Git Product home page Git Product logo

hackerone-reports's Introduction

#Hackerone-Reports

  1. https://hackerone.com/reports/120 | Missing SPF for hackerone.com
  2. https://hackerone.com/reports/280 | Real impersonation
  3. https://hackerone.com/reports/284 | Broken Authentication and session management OWASP A2
  4. https://hackerone.com/reports/288 | Session Management
  5. https://hackerone.com/reports/298 | RTL override symbol not stripped from file names
  6. https://hackerone.com/reports/321 | CSP not consistently applied
  7. https://hackerone.com/reports/353 | Session not expired on logout
  8. https://hackerone.com/reports/390 | Pixel flood attack
  9. https://hackerone.com/reports/400 | GIF flooding
  10. https://hackerone.com/reports/454 | PNG compression DoS
  11. https://hackerone.com/reports/477 | Flawed account creation process allows registration of usernames corresponding to existing file names
  12. https://hackerone.com/reports/487 | DNS Cache Poisoning
  13. https://hackerone.com/reports/499 | Ruby: Heap Overflow in Floating Point Parsing
  14. https://hackerone.com/reports/500 | OpenSSH: Memory corruption in AES-GCM support
  15. https://hackerone.com/reports/501 | TLS Virtual Host Confusion
  16. https://hackerone.com/reports/523 | PHP openssl_x509_parse() Memory Corruption Vulnerability
  17. https://hackerone.com/reports/546 | Logical issues with account settings
  18. https://hackerone.com/reports/547 | CSRF login
  19. https://hackerone.com/reports/575 | Email spoofing
  20. https://hackerone.com/reports/713 | Upload profile photo from URL
  21. https://hackerone.com/reports/727 | Switching the user to the attacker's account
  22. https://hackerone.com/reports/737 | Improper session management
  23. https://hackerone.com/reports/738 | Information disclosure (reset password token) and changing the user's password
  24. https://hackerone.com/reports/742 | A password reset page does not properly validate the authenticity token at the server side.
  25. https://hackerone.com/reports/774 | Log in a user to another account
  26. https://hackerone.com/reports/809 | Improperly implemented password recovery link functionality
  27. https://hackerone.com/reports/842 | Autocomplete enabled in Paypal preferences
  28. https://hackerone.com/reports/1356 | PHP Heap Overflow Vulnerability in imagecrop()
  29. https://hackerone.com/reports/1509 | DNS Misconfiguration
  30. https://hackerone.com/reports/2106 | Flash type confusion vulnerability leads to code execution
  31. https://hackerone.com/reports/2107 | Handling of jar: URIs bypasses AllowScriptAccess=never
  32. https://hackerone.com/reports/2140 | Flash local-with-fileaccess Sandbox Bypass
  33. https://hackerone.com/reports/2170 | Flash double free vulnerability leads to code execution
  34. https://hackerone.com/reports/2221 | CSS leaks SCSS debug info
  35. https://hackerone.com/reports/2224 | Bypass auth.email-domains
  36. https://hackerone.com/reports/2228 | Login CSRF using Twitter OAuth
  37. https://hackerone.com/reports/2233 | Bypass auth.email-domains (2)
  38. https://hackerone.com/reports/2421 | Value of JSESSIONID and XSRF token parameter in cookie remains same before and after login
  39. https://hackerone.com/reports/2427 | XSRF token problem
  40. https://hackerone.com/reports/2439 | Cross Site Scripting (XSS) - app.relateiq.com
  41. https://hackerone.com/reports/2497 | Reflective XSS can be triggered in IE
  42. https://hackerone.com/reports/2559 | Broken Authentication (including Slack OAuth bugs)
  43. https://hackerone.com/reports/2575 | Slack OAuth2 "redirect_uri" Bypass
  44. https://hackerone.com/reports/2584 | Weird Bug - Ability to see partial of other user's notification
  45. https://hackerone.com/reports/2617 | Stored XSS in www.slack-files.com
  46. https://hackerone.com/reports/2622 | URL redirection flaw
  47. https://hackerone.com/reports/2625 | Stored XSS in username.slack.com
  48. https://hackerone.com/reports/2628 | CSRF vulnerability on https://sehacure.slack.com/account/settings
  49. https://hackerone.com/reports/2652 | Stored XSS in Channel Chat
  50. https://hackerone.com/reports/2735 | HTML injection in "Invite Collaborators"
  51. https://hackerone.com/reports/2777 | Reflected Xss
  52. https://hackerone.com/reports/3227 | Control Characters Not Stripped From Username on Signup
  53. https://hackerone.com/reports/3356 | UnAuthorized Editorial Publishing to Blogs
  54. https://hackerone.com/reports/3370 | Directory traversal attack in view resolver
  55. https://hackerone.com/reports/3441 | Captcha Bypass With Extension
  56. https://hackerone.com/reports/3455 | flash content type sniff vulnerability in api.slack.com
  57. https://hackerone.com/reports/3596 | OAuth access_token stealing in Phabricator
  58. https://hackerone.com/reports/3921 | Control character allowed in username
  59. https://hackerone.com/reports/3930 | OAuth Stealing Attack (New)
  60. https://hackerone.com/reports/3986 | Securing sensitive pages from SearchBots
  61. https://hackerone.com/reports/4114 | Persistent XSS: Editor link
  62. https://hackerone.com/reports/4409 | TRACE disclosure attack may be possible
  63. https://hackerone.com/reports/4561 | Stored XSS in Slackbot Direct Messages
  64. https://hackerone.com/reports/4638 | Duplicate of #4550
  65. https://hackerone.com/reports/4689 | SPDY memory corruption
  66. https://hackerone.com/reports/4690 | SPDY heap buffer overflow
  67. https://hackerone.com/reports/5314 | Coinbase Android Application - Bitcoin Wallet Leaks OAuth Response Code
  68. https://hackerone.com/reports/5786 | Coinbase Android Security Vulnerabilities
  69. https://hackerone.com/reports/5928 | Uncontrolled Resource Consumption with XMPP-Layer Compression
  70. https://hackerone.com/reports/5933 | Multiple Issues related to registering applications
  71. https://hackerone.com/reports/5946 | Marking notifications as read CSRF bug
  72. https://hackerone.com/reports/6002 | Stored XSS in Slack.com
  73. https://hackerone.com/reports/6017 | Facebook Takeover using Slack using 302 from files.slack.com with access_token
  74. https://hackerone.com/reports/6350 | creating titleless and non-closable bugs
  75. https://hackerone.com/reports/6353 | Wildcard DNS in website
  76. https://hackerone.com/reports/6380 | Same Origin Security Bypass Vulnerability
  77. https://hackerone.com/reports/6389 | Integer overflow in strop.expandtabs
  78. https://hackerone.com/reports/6626 | TLS heartbeat read overrun
  79. https://hackerone.com/reports/6871 | Login CSRF
  80. https://hackerone.com/reports/6872 | Sign up CSRF
  81. https://hackerone.com/reports/6877 | Unsecure cookies, cookie flag secure not set
  82. https://hackerone.com/reports/6883 | Bruteforcing irccloud login
  83. https://hackerone.com/reports/6884 | Leaking Referrer in Reset Password Link
  84. https://hackerone.com/reports/6907 | Session Token is not Verified while changing Account Setting's which Result In account Takeover
  85. https://hackerone.com/reports/6910 | Full account takeover using CSRF and password reset
  86. https://hackerone.com/reports/6935 | Missing X-Content-Type-Options
  87. https://hackerone.com/reports/7036 | Bug in iOS application which could lead to unauthorised access.
  88. https://hackerone.com/reports/7041 | iOS application does not destroy session upon logout.
  89. https://hackerone.com/reports/7121 | Persistent Cross Site Scripting within the IRCCloud Pastebin
  90. https://hackerone.com/reports/7277 | TLS Triple Handshake Attack
  91. https://hackerone.com/reports/7357 | Host Header is not validated resulting in Open Redirect
  92. https://hackerone.com/reports/7369 | 2 factor authentication design flaw
  93. https://hackerone.com/reports/7441 | Dangerous Persistent xss
  94. https://hackerone.com/reports/7531 | Login CSRF can be bypassed (Similar approach to previous one).
  95. https://hackerone.com/reports/7803 | Security bypass could lead to information disclosure
  96. https://hackerone.com/reports/7931 | Issue with remember_user_token
  97. https://hackerone.com/reports/8082 | Password Reset Bug
  98. https://hackerone.com/reports/8724 | Clickjacking
  99. https://hackerone.com/reports/8846 | localStorage не чи�тит�� по�ле выхода
  100. https://hackerone.com/reports/9318 | Home page reflected XSS
  101. https://hackerone.com/reports/9375 | Stored XSS in all fields in Basic Google Maps Placemarks Settings
  102. https://hackerone.com/reports/9391 | Xss in CampTix Event Ticketing
  103. https://hackerone.com/reports/9479 | Anti-MIME-Sniffing header X-Content-Type-Options header has not been set.
  104. https://hackerone.com/reports/9774 | Stored XSS Found
  105. https://hackerone.com/reports/9919 | SQL injection [дырка в движке форума]
  106. https://hackerone.com/reports/9921 | Time based sql injection
  107. https://hackerone.com/reports/10037 | SQL inj
  108. https://hackerone.com/reports/10081 | SQL
  109. https://hackerone.com/reports/10297 | Stored XSS in slack.com (integrations)
  110. https://hackerone.com/reports/10373 | Bypassing Same Origin Policy With JSONP APIs and Flash
  111. https://hackerone.com/reports/10468 | SQL inj
  112. https://hackerone.com/reports/10554 | Bypassing 2FA for BTC transfers
  113. https://hackerone.com/reports/10563 | CSRF on "Set as primary" option on the accounts page
  114. https://hackerone.com/reports/10829 | CSRF in function "Set as primary" on accounts page
  115. https://hackerone.com/reports/11073 | XSS in gist integration
  116. https://hackerone.com/reports/11410 | XSS in https://e.mail.ru/cgi-bin/lstatic (Limited use)
  117. https://hackerone.com/reports/11861 | SQL injection update.mail.ru
  118. https://hackerone.com/reports/11919 | Stored XSS on http://top.mail.ru
  119. https://hackerone.com/reports/11927 | Stored XSS on http://cards.mail.ru
  120. https://hackerone.com/reports/12297 | Python vulnerability: reading arbitrary process memory
  121. https://hackerone.com/reports/12497 | Adobe Flash Player FileReference Use-after-Free Vulnerability
  122. https://hackerone.com/reports/12583 | XXE and SSRF on webmaster.mail.ru
  123. https://hackerone.com/reports/12588 | XSS in a file or folder name
  124. https://hackerone.com/reports/13195 | auth.mail.ru: XSS in login form
  125. https://hackerone.com/reports/13286 | Host Header Injection - irccloud.com
  126. https://hackerone.com/reports/13748 | Potential denial of service in hackerone.com/teams/new
  127. https://hackerone.com/reports/13959 | privilege escalation
  128. https://hackerone.com/reports/14033 | connect.mail.ru: SSRF
  129. https://hackerone.com/reports/14127 | SSRF on https://whitehataudit.slack.com/account/photo
  130. https://hackerone.com/reports/14570 | Login password guessing attack
  131. https://hackerone.com/reports/14631 | Clickjacking at https://www.mavenlink.com/ main website
  132. https://hackerone.com/reports/15166 | Password reset token not expiring
  133. https://hackerone.com/reports/15362 | Flash Sandbox Bypass
  134. https://hackerone.com/reports/15412 | Leaking CSRF token over HTTP resulting in CSRF protection bypass
  135. https://hackerone.com/reports/15762 | SQL Injection on 11x11.mail.ru
  136. https://hackerone.com/reports/15785 | Session not invalidated after password reset
  137. https://hackerone.com/reports/15852 | Non Validation of session after password reset
  138. https://hackerone.com/reports/16315 | Abusing VCS control on phabricator
  139. https://hackerone.com/reports/16330 | Multiple issues in looking-glass software (aka from web to BGP injections)
  140. https://hackerone.com/reports/16392 | Abusing daemon logs for Privilege escalation under certain scenarios
  141. https://hackerone.com/reports/16568 | Failed Certificate Validation On Custom Server (Register)
  142. https://hackerone.com/reports/16571 | SSRF (Portscan) via Register Function (Custom Server)
  143. https://hackerone.com/reports/16718 | Open Redirect login account
  144. https://hackerone.com/reports/16935 | e.mail.ru: SMS spam with custom content
  145. https://hackerone.com/reports/17160 | Password Policy issue (Weak Protect)
  146. https://hackerone.com/reports/17383 | Category- Broken Authentication and Session Management (leads to account compromise if some conditions are met)
  147. https://hackerone.com/reports/17474 | Broken Authentication and Session Management
  148. https://hackerone.com/reports/17540 | Reflected XSS in Pastebin-view
  149. https://hackerone.com/reports/17688 | LZ4 Core
  150. https://hackerone.com/reports/17785 | Denial of Service
  151. https://hackerone.com/reports/18691 | XSS in editor by any user
  152. https://hackerone.com/reports/18698 | Resubmitted with POC #18685 Password reset CSRF
  153. https://hackerone.com/reports/18843 | use-after-free vulnerability in Flash Player
  154. https://hackerone.com/reports/18992 | Possibility to attach any mobile number to any email
  155. https://hackerone.com/reports/20049 | Cross-site Scripting in mailing (username)
  156. https://hackerone.com/reports/20391 | m.agent.mail.ru: Подделываем j2me app-descriptor
  157. https://hackerone.com/reports/20616 | e.mail.ru: File upload "Chapito" circus
  158. https://hackerone.com/reports/20671 | integer overflow in 'buffer' type allows reading memory
  159. https://hackerone.com/reports/20720 | cloud.mail.ru: File upload XSS using Content-Type header
  160. https://hackerone.com/reports/20861 | moderate: mod_deflate denial of service
  161. https://hackerone.com/reports/20873 | rsync hash collisions may allow an attacker to corrupt or modify files
  162. https://hackerone.com/reports/21034 | Invoice Details activate JS that filled in
  163. https://hackerone.com/reports/21069 | Login CSRF
  164. https://hackerone.com/reports/21110 | Clickjacking
  165. https://hackerone.com/reports/21150 | Flash XSS on swfupload.swf showing at app.mavenlink.com
  166. https://hackerone.com/reports/21210 | privilege escalation
  167. https://hackerone.com/reports/21248 | Content spoofing at Stripe Integrations
  168. https://hackerone.com/reports/22093 | Content Spoofing all Integrations in https://team.slack.com/services/new/
  169. https://hackerone.com/reports/23363 | Forgot Password Issue
  170. https://hackerone.com/reports/23386 | Redirect while opening links in new tabs
  171. https://hackerone.com/reports/23852 | money.mail.ru: Странное поведение SMS
  172. https://hackerone.com/reports/25160 | Open redirection on secure.phabricator.com
  173. https://hackerone.com/reports/25281 | Change Any username and profile link in hackerone
  174. https://hackerone.com/reports/26647 | CSRF protection bypass on any Django powered site via Google Analytics
  175. https://hackerone.com/reports/26825 | Full path disclosure at ads.twitter.com
  176. https://hackerone.com/reports/26935 | XSS via .eml file
  177. https://hackerone.com/reports/26962 | open redirect in rfc6749
  178. https://hackerone.com/reports/27166 | Missing Rate Limiting on https://twitter.com/account/complete
  179. https://hackerone.com/reports/27404 | Delete Credit Cards from any Twitter Account in ads.twitter.com [New Vulnerability]
  180. https://hackerone.com/reports/27511 | ads.twitter.com xss
  181. https://hackerone.com/reports/27651 | Flash Local Sandbox Bypass
  182. https://hackerone.com/reports/27846 | Stored xss
  183. https://hackerone.com/reports/27987 | Window Opener Property Bug
  184. https://hackerone.com/reports/28150 | Cross site scripting on ads.twitter.com
  185. https://hackerone.com/reports/28445 | SPL ArrayObject/SPLObjectStorage Unserialization Type Confusion Vulnerabilities
  186. https://hackerone.com/reports/28449 | Active Record SQL Injection Vulnerability Affecting PostgreSQL
  187. https://hackerone.com/reports/28450 | Active Record SQL Injection Vulnerability Affecting PostgreSQL
  188. https://hackerone.com/reports/28500 | iOS App can establish Facetime calls without user's permission
  189. https://hackerone.com/reports/28832 | touch.mail.ru XSS via message id
  190. https://hackerone.com/reports/28865 | Redirect FILTER bypass in report/comment
  191. https://hackerone.com/reports/29234 | Credit Card Validation Issue
  192. https://hackerone.com/reports/29328 | XSS platform.twitter.com
  193. https://hackerone.com/reports/29331 | No email verification on username change
  194. https://hackerone.com/reports/29360 | XSS platform.twitter.com | video-js metadata
  195. https://hackerone.com/reports/29480 | Unvalidated Channel names causes IRC Command Injection
  196. https://hackerone.com/reports/29491 | homograph attack. IDNs displayed in unicode in bug reports and on external link warning page
  197. https://hackerone.com/reports/29835 | Profile Pic padding (Length-hiding) fails due to use of GZIP
  198. https://hackerone.com/reports/29839 | GNU Bourne-Again Shell (Bash) 'Shellshock' Vulnerability
  199. https://hackerone.com/reports/30238 | New Device confirmation tokens are not properly validated.
