| 1 |
Unauthorized access to █████████.com allows access to Uber Brazil tax documents and system. |
$4500.0 |
| 2 |
Account creation with invalid email addresses / email is accepting % and %0d%0a line termination chars |
$3750.0 |
| 3 |
Blind SSRF on errors.hackerone.net due to Sentry misconfiguration |
$3500.0 |
| 4 |
Changing email address on Twitter for Android unsets "Protect your Tweets" |
$2940.0 |
| 5 |
Periscope iOS app CSRF in follow action due to deeplink |
$2940.0 |
| 6 |
[m.airbnb.com] CRLF Injection |
$2500.0 |
| 7 |
Recursion causing uninitialized memory reads leading to a segfault |
$2000.0 |
| 8 |
Ability to publish a paid theme without purchasing it. |
$2000.0 |
| 9 |
Ability to publish a paid theme without purchasing it. |
$2000.0 |
| 10 |
Periscope android app deeplink leads to CSRF in follow action |
$1540.0 |
| 11 |
H1514 Get access to non public information by pivoting with graphql queries |
$1500.0 |
| 12 |
ubernycmarketplace.com is vulnerable to the Heartbleed Bug |
$1500.0 |
| 13 |
Bypassing domain deny_list rule in Smokescreen via trailing dot leads to SSRF |
$1500.0 |
| 14 |
url that twitter mobile site can not load |
$1120.0 |
| 15 |
Possible XSS Vulnerability in Action Controller |
$1068.0 |
| 16 |
HTML injection possible with soft email confirmations when Administrator manually confirms attacker email address |
$1060.0 |
| 17 |
Ability to perform various POST requests on quantopian.com as a different user - insecure by design. |
$1050.0 |
| 18 |
Crash: A call to Symbol.new leads to a crash when inspecting the resulting object |
$1000.0 |
| 19 |
Null pointer dereference regression in parse.y |
$1000.0 |
| 20 |
Segfault when passing invalid values to values_at |
$1000.0 |
| 21 |
Invalid memory write caused by incorrect upper bound in array_copy |
$1000.0 |
| 22 |
Incorrect code generation when result of NODE_NEGATE is not used |
$1000.0 |
| 23 |
Memory disclosure in timegm |
$1000.0 |
| 24 |
Segmentation fault while printing backtrace |
$1000.0 |
| 25 |
Mapbox Android SDK uses Broadcast Receiver instead of Local Broadcast Manager |
$1000.0 |
| 26 |
XSS on partners.uber.com due to no user input sanitisation |
$1000.0 |
| 27 |
Access to Employee calendar disclosing internal presentation and meetings |
$1000.0 |
| 28 |
Claiming package names in GitLab's automatic package referencer. |
$1000.0 |
| 29 |
All functions that allow users to specify color code are vulnerable to ReDoS |
$1000.0 |
| 30 |
DoS attack via comment on Issue |
$1000.0 |
| 31 |
Private System Note Disclosure using GraphQL |
$1000.0 |
| 32 |
Adds CodeQL query to check for insecure RequestValidationMode in ASP.NET |
$1000.0 |
| 33 |
CodeQL query to detect pages with validationRequest disabled |
$1000.0 |
| 34 |
CodeQL query to detect insecure MaxLengthRequest values in ASP.NET applications |
$1000.0 |
| 35 |
CodeQL query for finding ReDoS and Regex Injection vulnerabilities in Java |
$1000.0 |
| 36 |
No redirect_uri in the db for web-internal clientKey leads to one-click DoS on gitter.im |
$1000.0 |
| 37 |
Java: CWE-798 - Hardcoded AWS credentials |
$1000.0 |
| 38 |
xss stored in https://your store.myshopify.com/admin/ |
$1000.0 |
| 39 |
Cache poisoning via X-Forwarded-Host in www.shopify.com/partners/blog |
$1000.0 |
| 40 |
Instant open redirect on Live preview WEB Ide opening |
$1000.0 |
| 41 |
ihsinme: CPP Add query for CWE-14 compiler removal of code to clear buffers. |
$1000.0 |
| 42 |
ihsinme: CPP add query for CWE-788 Access of memory location after the end of a buffer using strlen. |
$1000.0 |
| 43 |
ihsinme: CPP add query for: CPP Add query for CWE-20 Improper Input Validation |
$1000.0 |
| 44 |
Chained vulnerabilities create DOS attack against users on desafio5estrelas.com |
$1000.0 |
| 45 |
[Java] CWE-759: Query to detect password hash without a salt |
$1000.0 |
| 46 |
[Java] CWE-1004: Query to check sensitive cookies without the HttpOnly flag set |
$1000.0 |
| 47 |
ihsinme: CPP Add query for CWE-691 Insufficient Control Flow Management When Using Bit Operations |
$1000.0 |
| 48 |
[GO] CWE-1004: Sensitive cookie without HttpOnly |
$1000.0 |
| 49 |
[JavaScript]: CWE-1004: Sensitive cookie without HttpOnly |
$1000.0 |
| 50 |
[C#]: HttpOnly and Secure Cookies for .NET Core and .NET |
$1000.0 |
| 51 |
HackerOne Staging uses Production data for testing |
$1000.0 |
| 52 |
ihsinme: CPP Add query for CWE-675 Duplicate Operations on Resource |
$1000.0 |
| 53 |
CPP: Add query for CWE-377 Insecure Temporary File |
$1000.0 |
| 54 |
[Java]: Timing attacks while comparing the headers value |
$1000.0 |
| 55 |
ihsinme: CPP Add a query to find incorrectly used exceptions. |
$1000.0 |
| 56 |
[python]: Zip Slip Vulnerability |
$1000.0 |
| 57 |
CPP: Add query for CWE-243 Creation of chroot Jail Without Changing Working Directory |
$1000.0 |
| 58 |
[Java]: CWE-625 - Query to detect regex dot bypass |
$1000.0 |
| 59 |
[CPP]: Add query for CWE-125 Out-of-bounds Read with different interpretation of the string when use mbtowc |
$1000.0 |
| 60 |
[CPP]Add query to detect bugs like CVE-2017-5123 |
$1000.0 |
| 61 |
[Go]: Add Beego.Input.RequestBody source to Beego framework |
$1000.0 |
| 62 |
Bypass parsing of transaction data, users on the phishing site will transfer/approve ERC20 tokens without being alerted |
$1000.0 |
| 63 |
JavaScript: Add some new XSS sinks and sources of Next.js (and some extra improvements) |
$1000.0 |
| 64 |
CPP: Add query for CWE-369: Divide By Zero. |
$1000.0 |
| 65 |
staffOrderNotificationSubscriptionCreate Is Not Blocked Entirely From Staff Member With Settings Permission |
$900.0 |
| 66 |
Ability to Disable the Login Attempt of any Shopify Owner for 24 hrs (Zero_Click) |
$900.0 |
| 67 |
Bypass of fix #1370749 |
$900.0 |
| 68 |
[h1-2102] HTML injection in packing slips can lead to physical theft |
$900.0 |
| 69 |
Shop App - Attacker is able to intercept authorization code during authentication (OAuth) and is able to get access to Microsoft Outlook email account |
$900.0 |
| 70 |
Attacker is able to query Github repositories of arbitrary Shopify Hydrogen Users |
$900.0 |
| 71 |
Heap Overflow in mrb_arb_splice |
$800.0 |
| 72 |
Heap Buffer overflow in mrb_funcall_with_block |
$800.0 |
| 73 |
Null pointer dereference in mrb_class |
$800.0 |
| 74 |
Null pointer dereference in mark_context_stack |
$800.0 |
| 75 |
Use-after-free leading to an invalid pointer dereference |
$800.0 |
| 76 |
Null pointer dereference in ary_concat |
$800.0 |
| 77 |
Null pointer dereference in mrb_class |
$800.0 |
| 78 |
Null pointer dereference in OP_ENTER |
$800.0 |
| 79 |
Invalid pointer dereference in OP_ENTER |
$800.0 |
| 80 |
Invalid read leading to a segfault |
$800.0 |
| 81 |
CVE-2021-22897: schannel cipher selection surprise |
$800.0 |
| 82 |
Shopify.com Web Cache Deception vulnerability leads to personal information and CSRF tokens leakage |
$800.0 |
| 83 |
Orders full read for a staff with only Customers permissions. |
$800.0 |
| 84 |
IE 11 Self-XSS on Jira Integration Preview Base Link |
$750.0 |
| 85 |
Access to SQL server of ubergreen.pt through password disclosure from different domain on same IP |
$750.0 |
| 86 |
Default Nextcloud Server and Android Client leak sharee searches to Nextcloud |
$750.0 |
| 87 |
XSS in Desktop Client in the notifications |
$750.0 |
| 88 |
XSS in www.shopify.com/markets?utm_source= |
$700.0 |
| 89 |
Guest Users can create issues for Sentry errors and track their status |
$610.0 |
| 90 |
IDOR to delete images from other stores |
$600.0 |
| 91 |
Staff with no permissions could possibly list and accept billing promotions |
$600.0 |
| 92 |
PUT Based CSRF via Client Side Path Traversal + Cookie Bomb on Acronis Cloud |
$600.0 |
| 93 |
Twitter for android is exposing user's location to any installed android app |
$560.0 |
| 94 |
Protected Tweets setting overridden by Android app |
$560.0 |
| 95 |
Wrong Interpretation of URL encoded characters, showing different punny code leads to redirection on different domain |
$560.0 |
| 96 |
Safe Redirect Bypass |
$560.0 |
| 97 |
Delete direct message history without access the proper conversation_id |
$560.0 |
| 98 |
Usage of disabled protocol in curl |
$560.0 |
| 99 |
CVE-2024-2379: QUIC certificate check bypass with wolfSSL |
$560.0 |
| 100 |
unsanitized input goes to regex function leads to ReDos that make request hangs |
$540.0 |
| 101 |
CVE-2023-40273: Session fixation in Apache Airflow web interface |
$540.0 |
| 102 |
Regular Expression Denial of Service (ReDoS) Vulnerability before 2.6.3 |
$540.0 |
| 103 |
Apache Airflow path traversal by authenticated user |
$540.0 |
| 104 |
CVE-2023-42663: Apache Airflow: Bypass permission verification to view task instances of other dags |
$540.0 |
| 105 |
[CVE-2023-38546] cookie injection with none file |
$540.0 |
| 106 |
CVE-2023-42780: Apache Airflow: Improper access control vulnerability in the "List dag warnings" feature |
$540.0 |
| 107 |
Pickle deserialization vulnerability in XComs |
$540.0 |
| 108 |
Command Injection using malicious hostname in expanded proxycommand |
$540.0 |
| 109 |
Apache Airflow: Bypass permission verification to read code of other dags |
$540.0 |
| 110 |
jdbc apache airflow provider code execution vulnerability |
$520.0 |
| 111 |
Bypass User Interaction to initiate a VoIP call to Another User |
$500.01 |
| 112 |
RXSS at image.hackerone.live via the url parameter |
$500.01 |
| 113 |
Type confusion in FutureIter_throw() which may potentially lead to an arbitrary code execution |
$500.0 |
| 114 |
Write out-of-bounds at number_format |
$500.0 |
| 115 |
memcpy negative size parameter in php_resolve_path |
$500.0 |
| 116 |
memcpy negative parameter _bc_new_num_ex |
$500.0 |
| 117 |
Invalid parameter in memcpy function trough openssl_pbkdf2 |
$500.0 |
| 118 |
Unsafe arithmetic in PyString_DecodeEscape |
$500.0 |
| 119 |
Escape sequence injection in "summary" field |
$500.0 |
| 120 |
SVG Server Side Request Forgery (SSRF) |
$500.0 |
| 121 |
Self-XSS in password reset functionality |
$500.0 |
| 122 |
Common response suggestion is sent to Google Analytics when user accepts duplicate comment Genius suggestion |
$500.0 |
| 123 |
ImageMagick GIF coder vulnerability leading to memory disclosure |
$500.0 |
| 124 |
Order notifications being sent for a deactivated staff account |
$500.0 |
| 125 |
Email Forwarding invitations for Drafts are not marked as accepted, allowing multiple users to join a program after disabling Email Forwarding |
$500.0 |
| 126 |
Improper access check by Kit leads to controlling attributes of store & getting analytics by deleted Store member via dual messenger A/C |
$500.0 |
| 127 |
People who interviewed for HackerOne security analyst position can be enumerated and their personal email address may be exposed |
$500.0 |
| 128 |
Hacktivity of a private program visible to banned user if he gets invited to a program by hackbot |
$500.0 |
| 129 |
Suspended users can bypass UGC upload ban |
$500.0 |
| 130 |
Stored XSS on buy button |
$500.0 |
| 131 |
Race condition at create new Location |
$500.0 |
| 132 |
User with privilege to maintain External Programs can update certain churned HackerOne programs |
$500.0 |
| 133 |
PII disclosure -- Past team members & their email ID(personal email) can be viewed by Staff member with no permissions on Partner Dashboard |
$500.0 |
| 134 |
Open Redirect in riders.uber.com |
$500.0 |
| 135 |
Hacker can request mediation for published reports |
$500.0 |
| 136 |
Notifications sent due to "Transfer report" functionality may be sent to users who are no longer authorized to see the report |
$500.0 |
| 137 |
Inline banner on Report page discloses whether organization runs a private program |
$500.0 |
| 138 |
Submitting report through Embedded Submission form gives user indefinite access to a profile |
$500.0 |
| 139 |
Response program can create bounty table |
$500.0 |
| 140 |
Deleting other people's comments on ModeratorMessages |
$500.0 |
| 141 |
Response program can display "eligible for bounty" in scope area in program policy |
$500.0 |
| 142 |
Cross-site Scripting (XSS) on HackerOne careers page |
$500.0 |
| 143 |
DOM Based XSS in www.hackerone.com via PostMessage |
$500.0 |
| 144 |
POST-based XSS on apps.shopify.com |
$500.0 |
| 145 |
Using GraphQL, STAFF with NO explicit permissions on Store can retrieve Shopify Payments Balance. |
$500.0 |
| 146 |
SSRF in hatchful.shopify.com |
$500.0 |
| 147 |
Invited team member can disclosure slack channels |
$500.0 |
| 148 |
H1514 Ability to Edit Packaging Slip Templates and View Product & Shipping Information by a low privileged staff in a Sandbox Store |
$500.0 |
| 149 |
H1514 Lack of access control on edit packing slip template |
$500.0 |
| 150 |
Order Creation Webhooks can be edited/deleted by STAFF with Settings only permission |
$500.0 |
| 151 |
Account recovery text message is sending a wrong domain to users. |
$500.0 |
| 152 |
Unpublished Product Images can be disclosed |
$500.0 |
| 153 |
XSS on services.shopify.com |
$500.0 |
| 154 |
STAFF member with NO Explicit permissions can view ActivityFeed via GraphQL |
$500.0 |
| 155 |
DOM XSS via Shopify.API.Modal.initialize |
$500.0 |
| 156 |
Disclosing a private program in an external link if program is paused |
$500.0 |
| 157 |
[Privilege Escalation] Shopify Admin -- Permission from Settings to Customer |
$500.0 |
| 158 |
Bypass of biometrics security functionality is possible in Android application (com.shopify.mobile) |
$500.0 |
| 159 |
Inject page in admin panel via Shopify.API.pushState |
$500.0 |
| 160 |
Windows builds with insecure path defaults (CVE-2019-1552) |
$500.0 |
| 161 |
Disclosure of Email title report in quick award paypout email (no content mode) |
$500.0 |
| 162 |
stack-buffer-overflow through "ResourceBundle" methods |
$500.0 |
| 163 |
Illegal write access through Locale methods |
$500.0 |
| 164 |
imagecropauto out-of-bounds access |
$500.0 |
| 165 |
Illegal write/read access caused by gdImageAALine overflow |
$500.0 |
| 166 |
Urllib connects to a wrong host |
$500.0 |
| 167 |
Use-after-free in _asyncio_Future_remove_done_callback |
$500.0 |
| 168 |
Incorrect GC behavior in xxlimited could lead to use-after-free |
$500.0 |
| 169 |
Inappropriately parsing HTTP response leads to PHP segment fault! |
$500.0 |
| 170 |
NULL pointer dereference in SimpleXMLElement::asXML() |
$500.0 |
| 171 |
crash in openssl_random_pseudo_bytes function |
$500.0 |
| 172 |
crash in gzcompress and 3 other compress functions |
$500.0 |
| 173 |
missing NULL check in dom_document_save_html |
$500.0 |
| 174 |
heap overflow in php_ereg_replace function |
$500.0 |
| 175 |
crash in implode() function |
$500.0 |
| 176 |
iconv() function missing string length check |
$500.0 |
| 177 |
crash in bzcompress function |
$500.0 |
| 178 |
crash in get_icu_value_internal function |
$500.0 |
| 179 |
crash in locale_get_keywords() when keyword value in locale string too long |
$500.0 |
| 180 |
another crash in locale_get_keywords function |
$500.0 |
| 181 |
Invalid memory access in zend_strtod() function |
$500.0 |
| 182 |
crash in simplestring_addn function |
$500.0 |
| 183 |
Invalid memory access in spl_filesystem_dir_open function |
$500.0 |
| 184 |
Invalid memory access in php_basename function |
$500.0 |
| 185 |
Invalid memory access in spl_filesystem_info_set_filename function |
$500.0 |
| 186 |
crash in locale_compose() function |
$500.0 |
| 187 |
php_snmp_parse_oid integer overflow in memory allocation |
$500.0 |
| 188 |
Team object in GraphQL disclosed of private programs via the industry |
$500.0 |
| 189 |
XSS on product comments in transfers |
$500.0 |
| 190 |
Stored XSS in Shopify Chat |
$500.0 |
| 191 |
CodeQL query to detect weak (duplicated) encryption keys for ASP.NET Telerik Upload |
$500.0 |
| 192 |
Total Paid Bounty Paid can be disclose |
$500.0 |
| 193 |
Timeline Editor Self-XSS (Previous Fix #738072 Incomplete) |
$500.0 |
| 194 |
None permission staff member can identify installed application and products attached to it |
$500.0 |
| 195 |
duplicate hsts headers lead to firefox ignoring hsts on business.uber.com |
$500.0 |
| 196 |
Reflected XSS on www.hackerone.com and resources.hackerone.com |
$500.0 |
| 197 |
Disclosure of the name of a program that has a private part with an external link |
$500.0 |
| 198 |
Java: CWE-532 sensitive info logging |
$500.0 |
| 199 |
Login CSRF vulnerability on hackerone.com |
$500.0 |
| 200 |
Pentester can obtain information about other pentesters who applied for the same test, but weren't accepted |
$500.0 |
| 201 |
EXIF metadata not stripped from JPG group logos |
$500.0 |
| 202 |
Staff member with no permission can delete POS staff from account settings |
$500.0 |
| 203 |
Reflected XSS on www.hackerone.com via Wistia embed code |
$500.0 |
| 204 |
Potential HTTP Request Smuggling in ruby webrick |
$500.0 |
| 205 |
Uninstalling Slack for Windows (64-bit), then reinstalling keeps you logged in without authentication |
$500.0 |
| 206 |
[Admin Panel] CSRF to resume/pause runner |
$500.0 |
| 207 |
The hacker has access to the administrative part of the management reports in publish report |
$500.0 |
| 208 |
CodeQL query to detect SSRF in Python |
$500.0 |
| 209 |
Inject page in admin panel via Shopify.API.pushState with protocol invalid |
$500.0 |
| 210 |
Inject page in admin panel via Shopify.API.pushState [New Payload] |
$500.0 |
| 211 |
View the Starred Projects in a Private Profile |
$500.0 |
| 212 |
Stored XSS в выборе метки на странице списка заказов. |
$500.0 |
| 213 |
Dangling cloud instance at vpn.inverselink.com |
$500.0 |
| 214 |
Open AWS S3 bucket at ubergreece.s3.amazonaws.com exposes confidential internal documents and files |
$500.0 |
| 215 |
Stored XSS при удалении группы из беседы (m.vk.com) |
$500.0 |
| 216 |
"Bounty splitting enabled" can discloses if public VDPs are running private VRP |
$500.0 |
| 217 |
ihsinme: CPP Add query for CWE-691 Insufficient Control Flow Management After Refactoring The Code |
$500.0 |
| 218 |
Private program disclosure of ██████████ through notifications |
$500.0 |
| 219 |
File drop public link can also be converted to federated share |
$500.0 |
| 220 |
Report Bulk endpoint "agree-on-going-public" action may reveal Report disclosure state for invite-only programs |
$500.0 |
| 221 |
lib/net/ftp.rb: trusting PASV responses allow client abuse |
$500.0 |
| 222 |
An invite-only's program submission state is accessible to users no longer part of the program |
$500.0 |
| 223 |
Private program disclosure through notifications |
$500.0 |
| 224 |
Tab nabbing in Hackerone inbox. |
$500.0 |
| 225 |
XSS в сюжетах. |
$500.0 |
| 226 |
XSS в выборе товара. |
$500.0 |
| 227 |
Ability to add address without being an admin or staff in the store via wholesale store |
$500.0 |
| 228 |
Cross site scripting via file upload in subdomain ads.tiktok.com |
$500.0 |
| 229 |
staffOrderNotificationSubscriptionDelete Could Be Used By Staff Member With Settings Permission |
$500.0 |
| 230 |
Bypass For #997350 your-store.myshopify.com preview link is leak on third party website Via Online Store |
$500.0 |
| 231 |
[h1-2102] Break permissions waterfall |
$500.0 |
| 232 |
Private invitation links/tokens leak to third-party analytics site |
$500.0 |
| 233 |
URL Scheme misconfiguration on TikTok for IOS |
$500.0 |
| 234 |
Clickjacking Vulnerability Can Leads To Delete Developer APP |
$500.0 |
| 235 |
[CPP]: Add query for CWE-190: Integer Overflow or Wraparound when using transform after operation |
$500.0 |
| 236 |
[Java] CWE-016: Query to detect insecure configuration of Spring Boot Actuator |
$500.0 |
| 237 |
Clickjacking Vulnerability In Whole Page Ads Tiktok |
$500.0 |
| 238 |
Theme editor oseid parameter is leaked to third-party services through the Referer header which leads to somekind of storefront password bypass. |
