Skip to content

Latest commit

 

History

History
720 lines (528 loc) · 9.55 KB

File metadata and controls

720 lines (528 loc) · 9.55 KB

Title

Получение чужого номера телефона (все цифры) через форму восстановления пароля

URL

https://hackerone.com/reports/350939

Severity score

null

Reporter

namthar

Bounty paid

$300


Title

Unauthorized Use of Victim Credit Card

URL

https://hackerone.com/reports/391385

Severity score

3.5

Reporter

hk755a

Bounty paid

$400


Title

GetReports works for hubs you don't have access to

URL

https://hackerone.com/reports/350937

Severity score

5

Reporter

milkgames

Bounty paid

$750


Title

Private target account appears in search results

URL

https://hackerone.com/reports/708696

Severity score

null

Reporter

magic_spell

Bounty paid

null


Title

[IRCCloud Android] Theft of arbitrary files leading to token leakage

URL

https://hackerone.com/reports/288955

Severity score

null

Reporter

bagipro

Bounty paid

$500


Title

Email PII disclosure due to Insecure Password Reset field

URL

https://hackerone.com/reports/520842

Severity score

null

Reporter

alyssa_herrera

Bounty paid

null


Title

Expired Available Domains in nordvpn.com website code

URL

https://hackerone.com/reports/791674

Severity score

null

Reporter

khizer47

Bounty paid

null


Title

Узнаем новые email приглашенного нами пользователя после смены, и так же часть номера телефона

URL

https://hackerone.com/reports/529367

Severity score

null

Reporter

povargek

Bounty paid

$300


Title

Tracking of users on third-party websites using the Twitter cookie, due to a flaw in authenticating image requests

URL

https://hackerone.com/reports/329957

Severity score

6.5

Reporter

cris-staicu

Bounty paid

$1,120


Title

CRITICAL Insecure Direct Object Reference (I.D.O.R) - Link Other User's Credit Card

URL

https://hackerone.com/reports/358143

Severity score

7.2

Reporter

hk755a

Bounty paid

$2,000


Title

Show hide privacy giving receiving on my website

URL

https://hackerone.com/reports/262088

Severity score

null

Reporter

test99767

Bounty paid

null


Title

Captcha Bypass on SignUp Form

URL

https://hackerone.com/reports/277300

Severity score

null

Reporter

apapedulimu

Bounty paid

null


Title

NordVPN Android Application privacy violation due to Google Advertising Identifier misuse

URL

https://hackerone.com/reports/803941

Severity score

null

Reporter

tomtenisse

Bounty paid

$200


Title

[marketplace.informatica.com] - Sensitive Data Exposure

URL

https://hackerone.com/reports/270695

Severity score

null

Reporter

shogunlab

Bounty paid

null


Title

[marketplace.informatica.com] User email disclosure

URL

https://hackerone.com/reports/230608

Severity score

null

Reporter

shogunlab

Bounty paid

null


Title

A small set of users were assigned someone else's payout preference

URL

https://hackerone.com/reports/498845

Severity score

2.7

Reporter

jobert

Bounty paid

null


Title

IP address can be leaked on Image preview in ICQ for Android chat

URL

https://hackerone.com/reports/736800

Severity score

3.4

Reporter

rainbow_json

Bounty paid

$150


Title

Trusted daemon check fails when proxied through torsocks or proxychains

URL

https://hackerone.com/reports/361269

Severity score

null

Reporter

equim

Bounty paid

null


Title

Physical Laptop Takeover

URL

https://hackerone.com/reports/393615

Severity score

null

Reporter

glassofbeer

Bounty paid

null


Title

Просмотр привязного к странице email, всего лишь раз скомпрометировав письмо-уведомление

URL

https://hackerone.com/reports/223172

Severity score

null

Reporter

povargek

Bounty paid

$100


Title

Any authenticated user can download full list of users, including email

URL

https://hackerone.com/reports/228399

Severity score

5

Reporter

arkadiyt

Bounty paid

$256


Title

application/x-brave-tab should not be readable.