  200. https://hackerone.com/reports/30567 | Adobe Flash Player MP4 Use-After-Free Vulnerability
  201. https://hackerone.com/reports/30852 | Relateiq SSLv3 deprecated protocol vulnerability.
  202. https://hackerone.com/reports/30975 | Improper Verification of email address while saving Account Settings
  203. https://hackerone.com/reports/31082 | Unauthorized Tweeting on behalf of Account Owners
  204. https://hackerone.com/reports/31168 | Cryptographic Side Channel in OAuth Library
  205. https://hackerone.com/reports/31383 | Ability to see common response titles of other teams (limited)
  206. https://hackerone.com/reports/31408 | Adobe Flash Player Out-of-Bound Read/Write Vulnerability
  207. https://hackerone.com/reports/31415 | PoodleBleed
  208. https://hackerone.com/reports/31554 | Singup Page HTML Injection Vulnerability
  209. https://hackerone.com/reports/31756 | Drupal 7 pre auth sql injection and remote code execution
  210. https://hackerone.com/reports/32519 | XSS in fabric.io
  211. https://hackerone.com/reports/32570 | OpenSSL HeartBleed (CVE-2014-0160)
  212. https://hackerone.com/reports/32825 | URGENT - Subdomain Takeover on media.vine.co due to unclaimed domain pointing to AWS
  213. https://hackerone.com/reports/33018 | a stored xss in slack integration https://onerror.slack.com/services/import
  214. https://hackerone.com/reports/33091 | DOM Cross-Site Scripting ( XSS )
  215. https://hackerone.com/reports/33935 | File Name Enumeration
  216. https://hackerone.com/reports/34084 | Bad extended ascii handling in HTTP 301 redirects of t.co
  217. https://hackerone.com/reports/34112 | SMPT Protection not used, I can hijack your email server.
  218. https://hackerone.com/reports/34686 | �шибка фильтрации
  219. https://hackerone.com/reports/34725 | XSS via Fabrico Account Name
  220. https://hackerone.com/reports/35102 | Locale::parseLocale Double Free
  221. https://hackerone.com/reports/35237 | Gain reputation by creating a duplicate of an existing report
  222. https://hackerone.com/reports/35287 | getting emails of users/removing them from victims account [using typical attack]
  223. https://hackerone.com/reports/35363 | [static.qiwi.com] XSS proxy.html
  224. https://hackerone.com/reports/35413 | [send.qiwi.ru] XSS at auth?login=
  225. https://hackerone.com/reports/36105 | CRLF Injection [ishop.qiwi.com]
  226. https://hackerone.com/reports/36211 | Logic Issue with Reputation: Boost Reputation Points
  227. https://hackerone.com/reports/36264 | mod_proxy_fcgi buffer overflow
  228. https://hackerone.com/reports/36279 | Adobe Flash Player MP4 Use-After-Free Vulnerability
  229. https://hackerone.com/reports/36319 | [qiwi.com] /oauth/confirm.action XSS
  230. https://hackerone.com/reports/36450 | [send.qiwi.ru] Soap-based XXE vulnerability /soapserver/
  231. https://hackerone.com/reports/36594 | New Device Confirmation, token is valid until not used.
  232. https://hackerone.com/reports/36986 | [Stored XSS] vine.co - profile page
  233. https://hackerone.com/reports/37240 | Race condition in Flash workers may cause an exploitabl​e double free
  234. https://hackerone.com/reports/38007 | Subdomain Takeover using blog.greenhouse.io pointing to Hubspot
  235. https://hackerone.com/reports/38157 | [qiwi.com] Open Redirect
  236. https://hackerone.com/reports/38170 | Misc Python bugs (Memory Corruption & Use After Free)
  237. https://hackerone.com/reports/38189 | xss in /browse/contacts/
  238. https://hackerone.com/reports/38232 | Breaking Bugs as team member
  239. https://hackerone.com/reports/38343 | Issue with password change
  240. https://hackerone.com/reports/38345 | [sms.qiwi.ru] XSS via Request-URI
  241. https://hackerone.com/reports/38615 | [connect.mail.ru] Memory Disclosure / IE XSS
  242. https://hackerone.com/reports/38965 | Phabricator Diffusion application allows unauthorized users to delete mirrors
  243. https://hackerone.com/reports/39181 | [vimeopro.com] CRLF Injection
  244. https://hackerone.com/reports/39428 | Phabricator Phame Blog Skins Local File Inclusion
  245. https://hackerone.com/reports/39486 | No bruteforce protection leads to enumeration of emails in http://e.mail.ru/
  246. https://hackerone.com/reports/39631 | Open redirection in fabric.io
  247. https://hackerone.com/reports/41240 | POODLE Bug: 199.16.156.44, 199.16.156.108, mx4.twitter.com
  248. https://hackerone.com/reports/41469 | Error stack trace
  249. https://hackerone.com/reports/41758 | Stored XSS in api key of operator wallet
  250. https://hackerone.com/reports/41856 | HTML/XSS rendered in Android App of Crashlytics through fabric.io
  251. https://hackerone.com/reports/42161 | stored xss in transaction
  252. https://hackerone.com/reports/42236 | URGENT - Subdomain Takeover on users.tweetdeck.com , the same issue of report #32825
  253. https://hackerone.com/reports/42240 | chrome allows POST requests with custom headers using flash + 307 redirect
  254. https://hackerone.com/reports/42393 | XSS on partners.uber.com
  255. https://hackerone.com/reports/42582 | Vimeo.com - Reflected XSS Vulnerability
  256. https://hackerone.com/reports/42584 | Vimeo.com - reflected xss vulnerability
  257. https://hackerone.com/reports/42587 | Vimeo.com Insecure Direct Object References Reset Password
  258. https://hackerone.com/reports/42702 | APIs for channels allow HTML entities that may cause XSS issue
  259. https://hackerone.com/reports/42797 | Denial of Service in Action Pack Exception Handling
  260. https://hackerone.com/reports/42961 | fabric.io - app member can make himself an admin
  261. https://hackerone.com/reports/43065 | Fabric.io - an app admin can delete team members from other user apps
  262. https://hackerone.com/reports/43440 | Arbitrary file existence disclosure in Action Pack
  263. https://hackerone.com/reports/43443 | PyUnicode_FromFormatV crasher
  264. https://hackerone.com/reports/43602 | Buying ondemand videos that 0.1 and sometimes for free
  265. https://hackerone.com/reports/43617 | Adding profile picture to anyone on Vimeo
  266. https://hackerone.com/reports/43672 | player.vimeo.com - Reflected XSS Vulnerability
  267. https://hackerone.com/reports/43770 | Ability to Download Music Tracks Without Paying (Missing permission check on/musicstore/download)
  268. https://hackerone.com/reports/43850 | abusing Thumbnails(https://vimeo.com/upload/select_thumb) to see a private video
  269. https://hackerone.com/reports/43988 | twitter android app Fragment Injection
  270. https://hackerone.com/reports/43998 | CRITICAL full source code/config disclosure for Cameo
  271. https://hackerone.com/reports/44052 | Hadoop Node available to public
  272. https://hackerone.com/reports/44146 | Make API calls on behalf of another user (CSRF protection bypass)
  273. https://hackerone.com/reports/44217 | Application XSS filter function Bypass may allow Multiple stored XSS
  274. https://hackerone.com/reports/44294 | Heartbleed: my.com (185.30.178.33) port 1433
  275. https://hackerone.com/reports/44492 | Flaw in login with twitter to steal Oauth tokens
  276. https://hackerone.com/reports/44512 | XSS on any site that includes the moogaloop flash player | deprecated embed code
  277. https://hackerone.com/reports/44513 | RCE due to Web Console IP Whitelist bypass in Rails 4.0 and 4.1
  278. https://hackerone.com/reports/44727 | Insecure Data Storage in Vine Android App
  279. https://hackerone.com/reports/44798 | Vimeo Search - XSS Vulnerability [http://vimeo.com/search]
  280. https://hackerone.com/reports/44888 | Improper way of validating a program
  281. https://hackerone.com/reports/45368 | ftp upload of video allows naming that is not sanitized as the manual naming
  282. https://hackerone.com/reports/45484 | XSS on Vimeo
  283. https://hackerone.com/reports/45960 | CRITICAL vulnerability - Insecure Direct Object Reference - Unauthorized access to Videos of Channel whose privacy is set to Private.
  284. https://hackerone.com/reports/46072 | Vulnerability with the way \ escaped characters in http://danlec.com style links are rendered
  285. https://hackerone.com/reports/46113 | Can message users without the proper authorization
  286. https://hackerone.com/reports/46345 | Directory index and information disclosure
  287. https://hackerone.com/reports/46366 | Error stack trace
  288. https://hackerone.com/reports/46397 | Insecure Direct Object Reference vulnerability
  289. https://hackerone.com/reports/46429 | Team member invitations to sandboxed teams are not invalidated consistently
  290. https://hackerone.com/reports/46485 | Problem with OAuth
  291. https://hackerone.com/reports/46618 | Frictionless Transferring of Wallet Ownership
  292. https://hackerone.com/reports/46747 | Team admin can change unauthorized team setting (require_at_for_mention)
  293. https://hackerone.com/reports/46750 | Team admin can change unauthorized team setting (allow_message_deletion)
  294. https://hackerone.com/reports/46818 | Twitter Card - Parent Window Redirection
  295. https://hackerone.com/reports/46916 | Markdown parsing issue enables insertion of malicious tags and event handlers
  296. https://hackerone.com/reports/47012 | Adobe Flash Player Out-of-Bound Access Vulnerability
  297. https://hackerone.com/reports/47227 | Race condition in workers may cause an exploitable double free by abusing bytearray.compress()
  298. https://hackerone.com/reports/47232 | Use after free during the StageVideoAvailabilityEvent can result in arbitrary code execution
  299. https://hackerone.com/reports/47234 | Use After Free in Flash MessageChannel.send can cause arbitrary code execution
  300. https://hackerone.com/reports/47280 | JSON keys are not properly escaped
  301. https://hackerone.com/reports/47472 | CSP Bypass: Click handler for links with data-method="post" can cause authenticity_token to be sent off domain
  302. https://hackerone.com/reports/47495 | Same Origin Policy bypass
  303. https://hackerone.com/reports/47536 | [ishop.qiwi.com] XSS + Misconfiguration
  304. https://hackerone.com/reports/47627 | Email Enumeration (POC)
  305. https://hackerone.com/reports/47779 | Heap overflow in H. Spencer’s regex library on 32 bit systems
  306. https://hackerone.com/reports/47888 | Reporting user's profile by using another people's ID
  307. https://hackerone.com/reports/47940 | Team admin can add billing contacts
  308. https://hackerone.com/reports/48065 | open authentication bug
  309. https://hackerone.com/reports/48100 | Bad Write in TTF font parsing (win32k.sys)
  310. https://hackerone.com/reports/48422 | Team member invitations to sandboxed teams are not invalidated consistently (v2)
  311. https://hackerone.com/reports/48516 | Redirect URL in /intent/ functionality is not properly escaped
  312. https://hackerone.com/reports/49035 | HDFS NameNode Public disclosure: http://185.5.139.33:50070/dfshealth.jsp
  313. https://hackerone.com/reports/49139 | scfbp.tng.mail.ru: Heartbleed
  314. https://hackerone.com/reports/49170 | Information disclosure - emails disclosed in response > staging.seatme.us
  315. https://hackerone.com/reports/49408 | RCE через JDWP
  316. https://hackerone.com/reports/49561 | Vimeo + & Vimeo PRO Unautorised Tax bypass
  317. https://hackerone.com/reports/49652 | Improperly validated fields allows injection of arbitrary HTML via spoofed React objects
  318. https://hackerone.com/reports/49663 | URGENT - Subdomain Takeover on status.vimeo.com due to unclaimed domain pointing to statuspage.io
  319. https://hackerone.com/reports/49759 | Open Redirect leak of authenticity_token lead to full account take over.
  320. https://hackerone.com/reports/49806 | Twitter Ads Campaign information disclosure through admin without any authentication.
  321. https://hackerone.com/reports/49935 | rails-ujs will send CSRF tokens to other origins
  322. https://hackerone.com/reports/49974 | The csrf token remains same after user logs in
  323. https://hackerone.com/reports/50134 | XSS in original referrer after follow
  324. https://hackerone.com/reports/50170 | FREAK: Factoring RSA_EXPORT Keys to Impersonate TLS Servers
  325. https://hackerone.com/reports/50752 | open redirect sends authenticity_token to any website or (ip address)
  326. https://hackerone.com/reports/50776 | A user can edit comments even after video comments are disabled
  327. https://hackerone.com/reports/50786 | A user can add videos to other user's private groups
  328. https://hackerone.com/reports/50829 | A user can post comments on other user's private videos
  329. https://hackerone.com/reports/50884 | Bypass pin(4 digit passcode on your android app)
  330. https://hackerone.com/reports/50885 | CVE-2014-0224 openssl ccs vulnerability
  331. https://hackerone.com/reports/50941 | A user can enhance their videos with paid tracks without buying the track
  332. https://hackerone.com/reports/51265 | Flash Cross Domain Policy Bypass by Using File Upload and Redirection - only in Chrome
  333. https://hackerone.com/reports/51817 | Post in private groups after getting removed
  334. https://hackerone.com/reports/52035 | Open redirect in "Language change".