$500.0 |
| 239 |
IDOR in report download functionality on ads.tiktok.com |
$500.0 |
| 240 |
IDOR on TikTok Seller |
$500.0 |
| 241 |
CSRF in Changing User Verification Email |
$500.0 |
| 242 |
HTML Injection in email via Name field |
$500.0 |
| 243 |
Local applications from user's computer can listen for webhooks via insecure gRPC server from stripe-cli |
$500.0 |
| 244 |
Stored XSS Payload when sending videos |
$500.0 |
| 245 |
Race condition in joining CTF group |
$500.0 |
| 246 |
HackerOne Undisclosed Report Leak via PoC of Full Disclosure on Hacktivity |
$500.0 |
| 247 |
Verifying email bypass |
$500.0 |
| 248 |
adding h1_analyst_* to username for normal users |
$500.0 |
| 249 |
HTML injection on newsroom.snap.com/* via search?q=1 |
$500.0 |
| 250 |
Reflected XSS on help.shopify.com |
$500.0 |
| 251 |
No Session Expiry after log-out, attacker can reuse the old cookies |
$500.0 |
| 252 |
Ability to bulk submit reports via query named based batching |
$500.0 |
| 253 |
CVE-2024-41937: Apache Airflow: Stored XSS Vulnerability on provider link |
$497.0 |
| 254 |
Unbounded memory growth with session handling in TLSv1.3 |
$497.0 |
| 255 |
Renderers can obtain access to random bluetooth device without permission |
$480.0 |
| 256 |
CVE-2022-27775: Bad local IPv6 connection reuse |
$480.0 |
| 257 |
CVE-2022-27776: Auth/cookie leak on redirect |
$480.0 |
| 258 |
CVE-2022-32205: Set-Cookie denial of service |
$480.0 |
| 259 |
CVE-2022-32208: FTP-KRB bad message verification |
$480.0 |
| 260 |
rubygems.org Batching attack to confirmation_token by bypass rate limit |
$480.0 |
| 261 |
Leak of sensitive values to Airflow rendered template |
$480.0 |
| 262 |
CVE-2023-23915: HSTS amnesia with --parallel |
$480.0 |
| 263 |
CVE-2023-23914: HSTS ignored on multiple requests |
$480.0 |
| 264 |
CVE-2023-27533: TELNET option IAC injection |
$480.0 |
| 265 |
CVE-2023-27534: SFTP path ~ resolving discrepancy |
$480.0 |
| 266 |
CVE-2023-27536: GSS delegation too eager connection re-use |
$480.0 |
| 267 |
CVE-2023-25692: Apache Airflow Google Provider: Google Cloud Sql Provider Denial Of Service and Remote Command Execution |
$480.0 |
| 268 |
CVE-2023-27538: SSH connection too eager reuse still |
$480.0 |
| 269 |
Possible DoS Vulnerability in Multipart MIME parsing in rack |
$480.0 |
| 270 |
CVE-2023-28320 - siglongjmp race condition |
$480.0 |
| 271 |
[CVE-2023-22799] Possible ReDoS based DoS vulnerability in GlobalID |
$480.0 |
| 272 |
[CVE-2023-22796] Possible ReDoS based DoS vulnerability in Active Support’s underscore |
$480.0 |
| 273 |
[CVE-2022-44572] Possible Denial of Service Vulnerability in Rack’s RFC2183 boundary parsing |
$480.0 |
| 274 |
[CVE-2022-44571] Possible Denial of Service Vulnerability in Rack Content-Disposition parsing |
$480.0 |
| 275 |
[CVE-2022-44570] Possible Denial of Service Vulnerability in Rack’s Range header parsing |
$480.0 |
| 276 |
Reflected XSS in error pages (NC-SA-2017-008) |
$450.0 |
| 277 |
Ability to bruteforce mopub account’s password due to lack of rate limitation protection using {ip rotation techniques} |
$420.0 |
| 278 |
Proxy-Authorization header not cleared on cross-origin redirect in undici.request |
$420.0 |
| 279 |
Cookie headers are not cleared in cross-domain redirect in undici-fetch |
$405.0 |
| 280 |
Proxy-Authorization header is not cleared in cross-domain redirect in undici |
$405.0 |
| 281 |
Open Redirect (verkkopalvelu.lahitapiola.fi) |
$400.0 |
| 282 |
Уязвимость приватных записей пользователя (личных) |
$400.0 |
| 283 |
[com.exness.android.pa Android] Universal XSS in webview. Lead to steal user cookies |
$400.0 |
| 284 |
Unclaimed official s3 bucket of tendermint(tendermint-packages) which is used by many other blockchain companies in their code |
$400.0 |
| 285 |
Control Character Injection In Messages |
$350.0 |
| 286 |
Profile bio at rockstar is accepting control characters |
$350.0 |
| 287 |
Invitation reminder emails contain insecure links |
$350.0 |
| 288 |
Default settings leak federated cloud id to lookup server of all users |
$350.0 |
| 289 |
Privilege escalation to root in Pages build image v2 |
$350.0 |
| 290 |
User with only Viewing Privilege can send message to Room |
$300.0 |
| 291 |
Garbage collector crash |
$300.0 |
| 292 |
use of unsafe host header leads to open redirect |
$300.0 |
| 293 |
Limitation of app specific password scope can be bypassed (NC-SA-2017-009) |
$300.0 |
| 294 |
Window.opener fix bypass |
$300.0 |
| 295 |
Open Redirection Vulnerability in m.vk.com |
$300.0 |
| 296 |
Уязвимость дает возможность видеть записи , которые предлагаются пабликам + еще |
$300.0 |
| 297 |
Просмотр приватных видео записей у Пользователей |
$300.0 |
| 298 |
Phishing user to download malicious app could lead to leakage of User Access Token, Email, Name and Profile photo via exported RemoteService |
$300.0 |
| 299 |
Exposing voting results on the Slowvote application without actually voting |
$300.0 |
| 300 |
Snippet JS template allows attacker to read a user's private snippets |
$300.0 |
| 301 |
XSS in vk.link |
$300.0 |
| 302 |
Open Redirect и подмена ссылки в сниппете приложения VKMA |
$300.0 |
| 303 |
Open redirect в карусели сообщения бота |
$300.0 |
| 304 |
Просмотр аватарки замороженной страницы/частной группы. |
$300.0 |
| 305 |
Open redirect bypass |
$300.0 |
| 306 |
Mystery with a leaked token and Reusability of email confirmation link leading to Account Takeover |
$300.0 |
| 307 |
iOS group chat denial of service |
$300.0 |
| 308 |
Operation CreateOrUpdateSo5LineupMutation does not restrict multiple captains |
$300.0 |
| 309 |
HTML Injection in email /webApp/lahti (viestinta.lahitapiola.fi) |
$264.0 |
| 310 |
HTML Injection in email from http://www.lahitapiola.fi/henkilo/sivut/tonttutesti |
$264.0 |
| 311 |
Open Redirect |
$258.0 |
| 312 |
DOM XSS vulnerability in search dialogue (NC-SA-2017-007) |
$250.0 |
| 313 |
Control characters incorrectly handled on Crew Status Update |
$250.0 |
| 314 |
CSRF in REPORT EMOTICON feature |
$250.0 |
| 315 |
Stats Token doesn't expire after deactivating account |
$250.0 |
| 316 |
[theacademy.upserve.com] Reflected XSS Query-String |
$250.0 |
| 317 |
Open redirect on chaturbate.com (tipping/purchase_success) |
$250.0 |
| 318 |
Open redirect vulnerability |
$250.0 |
| 319 |
DOM based CSS Injection on grammarly.com |
$250.0 |
| 320 |
Username and Access Token Disclousure |
$250.0 |
| 321 |
URL link spoofing |
$250.0 |
| 322 |
FileZilla 3.46.3 - 'Scale factor' Buffer Overflow |
$250.0 |
| 323 |
Java: CWE-918 - Server Side Request Forgery (SSRF) |
$250.0 |
| 324 |
[Java]: CWE-523 Insecure HSTS configuration |
$250.0 |
| 325 |
Potential HTTP Request Smuggling in nodejs |
$250.0 |
| 326 |
Slowloris, body parsing |
$250.0 |
| 327 |
End to end encryption folder locking is not properly protected |
$250.0 |
| 328 |
CSRF when unlocking lenses leads to lenses being forcefully installed without user interaction |
$250.0 |
| 329 |
Password reset link not expiring after changing password in settings |
$250.0 |
| 330 |
Brute Force against VMware Horizon |
$250.0 |
| 331 |
Open Redirect |
$250.0 |
| 332 |
Clients do not verify server public key |
$250.0 |
| 333 |
Cross-site leak allows attacker to de-anonymize members of his team from another origin |
$250.0 |
| 334 |
Yet another SSRF query for Javascript |
$250.0 |
| 335 |
Yet another SSRF query for Javascript |
$250.0 |
| 336 |
Uninstalling Rockstar Games Launcher for Windows (64-bit), then reinstalling keeps you logged in without authentication |
$250.0 |
| 337 |
Email html Injection |
$250.0 |
| 338 |
Notification implicit PendingIntent in com.nextcloud.client allows to access contacts |
$250.0 |
| 339 |
Email address disclosure via invite token validatiion |
$250.0 |
| 340 |
Sign in with Apple generates long-life JWTs, seemingly irrevocable, that grant immediate access to accounts |
$250.0 |
| 341 |
Race condition on https://judge.me/people |
$250.0 |
| 342 |
Unrestricted File Upload Blind Stored Xss in subdomain ads.tiktok.com |
$250.0 |
| 343 |
Access to arbitrary file of the Nextcloud Android app from within the Nextcloud Android app |
$250.0 |
| 344 |
SSRF via potential filter bypass with too lax local domain checking |
$250.0 |
| 345 |
Bypass two-factor authentication |
$250.0 |
| 346 |
cd=false (DNSSEC) not respected in DNS over HTTPS JSON requests |
$250.0 |
| 347 |
[Broken Access Control ] Unauthorized Linking accounts & Linked Accounts info DIsclosure |
$250.0 |
| 348 |
internal dev tokens disclosure |
$250.0 |
| 349 |
Text does not respect 'Allow download' permissions |
$250.0 |
| 350 |
HTML Injection on TikTok Ads |
$250.0 |
| 351 |
Bypassing x profile verification to receive instant blue checkmark and unlimited profile changes |
$250.0 |
| 352 |
"urllib" will result to deny of service |
$240.0 |
| 353 |
Authentication Issue |
$200.0 |
| 354 |
Heap use-after-free during range creation |
$200.0 |
| 355 |
reports.breadcrumb.com is vulnerable for Arbitrary file existence disclosur CVE-2014-7829 |
$200.0 |
| 356 |
Leak of Platform Authentication credentials via Repeater |
$200.0 |
| 357 |
Unrestricted POST request size on roomlogin endpoint |
$200.0 |
| 358 |
View Failed Approval and Pending videos other users |
$200.0 |
| 359 |
[0.vk.com] Reflected XSS на странице подтверждения. |
$200.0 |
| 360 |
Просмотр инфы на странице пользователя или группы который тебя добавил в ЧС |
$200.0 |
| 361 |
CVE-2019-5436: Heap Buffer Overflow at lib/tftp.c |
$200.0 |
| 362 |
Open redirect protection (https://www.pixiv.net/jump.php) is broken for novels |
$200.0 |
| 363 |
Potential buffer overflow in demoplayer module of GoldSource Engine |
$200.0 |
| 364 |
Circle email-members have still access to a shared folder/file after they are removed from the circle |
$200.0 |
| 365 |
Pixel Flood Attack leads to Application level DoS |
$200.0 |
| 366 |
Open Redirect at https://oauth.secure.pixiv.net |
$200.0 |
| 367 |
Получение стикеров |
$200.0 |
| 368 |
Api Token Leaked in [shoppers.shipt.com] |
$200.0 |
| 369 |
Wrong Url in Main Page |
$200.0 |
| 370 |
A profile page of a user can be denied from loading by appending .html to the username |
$200.0 |
| 371 |
WordPress Plugin Update Confusion at trafficfactory.com |
$200.0 |
| 372 |
CRLF Injection - Http Response Splitting |
$200.0 |
| 373 |
com.nextcloud.client bypass the protection lock in andoid app v 3.18.1 latest version. |
$200.0 |
| 374 |
Fix : (Security) Mitigate Path Traversal Bug |
$200.0 |
| 375 |
Subdomain Takeover via Unclaimed Amazon S3 Bucket (Musical.ly) |
$200.0 |
| 376 |
Domain Takeover - gl-canary.freetls.fastly.net |
$200.0 |
| 377 |
Cleartext Transmission of password via Email |
$200.0 |
| 378 |
Calendar and addressbook names disclosed (NC-SA-2017-012) |
$183.0 |
| 379 |
Bypassing authorization of linked Instagram account |
$170.0 |
| 380 |
User Able to Reopen a Ticket by Modify the Request |
$169.0 |
| 381 |
Attacker can read password from log data |
$168.68 |
| 382 |
Creating arbitrary cookies values /cs/CookieServer (www.lahitapiola.fi) |
$150.0 |
| 383 |
The Federalsit session cookie (federalist.sid) is not properly invalidated - backdoor access to the account is possible |
$150.0 |
| 384 |
Race condition on the Federalist API endpoints can lead to the Denial of Service attack |
$150.0 |
| 385 |
Information disclosure (system username) in the x-amz-meta-s3cmd-attrs response header on federation.data.gov |
$150.0 |
| 386 |
Table and Column Exposure |
$150.0 |
| 387 |
Private and group tokens per minute endpoint active for disabled users |
$150.0 |
| 388 |
CSRF in "send them an email and browser notification" feature |
$150.0 |
| 389 |
Found CSRF Vulnerability in https://support.rockstargames.com/ |
$150.0 |
| 390 |
[idp.fr.cloud.gov] Open Redirect |
$150.0 |
| 391 |
Link poisoning on https://secure.login.gov/ login page |
$150.0 |
| 392 |
SQL Injection found in NextCloud Android App Content Provider |
$150.0 |
| 393 |
Subdomain Takeover due to unclaimed domain pointing to AWS |
$150.0 |
| 394 |
SSRF in Search.gov via ?url= parameter |
$150.0 |
| 395 |
Talk - Leak of password-protected room name via already existent resource addition |
$150.0 |
| 396 |
Persistent XSS via filename in projects |
$150.0 |
| 397 |
Internal Hostname disclosure from multiple Apache servers via blank host header method |
$150.0 |
| 398 |
open redirect in eb9f.pivcac.prod.login.gov |
$150.0 |
| 399 |
[api.zomato.com] Abusing LocalParams (city_id) to Inject SOLR query |
$150.0 |
| 400 |
Race condition while removing the love react in community files. |
$150.0 |
| 401 |
HTML Injection @ /[restaurant]/order endpoint. |
$150.0 |
| 402 |
HTML injection leads to reflected XSS |
$150.0 |
| 403 |
Built-in TLS module unexpectedly treats "rejectUnauthorized: undefined" as "rejectUnauthorized: false", disabling all certificate validation |
$150.0 |
| 404 |
Script breaking tag (Forces website to render blank) (Informative) |
$150.0 |
| 405 |
[34.96.80.155] Server Logs Disclosure lead to Information Leakage |
$150.0 |
| 406 |
Open redirect GET-Based on https://www.flickr.com/browser/upgrade/?continue= |
$150.0 |
| 407 |
DoS via large console messages |
$150.0 |
| 408 |
Sensitive files/ data exists post deletion of user account |
$150.0 |
| 409 |
Email Verification Bypass by bruteforcing when setting up 2FA |
$150.0 |
| 410 |
Redirection in Repeater & Intruder Tab |
$150.0 |
| 411 |
DOS: out of memory from gif through upload api |
$150.0 |
| 412 |
Specially crafted message request crashes the webapp for users who view the message |
$150.0 |
| 413 |
Brave Shield for iOS is weak against IDN homograph attacks |
$150.0 |
| 414 |
Improper user validation on mentions and hashtags |
$150.0 |
| 415 |
Reflected XSS in OAuth complete endpoints |
$150.0 |
| 416 |
Posts sent via websockets aren't sanitized properly |
$150.0 |
| 417 |
User In The Same Center Can Create CSRF To Change The Information About Business |
$147.0 |
| 418 |
Full Path Disclosure at 27.prd.vine.co |
$140.0 |
| 419 |
No rate-limit in SERVER_SECURITY_CHECK |
$140.0 |
| 420 |
Bypass fix in https://hackerone.com/reports/151516 report. |
$100.0 |
| 421 |
Information disclosure at https://blockchain.atlassian.net |
$100.0 |
| 422 |
Access private list metadata |
$100.0 |
| 423 |
Subdomain takeover on podcasts.slack-core.com |
$100.0 |
| 424 |
Suspicious browser fingerprinting(?) scripts on http://www.lahitapiola.fi/ redirector |
$100.0 |
| 425 |
Incorrect code generation with redo inside NODE_RESCUE. |
$100.0 |
| 426 |
CSRF на сброс ключа трансляции. |
$100.0 |
| 427 |
Information disclosure same issue #176002 |
$100.0 |
| 428 |
Нет маркера на добавление песни в плейлист пользователя |
$100.0 |
| 429 |
Узнать название частной группы и ее аватарку по видеоролику. |
$100.0 |
| 430 |
Captcha Bypass in Coinbase SignUp Form |
$100.0 |
| 431 |
languagechange event fires simultaneously on all tabs |
$100.0 |
| 432 |
OS username disclosure |
$100.0 |
| 433 |
Узнаем название и аватарку частной группы, по ID приложения. |
$100.0 |
| 434 |
Registered users can change app password permissions for any user |
$100.0 |
| 435 |
Монипулирование на страницах пользоватлей значением "Подсказывать стикеры в полях ввода" |
$100.0 |
| 436 |
Просмотр аватара и название частной группы |
$100.0 |
| 437 |
Отсутствие flood контроля в ИСТОРИЯХ вк |
$100.0 |
| 438 |
Download attribute allows downloading local files |
$100.0 |
| 439 |
Zomato.com Reflected Cross Site Scripting |
$100.0 |
| 440 |
[Zomato's Blog] POST based XSS on https://www.zomato.com/blog/wp-admin/admin-ajax.php?td_theme_name=Newspaper&v=8.2 |
$100.0 |
| 441 |
[www.zomato.com] IDOR - Gold Subscription Details, Able to view "Membership ID" and "Validity Details" of other Users |
$100.0 |
| 442 |
Optionsbleed / CVE-2017-9798 |
$100.0 |
| 443 |
Часть админки доступна для всех пользователей |
$100.0 |
| 444 |
Уязвимость дает возможность смотреть кто лайкал приватным фото или видео |
$100.0 |
| 445 |
[FG-VD-17-063] NextCloud Insufficient Attack Protection Vulnerability Notification |
$100.0 |
| 446 |
HTML Injection inside Slack promotional emails |
$100.0 |
| 447 |
Bypass subdomain limits using race condition |
$100.0 |
| 448 |
Reflected XSS on developers.zomato.com |
$100.0 |
| 449 |
Stored XSS on chaturbate.com (wish list) |
$100.0 |
| 450 |
Full path disclosure on track.uber.com |
$100.0 |
| 451 |
Passive mixed content issues on the site https://*.fanduel.com |
$100.0 |
| 452 |
Open Redirect |
$100.0 |
| 453 |
Price manipulation via fraction values (Parameter Tampering) |
$100.0 |
| 454 |
Combination of content provider allows private data disclosure |
$100.0 |
| 455 |
SQLi allow query restriction bypass on exposed FileContentProvider |
$100.0 |
| 456 |
Linux Desktop application slack executable does not use pie / no ASLR |
$100.0 |
| 457 |
Staging Rabbitmq instance is exposed to the internet with default credentials |
$100.0 |
| 458 |
URL filter bypass in Enterprise Grid |
$100.0 |
| 459 |
Blind Stored XSS on iOS App due to Unsanitized Webview |
$100.0 |
| 460 |
Open S3 Bucket Accessible by any Aws User |
$100.0 |
| 461 |
XSS in PDF Viewer |
$100.0 |
| 462 |
Unrestricted file upload on the image of contacts |
$100.0 |
| 463 |
Lack of Input sanitization leads to database Character encoding configuration Disclosure |
$100.0 |
| 464 |
[www.zomato.com] Abusing LocalParams (city) to Inject SOLR query |
$100.0 |
| 465 |
Smartsheet employees email disclosure through enpoint after login. |
$100.0 |
| 466 |
Internal Path Disclosure |
$100.0 |
| 467 |
GET based Open redirect on [streamlabs.com/content-hub/streamlabs-obs/search?query=] |
$100.0 |
| 468 |
Brave Browser potentially logs the last time a Tor window was used |
$100.0 |
| 469 |
Guest users can change the confidentiality attribute on those issues that have been assigned to them |
$100.0 |
| 470 |
Forbidden access to https://apps-staging.pingone.com but "/packages.json" visible and full path disclosure |
$100.0 |
| 471 |
Information Disclosure of Garbage Collection Cycle 'Again' |
$100.0 |
| 472 |
XSS through image upload of contacts using svg file |
$100.0 |
| 473 |
Нет флуд-контроля на функции "Запрос денег" в VK Pay. Флуд уведомлениями и сообщениями пользователю, находящемуся в друзьях. |
$100.0 |
| 474 |
DOM XSS on http://talks.lystit.com |
$100.0 |
| 475 |
Отправляем смс на любой номер от имени vk.com. (Сообщение в смс всегда одно и то же, его менять нельзя.) |
$100.0 |
| 476 |
Android app does not clear end to end encryption keys |
$100.0 |
| 477 |
No brute force protection on web-api-cloud.acronis.com |
$100.0 |
| 478 |
Self XSS on Acronis Cyber Cloud |
$100.0 |
| 479 |
Error Page Content Spoofing or Text Injection |
$100.0 |
| 480 |
Ransomware protection is missing extentions take 2 |
$100.0 |
| 481 |
Login session not expire |
$100.0 |
| 482 |
public webdav endpoint not bruteforce protected |
$100.0 |
| 483 |
Add to your nextcloud endpoint is not properly protected |
$100.0 |
| 484 |
No Rate Limit on redditgifts gift when Adding Comment |
$100.0 |
| 485 |
No-Rate limit of current password on delete account endpoint(https://www.xvideos.com/account/close) |
$100.0 |
| 486 |
Получаем название и аватарку (50x50) частной группы. |
$100.0 |
| 487 |
Weak rate limit could lead to ATO due to weak password protection mechanisms |
$100.0 |
| 488 |
Broken link hijacking in https://kubernetes-csi.github.io/docs/drivers.html?highlight=chubaofs#production-drivers |
$100.0 |
| 489 |
Broken Domain Link Takeover from kubernetes.io docs |
$100.0 |
| 490 |
SSRF occurrence in website preview used by LINE Official Account Manager (https://manager.line.biz) |
$100.0 |
| 491 |
RCE via exposed JMX server on jabber.37signals.com/jabber.basecamp.com |