URL

https://hackerone.com/reports/258578

Severity score

null

Reporter

qab

Bounty paid

$250


Title

Incorrect details on OAuth permissions screen allows DMs to be read without permission

URL

https://hackerone.com/reports/434763

Severity score

4.3

Reporter

edent

Bounty paid

$2,940


Title

Unauthorized Access to Protected Tweets via niche.co API

URL

https://hackerone.com/reports/273698

Severity score

null

Reporter

eidelweiss

Bounty paid

null


Title

Weak Password Policy on techsupport.teradici.com

URL

https://hackerone.com/reports/228323

Severity score

null

Reporter

imxx

Bounty paid

null


Title

Detect Tor Browser's language

URL

https://hackerone.com/reports/588239

Severity score

0

Reporter

ryotak

Bounty paid

null


Title

Раскрытие имени файла приватных документов

URL

https://hackerone.com/reports/219715

Severity score

null

Reporter

zhumarin

Bounty paid

$100


Title

languagechange event fires simultaneously on all tabs

URL

https://hackerone.com/reports/257942

Severity score

null

Reporter

tomvg

Bounty paid

$100


Title

Unauthorized User Can Delete Any User Account

URL

https://hackerone.com/reports/803141

Severity score

null

Reporter

d4rk_g1rl

Bounty paid

$100


Title

Cross-domain linkability when system time changed in Tor Browser

URL

https://hackerone.com/reports/282339

Severity score

null

Reporter

xiaoyinl

Bounty paid

null


Title

Detecting Tor Browser UI Language

URL

https://hackerone.com/reports/282748

Severity score

null

Reporter

xiaoyinl

Bounty paid

$200


Title

Twitter ID exposure via error-based side-channel attack

URL

https://hackerone.com/reports/505424

Severity score

5.7

Reporter

terjanq

Bounty paid

$1,470


Title

Privacy violation для аттачей в сообщениях.

URL

https://hackerone.com/reports/377115

Severity score

null

Reporter

iframe

Bounty paid

$500


Title

Sensitive Email disclosure Due to Insecure Reactivate Account field

URL

https://hackerone.com/reports/235041

Severity score

null

Reporter

alyssa_herrera

Bounty paid

null


Title

Nextcloud domain and name of every user leaked to lookup server

URL

https://hackerone.com/reports/508490

Severity score

6.8

Reporter

leonklingele

Bounty paid

$100


Title

Email Not Completely Deleted after Deleting an account

URL

https://hackerone.com/reports/386596

Severity score

null

Reporter

0xspade

Bounty paid

$100


Title

Gateway information leakage

URL

https://hackerone.com/reports/258410

Severity score

null

Reporter

hackerfactor

Bounty paid

null


Title

Changing email address on Twitter for Android unsets "Protect your Tweets"

URL

https://hackerone.com/reports/472013

Severity score

null

Reporter

nyuszika7h

Bounty paid

$2,940


Title

Вставляем свой код в мобильном приложении в разделе помощи сообществам

URL

https://hackerone.com/reports/433904

Severity score

null

Reporter

catferq

Bounty paid

$300


Title

Confidential data of users and limited metadata of programs and reports accessible via GraphQL

URL

https://hackerone.com/reports/489146

Severity score

9.3

Reporter

yashrs

Bounty paid

$20,000


Title

Connection informaton is sent to a third-party service

URL

https://hackerone.com/reports/752402

Severity score

null

Reporter

martinbydefault

Bounty paid

$7,777


Title

User data not anonymized is sent to analytics server

URL

https://hackerone.com/reports/781238

Severity score

null

Reporter

martinbydefault

Bounty paid

$1,000


Title

OS username disclosure

URL

https://hackerone.com/reports/258585

Severity score

null

Reporter

qab

Bounty paid

$100


Title

User Profiles Leak PII in HTML Document for Mobile Browser User Agents

URL

https://hackerone.com/reports/288596

Severity score

5.3

Reporter

chriszielinski

Bounty paid

$500


Title

Information Disclosure which violate program privacy

URL

https://hackerone.com/reports/313075

Severity score

null

Reporter

eqbang

Bounty paid

null


Title

Corrupt RPC responses from remote daemon nodes can lead to transaction tracing

URL

https://hackerone.com/reports/304770

Severity score

null

Reporter

monero-hax123

Bounty paid

null


Title

User sensitive information disclosure

URL

https://hackerone.com/reports/975047

Severity score

null

Reporter

a_yang

Bounty paid

$1,000


Title

Account deletion requests not entirely honoured. Misinformation even after seeking clarification from customer support.

URL

https://hackerone.com/reports/813421

Severity score

null

Reporter

keshavkejriwal

Bounty paid

$100