  335. https://hackerone.com/reports/52042 | HTTP Response Splitting (CRLF injection) in report_story
  336. https://hackerone.com/reports/52176 | Insecure Direct Object References in https://vimeo.com/forums
  337. https://hackerone.com/reports/52181 | Insecure Direct Object References that allows to read any comment (even if it should be private)
  338. https://hackerone.com/reports/52635 | UniFi v3.2.10 Cross-Site Request Forgeries / Referer-Check Bypass
  339. https://hackerone.com/reports/52646 | Insecure direct object reference - have access to deleted DM's
  340. https://hackerone.com/reports/52707 | Invite any user to your group without even following him
  341. https://hackerone.com/reports/52708 | Share your channel to any user on vimeo without following him
  342. https://hackerone.com/reports/52822 | XSS with Time-of-Day Format
  343. https://hackerone.com/reports/52982 | [URGENT ISSUE] Add or Delete the videos in watch later list of any user .
  344. https://hackerone.com/reports/53004 | Blacklist bypass on Callback URLs
  345. https://hackerone.com/reports/53088 | SSRF vulnerability (access to metadata server on EC2 and OpenStack)
  346. https://hackerone.com/reports/53098 | XSS in twitter.com/safety/unsafe_link_warning
  347. https://hackerone.com/reports/53843 | HTTP Response Splitting (CRLF injection) due to headers overflow
  348. https://hackerone.com/reports/53858 | Insecure Direct Object Reference - access to other user/group DM's
  349. https://hackerone.com/reports/54094 | HTTP MitM on Flash Player settings manager allows attacker to set sandbox settings
  350. https://hackerone.com/reports/54321 | Xss in website's link
  351. https://hackerone.com/reports/54327 | Persistent cross-site scripting (XSS) in map attribution
  352. https://hackerone.com/reports/54610 | Logout any user of same team
  353. https://hackerone.com/reports/54631 | Vulnerable to JavaScript injection. (WXS) (Javascript injection)!
  354. https://hackerone.com/reports/54641 | Captcha Bypass in Snapchat's Geofilter Submission Process
  355. https://hackerone.com/reports/54719 | e.mail.ru stored XSS in agent via sticker (smile)
  356. https://hackerone.com/reports/54733 | Sandboxed iframes don't show confirmation screen
  357. https://hackerone.com/reports/54779 | Missing spf flags for myshopify.com
  358. https://hackerone.com/reports/55017 | Multiple Python integer overflows
  359. https://hackerone.com/reports/55018 | Segmentation fault for invalid PSS parameters
  360. https://hackerone.com/reports/55028 | Free called on unitialized pointer in exif.c
  361. https://hackerone.com/reports/55029 | Use after free vulnerability in unserialize() with DateTimeZone
  362. https://hackerone.com/reports/55030 | SoapClient's __call() type confusion through unserialize()
  363. https://hackerone.com/reports/55033 | Use after free vulnerability in unserialize()
  364. https://hackerone.com/reports/55140 | Race Conditions in OAuth 2 API implementations
  365. https://hackerone.com/reports/55431 | XML Parser Bug: XXE over which leads to RCE
  366. https://hackerone.com/reports/55525 | Open redirection in OAuth
  367. https://hackerone.com/reports/55530 | Authentication Failed Mobile version
  368. https://hackerone.com/reports/55546 | Open Redirect after login at http://ecommerce.shopify.com
  369. https://hackerone.com/reports/55670 | Fabric.io: Ex-admin of an organization can delete team members
  370. https://hackerone.com/reports/55716 | Force 500 Internal Server Error on any shop (for one user)
  371. https://hackerone.com/reports/55842 | [persistent cross-site scripting] customers can target admins
  372. https://hackerone.com/reports/55911 | CSRF token fixation in facebook store app that can lead to adding attacker to victim acc
  373. https://hackerone.com/reports/56002 | Shopify android client all API request's response leakage, including access_token, cookie, response header, response body content
  374. https://hackerone.com/reports/56385 | Double free vulnerability in Flash Player Settings Manager (CVE-2015-0346)
  375. https://hackerone.com/reports/56511 | IDOR expire other user sessions
  376. https://hackerone.com/reports/56626 | Shop admin can change external login services
  377. https://hackerone.com/reports/56742 | SPF whitelist of mandrill leads to email forgery
  378. https://hackerone.com/reports/56779 | XSS on ecommerce.shopify.com
  379. https://hackerone.com/reports/56828 | SSRF vulnerablity in app webhooks
  380. https://hackerone.com/reports/56936 | Notification request disclose private information about other myshopify accounts
  381. https://hackerone.com/reports/57163 | Open-redirect on hackerone.com
  382. https://hackerone.com/reports/57356 | DOM based cookie bomb
  383. https://hackerone.com/reports/57459 | XSS in experts.shopify.com
  384. https://hackerone.com/reports/57603 | API: missing invalidation of OAuth2 Authorization Code during access revocation causes authorization bypass
  385. https://hackerone.com/reports/57692 | Server responds with the server error logs on account creation
  386. https://hackerone.com/reports/57764 | ByPassing the email Validation Email on Sign up process in mobile apps
  387. https://hackerone.com/reports/57914 | HTML injection in email sent by romit.io
  388. https://hackerone.com/reports/57918 | Insecure Local Data Storage : Application stores data using a binary sqlite database
  389. https://hackerone.com/reports/58612 | Homograph attack
  390. https://hackerone.com/reports/58630 | Content Spoofing
  391. https://hackerone.com/reports/58679 | SSL cookie without secure flag set
  392. https://hackerone.com/reports/59015 | Stored XSS in the Shopify Discussion Forums
  393. https://hackerone.com/reports/59179 | Race condition when redeeming coupon codes
  394. https://hackerone.com/reports/59356 | XSS in dropbox main domain
  395. https://hackerone.com/reports/59369 | Making any Report Failed to load
  396. https://hackerone.com/reports/59375 | Homograph attack
  397. https://hackerone.com/reports/59469 | Fake URL + Additional vectors for homograph attack
  398. https://hackerone.com/reports/59505 | Create and Update patients vulnerability
  399. https://hackerone.com/reports/59508 | Accessing all appointments vulnerability
  400. https://hackerone.com/reports/59659 | Reopen Disable Accounts/ Hidden Access After Disable
  401. https://hackerone.com/reports/60016 | xss profile
  402. https://hackerone.com/reports/60058 | teach.udemy.com log poison vulnerability through wordpress debug.log being publically available
  403. https://hackerone.com/reports/60402 | Content Spoofing - External Link Warning Page
  404. https://hackerone.com/reports/60573 | http://fitter1.i.mail.ru/browser/ торчит Graphite в мир
  405. https://hackerone.com/reports/61312 | Bypass of the SSRF protection (Slack commands, Phabricator integration)
  406. https://hackerone.com/reports/61367 | xss on autoserch
  407. https://hackerone.com/reports/61371 | leak receipt of another user
  408. https://hackerone.com/reports/62301 | Ability to add pishing links in discusion ," Bypassing uneductional Links add "
  409. https://hackerone.com/reports/62400 | XSS on https://www.udemy.com/asset/export.html
  410. https://hackerone.com/reports/62427 | XSS in myshopify.com Admin site in TAX Overrides
  411. https://hackerone.com/reports/62531 | tt-mac.i.mail.ru: Quagga 0.99.23.1 (Router) : Default password and default enable password
  412. https://hackerone.com/reports/62544 | http://tp-dev1.tp.smailru.net/
  413. https://hackerone.com/reports/62778 | Multiple sub domain are vulnerable because of leaking full path
  414. https://hackerone.com/reports/62861 | Bulk Discount App in myshopify.com exposes http://bulkdiscounts.shopifyapps.com vulnerable to XSS
  415. https://hackerone.com/reports/63158 | External URL page bypass
  416. https://hackerone.com/reports/63324 | Flash Player information disclosure (etc.) CVE-2015-3044, PSIRT-3298
  417. https://hackerone.com/reports/63537 | XSS in https://app.mavenlink.com/workspaces/
  418. https://hackerone.com/reports/63729 | Logic error with notifications: user that has left team continues to receive notifications and can not 'clean' this area on account
  419. https://hackerone.com/reports/63865 | Potential denial of service in hackerone.com//reward_settings
  420. https://hackerone.com/reports/63888 | Cross site scripting
  421. https://hackerone.com/reports/64731 | Able to intercept app Traffic after choosing up the Secured Connection using SSL (HTTPS)
  422. https://hackerone.com/reports/64963 | API: Bug in method auth.validatePhone
  423. https://hackerone.com/reports/65013 | HTML Injection на e.mail.ru
  424. https://hackerone.com/reports/65084 | Big Bug with Vault which i have already reported: Case #606962
  425. https://hackerone.com/reports/65284 | Stored Cross-Site Scripting in Map Share Page
  426. https://hackerone.com/reports/65330 | �е до�таточна� проверка логина �кайп
  427. https://hackerone.com/reports/65729 | Activities are not Protected and able to crash app using other app (Can Malware or third parry app).
  428. https://hackerone.com/reports/66121 | XSS at http://vk.com on IE using flash files
  429. https://hackerone.com/reports/66151 | Invitation is not properly cancelled while inviting to bug reports.
  430. https://hackerone.com/reports/66235 | У�звимо�ть в Указание ме�т на фото + фича + хакинг
  431. https://hackerone.com/reports/66257 | [s.mail.ru] CRLF Injection
  432. https://hackerone.com/reports/66262 | mailto: link injection on https://hackerone.com/directory
  433. https://hackerone.com/reports/66386 | [www.*.myshopify.com] CRLF Injection
  434. https://hackerone.com/reports/66962 | Misusing of FPU Instruction Could Cause Security Vulnerabilities in Adobe Flash Player
  435. https://hackerone.com/reports/67125 | XSS at importing Product List
  436. https://hackerone.com/reports/67132 | XSS at Bulk editing products
  437. https://hackerone.com/reports/67161 | Possible xWork classLoader RCE: shared.mail.ru
  438. https://hackerone.com/reports/67220 | Expire User Sessions in Admin Site does not expire user session in Shopify Application in IOS
  439. https://hackerone.com/reports/67377 | SSRF via 'Add Image from URL' feature
  440. https://hackerone.com/reports/67386 | [my.mail.ru] CRLF Injection
  441. https://hackerone.com/reports/67389 | SSRF via 'Insert Image' feature of Products/Collections/Frontpage
  442. https://hackerone.com/reports/67660 | Verification code issues for Two-Step Authentication
  443. https://hackerone.com/reports/71614 | XSS in Myshopify Admin Site in DISCOUNTS
  444. https://hackerone.com/reports/72243 | Publicly exposed SVN repository, ht.pornhub.com
  445. https://hackerone.com/reports/72331 | XSS at Bulk editing ProductVariants
  446. https://hackerone.com/reports/72785 | CSV Injection with the CVS export feature
  447. https://hackerone.com/reports/73234 | out of bounds read crashes php-cgi
  448. https://hackerone.com/reports/73235 | Use After Free Vulnerability in unserialize()
  449. https://hackerone.com/reports/73236 | X509_to_X509_REQ NULL pointer deref
  450. https://hackerone.com/reports/73237 | Buffer Over flow when parsing tar/zip/phar in phar_set_inode
  451. https://hackerone.com/reports/73238 | Buffer Over-read in unserialize when parsing Phar
  452. https://hackerone.com/reports/73239 | ZIP Integer Overflow leads to writing past heap boundary
  453. https://hackerone.com/reports/73240 | Integer overflow in ftp_genlist() resulting in heap overflow
  454. https://hackerone.com/reports/73241 | Malformed ECParameters causes infinite loop
  455. https://hackerone.com/reports/73244 | Use after free vulnerability in unserialize() with DateInterval
  456. https://hackerone.com/reports/73245 | Type Confusion Vulnerability in SoapClient
  457. https://hackerone.com/reports/73246 | Use-after-free in php_curl related to CURLOPT_FILE/_INFILE/_WRITEHEADER
  458. https://hackerone.com/reports/73247 | php_stream_url_wrap_http_ex() type-confusion vulnerability
  459. https://hackerone.com/reports/73248 | Tokenizer crash when processing undecodable source code
  460. https://hackerone.com/reports/73249 | Multiple use after free bugs in element module
  461. https://hackerone.com/reports/73250 | Multiple use after free bugs in heapq module
  462. https://hackerone.com/reports/73251 | Multiple use after free bugs in json encoding
  463. https://hackerone.com/reports/73252 | Use after free in get_filter
  464. https://hackerone.com/reports/73253 | Multiple type confusions in unicode error handlers
  465. https://hackerone.com/reports/73255 | str_repeat() sign mismatch based memory corruption
  466. https://hackerone.com/reports/73256 | PHP yaml_parse/yaml_parse_file/yaml_parse_url Double Free
  467. https://hackerone.com/reports/73257 | PHP yaml_parse/yaml_parse_file/yaml_parse_url Unsafe Deserialization
  468. https://hackerone.com/reports/73258 | Python: imageop Unsafe Arithmetic
  469. https://hackerone.com/reports/73259 | Integer overflow in _pickle.c
  470. https://hackerone.com/reports/73260 | Integer overflow in _json_encode_unicode leads to crash
  471. https://hackerone.com/reports/73276 | Internet-based attacker can run Flash apps in local sandboxes by using special URL schemes (PSIRT-3299, CVE-2015-3079)
  472. https://hackerone.com/reports/73491 | Buffer Overflow in PHP of the AirMax Products
  473. https://hackerone.com/reports/73566 | Reflected XSS in chat
  474. https://hackerone.com/reports/73567 | Attention! Remote Code Execution at http://wpt.ec2.shopify.com/
  475. https://hackerone.com/reports/73808 | Extremely high Course rating values could be set in order to make really high Average rating of the course. Negative values could be set to.
  476. https://hackerone.com/reports/74004 | Other Buffer Overflow in PHP of the AirMax Products
  477. https://hackerone.com/reports/74025 | Yet another Buffer Overflow in PHP of the AirMax Products
  478. https://hackerone.com/reports/74147 | Potential for financial loss, negative Values for "Buy fee" and "Sell Fee"
  479. https://hackerone.com/reports/75357 | Session Cookie without HttpOnly and secure flag set
  480. https://hackerone.com/reports/75556 | Accessing title of the report of which you are marked as duplicate
  481. https://hackerone.com/reports/75702 | No rate limit which leads to "Users information Disclosure" including verfification documents etc.