$100.0 |
| 492 |
Possibility to force an admin to install recommended applications |
$100.0 |
| 493 |
Origin IP found, WAF Cloudflare Bypass |
$100.0 |
| 494 |
Moderator can enable cam/mic remotely if cam/mic-permission was disabled while user has activated cam/mic |
$100.0 |
| 495 |
bypass forced password protection via circles app |
$100.0 |
| 496 |
Federated editing allows iframing possibly malicious remotes |
$100.0 |
| 497 |
Moderators can send messages to users from banned subreddits via oauth.reddit.com/api/mod/conversations |
$100.0 |
| 498 |
Any expired reset password link can still be used to reset the password |
$100.0 |
| 499 |
IDOR Payments Status |
$100.0 |
| 500 |
Unrestricted File Upload on reddit.secure.force.com |
$100.0 |
| 501 |
Generated passwords are not fully validated by HIBPValidator |
$100.0 |
| 502 |
Misconfigured build on websites "abuse.cloudflare.com" |
$100.0 |
| 503 |
TikTok Account Creation Date Information Disclosure |
$100.0 |
| 504 |
Remotely Accessible Container Advisor exposed performance metrics and resource usage |
$100.0 |
| 505 |
Profile of disabled user stays accessible |
$100.0 |
| 506 |
Missing rate limiting on password reset functionality allows to send lot of emails |
$100.0 |
| 507 |
Stored XSS Via Filename On https://partners.line.me/ |
$100.0 |
| 508 |
https://www.wotif.com/vc/blog/info.php script is prone to reflected HTML/CSS injection and COOKIE leak |
$100.0 |
| 509 |
Git Arg Injection in kubernetes-sigs/release-sdk |
$100.0 |
| 510 |
UI spoofing by showing sms:/tel: dialog on another website |
$100.0 |
| 511 |
Information Disclosure - Pvt Gitlab Issue Disclosing Through GitLab Unfiltered YouTube channel. |
$100.0 |
| 512 |
Hacker email disclosed on submission at hackerone hactivity |
$100.0 |
| 513 |
Authentication Bypass to (CVE-2023-2982) |
$100.0 |
| 514 |
Admins can change authentication details of user configured external storage |
$100.0 |
| 515 |
Reflected XSS on https://travel.line.me |
$100.0 |
| 516 |
OAuth2 "authorization_code" is valid indefinetly |
$100.0 |
| 517 |
Open Redirect via Non-Latin Subdomain in vcc-*.8x8.com/AGUI/█.php |
$100.0 |
| 518 |
Events information leaked with shared calendars on recurrence exceptions |
$100.0 |
| 519 |
monitoring.prow-canary.k8s.io is vulnerable to CVE-2022-21703 (Grafana 0-day) |
$100.0 |
| 520 |
Brave Android: Incorrect URL Eliding in Brave Shields Pop Up |
$100.0 |
| 521 |
Remove obsolete domain from handbook subdomain |
$100.0 |
| 522 |
HTML Injection on Company Name on Email |
$79.0 |
| 523 |
Android content provider exposes password-protected share password hashes |
$75.0 |
| 524 |
RXSS on thankyou.pixels.php (yapi.mackeeper.com) |
$75.0 |
| 525 |
Reflected XSS (mackeeperapp2.mackeeper.com) |
$75.0 |
| 526 |
RXSS on unsubscribe feature (affiliates.kromtech.com) |
$75.0 |
| 527 |
RXSS on landings/land/3/ron_clean_17_app3_alerts/index.php (mackeeperapp3.mackeeper.com) |
$75.0 |
| 528 |
SSRF in upload IMG through URL |
$64.0 |
| 529 |
Reflected XSS on stage.mackeeper.com |
$60.0 |
| 530 |
More content spoofing through dir param in the files app |
$50.0 |
| 531 |
Content Spoofing in "files" app |
$50.0 |
| 532 |
Posting to Twitter CSRF on php/post_twitter_authenticate.php |
$50.0 |
| 533 |
Missing robots exclusion header for user uploads |
$50.0 |
| 534 |
Use any User to Follow you (Increase Followers) [IDOR] |
$50.0 |
| 535 |
Leaking Referrer in Reset Password Link |
$50.0 |
| 536 |
Internal IP Address Disclosure at https://www.lahitapiolarahoitus.fi/wp-json/wp/v2/pages |
$50.0 |
| 537 |
Bypassing lock protection |
$50.0 |
| 538 |
Gallery: No feedback for invalid password |
$50.0 |
| 539 |
EXIF Geolocation Data Not Stripped From Uploaded Images |
$50.0 |
| 540 |
No rate limiting on password reset page |
$50.0 |
| 541 |
open redirect at https://account.mackeeper.com/auth/signin/continue via improper uri sanitization |
$50.0 |
| 542 |
Reflected xss on mackeeper.com |
$50.0 |
| 543 |
Reflected xss |
$50.0 |
| 544 |
Multiple Links Vulnerable to Reflected xss |
$50.0 |
| 545 |
CORS Misconfiguration, could lead to disclosure of sensitive information (translate.kromtech.com) |
$50.0 |
| 546 |
CRLF Injection - http://stage-static-cdn.mackeeper.com/ |
$50.0 |
| 547 |
CRLF Injection - http://stage.mackeeper.com/ |
$50.0 |
| 548 |
Open Redirect at https://store.mackeeper.com/767/cookie via redirectto parameter |
$50.0 |
| 549 |
DOM based XSS in store.acronis.com//purl-corporate-standard-IT [cfg parameter] |
$50.0 |
| 550 |
Cookie injection leads to complete DoS over whole domain *.mackeeper.com. Injection point accountstage.mackeeper.com/ |
$50.0 |
| 551 |
Bypass "Industry Documents" Validation |
$50.0 |
| 552 |
Hyperlink Injection on Email Invitation |
$50.0 |
| 553 |
licenses key disclosure |
$50.0 |
| 554 |
Lack of session expiration after password reset on TikTok Careers Portal |
$50.0 |
| 555 |
Broken Link on Urban Company's Vulnerability Submission Form |
$50.0 |
| 556 |
Reflected XSS on my.acronis.com |
$50.0 |
| 557 |
unclaimed s3 bucket takeover in the 3 js file located on the github page of brave software |
$50.0 |
| 558 |
Cross Site Scripting (Reflected) on https://www.acronis.cz/ |
$50.0 |
| 559 |
Theft of protected files on Android |
$50.0 |
| 560 |
Self-XSS on Suggest Tag dialog box |
$50.0 |
| 561 |
GitHub Security Lab (GHSL) Vulnerability Report: Insufficient path validation in ReceiveExternalFilesActivity.java (GHSL-2022-060) |
$50.0 |
| 562 |
Cross Site Scripting (Reflected) on https://www.acronis.cz/dotaznik/roadshow-2020/ |
$50.0 |
| 563 |
Persistent XSS found on bin.pinion.gg due to outdated FlowPlayer SWF file with Remote File Inclusion vulnerability. |
$30.0 |
| 564 |
[DOS] denial of service using code snippet on brave browser |
$25.0 |
| 565 |
[DOS] Browser hangs on loading the code snippet |
$25.0 |
| 566 |
ssh: unprivileged users may hijack due to backdated ssh version open port found(███.unikrn.com) |
$25.0 |
| 567 |
bring grtp.co up to A grade on SSLLabs |
$1.0 |
| 568 |
Avoid "resend verification email" confusion |
$1.0 |
| 569 |
auto-logout after 20 minutes |
$0.0 |
| 570 |
Hacker.One Subdomain Takeover |
$0.0 |
| 571 |
Content spoofing in lookup.nextcloud.com |
$0.0 |
| 572 |
coinbase Email leak while sending and requesting |
$0.0 |
| 573 |
CSV Injection in Camptix |
$0.0 |
| 574 |
Bypassing CSV injection using new line charcter |
$0.0 |
| 575 |
Address Bar Spoofing - Already resolved - Retroactive report |
$0.0 |
| 576 |
Homograph attack |
$0.0 |
| 577 |
Status Bar Obfuscation |
$0.0 |
| 578 |
Information Disclosure on rate limit defense mechanism |
$0.0 |
| 579 |
[iOS] URI Obfuscation in iOS application |
$0.0 |
| 580 |
Possible CSRF during external programs |
$0.0 |
| 581 |
[ios] Address bar spoofing in Brave for iOS |
$0.0 |
| 582 |
(HackerOne SSO-SAML) Login CSRF, Open Redirect, and Self-XSS Possible Exploitation |
$0.0 |
| 583 |
Requesting Show CheckIn Alert for Non Friend User |
$0.0 |
| 584 |
Information disclosure via policy update notifications after removal from program |
$0.0 |
| 585 |
[oneclickdrsfdc-test.informatica.com] Tomcat Example Scripts Exposed Unauthenticated |
$0.0 |
| 586 |
race condition in adding team members |
$0.0 |
| 587 |
2 Directory Listing on ledger.brave.com & vault-staging.brave.com |
$0.0 |
| 588 |
Spoof Email with Hyperlink Injection via Invites functionality |
$0.0 |
| 589 |
htaccess file is accesible |
$0.0 |
| 590 |
Nginx server version disclosure |
$0.0 |
| 591 |
Arbitrary heap overread in strscan on 32 bit Ruby, patch included |
$0.0 |
| 592 |
Nginx version disclosure via response header |
$0.0 |
| 593 |
Researcher gets email updates on a private program after he/she quits that program. |
$0.0 |
| 594 |
Spam Some one using (user.saveInvite) system |
$0.0 |
| 595 |
XSS using javascript:alert(8007) |
$0.0 |
| 596 |
Order-phishing via Payment ID URL |
$0.0 |
| 597 |
Content (Text) Injection at NextCloud Server 9.0.52 - via http://custom_nextcloud_url/remote.php/dav/files/ |
$0.0 |
| 598 |
IDOR - Disable sharing |
$0.0 |
| 599 |
Wordpress Version Disclosure Bug On Nextcloud |
$0.0 |
| 600 |
[ecommerce.shopify.com] Invalidated redirection |
$0.0 |
| 601 |
[product360.informatica.com] Unauthenticated Apache Tomcat 8 Installation |
$0.0 |
| 602 |
Option method enabled (viestinta.lahitapiola.fi) |
$0.0 |
| 603 |
Reflected Xss on |
$0.0 |
| 604 |
server version dislosure |
$0.0 |
| 605 |
HTTP OPTION Method is Enabled on portswigger.net |
$0.0 |
| 606 |
Secure Pages Include Mixed Content |
$0.0 |
| 607 |
Files Drop: WebDAV endpoint is leaking existence of resources |
$0.0 |
| 608 |
Reflected XSS in a Navy website |
$0.0 |
| 609 |
Error Page Content Spoofing or Text Injection (viestinta.lahitapiola.fi) |
$0.0 |
| 610 |
Authentication Bypass on monitoring server |
$0.0 |
| 611 |
Unrestricted File Download / Path Traversal |
$0.0 |
| 612 |
XSS vulnerability on an Army website |
$0.0 |
| 613 |
DOM Based XSS on an Army website |
$0.0 |
| 614 |
Dom Based Xss DIV.innerHTML parameters store.starbucks* |
$0.0 |
| 615 |
http://digital.starbucks.com/ Creation of Google G Suite Account on Behalf of starbucks. |
$0.0 |
| 616 |
Disclosure of IBM Websphere page |
$0.0 |
| 617 |
No user confirmation when an auto-updated extension gets more permissions |
$0.0 |
| 618 |
Email Spoofing |
$0.0 |
| 619 |
Reflected XSS on sankarikoulutus (viestinta.lahitapiola.fi) |
$0.0 |
| 620 |
Wordpress 4.7.1 |
$0.0 |
| 621 |
Requestor Email Disclosure via Email Notification |
$0.0 |
| 622 |
Password complexity requirements not enforced |
$0.0 |
| 623 |
Segmentation fault on program counter |
$0.0 |
| 624 |
SIGABRT - mrb_default_allocf |
$0.0 |
| 625 |
Null pointer dereference in mrb_str_modify |
$0.0 |
| 626 |
Exposed Unencrypted Telnet Endpoint |
$0.0 |
| 627 |
Filename enumeration && DoS |
$0.0 |
| 628 |
HTML Injection possible due to bad filter |
$0.0 |
| 629 |
SIGSEGV on mruby mrb_get_args() |
$0.0 |
| 630 |
SIGSEGV mrb_obj_freeze() Manipulating Register RAX and RSI |
$0.0 |
| 631 |
SIGSEGV Null Pointer mrb_str_concat() |
$0.0 |
| 632 |
Denial of service attack on Brave Browser. |
$0.0 |
| 633 |
Stored XSS at https://finance.owox.com/customer/accountList |
$0.0 |
| 634 |
Persistent XSS vulnerability on a DoD website |
$0.0 |
| 635 |
Open Redirect in a DoD website |
$0.0 |
| 636 |
Email Spoofing |
$0.0 |
| 637 |
QuickTime Promotion on a DoD website |
$0.0 |
| 638 |
Reflected XSS on a DoD website |
$0.0 |
| 639 |
Mixed Active content issue on https://www.lyst.com |
$0.0 |
| 640 |
show control page if you insert ' at http://viestinta.lahitapiola.fi/ |
$0.0 |
| 641 |
Report redaction doesn't apply to report title update activities |
$0.0 |
| 642 |
Remote Unrestricted file Creation/Deletion and Possible RCE. |
$0.0 |
| 643 |
SIGSEGV on mrb_vm_exec() Null Deref |
$0.0 |
| 644 |
SIGSEGV - mrb_check_intern_str() - NullPointer |
$0.0 |
| 645 |
dom xss in https://www.slackatwork.com |
$0.0 |
| 646 |
SIGSEGV - mrb_vm_exec - vm.c in line:1272 |
$0.0 |
| 647 |
kh_get_n2s() stack overrun |
$0.0 |
| 648 |
SIGSEGV - kh_resize_iv - Null Deref |
$0.0 |
| 649 |
XSS vulnerability on a DoD website |
$0.0 |
| 650 |
Reflected XSS vulnerability on a DoD website |
$0.0 |
| 651 |
Cross-site scripting vulnerability on a DoD website |
$0.0 |
| 652 |
Information disclosure on a DoD website |
$0.0 |
| 653 |
Cross-site scripting (XSS) vulnerability on a DoD website |
$0.0 |
| 654 |
Information disclosure on a DoD website |
$0.0 |
| 655 |
Arbitrary Script Injection (Mail) in a DoD Website |
$0.0 |
| 656 |
Misconfigured user account settings on DoD website |
$0.0 |
| 657 |
Stored Cross Site Scripting in Customer Name |
$0.0 |
| 658 |
Incomplete or No Cache-control and Pragma HTTP Header Set |
$0.0 |
| 659 |
Limit email address length |
$0.0 |
| 660 |
Gitlab.com is vulnerable to reverse tabnabbing. |
$0.0 |
| 661 |
Server version/OS type disclosure via HTTP Response Header |
$0.0 |
| 662 |
Google Analytics could be used as CSP bypass for data exfiltration on hackerone.com |
$0.0 |
| 663 |
Limited Open redirection using SSO-SAML |
$0.0 |
| 664 |
Subdomain takeover at info.hacker.one |
$0.0 |
| 665 |
Publicy accessible IDRAC instance at api-m.inapp.pushwoosh.com |
$0.0 |
| 666 |
Subdomain Takeover at Landing.udemy.com |
$0.0 |
| 667 |
HTTP trace method is enabled on aspen.io |
$0.0 |
| 668 |
[account-global.ubnt.com] CRLF Injection |
$0.0 |
| 669 |
Content Spoofing or Text Injection in (403 forbidden page injection) and Nginx version disclosure via response header |
$0.0 |
| 670 |
[Android] XSS via start ContentActivity |
$0.0 |
| 671 |
Inadequate/dangerous jQuery behavior |
$0.0 |
| 672 |
olx.ph is vulnerable to POODLE attack |
$0.0 |
| 673 |
Reflected cross-site scripting vulnerability on a DoD website |
$0.0 |
| 674 |
Bypass file access control vulnerability on a DoD website |
$0.0 |
| 675 |
Transferring incorrect data to the http://gip.rocks/v1 endpoint with correct Content-Type leads to local paths disclosure through the error message |
$0.0 |
| 676 |
SSLv3 POODLE Vulnerability |
$0.0 |
| 677 |
web.xml configuration file disclosure |
$0.0 |
| 678 |
DoS vulnerability in mod_auth_digest CVE-2016-2161 |
$0.0 |
| 679 |
javascript: and mailto: links are allowed in JIRA integration settings |
$0.0 |
| 680 |
Content Spoofing/Text Injection in nextcloud.com |
$0.0 |
| 681 |
User Information Disclosure via REST API |
$0.0 |
| 682 |
The email API to reset password is unlimited and can be used as a email bomb |
$0.0 |
| 683 |
CSRF Token Bypass in Account Deletion |
$0.0 |
| 684 |
XSS on IOS app via HTML rendering |
$0.0 |
| 685 |
bug reporting template encourages users to paste config file with passwords |
$0.0 |
| 686 |
Web server is vulnerable to Beast Attack |
$0.0 |
| 687 |
Sensitive information disclosure via response headers on jenkins.brew.sh |
$0.0 |
| 688 |
XSS on username when register to proffesional account |
$0.0 |
| 689 |
Information disclosure vulnerability on a DoD website |
$0.0 |
| 690 |
HTML injection vulnerability on a DoD website |
$0.0 |
| 691 |
XSS on a DoD website |
$0.0 |
| 692 |
Information disclosure vulnerability on a DoD website |
$0.0 |
| 693 |
SIGSEGV - kh_get_n2s - in /src/symbol.c:37 |
$0.0 |
| 694 |
Update php-saml library to 2.10.5 |
$0.0 |
| 695 |
Full path Disclosure in Rockstargames.com██████████ |
$0.0 |
| 696 |
Content Spoofing/Text Injection in https://demo.nextcloud.com |
$0.0 |
| 697 |
Subdomain takeover #2 at info.hacker.one |
$0.0 |
| 698 |
Cross-site-Scripting |
$0.0 |
| 699 |
Full Path Disclousure on https://airship.paragonie.com |
$0.0 |
| 700 |
no session logout after changing the password in https://bridge.cspr.ng/ |
$0.0 |
| 701 |
HTTP 401 response injection on "amp.twimg.com/amplify-web-player/prod/source.html" through "image_src" parameter |
$0.0 |
| 702 |
Tabnabbing via Window.Opener @Mavenlink |
$0.0 |
| 703 |
Clickjacking Vulnerability found on Yelp |
$0.0 |
| 704 |
[IDOR][translate.twitter.com] Opportunity to change any comment at the forum |
$0.0 |
| 705 |
Content (Text) Injection at https://nextcloud.com |
$0.0 |
| 706 |
CSRF vulnerability in saving payment card on store.starbucks.com (COBilling -AddCreditCard) |
$0.0 |
| 707 |
password reset email spamming |
$0.0 |
| 708 |
Email verification over an unencrypted channel |
$0.0 |
| 709 |
No Password Length Restriction leads to Denial of Service |
$0.0 |
| 710 |
Improper Password Reset Policy on https://hosted.weblate.org/ |
$0.0 |
| 711 |
demo.weblate.org is vulnerable to SWEET32 Vulnerability |
$0.0 |
| 712 |
[hosted.weblate.org]Account Takeover |
$0.0 |
| 713 |
Content Spoofing |
$0.0 |
| 714 |
Login using disconnected google account i.e login using old email id |
$0.0 |
| 715 |
Insecure Account Removal |
$0.0 |
| 716 |
CSV Injection with the CVS export feature - Glossary |
$0.0 |
| 717 |
[demo.weblate.org] Stored Self-XSS via Editor Link in Profile |
$0.0 |
| 718 |
Logout CSRF |
$0.0 |
| 719 |
hosted.weblate.org: X-XSS-Protection not enabled |
$0.0 |
| 720 |
weblate.org: X-XSS-Protection not enabled |
$0.0 |
| 721 |
Specify maximal length in new comment |
$0.0 |
| 722 |
Content Spoofing |
$0.0 |
| 723 |
Abuse of Api that causes spamming users and possible DOS due to missing rate limit |
$0.0 |
| 724 |
Missing DMARC on weblate.org |
$0.0 |
| 725 |
No expiration of session ID after Password change |
$0.0 |
| 726 |
Content Spoofing in error message |
$0.0 |
| 727 |
Already Registered Email Disclosure |
$0.0 |
| 728 |
Spamming any user from Reset Password Function |
$0.0 |
| 729 |
User Enumeration when adding email to account |
$0.0 |
| 730 |
session id missing secure flag - Hosted Website |
$0.0 |
| 731 |
Self XSS at translation page through Editor Link at demo.weblate.org |
$0.0 |
| 732 |
Weak e-mail change functionality could lead to account takeover |
$0.0 |
| 733 |
Can upload files without authentication on AirFibre 3.2 |
$0.0 |
| 734 |
CSV Injection with the CSV export feature |
$0.0 |
| 735 |
CSRF : Reset API |
$0.0 |
| 736 |
Notify user about password change |
$0.0 |
| 737 |
Missing restriction on string size of Full Name at https://demo.weblate.org/accounts/register/ |
$0.0 |
| 738 |
Setting a password with a single character |
$0.0 |
| 739 |
Null Password - Setting a new password doesn't check for empty spaces |
$0.0 |
| 740 |
Expired SSL certificate |
$0.0 |
| 741 |
You can simply just use passwords that simply are as 123456 |
$0.0 |
| 742 |
Missing Rate Limit for Current Password field in nextcloud.com |
$0.0 |
| 743 |
Login with Google Not Authenticated on iOS App |
$0.0 |
| 744 |
invalid URL parsing with and '@' |
$0.0 |
| 745 |
Direct IP Access |
$0.0 |
| 746 |
Report invitation links not restricted to any existing user |
$0.0 |
| 747 |
HTML injection in Desktop Client |
$0.0 |
| 748 |
Race condition leads to duplicate payouts |
$0.0 |
| 749 |
Information leakage via CSV when content is valid JavaScript |
$0.0 |
| 750 |
OOB write in BN_bn2dec() (CVE-2016-2182) |
$0.0 |
| 751 |
OOB write in MDC2_Update() (CVE-2016-6303) |
$0.0 |
| 752 |
Excessive allocation of memory in dtls1_preprocess_fragment() (CVE-2016-6308) |
$0.0 |
| 753 |
Excessive allocation of memory in tls_get_message_header() (CVE-2016-6307) |
$0.0 |
| 754 |
Certificate message OOB reads (CVE-2016-6306) |
$0.0 |
| 755 |
OOB read in TS_OBJ_print_bio() (CVE-2016-2180) |
$0.0 |
| 756 |
Malformed SHA512 ticket DoS (CVE-2016-6302) |
$0.0 |
| 757 |
Gratipay Website CSP "script-scr" includes "unsafe-inline" |
$0.0 |
| 758 |
[buy.coinbase.com]Content Injection |
$0.0 |
| 759 |
heap-buffer-overflow (READ of size 11) in Perl 5.25.x |
$0.0 |
| 760 |
Heap overflow caused by type confusion vulnerability in merge_param() |
$0.0 |
| 761 |
XSS at in instacart.com/store/partner_recipe |
$0.0 |
| 762 |
Stored XSS in Adress Book (starbucks.com/account/profile) |
$0.0 |
| 763 |
Reflected XSS on a DoD website |
$0.0 |
| 764 |
Insecure direct object reference vulnerability on a DoD website |
$0.0 |
| 765 |
Server side information disclosure on a DoD website |
$0.0 |
| 766 |
Reflected XSS on a DoD website |
$0.0 |
| 767 |
Reflected XSS on a DoD website |
$0.0 |
| 768 |
Reflected XSS on a DoD website |
$0.0 |
| 769 |
No Rate Limiting at /contact |
$0.0 |
| 770 |
API Does Not Apply Access Controls to Translations |
$0.0 |
| 771 |
Information Disclosure on demo.weblate.org |
$0.0 |
| 772 |
Missing restriction on string size |
$0.0 |
| 773 |
Old password can be new password |
$0.0 |
| 774 |
Clickjacking docs.weblate.org |
$0.0 |
| 775 |
heap-buffer-overflow (READ of size 61) in Perl_re_intuit_start() |
$0.0 |
| 776 |
Stored XSS in Gallery application (NC-SA-2017-010) |
$0.0 |
| 777 |
CRLF Injection on https://vpn.mixmax.com |
$0.0 |
| 778 |
