, 2022, 4:05pm (UTC)
π https://hackerone.com/reports/1718371
πΉ Severity: High
πΉ Reported To: Equifax
πΉ Reported By: #valluvarsploit_h1
πΉ State: π’ Resolved
πΉ Disclosed: November 12, 2022, 4:05pm (UTC)
Admin can create a hidden admin account which even the owner can not detect and remove and do administrative actions on the application.
π https://hackerone.com/reports/1596663
πΉ Severity: High | π° 5,000 USD
πΉ Reported To: Reddit
πΉ Reported By: #41bin
πΉ State: π’ Resolved
πΉ Disclosed: November 14, 2022, 4:34am (UTC)
π https://hackerone.com/reports/1596663
πΉ Severity: High | π° 5,000 USD
πΉ Reported To: Reddit
πΉ Reported By: #41bin
πΉ State: π’ Resolved
πΉ Disclosed: November 14, 2022, 4:34am (UTC)
Open redirect at mc-beta-cloud-acronis.com
π https://hackerone.com/reports/846389
πΉ Severity: No Rating
πΉ Reported To: Acronis
πΉ Reported By: #angeltsvetkov
πΉ State: π’ Resolved
πΉ Disclosed: November 15, 2022, 9:49am (UTC)
π https://hackerone.com/reports/846389
πΉ Severity: No Rating
πΉ Reported To: Acronis
πΉ Reported By: #angeltsvetkov
πΉ State: π’ Resolved
πΉ Disclosed: November 15, 2022, 9:49am (UTC)
New /add_contacts /remove_contacts quick commands susseptible to XSS from Customer Contact firstname/lastname fields
π https://hackerone.com/reports/1578400
πΉ Severity: High | π° 13,950 USD
πΉ Reported To: GitLab
πΉ Reported By: #cryptopone
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 1:07am (UTC)
π https://hackerone.com/reports/1578400
πΉ Severity: High | π° 13,950 USD
πΉ Reported To: GitLab
πΉ Reported By: #cryptopone
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 1:07am (UTC)
XSS: `v-safe-html` is not safe enough
π https://hackerone.com/reports/1579645
πΉ Severity: High | π° 6,580 USD
πΉ Reported To: GitLab
πΉ Reported By: #yvvdwf
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 1:08am (UTC)
π https://hackerone.com/reports/1579645
πΉ Severity: High | π° 6,580 USD
πΉ Reported To: GitLab
πΉ Reported By: #yvvdwf
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 1:08am (UTC)
CSP-bypass XSS in project settings page
π https://hackerone.com/reports/1588732
πΉ Severity: High | π° 10,270 USD
πΉ Reported To: GitLab
πΉ Reported By: #yvvdwf
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 1:08am (UTC)
π https://hackerone.com/reports/1588732
πΉ Severity: High | π° 10,270 USD
πΉ Reported To: GitLab
πΉ Reported By: #yvvdwf
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 1:08am (UTC)
RCE via github import
π https://hackerone.com/reports/1672388
πΉ Severity: Critical | π° 33,510 USD
πΉ Reported To: GitLab
πΉ Reported By: #yvvdwf
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 1:10am (UTC)
π https://hackerone.com/reports/1672388
πΉ Severity: Critical | π° 33,510 USD
πΉ Reported To: GitLab
πΉ Reported By: #yvvdwf
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 1:10am (UTC)
Ability to bypass locked Cloudflare WARP on wifi networks.
π https://hackerone.com/reports/1635748
πΉ Severity: High | π° 1,000 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #joshatmotion
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 8:59am (UTC)
π https://hackerone.com/reports/1635748
πΉ Severity: High | π° 1,000 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #joshatmotion
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 8:59am (UTC)
[Git Gud] GitHub.com Svnbridge memcached deserialization vulnerability chain leading to Remote Code Execution
π https://hackerone.com/reports/1593913
πΉ Severity: Medium | π° 17,500 USD
πΉ Reported To: GitHub
πΉ Reported By: #ajxchapman
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 9:22pm (UTC)
π https://hackerone.com/reports/1593913
πΉ Severity: Medium | π° 17,500 USD
πΉ Reported To: GitHub
πΉ Reported By: #ajxchapman
πΉ State: π’ Resolved
πΉ Disclosed: November 16, 2022, 9:22pm (UTC)
CSRF in AppSearch allows creation of "curations"
π https://hackerone.com/reports/1477050
πΉ Severity: Medium | π° 833 USD
πΉ Reported To: Elastic
πΉ Reported By: #dee-see
πΉ State: π’ Resolved
πΉ Disclosed: November 17, 2022, 1:26pm (UTC)
π https://hackerone.com/reports/1477050
πΉ Severity: Medium | π° 833 USD
πΉ Reported To: Elastic
πΉ Reported By: #dee-see
πΉ State: π’ Resolved
πΉ Disclosed: November 17, 2022, 1:26pm (UTC)
Directory Listing at https://β.β.β.β
π https://hackerone.com/reports/1771051
πΉ Severity: Low
πΉ Reported To: 8x8
πΉ Reported By: #shuvam321
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 1:49am (UTC)
π https://hackerone.com/reports/1771051
πΉ Severity: Low
πΉ Reported To: 8x8
πΉ Reported By: #shuvam321
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 1:49am (UTC)
Default password on 34.120.209.175
π https://hackerone.com/reports/1415241
πΉ Severity: Medium | π° 245 USD
πΉ Reported To: Elastic
πΉ Reported By: #newspaper
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 8:14am (UTC)
π https://hackerone.com/reports/1415241
πΉ Severity: Medium | π° 245 USD
πΉ Reported To: Elastic
πΉ Reported By: #newspaper
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 8:14am (UTC)
LOGJ4 VUlnerability [HtUS]
π https://hackerone.com/reports/1624137
πΉ Severity: Critical | π° 1,000 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #fklet
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 6:07pm (UTC)
π https://hackerone.com/reports/1624137
πΉ Severity: Critical | π° 1,000 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #fklet
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 6:07pm (UTC)
Reflected XSS | https://ββββββββ
π https://hackerone.com/reports/1736433
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #x3ph_
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 6:33pm (UTC)
π https://hackerone.com/reports/1736433
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #x3ph_
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 6:33pm (UTC)
Reflected XSS | https://ββββ
π https://hackerone.com/reports/1736432
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #x3ph_
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 6:34pm (UTC)
π https://hackerone.com/reports/1736432
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #x3ph_
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 6:34pm (UTC)
IDOR on βββββββ [HtUS]
π https://hackerone.com/reports/1627974
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #nightm4re
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 6:36pm (UTC)
π https://hackerone.com/reports/1627974
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #nightm4re
πΉ State: π’ Resolved
πΉ Disclosed: November 18, 2022, 6:36pm (UTC)