  482. https://hackerone.com/reports/75727 | Stored Cross site scripting In developer.zendesk.com
  483. https://hackerone.com/reports/76307 | Self XSS Protection not used , I can trick users to insert JavaScript
  484. https://hackerone.com/reports/76713 | XSS - Gallery Search Listing
  485. https://hackerone.com/reports/76733 | Using GET method for account login with CSRF token leaking to external sites Via Referer.
  486. https://hackerone.com/reports/76738 | Open redirect filter bypass
  487. https://hackerone.com/reports/77060 | SMTP protection not used
  488. https://hackerone.com/reports/77065 | Stealing CSRF Tokens
  489. https://hackerone.com/reports/77067 | No rate limiting for sensitive actions (like "forgot password") enables user enumeration
  490. https://hackerone.com/reports/77076 | GA code not verified on the server side allows sending Verification Documents on behalf of another user
  491. https://hackerone.com/reports/77081 | Content Sniffing not disabled
  492. https://hackerone.com/reports/77221 | Open/Unvalidated Redirect Issue
  493. https://hackerone.com/reports/77231 | Weak Cryptographic Hash
  494. https://hackerone.com/reports/77319 | Full path disclosure at https://keybase.io/_/api/1.0/invitation_request.json
  495. https://hackerone.com/reports/77802 | TCP Source Port Pass Firewall
  496. https://hackerone.com/reports/78052 | xss in group
  497. https://hackerone.com/reports/78158 | Wrong Handling of Content-Type allows Flash injection and Rosseta flash patch bypass
  498. https://hackerone.com/reports/78219 | Покупка пе�ни дешевле, чем она �тоит.
  499. https://hackerone.com/reports/78253 | Покупка=>�качка пе�ен, которые не предназначены дл� продажи
  500. https://hackerone.com/reports/78412 | Cross site scripting
  501. https://hackerone.com/reports/78436 | (URGENT!) Покупка OK дешевле, чем он �тоит
  502. https://hackerone.com/reports/78443 | Time-Based Blind SQL Injection Attacks
  503. https://hackerone.com/reports/78516 | До�туп к чужим приватным фотографи�м (3) через обложку видео
  504. https://hackerone.com/reports/78765 | information disclosure
  505. https://hackerone.com/reports/79046 | До�туп к чужим групповым бе�едам.
  506. https://hackerone.com/reports/79185 | Content spoofing through Referel header
  507. https://hackerone.com/reports/79348 | OSX slack:// protocol handler javascript injection
  508. https://hackerone.com/reports/79393 | �ткрытый до�туп к корпоративным данным.
  509. https://hackerone.com/reports/79552 | [gratipay.com] CRLF Injection
  510. https://hackerone.com/reports/80298 | Внедрение произвольного javascript-�ценари� в функционале про�мотра изображений мобильной вер�ии �айта
  511. https://hackerone.com/reports/80597 | Number of invited researchers disclosed as part of JSON search response
  512. https://hackerone.com/reports/80936 | Private Program and bounty details disclosed as part of JSON search response
  513. https://hackerone.com/reports/80990 | JetBrains .idea project directory
  514. https://hackerone.com/reports/81083 | Internal bounty and swag details disclosed as part of JSON response
  515. https://hackerone.com/reports/81441 | XSS https://delivery.shopifyapps.com/ (Digital Downloads App in myshopify.com)
  516. https://hackerone.com/reports/81701 | Possible SQL injection on "Jump to twitter"
  517. https://hackerone.com/reports/81736 | XSS in WordPress
  518. https://hackerone.com/reports/81757 | Reflected XSS in chat.
  519. https://hackerone.com/reports/82725 | Stored XSS in comments
  520. https://hackerone.com/reports/84287 | DKIM records not present, Email Hijacking is possible
  521. https://hackerone.com/reports/84601 | XSS and cache poisoning via upload.twitter.com on ton.twitter.com
  522. https://hackerone.com/reports/84709 | [API ISSUE] agents can Create agents even after they are disabled !
  523. https://hackerone.com/reports/84740 | Stored XSS On Statement
  524. https://hackerone.com/reports/85201 | Full Path Disclosure
  525. https://hackerone.com/reports/85291 | XSS https://www.shopify.com/signup
  526. https://hackerone.com/reports/85488 | Stored XSS on player.vimeo.com
  527. https://hackerone.com/reports/85615 | Reflected XSS on vimeo.com/musicstore
  528. https://hackerone.com/reports/85624 | Highly wormable clickjacking in player card
  529. https://hackerone.com/reports/85720 | IDOR on remoing Share
  530. https://hackerone.com/reports/86022 | Multiple so called 'type juggling' attacks. Most notably PhabricatorUser::validateCSRFToken() is 'bypassable' in certain cases.
  531. https://hackerone.com/reports/86468 | [https://www.anghami.com/updatemailinfo/] Sql Injection
  532. https://hackerone.com/reports/86504 | [CRITICAL] Login To Any Account Linked With Google+ With Email Only
  533. https://hackerone.com/reports/87027 | [keybase.io] Open Redirect
  534. https://hackerone.com/reports/87040 | XSS on OAuth authorize/authenticate endpoint
  535. https://hackerone.com/reports/87168 | www.shopify.com XSS on blog pages via sharing buttons
  536. https://hackerone.com/reports/87505 | Full Path Disclosure
  537. https://hackerone.com/reports/87531 | Mail spaming
  538. https://hackerone.com/reports/87577 | Stored XSS on vimeo.com and player.vimeo.com
  539. https://hackerone.com/reports/87586 | �ебезопа�на� �хема выдачи номера карты QVC (возможно, также QVV и QVP)
  540. https://hackerone.com/reports/87588 | XSS Vulnerability
  541. https://hackerone.com/reports/87854 | XSS on vimeo.com/home after other user follows you
  542. https://hackerone.com/reports/88105 | XSS on vimeo.com | "Search within these results" feature (requires user interaction)
  543. https://hackerone.com/reports/88395 | Information leakage through Graphviz blocks
  544. https://hackerone.com/reports/88508 | XSS when using captions/subtitles on video player based on Flash (requires user interaction)
  545. https://hackerone.com/reports/88719 | Multiple DOMXSS on Amplify Web Player
  546. https://hackerone.com/reports/88881 | XSS: https://light.mail.ru/compose, https://m.mail.ru/compose/[id]/reply при ответе на �пециальным образом �формированное пи�ьмо
  547. https://hackerone.com/reports/89505 | Self-XSS in posts by formatting text as code
  548. https://hackerone.com/reports/89624 | Cross-site Scripting https://www.zendesk.com/product/pricing/
  549. https://hackerone.com/reports/90131 | CSV Excel Macro Injection Vulnerability in export customer tickets
  550. https://hackerone.com/reports/90172 | Tweetdeck (twitter owned app) not revoked
  551. https://hackerone.com/reports/90274 | CSV Excel Macro Injection Vulnerability in export chat logs
  552. https://hackerone.com/reports/90308 | User email enumuration using Gmail
  553. https://hackerone.com/reports/90688 | create staff member without owner access
  554. https://hackerone.com/reports/90690 | change Login Services settings without owner access
  555. https://hackerone.com/reports/90753 | Content Spoofing
  556. https://hackerone.com/reports/91343 | Information disclosure (No rate limting in forgot password & other login)
  557. https://hackerone.com/reports/91421 | Reflected Flash XSS using swfupload.swf with an epileptic reloading to bypass the button-event
  558. https://hackerone.com/reports/91599 | WooCommerce: Support Ticket indirect object reference
  559. https://hackerone.com/reports/91816 | Server Side Request Forgery In Video to GIF Functionality
  560. https://hackerone.com/reports/92251 | Issue with Password reset functionality
  561. https://hackerone.com/reports/92353 | CSV Injection in polldaddy.com
  562. https://hackerone.com/reports/92472 | Tokens from services like Facebook can be stolen
  563. https://hackerone.com/reports/92740 | SPF records not found
  564. https://hackerone.com/reports/93004 | unauthorized access to all collections name
  565. https://hackerone.com/reports/93020 | Спо�об узнать им� человека и ВУЗ удаленной �траницы
  566. https://hackerone.com/reports/93394 | Unauthenticated access to details of hidden products in any shop via title emuneration
  567. https://hackerone.com/reports/93691 | Arbitrary write on s3://shopify-delivery-app-storage/files
  568. https://hackerone.com/reports/93901 | Bypassing password requirement during deletion of accout
  569. https://hackerone.com/reports/93921 | Unauthorized access to all collections, products, pages from other stores
  570. https://hackerone.com/reports/94087 | Arbitrary read on s3://shopify-delivery-app-storage/files
  571. https://hackerone.com/reports/94230 | Cross-site Scripting in all Zopim
  572. https://hackerone.com/reports/94584 | Sql-inj in https://maximum.com/ajax/people
  573. https://hackerone.com/reports/94610 | Version Disclosure (NginX)
  574. https://hackerone.com/reports/94637 | Host Header Injection/Redirection
  575. https://hackerone.com/reports/94642 | SMS Invite Form Abuse
  576. https://hackerone.com/reports/94899 | Paid account can review\download any invoice of any other shop
  577. https://hackerone.com/reports/94909 | XSS risk reduction with X-XSS-Protection: 1; mode=block header
  578. https://hackerone.com/reports/95089 | Reflected XSS in cart at hardware.shopify.com
  579. https://hackerone.com/reports/95231 | XSS in the "Poll" Feature on Twitter.com
  580. https://hackerone.com/reports/95243 | Following a User Actually Follows Another User
  581. https://hackerone.com/reports/95552 | IDOR- Activate Mopub on different organizations- steal api token- Fabric.io
  582. https://hackerone.com/reports/95555 | CSRF on cards API
  583. https://hackerone.com/reports/95564 | Persistent XSS in image title
  584. https://hackerone.com/reports/95589 | Privilege escalation and circumvention of permission to limited access user
  585. https://hackerone.com/reports/95981 | Http Response Splitting - Validate link
  586. https://hackerone.com/reports/96229 | XSS on player.vimeo.com without user interaction and vimeo.com with user interaction
  587. https://hackerone.com/reports/96337 | Stored XSS in Slack (weird, trial and error)
  588. https://hackerone.com/reports/96470 | Missing of csrf protection
  589. https://hackerone.com/reports/96636 | Password Reset - query param overrides postdata
  590. https://hackerone.com/reports/96662 | crossdomain.xml too permissive on eu1.badoo.com, us1.badoo.com, etc.
  591. https://hackerone.com/reports/96847 | Un-handled exception leads to Information Disclosure
  592. https://hackerone.com/reports/96855 | Staff members with no permission to access domains can access them.
  593. https://hackerone.com/reports/96890 | A 'Full access' administrator is able to see the shop owners user details
  594. https://hackerone.com/reports/96908 | An administrator without the 'Settings' permission is able to see payment gateways
  595. https://hackerone.com/reports/97161 | Can see private tweets via keyword searches on tweetdeck
  596. https://hackerone.com/reports/97191 | Send AJAX request to external domain
  597. https://hackerone.com/reports/97292 | HTTP header injection in info.hackerone.com allows setting cookies for hackerone.com
  598. https://hackerone.com/reports/97295 | Multiple critical vulnerabilities in Odnoklassniki Android application
  599. https://hackerone.com/reports/97452 | Staff members with no permission can access to the files, uploaded by the administrator
  600. https://hackerone.com/reports/97501 | SVG parser loads external resources on image upload
  601. https://hackerone.com/reports/97510 | Following a User After Favoriting Actually Follows Another User (related to #95243)
  602. https://hackerone.com/reports/97535 | List of devices is accessible regardless of the account limitations
  603. https://hackerone.com/reports/97657 | File upload XSS (Java applet) on http://slackatwork.com/
  604. https://hackerone.com/reports/97672 | File Upload XSS in image uploading of App in mopub
  605. https://hackerone.com/reports/97683 | Reflected Self-XSS in Slack
  606. https://hackerone.com/reports/97938 | XSS m.imgur.com
  607. https://hackerone.com/reports/97948 | Cross-domain AJAX request
  608. https://hackerone.com/reports/98012 | Stored XSS on https://www.algolia.com/realtime-search-demo/*
  609. https://hackerone.com/reports/98247 | login to any user's cashier account and full account information disclosure
  610. https://hackerone.com/reports/98259 | 'Limited' RCE in certain places where Liquid is accepted
  611. https://hackerone.com/reports/98281 | XSS Reflected in test.qiwi.ru
  612. https://hackerone.com/reports/98432 | Urgent : Disclosure of all the apps with hash ID in mopub through API request (Authentication bypass)
  613. https://hackerone.com/reports/98469 | Email Verification Link can be Used as Password Reset Link!
  614. https://hackerone.com/reports/98499 | Apps can access 'channels' beta api
  615. https://hackerone.com/reports/99157 | RC4 cipher suites detected on status.slack.com
  616. https://hackerone.com/reports/99245 | XSS in L.mapbox.shareControl in mapbox.js
  617. https://hackerone.com/reports/99321 | [CSRF] Activate PayPal Express Checkout
  618. https://hackerone.com/reports/99368 | an xss issue
  619. https://hackerone.com/reports/99374 | deleted staff member can add his amazon marketplace web services account to the store.
  620. https://hackerone.com/reports/99424 | Mass Assignment Vulnerability in partners.uber.com
  621. https://hackerone.com/reports/99435 | Open redirect helps to steal Facebook access_token
  622. https://hackerone.com/reports/99594 | Reflected XSS on www.boozt.com
  623. https://hackerone.com/reports/99600 | Urgent : Unauthorised Access to Media content of all Direct messages and protected tweets(Indirect object reference)
  624. https://hackerone.com/reports/99647 | CSRF Add Album On onpatient.com
  625. https://hackerone.com/reports/99708 | Limited CSRF bypass.
  626. https://hackerone.com/reports/99857 | Request Accepts without X-CSRFToken [ Header - Cookie ]
  627. https://hackerone.com/reports/99969 | User with limited access to Index configuration can rename the Index
  628. https://hackerone.com/reports/100509 | Pre-generation of 2FA secret/backup codes seems like an unnecessary risk
  629. https://hackerone.com/reports/100820 | Add tweet to collection CSRF
  630. https://hackerone.com/reports/100849 | URGENT : NICHE.co Account Take Over Vulnerability
  631. https://hackerone.com/reports/100931 | xss in link items (mopub.com)
  632. https://hackerone.com/reports/100938 | An administrator without any permission is able to get order notifications using his APNS Token.