Подмена SSL-сертификата для любой группы в секции Управление группой->Работа с API неавторизированным пользователем. |
$0.0 |
| 779 |
invalid homepage URL causes 'uncaught typeerror' or blank state |
$0.0 |
| 780 |
Security Vulnerability - SMTP protection not used |
$0.0 |
| 781 |
Takeover of an account via reset password options after removing the account |
$0.0 |
| 782 |
Missing restriction on string size of contact field |
$0.0 |
| 783 |
Reflected XSS in a DoD Website |
$0.0 |
| 784 |
Existing sessions valid after removing third party auth |
$0.0 |
| 785 |
Reflected XSS on a DoD website |
$0.0 |
| 786 |
Reflected XSS on a DoD website |
$0.0 |
| 787 |
DOM Based XSS on a DoD website |
$0.0 |
| 788 |
Reflected XSS vulnerability on a DoD website |
$0.0 |
| 789 |
Reflected XSS vulnerability on a DoD website |
$0.0 |
| 790 |
Information disclosure vulnerability on a DoD website |
$0.0 |
| 791 |
Information disclosure vulnerability on a DoD website |
$0.0 |
| 792 |
Information disclosure vulnerability on a DoD website |
$0.0 |
| 793 |
Information disclosure vulnerability on a DoD website |
$0.0 |
| 794 |
Subdomain takeover #4 at info.hacker.one |
$0.0 |
| 795 |
Subdomain takeover #3 at info.hacker.one |
$0.0 |
| 796 |
Possible user session hijack by invalid HTTPS certificate on inside.gratipay.com domain |
$0.0 |
| 797 |
HTML Injection on airlink.ubnt.com |
$0.0 |
| 798 |
Open redirect vulnerability in a DoD website |
$0.0 |
| 799 |
Cross-site request forgery (CSRF) vulnerability in a DoD website |
$0.0 |
| 800 |
Remote code execution vulnerability on a DoD website |
$0.0 |
| 801 |
Reflected XSS vulnerability on a DoD website |
$0.0 |
| 802 |
Information disclosure vulnerability in a DoD website |
$0.0 |
| 803 |
Reflective XSS vulnerability on a DoD website |
$0.0 |
| 804 |
Information disclosure vulnerability on a DoD website |
$0.0 |
| 805 |
Reflected cross-site scripting (XSS) vulnerability on a DoD website |
$0.0 |
| 806 |
Stored cross site scripting (XSS) vulnerability on a DoD website |
$0.0 |
| 807 |
ShopifyAPI is vulnerable to timing attacks. |
$0.0 |
| 808 |
Open redirect on sign in |
$0.0 |
| 809 |
Arbitrary modification value "session" (Cookie) in badoo.com |
$0.0 |
| 810 |
Redirect in adding advance cash on delivery app |
$0.0 |
| 811 |
Improper parsing of input could lead to future XSS vulnerabilities in Sequences |
$0.0 |
| 812 |
API Webhooks Fire And Are Unlisted After Permissions Removed |
$0.0 |
| 813 |
Adding Email lacks Password validation |
$0.0 |
| 814 |
Captcha bypass at registration |
$0.0 |
| 815 |
Missing/Breach of Internal Security Boundary - Access to Job Queue Results in Remote Code Execution |
$0.0 |
| 816 |
Missing SPF Flags |
$0.0 |
| 817 |
Login page password - guessing attack |
$0.0 |
| 818 |
Rate Limit Issue on hosted.weblate.org |
$0.0 |
| 819 |
Forgot password link doesn't expire after used, only after some hours |
$0.0 |
| 820 |
No notificatoin sent on email after account deletion. |
$0.0 |
| 821 |
No redirect uri for Twitter Oath resulting in token leak |
$0.0 |
| 822 |
IDOR create accounts and verify them with original account email |
$0.0 |
| 823 |
Information disclosure on a DoD website |
$0.0 |
| 824 |
Invalidate session after password reset - hosted website |
$0.0 |
| 825 |
Missing filteration of meta characters in all full name field on wakatime.com |
$0.0 |
| 826 |
Clickjacking on authorized page https://wakatime.com/share/embed |
$0.0 |
| 827 |
UI Redressing on Embedded Charts |
$0.0 |
| 828 |
Reflected XSS vulnerability on a DoD website |
$0.0 |
| 829 |
Arbitary file download vulnerability on a DoD website |
$0.0 |
| 830 |
Violation of secure design principles on a DoD website |
$0.0 |
| 831 |
Information disclosure vulnerability on a DoD website |
$0.0 |
| 832 |
Cross-site scripting (XSS) vulnerability on a DoD website |
$0.0 |
| 833 |
Information disclosure vulnerability on a DoD website |
$0.0 |
| 834 |
Password Policy Issue |
$0.0 |
| 835 |
self cross site scripting |
$0.0 |
| 836 |
SSl Weak Ciphers |
$0.0 |
| 837 |
Node modules path disclosure due to lack of error handling |
$0.0 |
| 838 |
ntpd: read_mru_list() does inadequate incoming packet checks |
$0.0 |
| 839 |
Directory Listing In Subdomain Of nextcloud.com |
$0.0 |
| 840 |
no string size restriction on team name |
$0.0 |
| 841 |
Invitation tokens leak to Google Analytics |
$0.0 |
| 842 |
Intercom chat session information persists after logout |
$0.0 |
| 843 |
Insecure Cache-Control Leading to API key Retrieval |
$0.0 |
| 844 |
Blind SSRF due to img tag injection in career form |
$0.0 |
| 845 |
Stored self-XSS in mercantile.wordpress.org checkout |
$0.0 |
| 846 |
Open Redirect in shopify app URL |
$0.0 |
| 847 |
Content Spoofing in udemy |
$0.0 |
| 848 |
Password token validation in https://wakatime.com/ |
$0.0 |
| 849 |
https://wakatime.com/ website CSP "script-src" includes "unsafe-inline" |
$0.0 |
| 850 |
Unsafe Inline and Eval CSP Usage |
$0.0 |
| 851 |
[Cross-domain Referer leakage] Password reset token leakage via referer |
$0.0 |
| 852 |
Failure to check password history |
$0.0 |
| 853 |
SSL BREACH attack (CVE-2013-3587) |
$0.0 |
| 854 |
Lack of input validation in e-mail & user name, job title, company name field |
$0.0 |
| 855 |
Stored but [SELF] XSS in mercantile.wordpress.org |
$0.0 |
| 856 |
Weak Forgot Password implementation |
$0.0 |
| 857 |
Reflected XSS on Zones > Invocation Code |
$0.0 |
| 858 |
Credential gets exposed |
$0.0 |
| 859 |
Password Functionality not working correctly |
$0.0 |
| 860 |
Public calendar link can be invisible |
$0.0 |
| 861 |
[iOS] URL can be replaceState by blob URL in iOS Brave |
$0.0 |
| 862 |
Brave payments remembers history even after clearing all browser data. |
$0.0 |
| 863 |
Code injection |
$0.0 |
| 864 |
Weak Bithdate Validation Implemented on Sign Up |
$0.0 |
| 865 |
Unable to register in starbucks IN app |
$0.0 |
| 866 |
Incorrect error message |
$0.0 |
| 867 |
Wordpress Vulnerable to Potential Unauthorized Password Reset |
$0.0 |
| 868 |
Reflected XSS on a DoD website |
$0.0 |
| 869 |
Cross-site scripting (XSS) vulnerability on a DoD website |
$0.0 |
| 870 |
Server Side Request Forgery (SSRF) vulnerability in a DoD website |
$0.0 |
| 871 |
Cross-site scripting (XSS) on a DoD website |
$0.0 |
| 872 |
Cross-site scripting (XSS) vulnerability on a DoD website |
$0.0 |
| 873 |
Moneybird customers invoices leak in cacheable urls |
$0.0 |
| 874 |
Csrf in watch-unwatch projects |
$0.0 |
| 875 |
Stored XSS in Name field in User Groups/Group Details form |
$0.0 |
| 876 |
Weak password policy |
$0.0 |
| 877 |
Stored XSS vulnerability in RSS Feeds Description field |
$0.0 |
| 878 |
Password Restriction |
$0.0 |
| 879 |
XSS Vulnerability in WooCommerce Product Vendors plugin |
$0.0 |
| 880 |
[debian.weblate.org]-Missing SPF Record |
$0.0 |
| 881 |
Change password session fixed |
$0.0 |
| 882 |
Text injection on status.algolia.com |
$0.0 |
| 883 |
Password Restriction On Change |
$0.0 |
| 884 |
Password complexity not evenly enforced |
$0.0 |
| 885 |
Information disclosure |
$0.0 |
| 886 |
Password Policy Bypass |
$0.0 |
| 887 |
Invalid Email Verification |
$0.0 |
| 888 |
Logout CSRF |
$0.0 |
| 889 |
Information disclosue in Android Application |
$0.0 |
| 890 |
Information disclosure in coinbase android app |
$0.0 |
| 891 |
Improper Cookie expiration | Cookies Expiration Set to Future |
$0.0 |
| 892 |
IDOR on HackerOne Feedback Review |
$0.0 |
| 893 |
Password reset token issue |
$0.0 |
| 894 |
User enumeration from failed login error message |
$0.0 |
| 895 |
Logic issue in email change process |
$0.0 |
| 896 |
Gitlab is vulnerable to impersonation attacks due to broken links |
$0.0 |
| 897 |
Impersonation attack via Broken Link in Resellers Page |
$0.0 |
| 898 |
Sql query disclosure, |
$0.0 |
| 899 |
Homograph Attack Bypass [ Tested on Linux & Windows ] |
$0.0 |
| 900 |
2FA manual entry uses wrong encoding |
$0.0 |
| 901 |
Improper validation at Phone verification (possible cost increase + SMS SPAM attack) |
$0.0 |
| 902 |
WordPress < 4.8.2 vulnerable to multiple attacks |
$0.0 |
| 903 |
aspen | clickjacking |
$0.0 |
| 904 |
Validation of Password reset tokens |
$0.0 |
| 905 |
Race condition in GitLab import, giving access to other people their imports due to filename collision |
$0.0 |
| 906 |
password token validation |
$0.0 |
| 907 |
Can link to websites from profile |
$0.0 |
| 908 |
resolved bugs in a program are public despite the program settings |
$0.0 |
| 909 |
Non-secure requests are not automatically upgraded to HTTPS |
$0.0 |
| 910 |
Clickjacking wordcamp.org |
$0.0 |
| 911 |
Clickjacking mercantile.wordpress.org |
$0.0 |
| 912 |
Clickjacking - https://mercantile.wordpress.org/ |
$0.0 |
| 913 |
SSRF at iris.lystit.com |
$0.0 |
| 914 |
External links should be served in HTTPS. |
$0.0 |
| 915 |
Simple CSS line-height identifies platform |
$0.0 |
| 916 |
Scrollbar Width permits detecting browser platform |
$0.0 |
| 917 |
stack overflow in libsass |
$0.0 |
| 918 |
stack overflow #2 in libsass |
$0.0 |
| 919 |
stack overflow #3 in libsass |
$0.0 |
| 920 |
stack overflow #4 in libsass |
$0.0 |
| 921 |
stack overflow #5 in libsass |
$0.0 |
| 922 |
stack overflow #6 in libsass |
$0.0 |
| 923 |
Preferred language option fingerprinting issue in Tor Browser |
$0.0 |
| 924 |
Privilege Escalation. |
$0.0 |
| 925 |
xss flash on http://presentatie.werkenbijmcdonalds.nl/ |
$0.0 |
| 926 |
Fake mailing reports using mail service on [URL : mail-txn.identity.com] |
$0.0 |
| 927 |
Cross-domain linkability when system time changed in Tor Browser |
$0.0 |
| 928 |
User Enumeration |
$0.0 |
| 929 |
Mailgun misconfiguration on email.bitwarden.com |
$0.0 |
| 930 |
Using an outdated version of OpenSSH on db01.wakatime.com |
$0.0 |
| 931 |
Incorrect Functionality of Password reset links |
$0.0 |
| 932 |
Missing SSL can leak job token |
$0.0 |
| 933 |
XSS with needed user intervention |
$0.0 |
| 934 |
Stored XSS vulnerability in additional URLs in 'Location' dialog [Sitemap] |
$0.0 |
| 935 |
DOM-based XSS in store.starbucks.co.uk on IE 11 |
$0.0 |
| 936 |
SPF Misconfiguration |
$0.0 |
| 937 |
Weak Password Policy on Signup |
$0.0 |
| 938 |
Tabnabbing via window.opener |
$0.0 |
| 939 |
[marketplace.informatica.com] User email disclosure |
$0.0 |
| 940 |
Internal Ports Scanning via Blind SSRF (URL Redirection to beat filter) |
$0.0 |
| 941 |
Self-XSS in WordPress Editor Link Modal |
$0.0 |
| 942 |
[BuddyPress 2.9.1] Open Redirect via "wp_http_referer" parameter on "bp-profile-edit" endpoint |
$0.0 |
| 943 |
A10 – Unvalidated Redirects and Forwards |
$0.0 |
| 944 |
Email Spoofing |
$0.0 |
| 945 |
ClickJacking in editing business name |
$0.0 |
| 946 |
User can be fooled to Bookmark any restaurant by clickjacking |
$0.0 |
| 947 |
Clickjacking @ Main Domain[www.yelp.com] |
$0.0 |
| 948 |
Possible content spoofing due to missing error page |
$0.0 |
| 949 |
Weak Password Policy |
$0.0 |
| 950 |
Content spoofing on yelp.onelogin |
$0.0 |
| 951 |
Vulnerable exported broadcast receiver |
$0.0 |
| 952 |
Bypass insecure password validation |
$0.0 |
| 953 |
Issue with password change in Disabled Account |
$0.0 |
| 954 |
Nginx version disclosure via forbidden page |
$0.0 |
| 955 |
Oauth flow on the comments widget login can lead to the access code leakage |
$0.0 |
| 956 |
Invalid Host detection at https://hackerone.com/redirect |
$0.0 |
| 957 |
Content Spoofing @ https://irclogs.wordpress.org/ |
$0.0 |
| 958 |
Content Security Policy not applied to error pages at multiple HackerOne endpoints |
$0.0 |
| 959 |
Javascript Payload reflected Back in Report Embed Code |
$0.0 |
| 960 |
No Rate Limit on account deletion request(Leads to huge email flooding/email bombing) |
$0.0 |
| 961 |
Open redirect deceive in hackerone.com via another open redirect link. |
$0.0 |
| 962 |
X-XSS-Protection -> Misconfiguration |
$0.0 |
| 963 |
[marketplace.informatica.com] - Sensitive Data Exposure |
$0.0 |
| 964 |
NET::Ftp allows command injection in filenames |
$0.0 |
| 965 |
Cross-site scripting in "Contact customer" form |
$0.0 |
| 966 |
Fix for self-DoS in Security-txt Chrome Extension. |
$0.0 |
| 967 |
Stored XSS in dev-ucrm-billing-demo.ubnt.com In Client Custom Attribute |
$0.0 |
| 968 |
Improper Certificate Validation |
$0.0 |
| 969 |
XSS in api_v1 |
$0.0 |
| 970 |
Following links are vulnerable to clickjacking |
$0.0 |
| 971 |
Invitation token leaks to https://bat.bing.com |
$0.0 |
| 972 |
XSS when clicking "Share to Twitter" at quora.com/widgets/embed_iframe?path=... |
$0.0 |
| 973 |
Host Header Injection allow HiJack Password Reset Link |
$0.0 |
| 974 |
Reflected XSS using Header Injection |
$0.0 |
| 975 |
Reflected XSS vulnerability in Database name field on installation screen |
$0.0 |
| 976 |
[stagecafrstore.starbucks.com] CRLF Injection, XSS |
$0.0 |
| 977 |
[redis-commander] Reflected SWF XSS via vulnerable "clipboard.swf" component |
$0.0 |
| 978 |
While adding a payment method - Notification email not sent to newly added email ID as well as there is no verification for new email id (Paypal) |
$0.0 |
| 979 |
Open Redirection on auth.rbk.money |
$0.0 |
| 980 |
Email notification is not being sent while changing passwords |
$0.0 |
| 981 |
Domain spoofing in redirect page using RTLO |
$0.0 |
| 982 |
Keys |
$0.0 |
| 983 |
Reputation gain split by company can be used to track the existence of otherwise undisclosed reports |
$0.0 |
| 984 |
Leak IP internal |
$0.0 |
| 985 |
Host header Injection rubygems.org |
$0.0 |
| 986 |
Reflected Cross-site Scripting Vulnerability via JSON Error Message |
$0.0 |
| 987 |
See details of a unpublished word by guessing the word ID |
$0.0 |
| 988 |
Prototype pollution attack (lodash) |
$0.0 |
| 989 |
Prototype pollution attack (Hoek) |
$0.0 |
| 990 |
Frameset(Frame) html tag is allowed in html editor.(can lead to clickjacking) |
$0.0 |
| 991 |
Prototype pollution attack (mixin-deep) |
$0.0 |
| 992 |
Prototype pollution attack (assign-deep) |
$0.0 |
| 993 |
Prototype pollution attack (merge-deep) |
$0.0 |
| 994 |
Prototype pollution attack (defaults-deep) |
$0.0 |
| 995 |
Information Disclosure which violate program privacy |
$0.0 |
| 996 |
Single Sing On - Clickjacking |
$0.0 |
| 997 |
remote access to localhost daemon, can issue jsonrpc commands |
$0.0 |
| 998 |
Open Redirect on the nl.wordpress.net |
$0.0 |
| 999 |
Bypassing Homograph Attack Using /@ [ Tested On Windows ] |
$0.0 |
| 1000 |
Test Page available with Server details on /r/test (viestinta.lahitapiola.fi) |
$0.0 |
| 1001 |
Negative size in tar header causes infinite loop |
$0.0 |
| 1002 |
Password Complexity Not Enforced On Password Change |
$0.0 |
| 1003 |
Cleartext Password returned in JSON response |
$0.0 |
| 1004 |
CVE-2017-15277 on Profile page |
$0.0 |
| 1005 |
XSS through __e2e_action_id delivered by JSONP |
$0.0 |
| 1006 |
Cross-origin resource sharing misconfig |
$0.0 |
| 1007 |
SSLv3 Poodle Attack on Ip Of semrush |
$0.0 |
| 1008 |
Leakage badges on disabled user |
$0.0 |
| 1009 |
CORS (Cross-Origin Resource Sharing) |
$0.0 |
| 1010 |
[public] Stored XSS in filenames in directory served by public |
$0.0 |
| 1011 |
[glance] Stored XSS via file name allows to run arbitrary JavaScript when directory listing is displayed in browser |
$0.0 |
| 1012 |
Prototype pollution attack (deap) |
$0.0 |
| 1013 |
Prototype pollution attack (deep-extend) |
$0.0 |
| 1014 |
Prototype pollution attack (merge-recursive) |
$0.0 |
| 1015 |
Prototype pollution attack (merge-options) |
$0.0 |
| 1016 |
Content Spoofing or Text Injection support.mycrypto.com |
$0.0 |
| 1017 |
Stored XSS in partners dashboard |
$0.0 |
| 1018 |
[EE] Spoof the redirect process |
$0.0 |
| 1019 |
[EE] change the author of post using the author_id |
$0.0 |
| 1020 |
DOM XSS in edoverflow.com/tools/respond due to unsafe usage of the innerHTML property. |
$0.0 |
| 1021 |
Chrome Extension is vulnerable to the self-DOS issues in case it process the security.txt with a big size |
$0.0 |
| 1022 |
Buffer out of bound read in miniupnpc xml parser |
$0.0 |
| 1023 |
Out-of-bounds read when importing corrupt blockchain with monero-blockchain-import |
$0.0 |
| 1024 |
Response splitting vulnerability in WEBrick |
$0.0 |
| 1025 |
Rate-limit protection get executed in the last stage of the registration process, allowing enumeration of existing account. |
$0.0 |
| 1026 |
Account members can re-add themselve after has been deleted by administrator |
$0.0 |
| 1027 |
heap-buffer-overflow (WRITE of size 8) in Perl_pp_reverse() |
$0.0 |
| 1028 |
Bypassing one-time checkout router page (revealing payment information) |
$0.0 |
| 1029 |
Clickjacking on https://www.goodhire.com/api |
$0.0 |
| 1030 |
Insecure Transportation Security Protocol Supported (TLS 1.0) on https://www.jamieweb.net |
$0.0 |
| 1031 |
Bypassing CSRF Token On Reply Message & Send Message |
$0.0 |
| 1032 |
Import File Converter - local File inclusion |
$0.0 |
| 1033 |
[hekto] open redirect when target domain name is used as html filename on server |
$0.0 |
| 1034 |
XML Member Proccessing - Local File inclusion Vulnerability |
$0.0 |
| 1035 |
Administrator can create user without entering high security mode |
$0.0 |
| 1036 |
The "Download Raw Diff" URL is viewable by everyone |
$0.0 |
| 1037 |
Non-Cloudflare IPs allowed to access origin servers |
$0.0 |
| 1038 |
No Rate Limit in email leads to huge Mass mailings |
$0.0 |
| 1039 |
HackerOne support disclosing report state without checking user identity |
$0.0 |
| 1040 |
Authenticated reflected XSS on liberapay.com via the back_to parameter when leaving a team. |
$0.0 |
| 1041 |
Host header injection/redirection via newsletter signup |
$0.0 |
| 1042 |
XSS on redirection page( Bypassed) |
$0.0 |
| 1043 |
Disclosed Version of PORTS SSH|HTTP|SSL |
$0.0 |
| 1044 |
put allocates uninitialized Buffers when non-round numbers are passed in input |
$0.0 |
| 1045 |
utile allocates uninitialized Buffers when number is passed in input |
$0.0 |
| 1046 |
[file-static-server] Path Traversal allows to read content of arbitrary file on the server |
$0.0 |
| 1047 |
njwt allocates uninitialized Buffers when number is passed in base64urlEncode input |
$0.0 |
| 1048 |
File access control rules not enforced on image files |
$0.0 |
| 1049 |
[engineering.udemy.com] - Subdomain Takeover (ghost.io) |
$0.0 |
| 1050 |
Error Page Content Spoofing or Text Injection |
$0.0 |
| 1051 |
CSRF at [Apply to this program] that lead to submit your request automatic with out any validations |
$0.0 |
| 1052 |
Download of (later executed) .NET installer over insecure channel |
$0.0 |
| 1053 |
Potential SSRF and disclosure of sensitive site on *shopifycloud.com |
$0.0 |
| 1054 |
Open API For Username enumeration |
$0.0 |
| 1055 |
xss - reflected |
$0.0 |
| 1056 |
HTML TAG INJECTION ON PROFILE NAME |
$0.0 |
| 1057 |
epee will accept an arbitrary amount of leading line-breaks in an http request |
$0.0 |
| 1058 |
Trusted daemon check fails when proxied through torsocks or proxychains |
$0.0 |
| 1059 |
OPEN REDIRECTION at every 302 HTTP CODE |
$0.0 |
| 1060 |
CSRF-tokens on pages without no-cache headers, resulting in ATO when using CloudFlare proxy (Web Cache Deception) |
$0.0 |
| 1061 |
TeamProfile exposes partially sensitive information through GraphQL |
$0.0 |
| 1062 |
Basic auth details is still work on report ( 351555 ) |
$0.0 |
| 1063 |
Password reset token leakage via referer |
$0.0 |
| 1064 |
Post Based XSS On Upload Via CK Editor [semrush.com] |
$0.0 |
| 1065 |
Internal usage of AdBlockPlus may expose PoC URLs to unknown third-parties |
$0.0 |
| 1066 |
Clickjacking In jobs.wordpress.net |
$0.0 |
| 1067 |
Insecure Account Removal #2 |
$0.0 |
| 1068 |
Stored XSS on Add Event in Calendar |
$0.0 |
| 1069 |
Stored XSS on Add Calendar |
$0.0 |
| 1070 |