  633. https://hackerone.com/reports/101063 | Drivers can change profile picture
  634. https://hackerone.com/reports/101104 | Subdomain Expired
  635. https://hackerone.com/reports/101145 | Remove anyone's pic gravtar
  636. https://hackerone.com/reports/101324 | RC4 cipher suites detected
  637. https://hackerone.com/reports/101330 | SSL certificate invalid date
  638. https://hackerone.com/reports/101331 | RC4 cipher suites detected
  639. https://hackerone.com/reports/101450 | XSS in creating tweets
  640. https://hackerone.com/reports/101909 | account.ubnt.com CSRF
  641. https://hackerone.com/reports/101962 | Open redirect using theme install
  642. https://hackerone.com/reports/102194 | [CRITICAL] CSRF leading to account take over
  643. https://hackerone.com/reports/102234 | Same-Origin Policy bypass on main domain - ok.ru
  644. https://hackerone.com/reports/102236 | Same-Origin Policy Bypass #2
  645. https://hackerone.com/reports/102327 | content injection
  646. https://hackerone.com/reports/102376 | �бход защиты от csrf-ок в m.ok.ru
  647. https://hackerone.com/reports/102755 | Stored XSS in name selection
  648. https://hackerone.com/reports/103351 | [CSRF] Install premium themes
  649. https://hackerone.com/reports/103772 | Open Redirect at *.myshopify.com/account/login?checkout_url=
  650. https://hackerone.com/reports/103787 | CSRF possible when SOP Bypass/UXSS is available
  651. https://hackerone.com/reports/103990 | Null pointer dereference in phar_get_fp_offset()
  652. https://hackerone.com/reports/103991 | mod_lua: Crash in websockets PING handling
  653. https://hackerone.com/reports/103992 | Integer overflow in _Unpickler_Read
  654. https://hackerone.com/reports/103993 | Request Hijacking Vulnerability In RubyGems 2.4.6 And Earlier
  655. https://hackerone.com/reports/103994 | Python 3.3 - 3.5 product_setstate() Out-of-bounds Read
  656. https://hackerone.com/reports/103995 | Use After Free Vulnerability in unserialize() with SplDoublyLinkedList
  657. https://hackerone.com/reports/103996 | Use After Free Vulnerability in unserialize() with SplObjectStorage
  658. https://hackerone.com/reports/103997 | Use After Free Vulnerability in unserialize()
  659. https://hackerone.com/reports/103998 | Use After Free Vulnerability in session deserializer
  660. https://hackerone.com/reports/103999 | Use after free vulnerability in unserialize() with GMP
  661. https://hackerone.com/reports/104000 | Python xmlparse_setattro() Type Confusion
  662. https://hackerone.com/reports/104001 | time_strftime() Buffer Over-read
  663. https://hackerone.com/reports/104002 | Python scan_eol() Buffer Over-read
  664. https://hackerone.com/reports/104003 | Python deque.index() uninitialized memory
  665. https://hackerone.com/reports/104004 | Mem out-of-bounds write (segfault) in ZEND_ASSIGN_DIV_SPEC_CV_UNUSED_HANDLER
  666. https://hackerone.com/reports/104005 | null pointer deref (segfault) in zend_eval_const_expr
  667. https://hackerone.com/reports/104006 | Null pointer deref (segfault) in spl_autoload via ob_start
  668. https://hackerone.com/reports/104007 | Buffer over-read in exif_read_data with TIFF IFD tag
  669. https://hackerone.com/reports/104008 | Uninitialized pointer in phar_make_dirstream
  670. https://hackerone.com/reports/104009 | zend_throw_or_error() format string vulnerability
  671. https://hackerone.com/reports/104010 | SOAP serialize_function_call() type confusion / RCE
  672. https://hackerone.com/reports/104011 | AddressSanitizer reports a global buffer overflow in mkgmtime() function
  673. https://hackerone.com/reports/104012 | Integer overflow in unserialize() (32-bits only)
  674. https://hackerone.com/reports/104013 | heap buffer overflow in enchant_broker_request_dict()
  675. https://hackerone.com/reports/104014 | libcurl duphandle read out of bounds
  676. https://hackerone.com/reports/104015 | curl_setopt_array() type confusion
  677. https://hackerone.com/reports/104016 | Dangling pointer in the unserialization of ArrayObject items
  678. https://hackerone.com/reports/104017 | Arbitrary code execution in str_ireplace function
  679. https://hackerone.com/reports/104018 | Multiple Use After Free Vulnerabilites in unserialize()
  680. https://hackerone.com/reports/104019 | Files extracted from archive may be placed outside of destination directory
  681. https://hackerone.com/reports/104020 | audioop.lin2adpcm Buffer Over-read
  682. https://hackerone.com/reports/104021 | audioop.adpcm2lin Buffer Over-read
  683. https://hackerone.com/reports/104022 | hotshot pack_string Heap Buffer Overflow
  684. https://hackerone.com/reports/104023 | bytearray.find Buffer Over-read
  685. https://hackerone.com/reports/104024 | array.fromstring Use After Free
  686. https://hackerone.com/reports/104025 | use after free in load_newobj_ex
  687. https://hackerone.com/reports/104026 | invalid pointer free() in phar_tar_process_metadata()
  688. https://hackerone.com/reports/104027 | Memory Corruption in phar_parse_tarfile when entry filename starts with null
  689. https://hackerone.com/reports/104028 | Improved fix for bug #69545 (Integer overflow in ftp_genlist() resulting in heap overflow)
  690. https://hackerone.com/reports/104032 | PyFloat_FromString & PyNumber_Long Buffer Over-reads
  691. https://hackerone.com/reports/104033 | tokenizer crash when processing undecodable source code
  692. https://hackerone.com/reports/104087 | Trick make all fixed open redirect links vulnerable again
  693. https://hackerone.com/reports/104359 | shopifyapps.com XSS on sales channels via currency formatting
  694. https://hackerone.com/reports/104465 | git-fastclone allows arbitrary command execution through usage of ext remote URLs in submodules
  695. https://hackerone.com/reports/104543 | HTML injection in apps user review
  696. https://hackerone.com/reports/104559 | XSS on codex.wordpress.org
  697. https://hackerone.com/reports/104917 | Cross-Site Scripting Reflected On Main Domain
  698. https://hackerone.com/reports/104931 | CSRF in Connecting Pinterest Account
  699. https://hackerone.com/reports/105190 | Unsafe usage of Ruby string interpolation enabling command injection in git-fastclone
  700. https://hackerone.com/reports/105419 | Cookie-Based Injection
  701. https://hackerone.com/reports/105463 | risk of having secure=false in a crossdomain.xml
  702. https://hackerone.com/reports/105659 | many xss in widgets.shopifyapps.com
  703. https://hackerone.com/reports/105688 | DOM Based XSS in Checkout
  704. https://hackerone.com/reports/105887 | Know whether private program for company exist or not
  705. https://hackerone.com/reports/105953 | Parameter pollution in social sharing buttons
  706. https://hackerone.com/reports/105977 | DLL Hijacking Vulnerability in GlassWireSetup.exe
  707. https://hackerone.com/reports/105991 | "Remember me" token generated when "Remember me" box unchecked
  708. https://hackerone.com/reports/106084 | Team Member███ associated with a Custom Group Created with 'Program Managment' only permissions can Comments on Bug Reports
  709. https://hackerone.com/reports/106293 | Reflective XSS on wholesale.shopify.com
  710. https://hackerone.com/reports/106305 | Improve signals in reputation
  711. https://hackerone.com/reports/106348 | text injection can be used in phishing 404 page should not include attacker text
  712. https://hackerone.com/reports/106350 | text injection can be used in phishing 404 page should not include attacker text
  713. https://hackerone.com/reports/106384 | Application error message
  714. https://hackerone.com/reports/106427 | HTTP-Response-Splitting on v.shopify.com
  715. https://hackerone.com/reports/106548 | Format string vulnerability in zend_throw_or_error()
  716. https://hackerone.com/reports/106636 | Strored Cross Site Scripting
  717. https://hackerone.com/reports/106779 | Stored XSS in comments
  718. https://hackerone.com/reports/106897 | Stored XSS in /admin/orders
  719. https://hackerone.com/reports/106982 | XSS in imgur mobile
  720. https://hackerone.com/reports/107036 | XSS in imgur mobile 3
  721. https://hackerone.com/reports/107213 | GlassWireSetup.exe subject to EXE planting attack
  722. https://hackerone.com/reports/107296 | Possible Timing Side-Channel in XMLRPC Verification
  723. https://hackerone.com/reports/107336 | Team Member(s) associated with a Group have Read-only permission (Post internal comments) can post comment to all the participants
  724. https://hackerone.com/reports/107358 | reflected in xss
  725. https://hackerone.com/reports/107780 | [cfire.mail.ru] Time Based SQL Injection
  726. https://hackerone.com/reports/107960 | Reflected File Download in community.ubnt.com/restapi/
  727. https://hackerone.com/reports/108082 | Exploiting unauthenticated encryption mode
  728. https://hackerone.com/reports/108113 | Bypassing callback_url validation on Digits
  729. https://hackerone.com/reports/108681 | Use After Free Vulnerability in WDDX Packet Deserialization
  730. https://hackerone.com/reports/108682 | Type Confusion Vulnerability in PHP_to_XMLRPC_worker()
  731. https://hackerone.com/reports/108683 | Session WDDX Packet Deserialization Type Confusion Vulnerability
  732. https://hackerone.com/reports/109054 | HTTP trace method is enabled
  733. https://hackerone.com/reports/109161 | protect against tabnabbing in statement
  734. https://hackerone.com/reports/109175 | Use After Free in sortWithSortKeys()
  735. https://hackerone.com/reports/109212 | [parapa.mail.ru] SQL Injection
  736. https://hackerone.com/reports/109483 | User with Read-Only permissions can request/approve public disclosure
  737. https://hackerone.com/reports/109699 | Subdomain Takeover in http://assets.goubiquiti.com/
  738. https://hackerone.com/reports/109815 | Direct URL access to completed reports
  739. https://hackerone.com/reports/109843 | Uninitialized pointer in phar_make_dirstream()
  740. https://hackerone.com/reports/109959 | Extended policy checks are buggy
  741. https://hackerone.com/reports/110293 | Insufficient OAuth callback validation which leads to Periscope account takeover
  742. https://hackerone.com/reports/110352 | Perl 5.22 VDir::MapPathA/W Out-of-bounds Reads and Buffer Over-reads
  743. https://hackerone.com/reports/110417 | Heap corruption in tar/zip/phar parser
  744. https://hackerone.com/reports/110467 | Bypassing Digits bridge origin validation
  745. https://hackerone.com/reports/110578 | HTML injection can lead to data theft
  746. https://hackerone.com/reports/110655 | Information Exposure Through Directory Listing
  747. https://hackerone.com/reports/110720 | Arbitary Memory Read via gdImageRotateInterpolated Array Index Out of Bounds
  748. https://hackerone.com/reports/110722 | Heap BufferOver Flow in escapeshellargs and escapeshellcmd functions
  749. https://hackerone.com/reports/110801 | Internal GET SSRF via CSRF with Press This scan feature
  750. https://hackerone.com/reports/111078 | Sub Domain Take over
  751. https://hackerone.com/reports/111094 | Content Spoofing OR Text Injection in https://withinsecurity.com
  752. https://hackerone.com/reports/111192 | CSV Injection via the CSV export feature
  753. https://hackerone.com/reports/111216 | Twitter Disconnect CSRF
  754. https://hackerone.com/reports/111218 | Attach Pinterest account - no State/CSRF parameter in Oauth Call back
  755. https://hackerone.com/reports/111365 | XSS at www.woothemes.com
  756. https://hackerone.com/reports/111386 | Legacy API exposes private video titles
  757. https://hackerone.com/reports/111417 | Checking whether user liked the media or not even when you are blocked
  758. https://hackerone.com/reports/111500 | XSS at wordpress.com
  759. https://hackerone.com/reports/111752 | Big Bug in SSL : breach compression attack (CVE-2013-3587) affect imgur.com
  760. https://hackerone.com/reports/111860 | Error Page Text Injection #106350
  761. https://hackerone.com/reports/111915 | [CRITICAL] HTML injection issue leading to account take over
  762. https://hackerone.com/reports/111950 | [allods.my.com] SSRF / XSPA
  763. https://hackerone.com/reports/111968 | Interstitial redirect bypass / open redirect in https://hackerone.com/zendesk_session
  764. https://hackerone.com/reports/112057 | Heapoverflow in zipimporter module
  765. https://hackerone.com/reports/112386 | smartlist_add, smartlist_insert (may) cause heap corruption as a result of inadequate checks in smartlist_ensure_capacity
  766. https://hackerone.com/reports/112496 | Session Issue Maybe Can lead to huge loss [CRITICAL]
  767. https://hackerone.com/reports/112555 | [afisha.mail.ru] SQL Injection
  768. https://hackerone.com/reports/112632 | [tor] libevent dns remote stack overread vulnerability
  769. https://hackerone.com/reports/112723 | PHP-FPM fpm_log.c memory leak and buffer overflow
  770. https://hackerone.com/reports/112784 | libevent (stack) buffer overflow in evutil_parse_sockaddr_port
  771. https://hackerone.com/reports/112855 | EIP control using type confusion in json encoding
  772. https://hackerone.com/reports/112858 | UAF in xmlparser_setevents (1)
  773. https://hackerone.com/reports/112860 | UAF in xmlparser_setevents (2)
  774. https://hackerone.com/reports/112863 | Trivial age-old heap overflow in 32-bit PHP
  775. https://hackerone.com/reports/112935 | Unintended HTML inclusion as a result of https://hackerone.com/reports/110578
  776. https://hackerone.com/reports/112955 | WordPress Failure Notice page will generate arbitrary hyperlinks
  777. https://hackerone.com/reports/113070 | Multiple issues with Markdown and URL parsing
  778. https://hackerone.com/reports/113112 | Open-redirect on paragonie.com
  779. https://hackerone.com/reports/113120 | An integer overflow bug in php_implode() could lead heap overflow, make PHP to crash
  780. https://hackerone.com/reports/113122 | An integer overflow bug in php_str_to_str_ex() led arbitrary code execution.
  781. https://hackerone.com/reports/113268 | Integer overflow in wordwrap
  782. https://hackerone.com/reports/113288 | OpenSSL Key Recovery Attack on DH small subgroups (CVE-2016-0701)
  783. https://hackerone.com/reports/113424 | [tor] control connection pre-auth DoS (infinite loop) with --enable-bufferevents
  784. https://hackerone.com/reports/113798 | Null pointer deref with ob_start with compact
  785. https://hackerone.com/reports/113799 | Null pointer deref with ob_start with get_defined_vars
  786. https://hackerone.com/reports/114024 | Stack overflow when decompressing tar archives
  787. https://hackerone.com/reports/114078 | Use-after-free vulnerability in SPL(ArrayObject, unserialize)
  788. https://hackerone.com/reports/114079 | Use-after-free vulnerability in SPL(SplObjectStorage, unserialize)
  789. https://hackerone.com/reports/114125 | Remote Server Restart Lead to Denial of Server by only one Request.
  790. https://hackerone.com/reports/114169 | Bypassing Digits web authentication's host validation with HPP
  791. https://hackerone.com/reports/114172 | Out-of-Bound Read in phar_parse_zipfile()
  792. https://hackerone.com/reports/114339 | Type Confusion in WDDX Packet Deserialization
  793. https://hackerone.com/reports/114414 | openssl_seal() uninitialized memory usage
  794. https://hackerone.com/reports/114430 | CSRF on https://shopify.com/plus
  795. https://hackerone.com/reports/114476 | Внедрение внешних �ущно�тей в функционале импорта пользователей YouTrack
  796. https://hackerone.com/reports/114529 | Content Spoofing and Local Redirect in Mapbox Studio
  797. https://hackerone.com/reports/114698 | Remote Server Restart Lead to Denial of Service by only one Request.
  798. https://hackerone.com/reports/115007 | Race conditions can be used to bypass invitation limit
  799. https://hackerone.com/reports/115205 | Putting link inside link in markdown
  800. https://hackerone.com/reports/115230 | Content spoofing due to the improper behavior of the not-found meesage
  801. https://hackerone.com/reports/115275 | SPF DNS Record
  802. https://hackerone.com/reports/115284 | prevent content spoofing on /search
  803. https://hackerone.com/reports/115291 | [orsotenslimselfie.lady.mail.ru] SQL Injection
  804. https://hackerone.com/reports/115337 | Full Path Disclosure
  805. https://hackerone.com/reports/115686 | [tor] pre-emptive defenses, potential vulnerabilities
  806. https://hackerone.com/reports/115702 | [tor] libevent dns OOB read
  807. https://hackerone.com/reports/115748 | SSRF in https://imgur.com/vidgif/url
  808. https://hackerone.com/reports/115857 | SSRF and local file read in video to gif converter
  809. https://hackerone.com/reports/115978 | SSRF / Local file enumeration / DoS due to improper handling of certain file formats by ffmpeg
  810. https://hackerone.com/reports/116006 | XSS on hardware.shopify.com
  811. https://hackerone.com/reports/116029 | Private program activity timeline information disclosure
  812. https://hackerone.com/reports/116032 | Private Program Disclosure in /:handle/reports/draft.json endpoint
  813. https://hackerone.com/reports/116286 | Type confusion in partial.setstate, partial_repr, partial_call leads to memory corruption, reliable control flow hijack
  814. https://hackerone.com/reports/116360 | The POODLE attack (SSLv3 supported) for https://grtp.co/
  815. https://hackerone.com/reports/116372 | Use-After-Free / Double-Free in WDDX Deserialize
  816. https://hackerone.com/reports/116419 | an xss issue in https://hunter22.slack.com/help/requests/793043
  817. https://hackerone.com/reports/116508 | [3k.mail.ru] SQL Injection
  818. https://hackerone.com/reports/116570 | VERY DANGEROUS XSS STORED inside emails
  819. https://hackerone.com/reports/116764 | vk.com/login.php
  820. https://hackerone.com/reports/116773 | Type Confusion Vulnerability - SOAP / make_http_soap_request()
  821. https://hackerone.com/reports/116798 | Private Program Disclosure in /:handle/settings/allow_report_submission.json endpoint
  822. https://hackerone.com/reports/116937 | Chat History CSV Export Excel Injection Vulnerability
  823. https://hackerone.com/reports/116951 | Increase number of bugs by sending duplicate of your own valid report
  824. https://hackerone.com/reports/116973 | No Valid SPF Records.
  825. https://hackerone.com/reports/117068 | XSS @ love.uber.com
  826. https://hackerone.com/reports/117080 | Multiple Vulnerabilities (Including SQLi) in love.uber.com
  827. https://hackerone.com/reports/117097 | Email Forgery through Mandrillapp SPF
  828. https://hackerone.com/reports/117142 | limit HTTP methods on other domains
  829. https://hackerone.com/reports/117149 | SPF/DKIM/DMARC for grtp.co
  830. https://hackerone.com/reports/117159 | SPF/DKIM/DMARC for aspen.io
  831. https://hackerone.com/reports/117187 | Prevent content spoofing on /~username/emails/verify.html
  832. https://hackerone.com/reports/117190 | Reflected XSS on Uber.com careers
  833. https://hackerone.com/reports/117325 | DMARC is misconfigured for grtp.co
  834. https://hackerone.com/reports/117330 | stop serving grtp.co over HTTP
  835. https://hackerone.com/reports/117449 | XSS in Draft Orders in Timeline i SHOPIFY Admin Site!
  836. https://hackerone.com/reports/117458 | strengthen Diffie-Hellman (DH) key exchange parameters in grtp.co
  837. https://hackerone.com/reports/117480 | Stored XSS via Angular Expression injection on developer.zendesk.com
  838. https://hackerone.com/reports/117651 | Multiple Heap Overflow due to integer overflows | xml/filter_url/addcslashes
  839. https://hackerone.com/reports/117739 | limit number of images in statement
  840. https://hackerone.com/reports/117902 | Дорк
  841. https://hackerone.com/reports/118066 | Content Spoofing in mango.qiwi.com
  842. https://hackerone.com/reports/118582 | CSV Injection at the CSV export feature
  843. https://hackerone.com/reports/118631 | XSSI (Cross Site Script Inclusion)
  844. https://hackerone.com/reports/118688 | File name and folder enumeration.
  845. https://hackerone.com/reports/118718 | User with Read-Only permissions can manually public disclosure the report
  846. https://hackerone.com/reports/118855 | CVE-2016-0799 memory issues in BIO_*printf functions
  847. https://hackerone.com/reports/118925 | API Key added for one Indices works for all other indices too.
  848. https://hackerone.com/reports/118965 | Distinguish EP+Private vs Private programs in HackerOne
  849. https://hackerone.com/reports/119022 | Tweet Deck XSS- Persistent- Group DM name
  850. https://hackerone.com/reports/119166 | Able to view others' gifts on /gift/share URL, giftId is predictable, and easy to manipulate
  851. https://hackerone.com/reports/119220 | Sub-Domain Takeover
  852. https://hackerone.com/reports/119221 | User with Read-Only permissions can edit the Internal comment Activities on Bug Reports After Revoke the team access permissions
  853. https://hackerone.com/reports/119236 | Open Redirection on Uber.com
  854. https://hackerone.com/reports/119250 | xss in the all widgets of shopifyapps.com
  855. https://hackerone.com/reports/119317 | Read-Only user can execute arbitraty shell commands on AirOS
  856. https://hackerone.com/reports/119471 | DOMXSS in Tweetdeck
  857. https://hackerone.com/reports/119652 | Adobe Flash Player ASnative(101,10) Memory Corruption Vulnerability
  858. https://hackerone.com/reports/119653 | Adobe Flash Player ASnative(900,1).call(MovieClip) Use-After-Free Vulnerability
  859. https://hackerone.com/reports/119655 | Adobe Flash Player ASnative(900,1).call(TextField) Use-After-Free Vulnerability
  860. https://hackerone.com/reports/119657 | Adobe Flash Player Race Condition Vulnerability
  861. https://hackerone.com/reports/119873 | BN_hex2bn/BN_dec2bn NULL pointer deref/heap corruption (CVE-2016-0797)
  862. https://hackerone.com/reports/120026 | don't serve hidden files from Nginx
  863. https://hackerone.com/reports/121461 | Subdomain takeover due to unclaimed Amazon S3 bucket on a2.bime.io
  864. https://hackerone.com/reports/121469 | Broken Authentication on Badoo
  865. https://hackerone.com/reports/121489 | CRLF injection in https://verkkopalvelu.lahitapiola.fi/
  866. https://hackerone.com/reports/121696 | Bypass two-factor authentication
  867. https://hackerone.com/reports/121827 | Account Takeover
  868. https://hackerone.com/reports/121863 | Buffer overflow in HTTP url parsing functions
  869. https://hackerone.com/reports/121940 | Shell Injection via Web Management Console (dl-fw.cgi)
  870. https://hackerone.com/reports/122050 | Mapbox API Access Token with No Scope Can Read Styles
  871. https://hackerone.com/reports/122113 | OpenSSH / dropbearSSHd xauth command injection
  872. https://hackerone.com/reports/122254 | Adobe Flash Player TextField Use-After-Free Vulnerability
  873. https://hackerone.com/reports/122256 | Adobe Flash Player Uninitialised Memory Corruption
  874. https://hackerone.com/reports/122849 | Stored XSS in https://checkout.shopify.com/
  875. https://hackerone.com/reports/123027 | Edit Auto Response Messages
  876. https://hackerone.com/reports/123119 | Use after free with assign by ref to overloaded objects
  877. https://hackerone.com/reports/123125 | XSS on hardware.shopify.com
  878. https://hackerone.com/reports/123339 | CSRF allows attacker to delete item from customer's "Postilaatikko"
  879. https://hackerone.com/reports/123615 | SECURITY: Referencing previous Reports attachment_IDs on new Reports via Draft_Sync DELETES Attachments
  880. https://hackerone.com/reports/123742 | suppress version in Server header on gratipay.com or grtp.co
  881. https://hackerone.com/reports/123849 | Cookie Does Not Contain The "secure" Attribute
  882. https://hackerone.com/reports/123897 | auto-logout after 20 minutes
  883. https://hackerone.com/reports/124100 | Shopify GitHub Login and Password exposed all private source code might be available.
  884. https://hackerone.com/reports/124223 | CSV Injection via the CSV export feature
  885. https://hackerone.com/reports/124277 | XSS via React element spoofing
  886. https://hackerone.com/reports/124429 | Stored XSS via "Free Shipping" option (Discounts)
  887. https://hackerone.com/reports/124611 | Disclosure of private programs that have an "external" page on HackerOne
  888. https://hackerone.com/reports/124737 | Multiple Heap Overflows in php_raw_url_encode/php_url_encode
  889. https://hackerone.com/reports/124845 | Bypassed password authentication before enabling OTP verification
  890. https://hackerone.com/reports/124889 | Websites opened from reports can change url of report page
  891. https://hackerone.com/reports/124976 | Hijacking user session by forcing the use of invalid HTTPs Certificate on images.gratipay.com
  892. https://hackerone.com/reports/125000 | Open Redirect in m.uber.com
  893. https://hackerone.com/reports/125027 | Reflected XSS on developer.uber.com via Angular template injection
  894. https://hackerone.com/reports/125112 | XSS in getrush.uber.com
  895. https://hackerone.com/reports/125200 | Lack of rate limiting on get.uber.com leads to enumeration of promotion codes and estimation of a lower bound on the number of Uber drivers
  896. https://hackerone.com/reports/125250 | Avoiding Surge Pricing
  897. https://hackerone.com/reports/125498 | Dom Based Xss
  898. https://hackerone.com/reports/125505 | Possibility to brute force invite codes in riders.uber.com
  899. https://hackerone.com/reports/125587 | Hogging up all the resources on hackerone.com
  900. https://hackerone.com/reports/125791 | Reflected XSS via Unvalidated / Open Redirect in uber.com
  901. https://hackerone.com/reports/125849 | XSS found on Snapchat website
  902. https://hackerone.com/reports/125980 | uber.com may RCE by Flask Jinja2 Template Injection
  903. https://hackerone.com/reports/126010 | prevent content spoofing on /~username/emails/verify.html
  904. https://hackerone.com/reports/126099 | Stored XSS in drive.uber.com WordPress admin panel
  905. https://hackerone.com/reports/126109 | CSV Injection in business.uber.com
  906. https://hackerone.com/reports/126197 | XSS In archive.uber.com Due to Mime Sniffing in IE
  907. https://hackerone.com/reports/126203 | CBC "cut and paste" attack may cause Open Redirect(even XSS)
  908. https://hackerone.com/reports/126209 | Posting modified information in 'Investment section' will cause unintended information change in verkkopalvelu.tapiola.fi
  909. https://hackerone.com/reports/126416 | Integer Overflow in php_raw_url_encode
  910. https://hackerone.com/reports/126522 | Incorrect param parsing in Digits web authentication
  911. https://hackerone.com/reports/126539 | XSS on https://app.shopify.com/
  912. https://hackerone.com/reports/126652 | potential remote code execution with phar archive
  913. https://hackerone.com/reports/126797 | Use-after-free during XML transformations (MFSA-2016-27)
  914. https://hackerone.com/reports/126906 | Stored XSS in archive.uber.com Due to Injection of Javascript:alert(0)
  915. https://hackerone.com/reports/127077 | www.lahitapiola.fi DOM XSS by choosing regional company
  916. https://hackerone.com/reports/127154 | XSS using javascript:alert(8007)
  917. https://hackerone.com/reports/127212 | php_snmp_error() Format String Vulnerability
  918. https://hackerone.com/reports/127242 | Negative size parameter (-1) in memcpy mbfl_strcut
  919. https://hackerone.com/reports/127620 | New hacktivity view discloses report IDs of non-public reports
  920. https://hackerone.com/reports/127703 | [CRITICAL] Full account takeover using CSRF
  921. https://hackerone.com/reports/127844 | Web Authentication Endpoint Credentials Brute-Force Vulnerability
  922. https://hackerone.com/reports/127918 | Easy spam with USE My PHONE Feature
  923. https://hackerone.com/reports/127948 | Stored XSS on newsroom.uber.com admin panel / Stream WordPress plugin
  924. https://hackerone.com/reports/127995 | Limit email address length
  925. https://hackerone.com/reports/128088 | AWS S3 bucket writeable for authenticated aws users
  926. https://hackerone.com/reports/128114 | Administrator access to a Django Administration Panel on *.sc-corp.net via bruteforced credentials
  927. https://hackerone.com/reports/128121 | fix bug in username restriction
  928. https://hackerone.com/reports/128169 | BN_mod_exp may produce incorrect results on x86_64 (CVE-2015-3193)
  929. https://hackerone.com/reports/128750 | Read-Only user can execute arbitraty shell commands on AirOS
  930. https://hackerone.com/reports/128777 | No rate-limit in Two factor Authentication leads to bypass using bruteforce attack
  931. https://hackerone.com/reports/128856 | Send email asynchronously
  932. https://hackerone.com/reports/129001 | Cookie-based client-side denial-of-service to all of the Lähitapiola domains
  933. https://hackerone.com/reports/129091 | CPU utilization 99% on visiting wordpress site url & open redirect found
  934. https://hackerone.com/reports/129381 | niche s3 buckets are readable/writeable/deleteable by authorized AWS users
  935. https://hackerone.com/reports/129436 | xss in DM group name in twitter
  936. https://hackerone.com/reports/129771 | Python 2.7 strop.replace Integer Overflow
  937. https://hackerone.com/reports/129773 | Previous attachments can be referenced when creating a new report
  938. https://hackerone.com/reports/129862 | Stored XSS on [your_zendesk].zendesk.com in Facebook Channel
  939. https://hackerone.com/reports/129873 | Bypassing Digits origin validation which leads to account takeover
  940. https://hackerone.com/reports/130889 | Reflected XSS in scores.ubnt.com
  941. https://hackerone.com/reports/131065 | bring grtp.co up to A grade on SSLLabs
  942. https://hackerone.com/reports/131082 | Open Redirector via (apps/files_pdfviewer) for un-authenticated users.