Participation of expired account holders in Projects can occure financial loss to Mavenlink |
$0.0 |
| 1071 |
Open port leads to information disclosure |
$0.0 |
| 1072 |
Any user can completely delete their own account without authorization and/or going through any kind of membership cancellation protocol. |
$0.0 |
| 1073 |
CSV Injection with the CSV export feature |
$0.0 |
| 1074 |
Homograph attack on redirect URL (https://chaturbate.com/external_link/?url) |
$0.0 |
| 1075 |
Login form on non-HTTPS page on http://stream.highwebmedia.com/auth/login/ |
$0.0 |
| 1076 |
Client DoS due to large DH parameter (CVE-2018-0732) |
$0.0 |
| 1077 |
Go.imgur.com can be used to phish for account information |
$0.0 |
| 1078 |
Password protected rooms total number of viewers disclosure to unauthorized members |
$0.0 |
| 1079 |
Open redirection in OAuth |
$0.0 |
| 1080 |
DoS in Brave browser for iOS |
$0.0 |
| 1081 |
Unsafe handling of protocol handlers |
$0.0 |
| 1082 |
Navigation to chrome-extension:// origin (internal pages) from the web |
$0.0 |
| 1083 |
no notification send to victim if attacker hacks/accesses his victims WebLate account. |
$0.0 |
| 1084 |
twofactor_auth bypassable if provider fails to load |
$0.0 |
| 1085 |
Prototype pollution attack (merge.recursive) |
$0.0 |
| 1086 |
flood of comment no rate limit on commnets >> by using different user agent |
$0.0 |
| 1087 |
2nd issue>>> flood of email no rate limit on delete account confirmation email >> |
$0.0 |
| 1088 |
License verification mechanism can be bypassed |
$0.0 |
| 1089 |
Reflected xss on theacademy.upserve.com |
$0.0 |
| 1090 |
subdomain Takeover at blog.exchangemarketplace.com |
$0.0 |
| 1091 |
alert() dialogs on chrome-extension:// origin (internal pages) |
$0.0 |
| 1092 |
Cross-origin page stays focused before/after downloading + uninformative modal window for download |
$0.0 |
| 1093 |
settingcontent-ms files lacks "mark of the web" => execute code by dbl click in Downloads toolbar |
$0.0 |
| 1094 |
CSRF on change video thumbnail at https://chaturbate.com |
$0.0 |
| 1095 |
Missing Rate Limitation at /apps/upload_app/ |
$0.0 |
| 1096 |
CORS on (ws.infogram.com) |
$0.0 |
| 1097 |
No rate limiting in starting up a bot. |
$0.0 |
| 1098 |
No rate limiting in changing room subject. |
$0.0 |
| 1099 |
vulnerable to Cross-site Request Forgery | Jira |
$0.0 |
| 1100 |
xmlrpc.php on mariadb.org can lead to DDOS and brute force attacks |
$0.0 |
| 1101 |
Update Chat Allowed By Option ( without age verification ) |
$0.0 |
| 1102 |
[wakatime.com] HTML Injection github-btn.html |
$0.0 |
| 1103 |
No rate limit in stats api token endpoint |
$0.0 |
| 1104 |
No rate limit in affiliate statsapi endpoint |
$0.0 |
| 1105 |
Homograph attack on redirect URL |
$0.0 |
| 1106 |
Add non-existent room moderator |
$0.0 |
| 1107 |
Open redirection at https://chaturbate.com/auth/login/ |
$0.0 |
| 1108 |
Session fixation in password protected public download. |
$0.0 |
| 1109 |
[Клевер/Android] Небезопасный BroadcastReceiver позволяет создавать окно диалога в приложении посредством другого неавторизованного приложения |
$0.0 |
| 1110 |
Chaturbate "/chat_ignore_list/" endpoint does not check for Account status: Disabled before adding Ignore via POST |
$0.0 |
| 1111 |
XML hash collision DoS vulnerability in Python's xml.etree module |
$0.0 |
| 1112 |
Disclosure of top 10 vulnerability types for programs that haven't enabled the Insights feature |
$0.0 |
| 1113 |
Self DOM-Based XSS in www.hackerone.com |
$0.0 |
| 1114 |
SSRF in rompager-check |
$0.0 |
| 1115 |
Vulnerability Report - Missing Certificate Authority Authorization rule |
$0.0 |
| 1116 |
SMS/Call spamming due to truncated phone number |
$0.0 |
| 1117 |
Open redirect on rush.uber.com, business.uber.com, and help.uber.com |
$0.0 |
| 1118 |
Privacy policy contains hardcoded link using unencrypted HTTP |
$0.0 |
| 1119 |
Missing Rate Limitation at /photo_videos/photoset/create |
$0.0 |
| 1120 |
Is the 504 Gateway Time-out error ok? |
$0.0 |
| 1121 |
Revoking user session in https://hackerone.com/settings/sessions does not revoke the GraphQL query session |
$0.0 |
| 1122 |
Import of repositories from GitHub is tied to username instead of immutable ID |
$0.0 |
| 1123 |
Open Redirect |
$0.0 |
| 1124 |
65534 times efficient, Brute-force attack for api_key |
$0.0 |
| 1125 |
Request Hijacking Vulnerability in RubyGems 2.6.13 and earlier |
$0.0 |
| 1126 |
Cross-Domain JavaScript Source File Inclusion |
$0.0 |
| 1127 |
information disclosure which leak the apache version |
$0.0 |
| 1128 |
SMS URL verification link does not expire on phone number change and lacks rate limiting |
$0.0 |
| 1129 |
Editable Wiki repo by anyone |
$0.0 |
| 1130 |
User Controllable Cookie |
$0.0 |
| 1131 |
A user can request a report to be retested even though the program has not been verified by HackerOne |
$0.0 |
| 1132 |
Timing attack towards endpoints on the web without CSRF |
$0.0 |
| 1133 |
Information disclosure |
$0.0 |
| 1134 |
Exposure of tinyMCE js source code with plugin version disclosure which can leads to exploit further attacks. |
$0.0 |
| 1135 |
Disclosure of information about the system, configuration files. |
$0.0 |
| 1136 |
User login page doesn't implement any form of rate limiting |
$0.0 |
| 1137 |
User Enumeration |
$0.0 |
| 1138 |
[buttle] Unsafe rendering of Markdown files |
$0.0 |
| 1139 |
Error Page Content Spoofing or Text Injection |
$0.0 |
| 1140 |
Information Exposure Through Directory Listing - https://apps.nextcloud.com/static/ |
$0.0 |
| 1141 |
CSRF | Ban or unban users in broadcast's chat |
$0.0 |
| 1142 |
Comment restriction in subsection "Workshop" of domain "steamcommunity.com" can be bypassed using IDOR |
$0.0 |
| 1143 |
Content spoofing on error pages or text injection |
$0.0 |
| 1144 |
protocol & Ports are not shown in third-party site redirect warning page |
$0.0 |
| 1145 |
No Rate Limit On Add new word |
$0.0 |
| 1146 |
No Rate On Add Suggest |
$0.0 |
| 1147 |
Missing CSRF Token On Add Coupon To Basket |
$0.0 |
| 1148 |
Bypass GraphQL rate limit by abusing negative cost queries |
$0.0 |
| 1149 |
IDOR in activateFuelCard id allows bulk lookup of driver uuids |
$0.0 |
| 1150 |
Improper validation allows user to unlock Zomato Gold multiple times at the same restaurant within one day |
$0.0 |
| 1151 |
Disclosure of h1 challenges name through the calendar |
$0.0 |
| 1152 |
Missing CSRF Token On Remove Coupun From Cart |
$0.0 |
| 1153 |
Information Exposure Through Directory Listing vulnerability on 8 vcache**.usw2.snappytv.com websites |
$0.0 |
| 1154 |
DMARC RECORD MISSING |
$0.0 |
| 1155 |
Open Redirect On Your Login Panel |
$0.0 |
| 1156 |
report id is exposed for undisclosed reports in Hacktivity |
$0.0 |
| 1157 |
A small set of users were assigned someone else's payout preference |
$0.0 |
| 1158 |
User uploaded portfolio files can be accessed by any user even after deleted |
$0.0 |
| 1159 |
Users able to set video url for unpublished words and able to see the name of unpublished words |
$0.0 |
| 1160 |
Open redirect on the https://tt.hboeck.de |
$0.0 |
| 1161 |
credentials leakage in public lead to view dev websites |
$0.0 |
| 1162 |
Open Redirection in Login - Korean Starbucks |
$0.0 |
| 1163 |
All Burp Suite Scan report |
$0.0 |
| 1164 |
Text injection at https://media.hboeck.de |
$0.0 |
| 1165 |
Mssing Authorization on Private Message replies (BuddyPress) |
$0.0 |
| 1166 |
Path Disclosure Vulnerability http://crm.******.com |
$0.0 |
| 1167 |
Client-Side Race Condition using Marketo, allows sending user to data-protocol in Safari when form without onSuccess is submitted on www.hackerone.com |
$0.0 |
| 1168 |
[harp] Unsafe rendering of Markdown files |
$0.0 |
| 1169 |
CSV Injection at the CSV export feature |
$0.0 |
| 1170 |
Emails of invited collaborators are disclosed in full in payload for report participants |
$0.0 |
| 1171 |
Логирование ответов запросов VK API в приложении Клевер |
$0.0 |
| 1172 |
Ports are not shown in third-party site redirect warning page. |
$0.0 |
| 1173 |
Web cache deception attack - expose earning state information |
$0.0 |
| 1174 |
Previous attachments can be referenced when creating a new report |
$0.0 |
| 1175 |
No Rate Limit on CrowdSignal Polls when Adding Comment |
$0.0 |
| 1176 |
Bypassing the SMS sending limit for download app link. |
$0.0 |
| 1177 |
Homograph attack in escalate report |
$0.0 |
| 1178 |
SVG file that HTML Included is able to upload via File Manager |
$0.0 |
| 1179 |
Sensitive Clickjacking on admin login page. |
$0.0 |
| 1180 |
Unreleased CTF Levels are Revealed on /group/user/ID1?user=USERID endpoint |
$0.0 |
| 1181 |
Open redirect in switch account functionality |
$0.0 |
| 1182 |
Moving a report to a different program doesn't reassign the Custom Field Values |
$0.0 |
| 1183 |
Users can make accounts with a fake email address. |
$0.0 |
| 1184 |
[affiliates.udemy.com] Wordpress user admin information discloure |
$0.0 |
| 1185 |
"More on Wikipedia" link disclose "Referrer" and leak window.opener reference for arbitrary websites |
$0.0 |
| 1186 |
Emails from Grammarly missing sanitization(lack of validation?) -> HTML injection in emails |
$0.0 |
| 1187 |
Unrestricted POST request size on /customer_support/information_form/ endpoint |
$0.0 |
| 1188 |
DOM Based XSS in www.hackerone.com via PostMessage (bypass of #398054) |
$0.0 |
| 1189 |
Crash |
$0.0 |
| 1190 |
Security check failure or stack buffer overrun (crash) |
$0.0 |
| 1191 |
A stack buffer overflow in BabyGrid.cpp can lead to program crashes via a malicious localization file |
$0.0 |
| 1192 |
Potential use-after-free due to struct array_entry_t lacking an explicit copy constructor |
$0.0 |
| 1193 |
smtp service vulnerable to POODLE SSLv3 |
$0.0 |
| 1194 |
Stored XSS in OAuth redirect URI |
$0.0 |
| 1195 |
help.shopify.com Cross Site Scripting |
$0.0 |
| 1196 |
The auto login link does not expire on changing email id |
$0.0 |
| 1197 |
API Last Request Date/Time Not Updating |
$0.0 |
| 1198 |
Race condition in claiming program credentials |
$0.0 |
| 1199 |
Detecting Tor Browser UI Language |
$0.0 |
| 1200 |
Github wikis are editable by anyone #Githubwikistakeover |
$0.0 |
| 1201 |
Reflected XSS |
$0.0 |
| 1202 |
Grammarly Keyboard for Android <4.1 leaks user input through logs (except for sensitive input fields) |
$0.0 |
| 1203 |
DOM XSS via Shopify.API.remoteRedirect |
$0.0 |
| 1204 |
Password not checked when disabling 2FA on HackerOne |
$0.0 |
| 1205 |
Получение БД кэша из Android-приложения через стороннее приложение |
$0.0 |
| 1206 |
PHPinfo page |
$0.0 |
| 1207 |
H1514 Removed Staff members who had "Apps" permission can still modify flow app connections |
$0.0 |
| 1208 |
Plain text password for 'unknown' user exist in URL when opening jira.apiok.ru |
$0.0 |
| 1209 |
XSS Reflected on my_report |
$0.0 |
| 1210 |
Information leakage and default open port |
$0.0 |
| 1211 |
Cross Domain leakage of sensitive information - Leading to Account Takeover at Instagram Brand |
$0.0 |
| 1212 |
Private/confidential setting of calendar events is ignored on activity stream |
$0.0 |
| 1213 |
Click Jacking Nextcloud |
$0.0 |
| 1214 |
IDOR to update folder name of other user |
$0.0 |
| 1215 |
HTML injection in https://interviewing.shopify.com/index.php?candidate= |
$0.0 |
| 1216 |
View HackerOne challenge scope before challenge begins |
$0.0 |
| 1217 |
Missing Rate Limit in Password Change |
$0.0 |
| 1218 |
any staff members have the ability to comment in [discounts] he/she can disable comment section it to other staff even the admin of the store |
$0.0 |
| 1219 |
Testnet address being sent in cleartext as http://rinkeby.chain.link/ is missing SSL certificate |
$0.0 |
| 1220 |
Server side includes in https://lgtm-com.pentesting.semmle.net/internal_api/v0.2/savePublicInformation leads to 500 server error and D-DOS |
$0.0 |
| 1221 |
Developper's websites are easily accessibles leading to massive information disclosure |
$0.0 |
| 1222 |
Open Redirect in comment section |
$0.0 |
| 1223 |
Milestones leaked via search API |
$0.0 |
| 1224 |
Race Condition in Flag Submission |
$0.0 |
| 1225 |
Extremly simple way to bypass Nextcloud-Client PIN/Fingerprint lock |
$0.0 |
| 1226 |
Able to bypass "Device credentials" Lock |
$0.0 |
| 1227 |
Stored XSS on byddypress Plug-in via groups name |
$0.0 |
| 1228 |
No rate limit on app.crowdsignal.com (Finish quiz) |
$0.0 |
| 1229 |
Root user disclosure in data.gov domain though x-amz-meta-s3cmd-attrs header |
$0.0 |
| 1230 |
Unclaimed Github Repository Takeover on https://www.data.gov/labs |
$0.0 |
| 1231 |
RTL override char allowed at khanacademy redirect page |
$0.0 |
| 1232 |
Total bounties paid amount is disclosed because of redesign of the Program Profiles |
$0.0 |
| 1233 |
Disclosure of 152 cookie names via crafted input |
$0.0 |
| 1234 |
Captcha protection Bypass on Forgot password page |
$0.0 |
| 1235 |
Application Design issue for Phone Number field in Registration. |
$0.0 |
| 1236 |
Information disclosure (system username, server info) in the x-amz-meta-s3cmd-attrs response header on data.gov |
$0.0 |
| 1237 |
Program Email Nofication settings ignored when being added as an external contributor |
$0.0 |
| 1238 |
Link obfuscation bug |
$0.0 |
| 1239 |
Can register any mobile number in MFA without current code. |
$0.0 |
| 1240 |
Option method enabled in kartpay Webservers |
$0.0 |
| 1241 |
Access Projects And create projects in gitlab pre production server |
$0.0 |
| 1242 |
CSRF leads to a stored self xss |
$0.0 |
| 1243 |
Persistent XSS via e-mail when creating merge requests |
$0.0 |
| 1244 |
Passwords being stored as plain text in logging |
$0.0 |
| 1245 |
Last build status and coverage leaked to unauthorized users |
$0.0 |
| 1246 |
Vulnerability Name: Host Header Injection Redirect |
$0.0 |
| 1247 |
environment variable leakage in error reporting |
$0.0 |
| 1248 |
Delete permission can be added on reshare |
$0.0 |
| 1249 |
Email enumeration at SignUp page |
$0.0 |
| 1250 |
Content Spoofing /Text Injection in https://docs.nextcloud.com |
$0.0 |
| 1251 |
Disclosure of Program email Title Report when being removed as contributor. Bypass for Report #645264 |
$0.0 |
| 1252 |
IDOR in Report CSV export discloses the IDs of Custom Field Attributes of Programs |
$0.0 |
| 1253 |
[Bypass #645264] Report title disclosure despite the program settings for email notification is set to "No Content" |
$0.0 |
| 1254 |
Veracode and security audit record are publicly available |
$0.0 |
| 1255 |
Stored credentials instantly autofilled within sandboxed iframes |
$0.0 |
| 1256 |
Domain takeover on http://doesfranshaveashell.com/ due to expiration |
$0.0 |
| 1257 |
Lack of quarantine meta-attribute for downloaded files leads to GateKeeper bypass |
$0.0 |
| 1258 |
[http_server] Stored XSS in the filename when directories listing |
$0.0 |
| 1259 |
.git file accessible |
$0.0 |
| 1260 |
██████ DOM XSS via Shopify.API.remoteRedirect |
$0.0 |
| 1261 |
Clicking "http://burp" hyperlink on FireFox CA Installation guide redirects to "burp.com" (unclaimed website). |
$0.0 |
| 1262 |
antispambot does not always escape <, >, &, " and ' |
$0.0 |
| 1263 |
The twitter accounts are linked on page but unclaimed. |
$0.0 |
| 1264 |
Clickjacking in [exchangemarketplace.com] |
$0.0 |
| 1265 |
Add and Access to Labels of any Private Projects/Groups of Gitlab(IDOR) |
$0.0 |
| 1266 |
Application level denial of service due to shutting down the server |
$0.0 |
| 1267 |
Manipulate hacker profile and private program hacktivity to expose your name as researchers who is actively submitting reports with resolve status |
$0.0 |
| 1268 |
Last pipeline status for MR leaked |
$0.0 |
| 1269 |
Clientside resource Exhausting by exploiting gitlab math rendering |
$0.0 |
| 1270 |
Privilege escalation due to insecure use of logrotate |
$0.0 |
| 1271 |
Ruby is shipping a vulnerable jQuery |
$0.0 |
| 1272 |
full path disclosure on www.rockstargames.com via apache filename brute forcing |
$0.0 |
| 1273 |
Full Path disclosure on 500 error |
$0.0 |
| 1274 |
Know whether private project name exists or not within a group using link comments |
$0.0 |
| 1275 |
Non-secure requests to www.lahitapiola.fi are not automatically upgraded to HTTPS |
$0.0 |
| 1276 |
Information disclosure in mmap module - python 2.7.12 |
$0.0 |
| 1277 |
NULL Pointer Dereference in WDDX Packet Deserialization with PDORow |
$0.0 |
| 1278 |
Python 2.7 32-bit JSON encoding heap corruption |
$0.0 |
| 1279 |
[Brave browser] WebTorrent has DNS rebinding vulnerability |
$0.0 |
| 1280 |
Reflected cross-site scripting on multiple Starbucks assets. |
$0.0 |
| 1281 |
Exposing debug.log file leads to server full path disclosure |
$0.0 |
| 1282 |
URL is vulnerable to clickjacking |
$0.0 |
| 1283 |
Open redirect in semrush.com |
$0.0 |
| 1284 |
"Test target" of the "HTTP target" extension can unintentionally send username and password in the Authorization header |
$0.0 |
| 1285 |
Insecure Frame (External) |
$0.0 |
| 1286 |
Assertion `col >= 0 && col < line->cols' failed, process aborted while streaming ouput from remote server |
$0.0 |
| 1287 |
heap-use-after-free (READ of size 8) in main() |
$0.0 |
| 1288 |
puttygen: heap-buffer-overflow in mp_get_decimal() |
$0.0 |
| 1289 |
puttygen: 160MB memory leak while trying to extract openssh public key from crafted key file |
$0.0 |
| 1290 |
Invalidate session after password reset |
$0.0 |
| 1291 |
latest_activity_id and latest_activity_at may disclose information about internal activities to unauthorized users |
$0.0 |
| 1292 |
WordPress Plugin Insert or Embed Articulate Content into WordPress Remote Code Execution (UNAUTHORIZED) |
$0.0 |
| 1293 |
Username Enumeration |
$0.0 |
| 1294 |
Nextcloud Clickjacking Vulnerability |
$0.0 |
| 1295 |
Heap Buffer Overflow |
$0.0 |
| 1296 |
Multiple use after frees in obj2ast_* methods |
$0.0 |
| 1297 |
CachingIterator null dereference when convert to string |
$0.0 |
| 1298 |
Memory corruption in _php_math_number_format_ex() |
$0.0 |
| 1299 |
Heap overflow due to integer overflow in bzdecompress() function |
$0.0 |
| 1300 |
Memory corruption due to missing check size in _php_math_number_format_ex() |
$0.0 |
| 1301 |
Heap overflow due to integer overflow in pg_escape_string() function |
$0.0 |
| 1302 |
Heap overflow due to integer overflow in php_escape_html_entities_ex() function |
$0.0 |
| 1303 |
malloc negative size parameter |
$0.0 |
| 1304 |
Information disclosure on sim.starbucks.com |
$0.0 |
| 1305 |
bypass captcha in the form forgot password |
$0.0 |
| 1306 |
WEBrick::HTTPAuth::DigestAuth authentication is vulnerable to regular expression denial of service (ReDoS) |
$0.0 |
| 1307 |
доступ к com.vk.usersstore.UsersContentProvider, возможна утечка exchange_token на android < 21 |
$0.0 |
| 1308 |
previous token seems to work even though it does not verify email |
$0.0 |
| 1309 |
indexFile option passed as an argument to node-server can lead to arbitrary file read |
$0.0 |
| 1310 |
CSRF vulnerability that allows an attacker to modify encryption settings |
$0.0 |
| 1311 |
Reflected XSS in pubg.com |
$0.0 |
| 1312 |
Reflected XSS in https://lite.pubg.com |
$0.0 |
| 1313 |
Мини-уязвимость в обработке ссылок |
$0.0 |
| 1314 |
Bypass Rejected ads so user can view it as normal live ad. |
$0.0 |
| 1315 |
Project Milestones Disclosed Via Groups When the Victim disabled milestones access in project settings |
$0.0 |
| 1316 |
Head pipeline leaked to unauthorized users via blocking merge request feature |
$0.0 |
| 1317 |
IDOR in Bugs overview enables attacker to determine the date range a hackathon was active |
$0.0 |
| 1318 |
Camo Image Proxy Bypass with CSS Escape Sequences |
$0.0 |
| 1319 |
Redirection through referer tag |
$0.0 |
| 1320 |
SSO through odnoklassniki uses http rather than https |
$0.0 |