  943. https://hackerone.com/reports/131108 | Akismet Several CSRF vulnerabilities
  944. https://hackerone.com/reports/131202 | [Critical] - Steal OAuth Tokens
  945. https://hackerone.com/reports/131450 | Stored XSS in developer.uber.com
  946. https://hackerone.com/reports/132104 | Stored XSS on team.slack.com using new Markdown editor of posts inside the Editing mode and using javascript-URIs
  947. https://hackerone.com/reports/132602 | Stored XSS at Udemy
  948. https://hackerone.com/reports/133963 | XSS on www.wordpress.com
  949. https://hackerone.com/reports/134061 | Reflected XSS via Livefyre Media Wall in newsroom.uber.com
  950. https://hackerone.com/reports/134321 | RCE on facebooksearch.algolia.com
  951. https://hackerone.com/reports/134388 | Content Spoofing or Text Injection (404 error page injection on yrityspalvelu)
  952. https://hackerone.com/reports/134434 | XSS In /zuora/ functionality
  953. https://hackerone.com/reports/134546 | WordPress Flash XSS in flashmediaelement.swf
  954. https://hackerone.com/reports/134738 | WordPress SOME bug in plupload.flash.swf leading to RCE
  955. https://hackerone.com/reports/134757 | staff memeber can install apps even if have limitied access
  956. https://hackerone.com/reports/134880 | ASN.1 BIO excessive memory allocation (CVE-2016-2109)
  957. https://hackerone.com/reports/135072 | RCE in profile picture upload
  958. https://hackerone.com/reports/135152 | Integer overflow in ZipArchive::getFrom*
  959. https://hackerone.com/reports/135217 | Reflected cross-site scripting (XSS) on api.tiles.mapbox.com
  960. https://hackerone.com/reports/135288 | Multiple vulnerabilities in a WordPress plugin at drive.uber.com
  961. https://hackerone.com/reports/135291 | Out-of-bounds reads in zif_grapheme_stripos with negative offset
  962. https://hackerone.com/reports/135293 | bcpowmod accepts negative scale and corrupts one definition
  963. https://hackerone.com/reports/135294 | xml_parse_into_struct segmentation fault
  964. https://hackerone.com/reports/135756 | View all deleted comments and rating of any app .
  965. https://hackerone.com/reports/135797 | Session Fixation
  966. https://hackerone.com/reports/135944 | EVP_EncodeUpdate overflow (CVE-2016-2105)
  967. https://hackerone.com/reports/135945 | EVP_EncryptUpdate overflow (CVE-2016-2106)
  968. https://hackerone.com/reports/135946 | EBCDIC overread (CVE-2016-2176)
  969. https://hackerone.com/reports/136169 | OneLogin authentication bypass on WordPress sites
  970. https://hackerone.com/reports/136221 | Denial of service in account statistics endpoint
  971. https://hackerone.com/reports/136454 | User credentials leak and arbitrary local file read/leak due to same-origin-policy violation
  972. https://hackerone.com/reports/136481 | CSRF on Vimeo via cross site flashing leading to info disclosure and private videos go public
  973. https://hackerone.com/reports/136582 | OAuth 2 Authorization Bypass via CSRF and Cross Site Flashing
  974. https://hackerone.com/reports/136600 | Reflected XSS in Backend search
  975. https://hackerone.com/reports/136720 | don't leak server version of grtp.co in error pages
  976. https://hackerone.com/reports/136850 | Images and Subtitles Leakage from private videos
  977. https://hackerone.com/reports/136986 | Padding oracle in AES-NI CBC MAC check (CVE-2016-2107)
  978. https://hackerone.com/reports/137487 | Amazon Bucket Accessible (http://inpref.s3.amazonaws.com/)
  979. https://hackerone.com/reports/137502 | All Vimeo Private videos disclosure via Authorization Bypass
  980. https://hackerone.com/reports/137956 | SQL Injection
  981. https://hackerone.com/reports/138025 | Heap corruption via memarea.c
  982. https://hackerone.com/reports/138075 | [stored xss, pornhub.com] stream post function
  983. https://hackerone.com/reports/138179 | Divide-and-conquer session key recovery in SSLv2 (CVE-2016-0703)
  984. https://hackerone.com/reports/138181 | Bleichenbacher oracle in SSLv2 (CVE-2016-0704)
  985. https://hackerone.com/reports/138243 | [IDOR] Deleting other users comment
  986. https://hackerone.com/reports/138244 | Missing access control exposing detailed information on all users
  987. https://hackerone.com/reports/138516 | Adobe Flash Player ContentFactory class Memory Corruption Vulnerability
  988. https://hackerone.com/reports/138517 | Adobe Flash Player Metadata class Memory Corruption Vulnerability
  989. https://hackerone.com/reports/138518 | Adobe Flash Player OpportunityGenerator class Memory Corruption Vulnerability
  990. https://hackerone.com/reports/138869 | OneLogin authentication bypass on WordPress sites via XMLRPC
  991. https://hackerone.com/reports/139004 | Persistent XSS at verkkopalvelu.tapiola.fi using spoofed React element and React v.0.13.3
  992. https://hackerone.com/reports/139192 | Ability to collect users' ids that have visited a specific web page with malicious code
  993. https://hackerone.com/reports/139245 | WordPress core stored XSS via attachment file name
  994. https://hackerone.com/reports/139398 | Read-Only user can execute arbitraty shell commands on AirOS
  995. https://hackerone.com/reports/139626 | Passphrase credential lock bypass
  996. https://hackerone.com/reports/139879 | Adobe Flash Player Regular Expression UAF Remote Code Execution Vulnerability
  997. https://hackerone.com/reports/140432 | configure a redirect URI for Facebook OAuth
  998. https://hackerone.com/reports/140447 | Open Redirect on slack.com
  999. https://hackerone.com/reports/140548 | [upload-X.my.mail.ru] /uploadphoto Insecure Direct Object References
  1000. https://hackerone.com/reports/140616 | www.starbucks.co.uk Reflected XSS via utm_source parameter
  1001. https://hackerone.com/reports/140705 | [my.mail.ru] HTML injection в пиÑ�ьмах от [email protected]
  1002. https://hackerone.com/reports/140865 | Integer Overflow in php_html_entities()
  1003. https://hackerone.com/reports/141065 | Security Issue : CSRF Token Design Flaw
  1004. https://hackerone.com/reports/141125 | Ngnix Server version disclosure
  1005. https://hackerone.com/reports/141174 | node.drchrono.com - Information Disclosure and Windows Host Exposed
  1006. https://hackerone.com/reports/141197 | get_icu_value_internal out-of-bounds read
  1007. https://hackerone.com/reports/141198 | Template stored XSS
  1008. https://hackerone.com/reports/141202 | imagescale out-of-bounds read
  1009. https://hackerone.com/reports/141212 | Integer underflow / arbitrary null write in fread/gzread
  1010. https://hackerone.com/reports/141240 | Angular injection in the profile name of onpatient
  1011. https://hackerone.com/reports/141244 | XSS in zendesk.com/product/
  1012. https://hackerone.com/reports/141344 | [CRITICAL] CSRF leading to account take over
  1013. https://hackerone.com/reports/141463 | Stored XSS via AngularJS Injection
  1014. https://hackerone.com/reports/141541 | User with no permissions can access full wdcalendar feed
  1015. https://hackerone.com/reports/141629 | Able to remove the admin access of my program
  1016. https://hackerone.com/reports/141700 | Bypass GlassWire's monitoring of Hosts file
  1017. https://hackerone.com/reports/141734 | Bypassing Password Reset
  1018. https://hackerone.com/reports/141839 | Multiple vulnerabilities related to PCRE functions (already fixed)
  1019. https://hackerone.com/reports/142084 | Stored XSS in unifi.ubnt.com
  1020. https://hackerone.com/reports/142096 | [Screenhero] Subdomain takeover
  1021. https://hackerone.com/reports/142101 | User with no permissions can create, edit, delete favorite prescriptions /erx/
  1022. https://hackerone.com/reports/142135 | XSS в upload.php
  1023. https://hackerone.com/reports/142472 | CVE-2016-2177 Undefined pointer arithmetic in SSL code
  1024. https://hackerone.com/reports/142549 | Information Disclosure through .DS_Store in ██████████
  1025. https://hackerone.com/reports/142709 | Fetching external resources through svg images
  1026. https://hackerone.com/reports/142773 | 16 instances where return value of OpenSSL i2d_RSAPublicKey is discarded -- might lead to use of uninitialized memory
  1027. https://hackerone.com/reports/142940 | Bug Report
  1028. https://hackerone.com/reports/142946 | xss vulnerability in http://ubermovement.com/community/daniel
  1029. https://hackerone.com/reports/143022 | Heap corruption via Python 2.7.11 IOBase readline()
  1030. https://hackerone.com/reports/143064 | Information Disclosure
  1031. https://hackerone.com/reports/143139 | upgrade Aspen on inside.gratipay.com to pick up CR injection fix
  1032. https://hackerone.com/reports/143220 | XSS on www.mapbox.com/authorize
  1033. https://hackerone.com/reports/143234 | Integer Overflow in _gd2GetHeader() resulting in heap overflow
  1034. https://hackerone.com/reports/143240 | XSS on www.mapbox.com/authorize/ because of open redirect at /core/oauth/auth
  1035. https://hackerone.com/reports/143669 | Получение оригинала �крытого изображени�
  1036. https://hackerone.com/reports/143717 | Change any Uber user's password through /rt/users/passwordless-signup - Account Takeover (critical)
  1037. https://hackerone.com/reports/143903 | File upload over private IM channel
  1038. https://hackerone.com/reports/143935 | [sms-be-vip.twitter.com] vulnerable to Jetleak
  1039. https://hackerone.com/reports/143966 | Insufficient shell characters filtering leads to (potentially remote) code execution (CVE-2016-3714)
  1040. https://hackerone.com/reports/143975 | Homograph attack in escalate report
  1041. https://hackerone.com/reports/144000 | Authorization Bypass in Delivery Chat Logs
  1042. https://hackerone.com/reports/144129 | Old titles are not hidden in reports with limited disclosure
  1043. https://hackerone.com/reports/144482 | StringIO strio_getline() can divulge arbitrary memory
  1044. https://hackerone.com/reports/144616 | Brute-Forcing invite codes in partners.uber.com
  1045. https://hackerone.com/reports/144674 | [townwars.mail.ru] Time-Based SQL Injection
  1046. https://hackerone.com/reports/144782 | CVE-2016-0772 - python: smtplib StartTLS stripping attack
  1047. https://hackerone.com/reports/145086 | Stored XSS in SupportFlow Ticket Subject
  1048. https://hackerone.com/reports/145091 | Stored XSS from ticket messages in admin table in SupportFlow
  1049. https://hackerone.com/reports/145128 | [account-global.ubnt.com] CRLF Injection
  1050. https://hackerone.com/reports/145150 | Bulk UUID enumeration via invite codes
  1051. https://hackerone.com/reports/145224 | Subdomain takeover on partners.ubnt.com due to non-used CloudFront DNS entry
  1052. https://hackerone.com/reports/145265 | Adobe Flash Player ShimContentFactory class Memory Corruption Vulnerability
  1053. https://hackerone.com/reports/145266 | Adobe Flash Player ShimContentFactory.retrieveResolvers Memory Corruption Vulnerability
  1054. https://hackerone.com/reports/145267 | Adobe Flash Player ShimContentResolver.configure Memory Corruption Vulnerability
  1055. https://hackerone.com/reports/145269 | Adobe Flash Player ShimOpportunityGenerator class Memory Corruption Vulnerability
  1056. https://hackerone.com/reports/145271 | Adobe Flash Player ShimContentResolver(resolverType=0) class Memory Corruption Vulnerability
  1057. https://hackerone.com/reports/145272 | Adobe Flash Player ShimContentResolver(resolverType=1) class Memory Corruption Vulnerability
  1058. https://hackerone.com/reports/145278 | xss in https://www.uber.com
  1059. https://hackerone.com/reports/145355 | Stored XSS on Share-popup of a directory's Gallery-view
  1060. https://hackerone.com/reports/145452 | Share owner has no possibility to list all existing derived shares
  1061. https://hackerone.com/reports/145463 | Nextcloud server software: Content Spoofing
  1062. https://hackerone.com/reports/145467 | Downloading password protected / restricted videos
  1063. https://hackerone.com/reports/145629 | 2-factor authentication bypass
  1064. https://hackerone.com/reports/145950 | Uploading files to a folder where invited user don't have any EDIT privilege
  1065. https://hackerone.com/reports/146180 | Integer Overflow in SplFileObject::fread
  1066. https://hackerone.com/reports/146182 | Integer Overflow/Heap Overflow in json_encode()/json_decode()
  1067. https://hackerone.com/reports/146183 | Integer Overflow in nl2br()
  1068. https://hackerone.com/reports/146184 | Integer Overflow in addcslashes()/addslashes()
  1069. https://hackerone.com/reports/146185 | Integer Overflow in Length of String-typed ZVAL
  1070. https://hackerone.com/reports/146200 | _php_mb_regex_ereg_replace_exec - double free
  1071. https://hackerone.com/reports/146202 | Invalid free in phar_extract_file()
  1072. https://hackerone.com/reports/146233 | Use After Free Vulnerability in PHP's GC algorithm and unserialize
  1073. https://hackerone.com/reports/146235 | ZipArchive class Use After Free Vulnerability in PHP's GC algorithm and unserialize
  1074. https://hackerone.com/reports/146255 | Double Free Corruption in wddx.c (extension)
  1075. https://hackerone.com/reports/146278 | Log pollution can lead to HTML Injection.
  1076. https://hackerone.com/reports/146336 | XSS vulnerable parameter in a location hash
  1077. https://hackerone.com/reports/146360 | Heap Overflow Due To Integer Overflow
  1078. https://hackerone.com/reports/146707 | Mixed Active Scripting Issue on https://www.lahitapiola.fi
  1079. https://hackerone.com/reports/146845 | Race Conditions in Popular reports feature.
  1080. https://hackerone.com/reports/146910 | RC4 cipher suites detected
  1081. https://hackerone.com/reports/146911 | The POODLE attack (SSLv3 supported)
  1082. https://hackerone.com/reports/146936 | CVE-2015-8874 Stack overflow with imagefilltoborder
  1083. https://hackerone.com/reports/146940 | pass2_no_dither out-of-bounds access
  1084. https://hackerone.com/reports/146944 | NULL Pointer Dereference at _gdScaleVert
  1085. https://hackerone.com/reports/147125 | Integer Overflow in gdImagePaletteToTrueColor() resulting in heap overflow
  1086. https://hackerone.com/reports/147369 | User can start call in a channel of an unpaid account
  1087. https://hackerone.com/reports/147544 | Generate new Test token
  1088. https://hackerone.com/reports/147577 | Application error message
  1089. https://hackerone.com/reports/147776 | Change contents of the careers iframe in https://corp.badoo.com/jobs
  1090. https://hackerone.com/reports/148050 | Know undisclosed Bounty Amount when Bounty Statistics are enabled.
  1091. https://hackerone.com/reports/148151 | SMB User Authentication Bypass and Persistence
  1092. https://hackerone.com/reports/148467 | Паблики: Модератор паблика может удал�ть добавленные редакторами материалы � таймером на публикаци�.
  1093. https://hackerone.com/reports/148609 | Register multiple users using one invitation (race condition)
  1094. https://hackerone.com/reports/148741 | Stored Cross-Site-Scripting in CMS Airship's authors profiles
  1095. https://hackerone.com/reports/148751 | Stored XSS in comments
  1096. https://hackerone.com/reports/148764 | [idor] Unauthorized Read access to all the private posts(Including Photos,Videos,Gifs)
  1097. https://hackerone.com/reports/148770 | Subdomain takeover at api.legalrobot.com due to non-used domain in Modulus.io.