| 1321 |
Clickjacking in the admin page |
$0.0 |
| 1322 |
XSS (leads to arbitrary file read in Rocket.Chat-Desktop) |
$0.0 |
| 1323 |
[atlasboard-atlassian-package] Cross-site Scripting (XSS) |
$0.0 |
| 1324 |
DoS of https://nordvpn.com/ via CVE-2018-6389 exploitation |
$0.0 |
| 1325 |
Version problem in wordpress leads to the many vulnearability |
$0.0 |
| 1326 |
Stored XSS (Hexo-admin plugin) |
$0.0 |
| 1327 |
Same site Scripting |
$0.0 |
| 1328 |
Follow by email allows for following by unverified emails |
$0.0 |
| 1329 |
Theme Assets uploader allows HTML content |
$0.0 |
| 1330 |
Wordpress users disclosure on blog.makerdao.con |
$0.0 |
| 1331 |
Disclosure of User Information |
$0.0 |
| 1332 |
Double linking cause XSS (but blokeced by CSP in gitlab.com) |
$0.0 |
| 1333 |
Disclosure of Users Information On Wordpress Api [https://jitsi.org/] |
$0.0 |
| 1334 |
Creating malformed URLs via new line character in-between two URLs leads to misrepresented hyperlinks in Tweets/DMs |
$0.0 |
| 1335 |
Denial Of Service in Strapi Framework using argument injection |
$0.0 |
| 1336 |
WAF bypass via double encoded non standard ASCII chars permitted a reflected XSS on response page not found pages - (629745 bypass) |
$0.0 |
| 1337 |
Tabnabbing in template comments - stripo.email |
$0.0 |
| 1338 |
SQL exception in JSON format |
$0.0 |
| 1339 |
Nextcloud logs ldap passwords |
$0.0 |
| 1340 |
HTML injection and limited XSS via logo image upload - Nextcloud 12.0.0 |
$0.0 |
| 1341 |
Directory listing is enabled that exposes non public data through multiple path |
$0.0 |
| 1342 |
Stored XSS in Name of Team Member Invitation |
$0.0 |
| 1343 |
The password limit is not set, [DoS]. |
$0.0 |
| 1344 |
[script-manager] Unintended require |
$0.0 |
| 1345 |
Able to download any hosted content on AWS S3 bucket(stripo) |
$0.0 |
| 1346 |
Clickjacking at join.nordvpn.com |
$0.0 |
| 1347 |
'X-Forwarded-Host' key used in input without sanitation - possible cache poisoning |
$0.0 |
| 1348 |
CORS misconfiguration which leads to the disclosure of certain data concerning the user. |
$0.0 |
| 1349 |
Host header injection/redirection | signup and login page |
$0.0 |
| 1350 |
"Bounties paid in the last 90 days" discloses the undisclosed bounty amount in program statistics |
$0.0 |
| 1351 |
Twitter Source Label allow 'mongolian vowel separator' U+180E (app name) |
$0.0 |
| 1352 |
Modify account details by exploiting clickjacking vulnerability on refer.wordpress.com |
$0.0 |
| 1353 |
Password Reset Link Works Multiple Times |
$0.0 |
| 1354 |
Blind SSRF on debug.nordvpn.com due to misconfigured sentry instance |
$0.0 |
| 1355 |
Password authentication at newsletter.nextcloud.com discloses username list |
$0.0 |
| 1356 |
[Reflected XSS] In Request URL |
$0.0 |
| 1357 |
Stored XSS on scan.nextcloud.com |
$0.0 |
| 1358 |
Improper protection of FileContentProvider |
$0.0 |
| 1359 |
DOMPurify 0.8.9 released |
$0.0 |
| 1360 |
Broken link for wrong domain entry may be leveraged for Phishing, Misinformation, Serving Malware |
$0.0 |
| 1361 |
Delete All Data of Any User |
$0.0 |
| 1362 |
Hong Kong - Open Redirect on card.starbucks.com.hk |
$0.0 |
| 1363 |
Potential linkage of public/private (anonymous) node addresses |
$0.0 |
| 1364 |
Monero wallet password change is confirmed when not matching |
$0.0 |
| 1365 |
Disabled account can still use GraphQL endpoint |
$0.0 |
| 1366 |
Open redirection bypass in /www/admin/campaign-modify.php |
$0.0 |
| 1367 |
bypass old password with array in /admin/account-user-email.php |
$0.0 |
| 1368 |
Minimal information disclosure of internal asset names and links which were not publicly accessible. |
$0.0 |
| 1369 |
scripts loader (denial of service) vulnerability |
$0.0 |
| 1370 |
Race Condition leads to undeletable group member |
$0.0 |
| 1371 |
SSRF leads to internal port scan |
$0.0 |
| 1372 |
Account deletion requests not entirely honoured. Misinformation even after seeking clarification from customer support. |
$0.0 |
| 1373 |
Reset password without knowing current password |
$0.0 |
| 1374 |
program_analytics_benchmarks query shows information not visible in public |
$0.0 |
| 1375 |
Session works after logout from Shopify account |
$0.0 |
| 1376 |
Content Injection on api.semrush.com to Reflected XSS |
$0.0 |
| 1377 |
Reflected XSS on https://www.semrush.com/my_reports/externalSource/callback/googleAccountsGMB |
$0.0 |
| 1378 |
Arbitrary Set-Cookie via "?coupon=" due to semi-colon not encoded |
$0.0 |
| 1379 |
Denial of Service with Cookie Bomb |
$0.0 |
| 1380 |
Leaking Of Sensitive Information on Github |
$0.0 |
| 1381 |
Stored XSS through Facebook Page Connection |
$0.0 |
| 1382 |
Self xss |
$0.0 |
| 1383 |
Code injection in macOS Desktop Client |
$0.0 |
| 1384 |
IDOR leading to downloading of any attachment |
$0.0 |
| 1385 |
Private account causes displayed through API |
$0.0 |
| 1386 |
Open Redirect on Greater Asia domains |
$0.0 |
| 1387 |
Full Path and internal information disclosure+ SQLNet.log file disclose internal network information |
$0.0 |
| 1388 |
Session works after logout from Shopify account and password of online store is displayed |
$0.0 |
| 1389 |
XSS in select attribute options |
$0.0 |
| 1390 |
Read-only team members can read all properties of webhooks |
$0.0 |
| 1391 |
Week Passwords generated by password reset function |
$0.0 |
| 1392 |
Prevent XSS when passing a parameter directly into link_to |
$0.0 |
| 1393 |
XSS due to incomplete JS escaping |
$0.0 |
| 1394 |
MK Site Cross-Site Scripting (XSS) in script context |
$0.0 |
| 1395 |
Information disclosure of Internal php files on [mackeeper.com/blog/api/send-event] |
$0.0 |
| 1396 |
CSS Injection on static.mackeeper.com - Potential XSS |
$0.0 |
| 1397 |
Subdomain takeover of resources.hackerone.com |
$0.0 |
| 1398 |
404-response contains debug-information with all headers |
$0.0 |
| 1399 |
Thailand - IDOR on www.starbuckscardth.in.th: A logged in user could view any Thailand Starbucks card balance if they knew that Starbucks card number |
$0.0 |
| 1400 |
Unauthenticated Reflected Cross-Site Scripting on https://account.mackeeper.com/signin page |
$0.0 |
| 1401 |
Reflected XSS |
$0.0 |
| 1402 |
Bypass for blind SSRF #281950 and #287496 |
$0.0 |
| 1403 |
Attacker with an Old account might still be able to DoS ctf.hacker101.com by sending a Crafted request |
$0.0 |
| 1404 |
[www.stripo.email] There is no rate limit for contact-us endpoints |
$0.0 |
| 1405 |
CSRF header is sent to external websites when using data-remote forms |
$0.0 |
| 1406 |
Error Page Content Spoofing or Text Injection |
$0.0 |
| 1407 |
Username Information Disclosure via Json response - Using parameter number Intruder |
$0.0 |
| 1408 |
[Limited bypass of #793704] Blind SSRF in Ghost CMS |
$0.0 |
| 1409 |
[www.drive2.ru] There is no rate limit for comments endpoints. |
$0.0 |
| 1410 |
Directory listing of https://get8x8.com/ |
$0.0 |
| 1411 |
Email HTML injection |
$0.0 |
| 1412 |
Open redirect on https://account.mackeeper.com |
$0.0 |
| 1413 |
Multiple Information Disclosure with Go PPROF on api-ne.mackeeper.com |
$0.0 |
| 1414 |
Open redirect in https://www.rockstargames.com/GTAOnline/restricted-content/agegate/form may lead to Facebook OAuth token theft |
$0.0 |
| 1415 |
Information Disclosure in https://www.rockstargames.com/search |
$0.0 |
| 1416 |
insecure redirect in https://www.rockstargames.com |
$0.0 |
| 1417 |
Affiliates - Session Fixation |
$0.0 |
| 1418 |
rxss at https://mackeeper.com page not found via rid parameter |
$0.0 |
| 1419 |
Rack parses encoded cookie names allowing an attacker to send malicious __Host- and __Secure- prefixed cookies |
$0.0 |
| 1420 |
SSH port on store.greenhouse.io is vulnerable to brute force attacks |
$0.0 |
| 1421 |
Referer Referer Header Leakage in language changer may lead to FB token theft |
$0.0 |
| 1422 |
[www.werkenbijbakertilly.nl] Information Disclosure |
$0.0 |
| 1423 |
China - Open redirect at trackinghub.starbucks.com.cn |
$0.0 |
| 1424 |
Node.js HTTP/2 Large Settings Frame DoS |
$0.0 |
| 1425 |
PHPinfo page on http://█████.callstats.io |
$0.0 |
| 1426 |
[www.stripo.email] There is no rate limit for /it/contact-us/ endpoints |
$0.0 |
| 1427 |
Stored XSS on express entries |
$0.0 |
| 1428 |
Stored XSS in the file search filter |
$0.0 |
| 1429 |
Enumeration of username on password reset page |
$0.0 |
| 1430 |
Testing for arbitrary HTTP methods |
$0.0 |
| 1431 |
Logout page does not prevent CSRF |
$0.0 |
| 1432 |
csrf in https://www.rockstargames.com/reddeadonline/feedback/submit.json |
$0.0 |
| 1433 |
CSRF Vulnerability on post creation page /community/create-post.json |
$0.0 |
| 1434 |
Pending MFA logins aren't immediatly expired after a password change |
$0.0 |
| 1435 |
Open Redirect - www.shopify.com |
$0.0 |
| 1436 |
Subdomain Takeover of multiple *.ttcdn.co domains |
$0.0 |
| 1437 |
Account takeover intercepting magic link for Arrive app |
$0.0 |
| 1438 |
Clickjacking on donation page |
$0.0 |
| 1439 |
SSO Provider Credential Cache (logged out of Google/GitHub, could still log into Courier) |
$0.0 |
| 1440 |
Stored XSS in app.lemlist.com |
$0.0 |
| 1441 |
"Self" DOS with large deployment and scaling |
$0.0 |
| 1442 |
Github test clientID and clientSecret leaked |
$0.0 |
| 1443 |
DoS for client-go jsonpath func |
$0.0 |
| 1444 |
Stored XSS at [ █████ ] in " LINKEDIN URL" Field. |
$0.0 |
| 1445 |
CVE-2019-19935 - DOM based XSS in the froala editor |
$0.0 |
| 1446 |
SAML Response Reuse on hackerone.com/users/saml/auth |
$0.0 |
| 1447 |
Contacts menu (not app) fails to restrict (to local groups) for contacts from federated servers |
$0.0 |
| 1448 |
IDOR: Adding Contacts to Other User Groups |
$0.0 |
| 1449 |
Ngnix Server version disclosure. |
$0.0 |
| 1450 |
GCM sender key leak |
$0.0 |
| 1451 |
Implement rate limit on internal password checks |
$0.0 |
| 1452 |
Private list members disclosure via GraphQL |
$0.0 |
| 1453 |
Ability to manipulate price with a max threshold of <1 Rupee in support rider parameter |
$0.0 |
| 1454 |
Unauthenticated users can access all food.grammarly.io user's data |
$0.0 |
| 1455 |
Host Header Injection. |
$0.0 |
| 1456 |
Arbitrary code execution via untrusted schemas in ajv |
$0.0 |
| 1457 |
[www.yoti.com] Wordpress user admin information discloure |
$0.0 |
| 1458 |
SVG file upload leads to XML injection |
$0.0 |
| 1459 |
[mijn.werkenbijdefensie.nl] Denial of service occurs due to lack of email length confirmation |
$0.0 |
| 1460 |
Django should not have debug mode enabled |
$0.0 |
| 1461 |
Django debug enabled showing information about system, database, configuration files. |
$0.0 |
| 1462 |
Unauthorized Use of Victim Credit Card |
$0.0 |
| 1463 |
ClickJacking on IMPORTANT Functions of Yelp |
$0.0 |
| 1464 |
Recently added 'Country' field doesn't send email notification when changed |
$0.0 |
| 1465 |
Stored XSS on Broken Themes via filename |
$0.0 |
| 1466 |
Graphql: Sorting the reports by jira_status field resulted to different value |
$0.0 |
| 1467 |
XSS Stored via Upload avatar PNG [HTML] File in accounts.shopify.com |
$0.0 |
| 1468 |
IDOR in locid parameter allowing to view others accounts Profile Locations |
$0.0 |
| 1469 |
Race Condition when following a user |
$0.0 |
| 1470 |
bypass the [OKTA] login redirect can lead to disclosing limited-information about the sub-domain at [ shiptsec.com ] |
$0.0 |
| 1471 |
Blind HTTP GET SSRF via website icon fetch (bypass of pull#812) |
$0.0 |
| 1472 |
[flsaba] Stored XSS in the file and directory name when directories listing |
$0.0 |
| 1473 |
XSS / SELF XSS |
$0.0 |
| 1474 |
staff can able to extend shopify trial period without admin permission |
$0.0 |
| 1475 |
Clear text storage of proxy parameters and passwords |
$0.0 |
| 1476 |
Java : add MongoDB injection sinks |
$0.0 |
| 1477 |
Stored XSS in collabora via user name |
$0.0 |
| 1478 |
Cross Site Scripting (XSS) Stored - Private messaging |
$0.0 |
| 1479 |
Bypass Filter on link of build |
$0.0 |
| 1480 |
No rate limiting on sinup page |
$0.0 |
| 1481 |
Making program preference -> program visibilty feature usless and disclosing API Identifier in the progress and data that may cause potential IDORS. |
$0.0 |
| 1482 |
Password Reset Link Leaked In Refer Header In Request To Third Party Sites |
$0.0 |
| 1483 |
[api.tumblr.com] Exploiting clickjacking vulnerability to trigger self DOM-based XSS |
$0.0 |
| 1484 |
PHP Integer Overflow in gdImageWebpCtx |
$0.0 |
| 1485 |
Use of uninitialized value in ftp_getrc_msg method of mod_proxy_ftp.c |
$0.0 |
| 1486 |
Null Pointer Dereference in phar_create_or_parse_filename |
$0.0 |
| 1487 |
Send Empty CSRF leads to log out user on [https://hosted.weblate.org/accounts/profile] |
$0.0 |
| 1488 |
Getting New Invitations without Leaving Programs |
$0.0 |
| 1489 |
[www.drive2.ru] Insufficient Security Configurability - Email notification is not being sent while changing passwords |
$0.0 |
| 1490 |
[www.drive2.ru] Insufficient Security Configurability - Notification email is not sent when email is changed. |
$0.0 |
| 1491 |
[www.drive2.ru] Insufficient Security Configurability - Notification message not sent when account is deleted |
$0.0 |
| 1492 |
[www.drive2.ru] Insufficient Security Configurability - The user can using the same password as your current ID. |
$0.0 |
| 1493 |
[www.drive2.ru] Insufficient Security Configurability - The user's can set an existing password as a new password. |
$0.0 |
| 1494 |
Admin/Info lekage |
$0.0 |
| 1495 |
Open Redirect on [blog.wavecell.com] |
$0.0 |
| 1496 |
Password Reset Link not expiring after changing the email Leads To Account Takeover |
$0.0 |
| 1497 |
Reduced purmations on encryption |
$0.0 |
| 1498 |
The password of a mail share is not hashed if the password is given when the share is created |
$0.0 |
| 1499 |
[zenn-cli] Path traversal on Windows allows the attacker to read arbitrary .md files |
$0.0 |
| 1500 |
Grafana Improper authorization |
$0.0 |
| 1501 |
Possibilty to purchase Ultimate - 1 Year (EDU or OSS) |
$0.0 |
| 1502 |
Clickjacking on cas.acronis.com login page |
$0.0 |
| 1503 |
Information Disclosure of Garbage Collection Cycle |
$0.0 |
| 1504 |
Message Authentication Codes calculated by the Default Encryption Module allow an attacker to silently overwrite blocks in a file |
$0.0 |
| 1505 |
CVE-2020-8231: Connect-only connections can use the wrong connection |
$0.0 |
| 1506 |
Exposed Configuration Files at https://www.exodus.io/keybase.txt |
$0.0 |
| 1507 |
Broken Authentication and Session Management Flaw After Change Password and Logout |
$0.0 |
| 1508 |
No rate limiting for confirmation email lead to email flooding and leads to enumeration of emails in publishers.basicattentiontoken.org |
$0.0 |
| 1509 |
Possibility to freeze/crash the host system of all Slack Desktop users easily |
$0.0 |
| 1510 |
Content Spoofing/Text Injection in https://support.cs.money and JS file not minified and uglyfied which makes it clearly readable |
$0.0 |
| 1511 |
XSS In https://docs.gocd.org/current/ |
$0.0 |
| 1512 |
Session misconfiguration on change password feature at https://apps-staging.pingone.com/myaccount/?environmentId=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx# |
$0.0 |
| 1513 |
Session misconfiguration on forget password feature at https://ort-admin.pingone.com |
$0.0 |
| 1514 |
self-xss with ClickJacking can leads to account takeover in Firefox |
$0.0 |
| 1515 |
Slack server disclose h1 private issue report |
$0.0 |
| 1516 |
No Rate Limit when accessing "Password protection" enabled surveys leads to bypassing passwords via "pd-pass_surveyid" cookie |
$0.0 |
| 1517 |
XSS stored in the Shopify Email app |
$0.0 |
| 1518 |
kubeadm logs tokens before deleting them |
$0.0 |
| 1519 |
Apparent ██████████ website is publicly exposed, suggests default account details on page and has expired SSL/TLS cert |
$0.0 |
| 1520 |
IDOR when creating App on [platform.streamlabs.com/api/v1/store/whitelist] with user_id field |
$0.0 |
| 1521 |
[chart.js] Prototype pollution |
$0.0 |
| 1522 |
CVE-2019-5435: An integer overflow found in /lib/urlapi.c |
$0.0 |
| 1523 |
Race Condition on "Get free Badoo Premium" which allows to get more days of free premium for Free. |
$0.0 |
| 1524 |
Slack-Corp Heroku application disclosing limited info about company members |
$0.0 |
| 1525 |
SSRF external interaction |
$0.0 |
| 1526 |
Blind SSRF in ads.tiktok.com |
$0.0 |
| 1527 |
Server Side Request Forgery in 'Jabber settings' in Admin Control Panel |
$0.0 |
| 1528 |
Probably unexploitable XSS via Header Injection |
$0.0 |
| 1529 |
Improper Input Validation on User's Location on PUT /WhoService/putLocation Could Affect Availability/Falsify Users |
$0.0 |
| 1530 |
Bypass SMS verification to delete TikTok account |
$0.0 |
| 1531 |
Reauthentication for changing password bypass |
$0.0 |
| 1532 |
Reflected XSS via IE |
$0.0 |
| 1533 |
Add check for disabled HTTPOnly setting in Tomcat |
$0.0 |
| 1534 |
XSS through image upload of contacts using svg file with png extension |
$0.0 |
| 1535 |
Stored XSS in [https://streamlabs.com/dashboard#/*goal] pages |
$0.0 |
| 1536 |
[tumblr.com] CSRF in /svc/user/filtered_content |
$0.0 |
| 1537 |
CORS misconfiguration in TikTok ads portal |
$0.0 |
| 1538 |
Integer overflows in tool_operate.c at line 1541 |
$0.0 |
| 1539 |
Hyper Link Injection while signup |
$0.0 |
| 1540 |
Blind SSRF on velodrome.canary.k8s.io |
$0.0 |
| 1541 |
Curl_auth_create_plain_message integer overflow leads to heap buffer overflow |
$0.0 |
| 1542 |
Heap Buffer Overflow (READ of size 1) in ourWriteOut |
$0.0 |
| 1543 |
Race condition with CURL_LOCK_DATA_CONNECT can cause connections to be used at the same time |
$0.0 |
| 1544 |
Login page vulnerable to bruteforce attacks via rate limiting bypass |
$0.0 |
| 1545 |
IDOR Vulnerability in Job Preferences |
$0.0 |
| 1546 |
SQL injection when configuring a database |
$0.0 |
| 1547 |
[intensedebate.com] XSS Reflected POST-Based |
$0.0 |
| 1548 |
Cross Site Scripting and Open Redirect in affiliate-preview.php file |
$0.0 |
| 1549 |
phpinfo() on graph.rockstargames.com exposes sensitive information |
$0.0 |
| 1550 |
Reset password policy isn't consistent with registration / change password policy. |
$0.0 |
| 1551 |
Google API key leaked to Public |
$0.0 |
| 1552 |
User password left in memory in plain text after GUI launch |
$0.0 |
| 1553 |
Denial Of Service (Out Of Memory) on Updating Bounty Table [Urgent] |
$0.0 |
| 1554 |
Rate limiting on report video |
$0.0 |
| 1555 |
use after free in cookie.c |
$0.0 |
| 1556 |
Potential invocation of qsort on uninitialized memory during cookie save |
$0.0 |
| 1557 |
Buffer write overflow when forming dns over http request |
$0.0 |
| 1558 |
Integer overflow at line 1603 in the src/operator.c file |
$0.0 |
| 1559 |
huge COLUMNS causes progress-bar to buffer overflow |
$0.0 |
| 1560 |
CVE-2020-8284: trusting FTP PASV responses |
$0.0 |
| 1561 |
HostAuthorization middleware does not suitably sanitize the Host / X-Forwarded-For header allowing redirection. |
$0.0 |
| 1562 |
The authentication code when activating 2FA can be used again to log in |
$0.0 |
| 1563 |
xss on polaris.shopify.com/demo using postMessage |
$0.0 |
| 1564 |
Content spoofing on https://surveyserver.nextcloud.com |
$0.0 |
| 1565 |
xss on setup config page |
$0.0 |
| 1566 |
New users can read all Nextcloud Deck data from previous user with same username |
$0.0 |
| 1567 |
DoS attack against the client when entering a long password |
$0.0 |
| 1568 |
Non-changing "_idnonce" value leads to CSRF on accounts at https://intensedebate.com for account takeover |
$0.0 |
| 1569 |
Open redirect on https://signin.rockstargames.com/connect/authorize/rsg |
$0.0 |
| 1570 |
Stored XSS in markdown file with Nextcloud Talk using Internet Explorer |
$0.0 |
| 1571 |
Cookie Bombing cause DOS - businesses.uber.com |
$0.0 |
| 1572 |
information disclosure lead to disclose users private notes |
$0.0 |
| 1573 |
Race Condition allows to get more free trials and get more than 100 languages and strings for free |
$0.0 |
| 1574 |
Disclosure of Co-Rider user (Uber-pooling) profile picture at Amazon AWS Cloudfront within HTTP RESPONSE |
$0.0 |
| 1575 |
DOM-based XSS in d.miwifi.com on IE 11 |
$0.0 |
| 1576 |
CORS Misconfiguration, could lead to disclosure of users information |
$0.0 |
| 1577 |
Minor Account Privacy can Set to Everyone. |
$0.0 |
| 1578 |
The password of a mail share is not set if the password is given when the share is created (Nextcloud < 18) |
$0.0 |
| 1579 |
Command injection in OptionParser.load |
$0.0 |
| 1580 |
[information disclosure] Validate existence of a private project. |
$0.0 |
| 1581 |
Failure to Invalid Session after Password Change |
$0.0 |
| 1582 |
Leak of Internal IP addresses |
$0.0 |
| 1583 |
Misconfigured oauth leads to Pre account takeover |
$0.0 |
| 1584 |
Server Side Request Forgery |
$0.0 |
| 1585 |
HTML Injection through Account Name field on TikTok ads portal being rendered on emails |
$0.0 |
| 1586 |
HTML Injection on "polls" app - comments section (possibly XSS) |
$0.0 |
| 1587 |
Access control issue on invoice documents downloading feature. |
$0.0 |
| 1588 |
KOPS documentation references domains which were not registered |
$0.0 |
| 1589 |
Login CSRF : Login Authentication Flaw on https://liberapay.com/ |
$0.0 |
| 1590 |
Ability to invite a new member on Sandbox Program |
$0.0 |
| 1591 |
The POS app doesn't revoke the Xauth token |
$0.0 |
| 1592 |
CRLF INJECTION |
$0.0 |
| 1593 |
Reflected XSS on http://www.grouplogic.com/files/glidownload/verify.asp |
$0.0 |
| 1594 |
Reflected XSS on www.grouplogic.com/video.asp |
$0.0 |
| 1595 |
Flash Based Reflected XSS on www.grouplogic.com/jwplayer/player.swf |
$0.0 |
| 1596 |
PHP info page disclosure |
$0.0 |
| 1597 |
CSRF in Demographic Settings with valid gdtoken of other account |
$0.0 |
| 1598 |
web.xml configuration file disclosure |
$0.0 |
| 1599 |
Social media link hijack of team member [Linkedin] at https://mackeeper.com/team/ |
$0.0 |
| 1600 |
Password policy changes not enforced for existing passwords |
$0.0 |
| 1601 |
Privilege Escalation Leads to Control The Owner Access Token Which leads to control the stream [streamlabs.com] |
$0.0 |
| 1602 |
credentials found in config file on github |
$0.0 |
| 1603 |
Hi! Security Team Rocket.Chat, It's possible to get information about the users emails without authentication |
$0.0 |
| 1604 |
CVE-2021-22876: Automatic referer leaks credentials |
$0.0 |
| 1605 |
CVE-2021-22890: TLS 1.3 session ticket proxy host mixup |
$0.0 |
| 1606 |
Code Injection via Insecure Yaml.load |
$0.0 |
| 1607 |
No rate Limit |
$0.0 |
| 1608 |
[Java] CWE-348: Use of less trusted source |
$0.0 |
| 1609 |
Open Redirect on https://www.twitterflightschool.com/widgets/experience?destination_url=https://evil.com |
$0.0 |
| 1610 |
Disavowing an account doesn't disable it |
$0.0 |
| 1611 |
wrong url in hackerone > goes to wix.com > unconnected |
$0.0 |
| 1612 |
Subdomain Takeover At the Main Domain Of Your Site |
$0.0 |
| 1613 |
redirect_to(["string"]) remote code execution |
$0.0 |
| 1614 |
Graphql introspection is enabled and leaks details about the schema |
$0.0 |
| 1615 |
PHP-FPM status page disclosure |
$0.0 |
| 1616 |
Email Spoofing on sifchain.finance |
$0.0 |
| 1617 |
Wordpress Users Disclosure (/wp-json/wp/v2/users/) on sifchain.finance |
$0.0 |
| 1618 |
No Rate Limit protection in user subscription form |
$0.0 |
| 1619 |
Bypass t.co link shortener in Twitter direct messages |
$0.0 |
| 1620 |
No Rate Limit On Forgot Password Page |
$0.0 |
| 1621 |
Nextcloud deck sharee search leaks searches to lookupserver by default |
$0.0 |
| 1622 |
Talk discloses turn server to anybody |
$0.0 |
| 1623 |
CSRF in changing password after using reset password link |
$0.0 |
| 1624 |
DOM XSS в learning.ozon.ru |
$0.0 |
| 1625 |
[www.drive2.ru] Insufficient Session Expiration - Previously issued email change tokens do not expire upon issuing a new email change token |
$0.0 |
| 1626 |
Default Nextcloud server config and iOS Nextcloud client leak sharee searches to Nextcloud |
$0.0 |
| 1627 |
Cross-Site Scripting through search form on mtnplay.co.zm |
$0.0 |
| 1628 |
HTTPS not enforced at dex.sifchain.finance |
$0.0 |
| 1629 |
Error Page Content Spoofing or Text Injection |
$0.0 |
| 1630 |
Serverinfo endpoints are not bruteforce protected nor are tokens properly generated |
$0.0 |
| 1631 |
No admin audit entry for enabling/disabling 2FA |
$0.0 |
| 1632 |
No admin audit log for auth tokens |
$0.0 |
| 1633 |
Ransomware protection is missing extentions |
$0.0 |
| 1634 |
Trusted server shared secret stored unencrypted in the database |
$0.0 |
| 1635 |
Broken Link on Ping Identity's Vulnerability Submission Form on Hackerone |
$0.0 |
| 1636 |
Low Privileged user can add or remove cash to/from sales register |
$0.0 |
| 1637 |
XSS on https://partners.acronis.com/ |
$0.0 |
| 1638 |
TikTok Session Donation CSRF via QR code login |
$0.0 |
| 1639 |
Subdomain Takeover – www.jet.acronis.com pointing to unclaimed Webflow services |
$0.0 |
| 1640 |
Subdomain Takeover – jet.acronis.com pointing to unclaimed Webflow services |
$0.0 |
| 1641 |
Second-order SOQL injection through email and campaign name parameter in Salesforce lead submission |
$0.0 |
| 1642 |
Insufficient Session Expiration |
$0.0 |
| 1643 |
Report Duplicate Detector can match deleted and draft reports, may disclose title and vulnerability information |
$0.0 |
| 1644 |
clickjacking at brew.sh |
$0.0 |
| 1645 |
F5 BIG-IP Cookie potentially reveal BigIP pool name, backend's IP address and port, routed domain. |
$0.0 |
| 1646 |
rXSS on https://mackeeperapp.mackeeper.com/landings/download-blue/ |
$0.0 |
| 1647 |
Ratelimiting can be bypassed using IPv6 subnets |
$0.0 |
| 1648 |
New link opening method makes hackerone vulnerable to tabnabbing |
$0.0 |
| 1649 |
Blocked user can send notification by liking the message due to Logical Bug |
$0.0 |
| 1650 |
Reflected XSS in https://www.topcoder.com/blog/category/community-stories/ |
$0.0 |
| 1651 |
Admin audit is not properly logging unsetting of expiration date |
$0.0 |
| 1652 |
[Java] CWE-918: Added URLClassLoader and WebClient SSRF sinks |
$0.0 |
| 1653 |
Information Disclosure .htaccess accesible for public |
$0.0 |
| 1654 |
CVE-2021-22925: TELNET stack contents disclosure again |
$0.0 |
| 1655 |
hackers.upchieve.org and argocd.upchieve.org is not preloaded. |
$0.0 |
| 1656 |
Vulnerable javascript dependency at Main domain |
$0.0 |
| 1657 |
Information disclosure - Feedback is accessible on Public profile even after 'disallowed' at https://hackerone.com/settings/feedback |
$0.0 |
| 1658 |
PII data Leakage through hackerone reports |
$0.0 |
| 1659 |
Text app leaks file path of shared files |
$0.0 |
| 1660 |
Business logic error |
$0.0 |
| 1661 |
Domain Takeover [3737signals.com] |
$0.0 |
| 1662 |
Information Disclosure on TikTok Unplugged Site |
$0.0 |
| 1663 |
CLICKJACKING LEADS TO DEACTIVATE ACCOUNT |
$0.0 |
| 1664 |
Full Path Disclosure of Server through 500 Server Error |
$0.0 |
| 1665 |
[acronis.secure.force.com] - Insecure Salesforce default/custom object permissions leads to information disclosure |
$0.0 |
| 1666 |
No DMARC record at cordacon.com |
$0.0 |
| 1667 |
kubectl creating secrets from stringData leaves secret in plain text |
$0.0 |
| 1668 |
Organization Members in Snap Kit may Deactivate Apps |
$0.0 |
| 1669 |
Bypass of the installation sandbox by injecting keystrokes with TIOCSTI |
$0.0 |
| 1670 |
Failed to validate Session after Password Change |
$0.0 |
| 1671 |
Open Redirect at https://www.nutanix.com/tw/login via icid parameter |
$0.0 |
| 1672 |
No Rate Limit On Reset Password |
$0.0 |
| 1673 |
Subdomain takeover due to non registered TLD [ ██████████.█████.██████.com ] |
$0.0 |
| 1674 |
Protocol Smuggling over LDAP password field |
$0.0 |
| 1675 |
No Limit on Email Subscription |
$0.0 |
| 1676 |
Holes in EndpointSlice Validation Enable Host Network Hijack |
$0.0 |
| 1677 |
Bootstrap library is vulnerable |
$0.0 |
| 1678 |
Privilege Escalation leading to post in channel without having privilege |
$0.0 |
| 1679 |
Webview address bar spoofing in LINE client for iOS |
$0.0 |
| 1680 |
Hacker can bypass minimum bounty amount restrictions in "invitation preferences" setting via UpdateInvitationPreferencesMutation GraphQL operation |
$0.0 |
| 1681 |
Open Redirect through POST Request in OAuth |
$0.0 |
| 1682 |
IDOR in https://moneybird.com/user/accountant_company/edit(change company name) |
$0.0 |
| 1683 |
Broken Link on TikTokUS.Info |
$0.0 |
| 1684 |
Path Traversal on meetcqpub1.gsa.gov allows attackers to see arbitrary file listings. |
$0.0 |
| 1685 |
SSRF bypass |
$0.0 |
| 1686 |
Ability to subscribe to inactive Post+ creators |
$0.0 |
| 1687 |
Open redirect in fastify-static via mishandled user's input when attempt to redirect |
$0.0 |
| 1688 |
Store Deletion or Sell without authentication |
$0.0 |
| 1689 |
Content Spoofing |
$0.0 |
| 1690 |
S3 bucket Upload on studio.redditinc.com (s3-r-w.ap-east-1.amazonaws.com) |
$0.0 |
| 1691 |
Outsider can affect Upvote Percentage of private subreddit post by calling /api/vote API |
$0.0 |
| 1692 |
Exposed PHP dependencies at ██.8x8.com |
$0.0 |
| 1693 |
HTML Injection on tiktoktutorials via firstName parameter |
$0.0 |
| 1694 |
Делаем плейлист от любого(почти) пользователя/группы/артиста. |
$0.0 |
| 1695 |
Обход фильтра на ссылки в загрузке историй.. |
$0.0 |
| 1696 |
clickjacking on deleting user's clips [https://crossclip.com/clips] |
$0.0 |
| 1697 |
Broken Link Hijacking on kubernetes.io Documentation |
$0.0 |
| 1698 |
Information disclosure on error message |
$0.0 |
| 1699 |
Fix for CVE-2021-22151 (Kibana path traversal issue) can be bypassed on Windows |
$0.0 |
| 1700 |
HTTP Request Smuggling on https://promosandbox.acronis.com |
$0.0 |
| 1701 |
HTTP Request Smuggling on https://consumer.acronis.com |
$0.0 |
| 1702 |
Clickjacking ar https://hackers.upchieve.org/login |
$0.0 |
| 1703 |
Insufficient session expiration in the com.shopify.ping android app |
$0.0 |
| 1704 |
Просмотр аттачей удаленного сообщения..... |
$0.0 |
| 1705 |
Privilege Escalation leads to trash other users comment without having admin rights. |
$0.0 |
| 1706 |
CSS injection via link tag whitelisted-domain bypass - https://www.glassdoor.com |
$0.0 |
| 1707 |
Bypassing HTML filter in "Packing Slip Template" Lead to SSRF to Internal Kubernetes Endpoints |
$0.0 |
| 1708 |
File System Monitoring Queue Overflow |
$0.0 |
| 1709 |
[h1-2102] [Yaworski's Broskis] Suspected overcharge and chargebacks in PoS |
$0.0 |
| 1710 |
[h1-2102] Wholesale - CSRF to Generate Invitation Token for a Customer and Move Customer to Invited Status |
$0.0 |
| 1711 |
Blind XSS |
$0.0 |
| 1712 |
php info file and sql backup at vendor's subdomain |
$0.0 |
| 1713 |
Clickjacking |
$0.0 |
| 1714 |
Wrong Url in Main page of sifchain.finance |
$0.0 |
| 1715 |
Wrong Implementation of Url in https://docs.sifchain.finance/ |
$0.0 |
| 1716 |
Design Issues at Main Domain |
$0.0 |
| 1717 |
Username disclosure at Main Domain |
$0.0 |
| 1718 |
No Rate limit on change password leads to account takeover |
$0.0 |
| 1719 |
[dubsmash] Username and password bruteforce |
$0.0 |
| 1720 |
Broken Link Takeover from kubernetes.io docs |
$0.0 |
| 1721 |
Reflected Cross-Site Scripting/HTML Injection |
$0.0 |
| 1722 |
Xss At Shopify Email App |
$0.0 |
| 1723 |
Bot setting information leakage in OpenChat room |
$0.0 |
| 1724 |
%0A (New line) and limitness URL leads to DoS at all system [Main adress (https://www.acronis.com/)] |
$0.0 |
| 1725 |
OPEN REDIRECT |
$0.0 |
| 1726 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
$0.0 |
| 1727 |
Prototype pollution via console.table properties |
$0.0 |
| 1728 |
Yet another SSRF query for Javascript |
$0.0 |
| 1729 |
Yet another SSRF query for Javascript |
$0.0 |
| 1730 |
Misconfiguration in build environment allows DLL preloading attack |
$0.0 |
| 1731 |
text injection and content spoofing |
$0.0 |
| 1732 |
Race condition in User comments Likes |
$0.0 |
| 1733 |
Missing SPF record on trycourier.app |
$0.0 |
| 1734 |
Self XSS in Create New Workspace Screen |
$0.0 |
| 1735 |
FULL SSRF |
$0.0 |
| 1736 |
Attachment references in markdown don't warn before downloading |
$0.0 |
| 1737 |
Bypass Email Verification in Customer Portal |
$0.0 |
| 1738 |
Open Redirect TO Stealing aadvid |
$0.0 |
| 1739 |
High memory usage for generating preview of broken image |
$0.0 |
| 1740 |
Occasional use-after-free in multi_done() libcurl-7.81.0 |
$0.0 |
| 1741 |
Binary output bypass |
$0.0 |
| 1742 |
Open Redirect on https://██.8x8.com/login?nextPage=%2F |
$0.0 |
| 1743 |
registering with the same email address multiple times leads to account takeover |
$0.0 |
| 1744 |
Instance Page DOS within Organization on TikTok Ads |
$0.0 |
| 1745 |
Race condition on action: Invite members to a team |
$0.0 |
| 1746 |
Potential Authentication Bypass through "autologin" feature |
$0.0 |
| 1747 |
Misconfigured rate limit at app.sign.plus/forgot_password |
$0.0 |
| 1748 |
EC2 Takeover at turn.shopify.com |
$0.0 |
| 1749 |
[Python]: Add shutil module sinks for path injection query |
$0.0 |
| 1750 |
Information Leakage via TikTok Ads Web Cache Deception |
$0.0 |
| 1751 |
[api.krisp.ai] Race condition on /v2/seats endpoint allows bypassing the original seat limit |
$0.0 |
| 1752 |
Exposed Golang Pprof debugger at https://cn-geo1.uber.com/ |
$0.0 |
| 1753 |
HTML injection through Invite Teammate email |
$0.0 |
| 1754 |
Improper Implementation of SDK Allows Universal XSS in Webview Leading to Account Takeover |
$0.0 |
| 1755 |
User with no Develop apps permission can Uninstall Custom App |
$0.0 |
| 1756 |
Open redirect by the parameter redirectUri in the URL |
$0.0 |
| 1757 |
After changing the storefront password, the preview link is still valid |
$0.0 |
| 1758 |
--libcurl code injection via trigraphs |
$0.0 |
| 1759 |
Force User to Accept Attacker's invite [ Restrict user to create account] |
$0.0 |
| 1760 |
CVE-2022-27775: Bad local IPv6 connection reuse |
$0.0 |
| 1761 |
Github Account Takeover which is used as gradle vcs in "github.com/palantir/gradle-launch-config-plugin" |
$0.0 |
| 1762 |
subdomain takeover at status.hosting24.com |
$0.0 |
| 1763 |
CVE-2022-27781: CERTINFO never-ending busy-loop |
$0.0 |
| 1764 |
Site information's Display Name section vulnerable for XSS attacks and HTML Injections. |
$0.0 |
| 1765 |
Bypass global deny-lists by wrapping domains using "[]" in https://github.com/stripe/smokescreen |
$0.0 |
| 1766 |
Error in Deleting Deck cards attachment reveals the full path of the website |
$0.0 |
| 1767 |
Possible Domain Takeover on AWS Instance. |
$0.0 |
| 1768 |
Waitlist bypass for accessing SIGN.PLUS Beta |
$0.0 |
| 1769 |
Self XSS in attachments name |
$0.0 |
| 1770 |
Github Account Takeover from Docs page of kubernetes-csi.github.io |
$0.0 |
| 1771 |
Heap overflow via HTTP/2 PUSH_PROMISE |
$0.0 |
| 1772 |
Open redirect on https://www.glassdoor.com/profile/siwa.htm via state parameter |
$0.0 |
| 1773 |
Integer overflows in unescape_word() |
$0.0 |
| 1774 |
Reflected Cross Site Scripting at http://www.grouplogic.com/files/glidownload/verify3.asp [Uppercase Filter Bypass] |
$0.0 |
| 1775 |
Reflected Cross Site Scripting at ColdFusion Debugging Panel http://www.grouplogic.com/CFIDE/debug/cf_debugFr.cfm |
$0.0 |
| 1776 |
HTML Injection in E-mail |
$0.0 |
| 1777 |
Hyper Link Injection while signup |
$0.0 |
| 1778 |
curl "globbing" can lead to denial of service attacks |
$0.0 |
| 1779 |
xmlrpc file enabled |
$0.0 |
| 1780 |
Race condition via project team member invitation system. |
$0.0 |
| 1781 |
CSRF Bypassed on Logout Endpoint |
$0.0 |
| 1782 |
Weak rate limit for SIGN.PLUS email verification |
$0.0 |
| 1783 |
CVE-2022-32208: FTP-KRB bad message verification |
$0.0 |
| 1784 |
CVE-2022-32205: Set-Cookie denial of service |
$0.0 |
| 1785 |
Read beyond bounds in ap_strcmp_match() [zhbug_httpd_47.7] |
$0.0 |
| 1786 |
Controllable read beyond bounds in lua_websocket_readbytes() [zhbug_httpd_126] |
$0.0 |
| 1787 |
Read beyond bounds in mod_isapi.c [zhbug_httpd_41] |
$0.0 |
| 1788 |
Read beyond bounds via ap_rwrite() [zhbug_httpd_47.2] |
$0.0 |
| 1789 |
DoS via lua_read_body() [zhbug_httpd_94] |
$0.0 |
| 1790 |
Improper deep link validation |
$0.0 |
| 1791 |
Github base action takeover which is used in github.com/Shopify/unity-buy-sdk |
$0.0 |
| 1792 |
Open Redirect ███.8x8.com |
$0.0 |
| 1793 |
CVE-2019-11248 on http://█.█.█.█:9100/debug/pprof/goroutine |
$0.0 |
| 1794 |
subdomain takeover at odoo-staging.exness.io |
$0.0 |
| 1795 |
Without verifying email and activate account, user can perform all action which are not supposed to be done |
$0.0 |
| 1796 |
CVE-2022-27781: CERTINFO never-ending busy-loop |
$0.0 |
| 1797 |
HTML Injection via Email Share |
$0.0 |
| 1798 |
Twitter Account hijack through broken link in https://runpanther.io |
$0.0 |
| 1799 |
@nextcloud/logger NPM package brings vulnerable ansi-regex version |
$0.0 |
| 1800 |
Open redirection at https://smartreports.mtncameroon.net |
$0.0 |
| 1801 |
Insecure TLS Configuration #3530 |
$0.0 |
| 1802 |
Sensei LMS IDOR to send message |
$0.0 |
| 1803 |
Lack of Brute force protection while joining video call in talk section which is password protected |
$0.0 |
| 1804 |
Disable xmlrpc.php file |
$0.0 |
| 1805 |
Golang expvar Information Disclosure |
$0.0 |
| 1806 |
Blind SSRF on platform.dash.cloudflare.com Due to Sentry misconfiguration |
$0.0 |
| 1807 |
CVE-2022-35252: control code in cookie denial of service |
$0.0 |
| 1808 |
Password reset tokens sent to CSP reporting endpoints |
$0.0 |
| 1809 |
API Key reported in #1465145 not rotated and thus is still valid and can be used by anyone |
$0.0 |
| 1810 |
Wordpress users disclosure from json and xml file |
$0.0 |
| 1811 |
Federated share accepting/declining is not logged in audit log |
$0.0 |
| 1812 |
Password disclosure in initial setup of Mail App |
$0.0 |
| 1813 |
Brute force protections don't work |
$0.0 |
| 1814 |
Exposed gitlab repo at https://adammanco.mtn.com/api/v4/projects |
$0.0 |
| 1815 |
Modifying Sprunk vs eCola crew data |
$0.0 |
| 1816 |
Information exposure in in guzzlehttp/guzzle (https://github.com/nextcloud/3rdparty/tree/master/guzzlehttp/guzzle) |
$0.0 |
| 1817 |
DLL Search-Order Hijacking Vulnerability in work-64-exe-v7.16.3-1.exe |
$0.0 |
| 1818 |
Directory Listing vulnerability on █.packet8.net/php/include/ |
$0.0 |
| 1819 |
Password Policy Restriction Bypass |
$0.0 |
| 1820 |
jira discloser information |
$0.0 |
| 1821 |
Self XSS in https://linkpop.com/dashboard/admin |
$0.0 |
| 1822 |
Found Origin IP's Lead To Access ████ |
$0.0 |
| 1823 |
Bypassing domain deny_list rule in Smokescreen via double brackets [[]] which leads to SSRF |
$0.0 |
| 1824 |
Card requirement bypass for business trial |
$0.0 |
| 1825 |
installed.json sensitive file was publicly accessible on your web application which discloses information about authors and admins |
$0.0 |
| 1826 |
CVE-2022-35260: .netrc parser out-of-bounds access |
$0.0 |
| 1827 |
HTML INJECTION FOUND ON https://adobedocs.github.io/analytics-1.4-apis/swagger-docs.html DUE TO OUTDATED SWAGGER UI |
$0.0 |
| 1828 |
Archived / Deleted / Private Poll Can Be Viewed by Another Users [Crowdsignal WordPress plugins] |
$0.0 |
| 1829 |
Path paths and file disclosure vulnerabilities at influxdb.quality.gitlab.net |
$0.0 |
| 1830 |
CVE-2022-35252: control code in cookie denial of service |
$0.0 |
| 1831 |
Exceed photo dimensions, Flickr.com |
$0.0 |
| 1832 |
Subdomain Takeover on delivey.yelp.com |
$0.0 |
| 1833 |
Directory Listing at https://█.█.█.█ |
$0.0 |
| 1834 |
Jitsi: Attacker is able to cast a vote using the Victim's name on the Polls |
$0.0 |
| 1835 |
CGI::Cookieクラスにおけるセキュリティ上好ましくない仕様および実装 |
$0.0 |
| 1836 |
XSS in Desktop Client via user status and information |
$0.0 |
| 1837 |
XSS in Desktop Client in call notification popup |
$0.0 |
| 1838 |
SSRF - pivoting in the private LAN |
$0.0 |
| 1839 |
SSRF mitigation bypass using DNS Rebind attack |
$0.0 |
| 1840 |
If the website does not impose additional defense against CSRF attacks, failing to use the 'Lax' or 'Strict' values could increase the risk of exposur |
$0.0 |
| 1841 |
Calendar name length not validated before writing to database |
$0.0 |
| 1842 |
CVE-2022-35260: .netrc parser out-of-bounds access |
$0.0 |
| 1843 |
Able to take over .zyrosite.com subdomains via /v3/publish/connect-domain-hostinger API endpoint |
$0.0 |
| 1844 |
A vulnerability classified as critical has been found in gsi-openssh-server 7.9p1 on Fedora (Connectivity Software) on server (http://95.217.64.181:22 |
$0.0 |
| 1845 |
Exposed Log File Lead to Full Internal path disclosure at [https://nextcloud.com/wp-content/debug.log] |
$0.0 |
| 1846 |
Akismet API keys are exposed by authentication method |
$0.0 |
| 1847 |
[user_oidc] Unencrypted Communications |
$0.0 |
| 1848 |
[user_oidc] Stored XSS via Authorization Endpoint - Safari-Only |
$0.0 |
| 1849 |
Missing length validation of user displayname allows to generate an SQL error |
$0.0 |
| 1850 |
mysql credentials exposed on - https://cz.acronis.com/docker-compose.yml |
$0.0 |
| 1851 |
Talk Android broadcast receiver is not protected by broadcastPermission allowing malicious apps to communicate |
$0.0 |
| 1852 |
nextcloudcmd incorrectly trusts bad TLS certificates |
$0.0 |
| 1853 |
CVE-2022-43552: HTTP Proxy deny use-after-free |
$0.0 |
| 1854 |
Dom-Based XSS on parameter ?vsid= |
$0.0 |
| 1855 |
Disabled download shares still allow download through preview images |
$0.0 |
| 1856 |
No password length limit when creating a user as an administrator |
$0.0 |
| 1857 |
libssh backend CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 validation bypass |
$0.0 |
| 1858 |
curl file writing susceptible to symlink attacks |
$0.0 |
| 1859 |
Missing character limitation allows to put generate a database error |
$0.0 |
| 1860 |
Possibility to delete files attached to deck cards of other users |
$0.0 |
| 1861 |
Passcode bypass on Talk Android app |
$0.0 |
| 1862 |
Robots.txt file with potentially sensitive content. |
$0.0 |
| 1863 |
Uninstalling Mattermost Launcher for Windows (64-bit), then reinstalling keeps you logged in without authentication |
$0.0 |
| 1864 |
html injection via invite members can be leads account takeover |
$0.0 |
| 1865 |
Invitation Email is resent as a Reminder after invalidating pending email invites |
$0.0 |
| 1866 |
ABLE TO TRICK THE VICTIM INTO USING A CRAFTED EMAIL ADDRESS FOR A PARTICULAR SESSION AND THEN LATER TAKE BACK THE ACCOUNT |
$0.0 |
| 1867 |
Account takeover due to misconfiguration |
$0.0 |
| 1868 |
PURGE is not authenticated |
$0.0 |
| 1869 |
[song.link] Open Redirect |
$0.0 |
| 1870 |
Any user can vote on Friend Only video pull |
$0.0 |
| 1871 |
wavecell.com: Broken Link Hijacking / Instagram Takeover @██ |
$0.0 |
| 1872 |
Open Redirect |
$0.0 |
| 1873 |
Open Redirection |
$0.0 |
| 1874 |
Mail app - blind SSRF via imapHost parameter |
$0.0 |
| 1875 |
Mail app - Blind SSRF via Sierve server fonctionnality and sieveHost parameter |
$0.0 |
| 1876 |
Mail app - blind SSRF via smtpHost parameter |
$0.0 |
| 1877 |
No password length restriction in reset password endpoint |
$0.0 |
| 1878 |
Double forward slash breaks server-side restrictions & allows access to prohibited services from a partner account |
$0.0 |
| 1879 |
Promotion code can be used more than redemption limit. |
$0.0 |
| 1880 |
HTML injection that may lead to XSS on HackerOne.com through H1 Triage Wizard Chrome Extension |
$0.0 |
| 1881 |
CVE-2023-23915: HSTS amnesia with --parallel |
$0.0 |
| 1882 |
CVE-2023-23914: curl HSTS ignored on multiple requests |
$0.0 |
| 1883 |
View thumbnail of any private video (friends or followers only) of Private/Public account |
$0.0 |
| 1884 |
Messages can still be seen on conversation after expiring when cron is misconfigured |
$0.0 |
| 1885 |
Direct access to tox.ini file which is contain configuration details |
$0.0 |
| 1886 |
Object injection in stripe-billing-typographic GitHub project via /auth/login |
$0.0 |
| 1887 |
Mail app stores cleartext password in database until OAUTH2 setup is done |
$0.0 |
| 1888 |
information disclosure of another company bug on video. |
$0.0 |
| 1889 |
Open Redirect - https://████████.jetblue.com/███?url= |
$0.0 |
| 1890 |
CSRF in Importing CSV files [app.taxjar.com] |
$0.0 |
| 1891 |
Insecure loading of ICU data through ICU_DATA environment variable |
$0.0 |
| 1892 |
Regular Expression Denial of Service in Headers |
$0.0 |
| 1893 |
CVE-2023-27537: HSTS double-free |
$0.0 |
| 1894 |
CVE-2023-27533: Telnet option IAC injection |
$0.0 |
| 1895 |
CVE-2023-27534: SFTP path ~ resolving discrepancy |
$0.0 |
| 1896 |
CVE-2023-27536: GSS delegation too eager connection re-use |
$0.0 |
| 1897 |
CVE-2023-27538: SSH connection too eager reuse still |
$0.0 |
| 1898 |
CVE-2023-27537: HSTS double-free |
$0.0 |
| 1899 |
Bypassing Whitelist to perform SSRF for internal host scanning |
$0.0 |
| 1900 |
Bypassing creation of API tokens without email verification |
$0.0 |
| 1901 |
speedtest.8x8.com: Enabled Directory Listing |
$0.0 |
| 1902 |
Debugging panel exposure |
$0.0 |
| 1903 |
Insecure randomness for default password in file sharing when password policy app is disabled |
$0.0 |
| 1904 |
the complete server installation path is visible in cloud/user endpoint |
$0.0 |
| 1905 |
Dangling DNS Record docs.jitsi.net (unsuccessful GSuite takeover) |
$0.0 |
| 1906 |
Security Unfavorable Specifications and Implementations in the CGI::Cookie Class |
$0.0 |
| 1907 |
Ability to control the filename when uploading a logo or favicon on theming |
$0.0 |
| 1908 |
Testing flow includes a DeepSource secret |
$0.0 |
| 1909 |
Sensitive information for phpinfo.php at https://products.ean.com/ |
$0.0 |
| 1910 |
Possible to spoof Origin in "Connected Sites" |
$0.0 |
| 1911 |
Twitter Broken Link in https://gener8ads.com (Hackerone Profile) |
$0.0 |
| 1912 |
Full Passcode bypass on Nextcloud App iOS |
$0.0 |
| 1913 |
CVE-2018-6389 exploitation - using scripts loader |
$0.0 |
| 1914 |
Delete any user's added Email,Telephone,Fax,Address,Skype via csrf in (https://academy.acronis.com/) |
$0.0 |
| 1915 |
Missing brute force protection for passwords of password protected share links |
$0.0 |
| 1916 |
Improper Access Control - Generic |
$0.0 |
| 1917 |
HTML INJECTION on coins.state.gov |
$0.0 |
| 1918 |
Credential leak on GitHub: https://github.com/█/█/ (Peoplesoft CRM) |
$0.0 |
| 1919 |
Hide download previews are accessible without a watermark |
$0.0 |
| 1920 |
App pin of the Android app can be bypassed via 3rdparty apps generating deep links |
$0.0 |
| 1921 |
Attacker can unpin posts from companies he's not part of. |
$0.0 |
| 1922 |
HTML injection in email at https://www.hackerone.com/ |
$0.0 |
| 1923 |
No rate limit while adding Additional emails feature |
$0.0 |
| 1924 |
CVE-2023-28320: siglongjmp race condition |
$0.0 |
| 1925 |
CVE-2023-28322: more POST-after-PUT confusion |
$0.0 |
| 1926 |
CVE-2023-28321: IDN wildcard match |
$0.0 |
| 1927 |
Program managers can see draft reports using Export Reports feature |
$0.0 |
| 1928 |
Rate limit is implemented in Reddit , but its not working . |
$0.0 |
| 1929 |
Impact of Using the PHP Function "phpinfo()" on System Security - PHP info page disclosure |
$0.0 |
| 1930 |
Blind SSRF as normal user from mailapp |
$0.0 |
| 1931 |
Any one can view collaborater email address via path /reports//participants |
$0.0 |
| 1932 |
Arbitrary escape sequence injection in docker-machine from worker nodes |
$0.0 |
| 1933 |
IDOR in family pairing API |
$0.0 |
| 1934 |
DOS via cache poisoning on [developer.mozilla.org] |
$0.0 |
| 1935 |
Attachment in published HackerOne report exposure private program |
$0.0 |
| 1936 |
[python]: Add some dangerous sinks for paramiko ssh clients |
$0.0 |
| 1937 |
Error in Booking an appointment reveals the full path of the website |
$0.0 |
| 1938 |
CRLF Inection at ██████████ |
$0.0 |
| 1939 |
CVE-2023-28322: more POST-after-PUT confusion |
$0.0 |
| 1940 |
CVE-2023-28321: IDN wildcard match |
$0.0 |
| 1941 |
connect.8x8.com: Too much resource consumption of the server due to incorrect date range control via /api/v1/reports?dateFrom= |
$0.0 |
| 1942 |
The stripe/veneur GitHub repository links to a domain veneur.org, which is not under stripe's control |
$0.0 |
| 1943 |
Error Page Content Spoofing or Text Injection |
$0.0 |
| 1944 |
2M Reports on HackerOne Celebration! - Ability to bulk-submit many reports. |
$0.0 |
| 1945 |
RDoc::MethodAttr is vulnerable to Regular Expression Denial of Service (ReDoS) |
$0.0 |
| 1946 |
💥💥Crash report -Cloudflare WARP doesn't verify text length in "Excluded Host" name input data💥💥 |
$0.0 |
| 1947 |
Apache mod_negotiation filename bruteforcing https://api.ratelimited.me |
$0.0 |
| 1948 |
Usernames still visible on report export pdf despite "I want to redact all usernames" is selected |
$0.0 |
| 1949 |
Notes attachments render HTML in preview mode |
$0.0 |
| 1950 |
fs.mkdtemp() and fs.mkdtempSync() are missing getValidatedPath() checks. |
$0.0 |
| 1951 |
Cross-origin resource sharing: arbitrary origin trusted |
$0.0 |
| 1952 |
Bypass of #2035332 RXSS at image.hackerone.live via the url parameter |
$0.0 |
| 1953 |
App stores client secret unencrypted in database |
$0.0 |
| 1954 |
Improper access control on Linkedin Page |
$0.0 |
| 1955 |
A Unverified User Can Post Newsletter (Which Is Not Allowed Through Application UI) |
$0.0 |
| 1956 |
Entering passwords on the Share Login Page can lead to a brute-force attack |
$0.0 |
| 1957 |
Names not completely redacted despite "Redact the names of the involved users" is selected |
$0.0 |
| 1958 |
Google dork lead to unsubscribe anyone from all Banfield emails |
$0.0 |
| 1959 |
fs.statfs bypasses Permission Model |
$0.0 |
| 1960 |
No Rate Limit On Forgot Password Page |
$0.0 |
| 1961 |
Multiple cross-site scripting (XSS) vulnerabilities in Revive Adserver |
$0.0 |
| 1962 |
Potential NULL dereference in libssh's sftp server |
$0.0 |
| 1963 |
Possibility to guess email address from gravatar image URL |
$0.0 |
| 1964 |
Stored Xss on bugzilla.mozilla.org via comment edit feature from non-admin to admin. |
$0.0 |
| 1965 |
If rate limit is hit, IP address is leaked to anyone who tries to login |
$0.0 |
| 1966 |
Existance of calendars and addressbooks can be checked by unauthenticated users |
$0.0 |
| 1967 |
Twitter account hijack @Costalfy |
$0.0 |
| 1968 |
Previously created sessions continue being valid after 2FA activation |
$0.0 |
| 1969 |
(CVE-2023-32003) fs.mkdtemp() and fs.mkdtempSync() are missing getValidatedPath() checks |
$0.0 |
| 1970 |
No Rate Limit in Login Page |
$0.0 |
| 1971 |
CVE-2023-38546: cookie injection with none file |
$0.0 |
| 1972 |
Exposing Django Debug Panel and Sensitive Infrastructure Information at https://dev.fxprivaterelay.nonprod.cloudops.mozgcp.net |
$0.0 |
| 1973 |
Open Redirect - Polycom Company Directory |
$0.0 |
| 1974 |
HTML injection at Company Name or Product Name and can be shown on Contact Sales form |
$0.0 |
| 1975 |
HTML Injection at https://stage.firefoxmonitor.nonprod.cloudops.mozgcp.net/user/unsubscribe |
$0.0 |
| 1976 |
Flickr API key leaked in GitHub commit |
$0.0 |
| 1977 |
Possibility of Deface through translation tool - www.mozilla.com |
$0.0 |
| 1978 |
Race condition in up voting and down voting |
$0.0 |
| 1979 |
Unauthorized Access to Deleted Interviews on Glassdoor Platform |
$0.0 |
| 1980 |
CVE-2023-40611: Apache Airflow Dag Runs Broken Access Control Vulnerability |
$0.0 |
| 1981 |
Security bug https://bugzilla.mozilla.org/oauth/authorize - CRLF Header injection via "redirect_uri" parameter |
$0.0 |
| 1982 |
YAML schema injection risk in Swagger UI via schema_url parameter at developers.cloudflare.com |
$0.0 |
| 1983 |
Able to see highest poll result without voting or view result |
$0.0 |
| 1984 |
HTML injection in search UI when selecting a circle with HTML in the display name |
$0.0 |
| 1985 |
CSRF to Information disclosure on password reset |
$0.0 |
| 1986 |
Content spoofing on |
$0.0 |
| 1987 |
Tor Project - Full Path Disclosure |
$0.0 |
| 1988 |
solving TOR vulnerability, in other to make bruteforce difficult |
$0.0 |
| 1989 |
Potential IP revealing using UNC Path in Windows File Picker |
$0.0 |
| 1990 |
CVE-2023-47037: Airflow Broken Access Control Vulnerability |
$0.0 |
| 1991 |
internal path disclosure via register error |
$0.0 |
| 1992 |
User Details Can Be Disclosed Even If The Account IS In Hibernation State |
$0.0 |
| 1993 |
CVE-2023-46219: HSTS long file name clears contents |
$0.0 |
| 1994 |
Private program name disclosure in the invitation mail for another program |
$0.0 |
| 1995 |
Web API key registration allows registering multiple keys by reusing request_id |
$0.0 |
| 1996 |
App PIN code can be bypassed in Files iOS |
$0.0 |
| 1997 |
Text Injection/ Content Spoofing on https://cloud.e.khanacademy.org by breaking out of input tag. |
$0.0 |
| 1998 |
Blind SSRF in Mail App |
$0.0 |
| 1999 |
Exposure of account recovery hint by querying by user email |
$0.0 |
| 2000 |
[h1-2102] [Oberlo] Least privileged user can cancel account owner's subscription via POST on /payments/subscribe |
$0.0 |
| 2001 |
Open redirect in user_saml via RelayState parameter |
$0.0 |
| 2002 |
curl HSTS long file name clears contents |
$0.0 |
| 2003 |
Html injection in event Description |
$0.0 |
| 2004 |
No CSRF protection when adding an item to cart |
$0.0 |
| 2005 |
CVE-2024-0853: OCSP verification bypass with TLS session reuse |
$0.0 |
| 2006 |
CORS Misconfiguration on █████ |
$0.0 |
| 2007 |
Vulnerability Report: NO RATE LIMIT Password RESET |
$0.0 |
| 2008 |
CSRF to delete a pet on ██████ |
$0.0 |
| 2009 |
Host Header Injection - internal.qa.delivery.indrive.com |
$0.0 |
| 2010 |
Information Disclosure |
$0.0 |
| 2011 |
Multiple Open Redirect on TikTok domains |
$0.0 |
| 2012 |
Sensitive information disclosure on grafana |
$0.0 |
| 2013 |
Session Doesn't expire after 2fa and also other session can change passsword |
$0.0 |
| 2014 |
Program admins could add verified domains to an organization |
$0.0 |
| 2015 |
Proxy-Authorization header is not cleared in cross-domain redirect in undici |
$0.0 |
| 2016 |
Insecure S3 Bucket Exposing Git Directory in Mozilla Foundation Infographics Project |
$0.0 |
| 2017 |
Github app(link) Takeover Listed on "https://docs.doppler.com/docs/github-actions" page |
$0.0 |
| 2018 |
XSS in new.loading.page.html |
$0.0 |
| 2019 |
PATCH method manipulation allowing the users to escalate their functionalities and edit (upgrade/downgrade) API Keys settings which is not allowed |
$0.0 |
| 2020 |
CVE-2024-2379: QUIC certificate check bypass with wolfSSL |
$0.0 |
| 2021 |
CVE-2024-0853: OCSP verification bypass with TLS session reuse |
$0.0 |
| 2022 |
CVE-2024-2004: Usage of disabled protocol |
$0.0 |
| 2023 |
#3 XSS on watchdocs.indriverapp.com |
$0.0 |
| 2024 |
#1 XSS on watchdocs.indriverapp.com |
$0.0 |
| 2025 |
Adobe Experience Manager 'Childlist selector' - Cross-Site Scripting on cbconnection-stage.adobe.com |
$0.0 |
| 2026 |
Adobe Experience Manager 'Childlist selector' - Cross-Site Scripting on cbconnection.adobe.com |
$0.0 |
| 2027 |
Proxy-Authorization header not cleared on cross-origin redirect in undici.request |
$0.0 |
| 2028 |
Unsafe yaml load can lead to remote code execution |
$0.0 |
| 2029 |
Confirmed #2118458: Intentional redirect from www.hackerone.com to domain which is up for sale |
$0.0 |
| 2030 |
Bitly link takeover |
$0.0 |
| 2031 |
Changing the administrator password via admin console does not invalidate other sessions |
$0.0 |
| 2032 |
A user with only [MODIFY_SETTINGS] permmision could takeover any user accounts |
$0.0 |
| 2033 |
Acquisition on broken link listed on the page "https://docs.doppler.com/docs/removal-deprecated-packages-scripts in [scheduling a call] |
$0.0 |
| 2034 |
[CVE-2024-25126] Denial of Service Vulnerability in Rack Content-Type Parsing |
$0.0 |
| 2035 |
[CVE-2024-26142] ReDoS vulnerability in Accept header parsing in Action Dispatch |
$0.0 |
| 2036 |
[CVE-2024-26146] Header Parsing leads to Possible Denial of Service Vulnerability |
$0.0 |
| 2037 |
Stored XSS filter bypass on discussion forum. |
$0.0 |
| 2038 |
Comment/channel unsubscribe GET CSRF |
$0.0 |
| 2039 |
Arbitrary forum topic close with GET CSRF. |
$0.0 |
| 2040 |
Arbitrary comment content change with GET CSRF. |
$0.0 |
| 2041 |
Import/Convert user file exposure leading to logins/passwords/PII leak. |
$0.0 |
| 2042 |
[ Spot Check ] Team members can edit a user's write-up |
$0.0 |
| 2043 |
Incorrect Encoding Conversion in hostname results in indeterminate SSRF vulnerabilities |
$0.0 |
| 2044 |
Cloudflare /cdn-cgi/ path allows resizing images from unauthorised sources on enjinusercontent.com |
$0.0 |
| 2045 |
[IDOR] Improper Access Control on Embedded Submission Form |
$0.0 |
| 2046 |
NULL dereference when encoding DN of x509 certificate |
$0.0 |
| 2047 |
CSRF resulting in adding pet at ███████ |
$0.0 |
| 2048 |
Authentication Bypass on TikTok Seller Signup Process Allows Account Creation Without Phone Verification |
$0.0 |
| 2049 |
fs.fchown/fchmod bypasses permission model |
$0.0 |
| 2050 |
fs.lstat bypasses permission model |
$0.0 |
| 2051 |
XSS on LINE CAREERS |
$0.0 |
| 2052 |
Rocket.Chat Desktop client fails to open browser on 3rd party external actions from PDF documents |
$0.0 |
| 2053 |
Reports submitted by a non 2fa setupped user account can be transferred to a 2fa require submission program |
$0.0 |
| 2054 |
Missing permission check when removing a photo from an album |
$0.0 |
| 2055 |
Permission model improperly processes UNC paths |
$0.0 |
| 2056 |
HTML Injection into https://www.██████.mil |
$0.0 |
| 2057 |
Minor security issue with Hackerone Invitations from sandbox program |
$0.0 |
| 2058 |
CVE-2024-6874: macidn punycode buffer overread |
$0.0 |
| 2059 |
CVE-2024-7264: ASN.1 date parser overread |
$0.0 |
| 2060 |
IDOR lets a malicious user reveal the unpinned achievement badges of any Reddit user |
$0.0 |
| 2061 |
Bypassing 2FA with conventional session management - open.rocket.chat |
$0.0 |
| 2062 |
Source Code and data exfiltration via Github Copilot |
$0.0 |
| 2063 |
CSRF and XSS on www.acronis.com |
$0.0 |
| 2064 |
XSS in https://promo.acronis.com/ |
$0.0 |
| 2065 |
HTML injection in swagger UI |
$0.0 |
| 2066 |
Local Privilege Escalation via EXE hijacking with Acronis True Image 2021 installer |
$0.0 |
| 2067 |
Local Privilege Escalation via EXE hijacking with Acronis True Image 2021 - Acronis Scheduler2 Service |
$0.0 |
| 2068 |
Acronis True Image 2020 Build 22510 Nonstop Backup Service Unquoted service path (privilege escalation) |
$0.0 |
| 2069 |
Reflected XSS on www.acronis.com/de-de/my/subscriptions/index.html |
$0.0 |
| 2070 |
Unauthenticated Varnish Cache Purge |
$0.0 |
| 2071 |
curl: stack-buffer overread during punycode conversions |
$0.0 |
| 2072 |
Able to see location coordinates in any event without permission to do so |
$0.0 |
| 2073 |
XSS when using translate in Action Controller (Rails 7.0, 7.1) |
$0.0 |
| 2074 |
Stored-XSS-ads.tiktok.com |
$0.0 |
| 2075 |
Subdomain takeover in Gitlab pages |
$0.0 |
| 2076 |
IDOR vulnerability leads to Deleting message after leaving/getting banned from group using message ID |
$0.0 |