  1098. https://hackerone.com/reports/148777 | Microsoft IIS tilde directory enumeration
  1099. https://hackerone.com/reports/148848 | "a stored xss issue in share post menu"
  1100. https://hackerone.com/reports/148853 | Stored XSS using SVG
  1101. https://hackerone.com/reports/148865 | HTML in Diffusion not escaped in certain circumstances
  1102. https://hackerone.com/reports/148963 | Application error message
  1103. https://hackerone.com/reports/149011 | a stored xss issue in https://files.slack.com
  1104. https://hackerone.com/reports/149154 | Stored xss
  1105. https://hackerone.com/reports/149287 | Reflected Xss in AirMax [Nanostation Loco M2]
  1106. https://hackerone.com/reports/149571 | Stored XSS in wis.pr
  1107. https://hackerone.com/reports/149798 | Content (Text) Injection at NextCloud Server 9.0.52 - via http://custom_nextcloud_url/remote.php/dav/files/
  1108. https://hackerone.com/reports/149855 | Reflected XSS in m.imgur.com
  1109. https://hackerone.com/reports/149907 | Urgent: attacker can access every data source on Bime
  1110. https://hackerone.com/reports/149914 | Attacker can access graphic representation of every query
  1111. https://hackerone.com/reports/150083 | Cross Site Scripting(XSS) on IRCCloud Badges Page (using Parameter Pollution)
  1112. https://hackerone.com/reports/150156 | SQL Injection on sctrack.email.uber.com.cn
  1113. https://hackerone.com/reports/150179 | Html Injection and Possible XSS in sms-be-vip.twitter.com
  1114. https://hackerone.com/reports/150374 | https://windsor.shopify.com/ takeover
  1115. https://hackerone.com/reports/150626 | Heap Buffer Overflow
  1116. https://hackerone.com/reports/150905 | Information disclosure through directory listing at http://dockerhost01.maximum.nl:8080
  1117. https://hackerone.com/reports/150976 | Flash “local-with-filesystem� Bypass in navigateToURL
  1118. https://hackerone.com/reports/151034 | Xss on billing
  1119. https://hackerone.com/reports/151039 | Adobe Flash Player TimedEvent.parent Memory Corruption Vulnerability
  1120. https://hackerone.com/reports/151040 | Adobe Flash Player ShimAdPolicySelector(adPolicySelectorType=0) class Memory Corruption
  1121. https://hackerone.com/reports/151043 | Adobe Flash Player PSDK Class Use After Free Vulnerability
  1122. https://hackerone.com/reports/151058 | Stealing livechat token and using it to chat as the user - user information disclosure
  1123. https://hackerone.com/reports/151117 | [bbPress] Stored XSS in any forum post.
  1124. https://hackerone.com/reports/151459 | Creating Post on a restricted channel
  1125. https://hackerone.com/reports/151465 | Get organization info base on uuid
  1126. https://hackerone.com/reports/151470 | [IODR] Get business trip via organization id
  1127. https://hackerone.com/reports/151475 | ownCloud 2.2.2.6192 DLL Hijacking Vulnerability
  1128. https://hackerone.com/reports/151516 | CSV Injection at Camptix Event Ticketing
  1129. https://hackerone.com/reports/151868 | No Rate Limit In Inviting Similar Contact Multiple Times
  1130. https://hackerone.com/reports/152013 | CSRF in 'set.php' via age causes stored XSS on 'get.php' - http://www.rockstargames.com/php/videoplayer_cache/get.php'
  1131. https://hackerone.com/reports/152067 | Stored XSS on developer.uber.com via admin account compromise
  1132. https://hackerone.com/reports/152231 | Out of bound read in exif_process_IFD_in_MAKERNOTE
  1133. https://hackerone.com/reports/152232 | NULL Pointer Dereference in exif_process_user_comment
  1134. https://hackerone.com/reports/152266 | Use After Free Vulnerability in SNMP with GC and unserialize()
  1135. https://hackerone.com/reports/152267 | Use After Free in unserialize() with Unexpected Session Deserialization
  1136. https://hackerone.com/reports/152278 | Stack-based buffer overflow vulnerability in php_stream_zip_opener
  1137. https://hackerone.com/reports/152280 | Stack-based buffer overflow vulnerability in virtual_file_ex
  1138. https://hackerone.com/reports/152281 | Use After Free/Double Free in Garbage Collection
  1139. https://hackerone.com/reports/152398 | In correct casting from size_t to int lead to heap overflow in mcrypt_generic
  1140. https://hackerone.com/reports/152399 | php curl ext size_t overflow lead to heap corruption
  1141. https://hackerone.com/reports/152400 | php mcrypt ext - In correct casting from size_t to int lead to heap overflow in mdecrypt_generic
  1142. https://hackerone.com/reports/152407 | Missing Access Control(IDOR) To Know LinkedAccounts
  1143. https://hackerone.com/reports/152416 | Lazy Load stored XSS
  1144. https://hackerone.com/reports/152569 | Cross-Site Request Forgery (CSRF)
  1145. https://hackerone.com/reports/152577 | Content Injection at First & Last Name Parameters that could Lead Fraud Issue
  1146. https://hackerone.com/reports/152584 | S3 bucket takeover due to proxy.harvestfiles.com
  1147. https://hackerone.com/reports/152586 | CSRF token fixation in Sign in with Google
  1148. https://hackerone.com/reports/152591 | Stored XSS on invoice, executing on any subdomain
  1149. https://hackerone.com/reports/152669 | Users enumeration is possible through cycling through recurring[client_id] argument value.
  1150. https://hackerone.com/reports/152692 | Persistent Cross-Site Scripting in WooCommerce WordPress plugin
  1151. https://hackerone.com/reports/152696 | Leak of all project names and all user names , even across applications
  1152. https://hackerone.com/reports/152772 | Inadequate error handling in bzread()
  1153. https://hackerone.com/reports/152782 | locale_accept_from_http out-of-bounds access
  1154. https://hackerone.com/reports/152784 | imagegif/output out-of-bounds access
  1155. https://hackerone.com/reports/152929 | Project Disclosure of all Harvest Instances
  1156. https://hackerone.com/reports/152958 | Multiple XSS in Camptix Event Ticketing Plugin
  1157. https://hackerone.com/reports/153093 | WordPress core - Denial of Service via Cross Site Request Forgery
  1158. https://hackerone.com/reports/153618 | Reflected XSS via #tags= while using a callback in newswire http://www.rockstargames.com/newswire
  1159. https://hackerone.com/reports/153666 | csp bypass + xss
  1160. https://hackerone.com/reports/153776 | gdImageTrueColorToPaletteBody allows arbitrary write/read access
  1161. https://hackerone.com/reports/153863 | heap-buffer-overflow (write) simplestring_addn simplestring.c
  1162. https://hackerone.com/reports/153905 | IDOR - Disable sharing
  1163. https://hackerone.com/reports/154096 | Blind OOB XXE At "http://ubermovement.com/"
  1164. https://hackerone.com/reports/154369 | Unauthorized access to Zookeeper on http://locutus-zk3.ec2.shopify.com:2181
  1165. https://hackerone.com/reports/154400 | Opportunity to set arbitrary cookies
  1166. https://hackerone.com/reports/154405 | Read access to hidden orders,products,customers etc. by limited access Staff member through reference page in Comments (Information disclosure )
  1167. https://hackerone.com/reports/154410 | Delete/modify your own comment after limited access(IDOR)
  1168. https://hackerone.com/reports/154425 | Subdomain takeover on http://fastly.sc-cdn.net/
  1169. https://hackerone.com/reports/154827 | More content spoofing through dir param in the files app
  1170. https://hackerone.com/reports/154963 | Stealing User emails by clickjacking cards.twitter.com/xxx/xxx
  1171. https://hackerone.com/reports/155222 | (BYPASS) Open Redirect after login at http://ecommerce.shopify.com
  1172. https://hackerone.com/reports/155223 | Use After Free Vulnerability in array_walk()/array_walk_recursive()
  1173. https://hackerone.com/reports/155618 | Watch any Password Video without password
  1174. https://hackerone.com/reports/155657 | Arbitrary Code Injection in ownCloud’s Windows Client
  1175. https://hackerone.com/reports/155704 | Staff member can delete Private Apps
  1176. https://hackerone.com/reports/155774 | CSRF - Add optional two factor mobile number
  1177. https://hackerone.com/reports/156258 | OX (Guard): Stored Cross-Site Scripting via Incoming Email
  1178. https://hackerone.com/reports/156347 | Stored XSS triggered by json key during UI generation
  1179. https://hackerone.com/reports/156373 | Stored xss
  1180. https://hackerone.com/reports/156387 | Stored XSS from Display Settings triggered on Save and viewing realtime search demo
  1181. https://hackerone.com/reports/156520 | Unauthorized team members can leak information and see all API calls through /1/admin/* endpoints, even after they have been removed.
  1182. https://hackerone.com/reports/156542 | Avoid "resend verification email" confusion
  1183. https://hackerone.com/reports/156948 | Repeated mediation requests and multiple emails possible on a report.
  1184. https://hackerone.com/reports/157412 | Querying private posts and changing post meta
  1185. https://hackerone.com/reports/157699 | Disclosure of external users invited to a specific report
  1186. https://hackerone.com/reports/157876 | (FULL PATH DISCLOSURE) Unknown MySQL server host 'shardm-reader.chi2.shopify.io'
  1187. https://hackerone.com/reports/157956 | CSRF To change Email Notification Settings
  1188. https://hackerone.com/reports/157958 | Stored XSS
  1189. https://hackerone.com/reports/157993 | Cross-Site Request Forgery (CSRF)
  1190. https://hackerone.com/reports/157996 | Race Condition in Redeeming Coupons
  1191. https://hackerone.com/reports/158002 | Missing rel=noreferrer tag allows link in list to change url of currently open tab
  1192. https://hackerone.com/reports/158016 | Server side request forgery on image upload for lists
  1193. https://hackerone.com/reports/158019 | Host Header Injection/Redirection in: https://www.instacart.com/
  1194. https://hackerone.com/reports/158021 | Image Upload Path Disclosure
  1195. https://hackerone.com/reports/158118 | Access to Splunk at https://apt.ec2.shopify.com:8089
  1196. https://hackerone.com/reports/158148 | reverb.twitter.com redirects to vulnerable reverb.guru
  1197. https://hackerone.com/reports/158157 | shopper login_code's can be brute forced
  1198. https://hackerone.com/reports/158186 | Non-secure requests are not automatically upgraded to HTTPS
  1199. https://hackerone.com/reports/158434 | (BYPASS) Open redirect and XSS in supporthiring.shopify.com
  1200. https://hackerone.com/reports/158484 | [scores.ubnt.com] DOM based XSS at form.html
  1201. https://hackerone.com/reports/158554 | Hyperlink Injection in Friend Invitation Emails
  1202. https://hackerone.com/reports/158853 | OX Guard: DOM Based Cross-Site Scripting
  1203. https://hackerone.com/reports/158979 | PM with can Set up email for invoices and estimates (Access control Issue)
  1204. https://hackerone.com/reports/159156 | Hacker.One Subdomain Takeover
  1205. https://hackerone.com/reports/159387 | PM can delete the company logo image (Vertical Privilege Escalation )
  1206. https://hackerone.com/reports/159391 | Record payment for any invoice by PM (Access control Issue)
  1207. https://hackerone.com/reports/159393 | PM can delete payment of any invoice in company (Access control Issue)
  1208. https://hackerone.com/reports/159395 | Unauthorized access to all the actions of invoices by PM (Access control Issues)
  1209. https://hackerone.com/reports/159399 | Unauthorized read access to Invoices by PM (Access control Issues)
  1210. https://hackerone.com/reports/159460 | Stored XSS(Cross Site Scripting) In Slack App Name
  1211. https://hackerone.com/reports/159498 | Blind Stored XSS Against Lahitapiola Employees - Session and Information leakage
  1212. https://hackerone.com/reports/159512 | Requesting Mediation possible on reports that are too old for mediation
  1213. https://hackerone.com/reports/159522 | Open redirect using checkout_url
  1214. https://hackerone.com/reports/159526 | Information leakage of private program
  1215. https://hackerone.com/reports/159686 | integer overflow in the _csv module's join_append_data function
  1216. https://hackerone.com/reports/159687 | integer overflow in binascii.b2a_qp
  1217. https://hackerone.com/reports/159690 | stack buffer overflows in the curses module
  1218. https://hackerone.com/reports/159693 | Py_DECREF on a non-owned object in the _sre module
  1219. https://hackerone.com/reports/159696 | Two vulnerabilities in the ssl module
  1220. https://hackerone.com/reports/159820 | Issues with uploading list images
  1221. https://hackerone.com/reports/159878 | [render.bitstrips.com] Stored XSS via an incorrect avatar property value
  1222. https://hackerone.com/reports/159943 | Create an Unexpected Object and Don't Invoke __wakeup() in During Deserialization
  1223. https://hackerone.com/reports/159946 | PHP Session Data Injection Vulnerability
  1224. https://hackerone.com/reports/159948 | Use After Free Vulnerability in unserialize()
  1225. https://hackerone.com/reports/159953 | integer overflow in curl_escape caused heap corruption
  1226. https://hackerone.com/reports/159954 | integer overflow in base64_decode caused heap corruption
  1227. https://hackerone.com/reports/159955 | integer overflow in bzdecompress caused heap corruption
  1228. https://hackerone.com/reports/159958 | Integer overflow lead to heap corruption in sql_regcase
  1229. https://hackerone.com/reports/159959 | integer overflow in quoted_printable_encode caused heap corruption
  1230. https://hackerone.com/reports/159960 | integer overflow in urlencode caused heap corruption
  1231. https://hackerone.com/reports/159961 | integer overflow in php_uuencode caused heap corruption
  1232. https://hackerone.com/reports/159988 | Heap Overflow due to integer overflows
  1233. https://hackerone.com/reports/159992 | memory allocator fails to realloc small block to large one
  1234. https://hackerone.com/reports/160047 | [apps.shopify.com] Open Redirect
  1235. https://hackerone.com/reports/160109 | Brute force login and bypass locked account restrictions via iOS app
  1236. https://hackerone.com/reports/160294 | Memory Leakage In exif_process_IFD_in_TIFF (CVE-2016-7128)
  1237. https://hackerone.com/reports/160295 | Heap overflow in curl_escape
  1238. https://hackerone.com/reports/160520 | Bypass fix in https://hackerone.com/reports/151516 report.
  1239. https://hackerone.com/reports/160981 | Extracting private info of estimates.
  1240. https://hackerone.com/reports/161189 | select_colors write out-of-bounds
  1241. https://hackerone.com/reports/161193 | imagegammacorrect allows arbitrary write access
  1242. https://hackerone.com/reports/161198 | wddx_deserialize null dereference with invalid xml
  1243. https://hackerone.com/reports/161200 | wddx_deserialize allows illegal memory access
  1244. https://hackerone.com/reports/161216 | wddx_deserialize null dereference
  1245. https://hackerone.com/reports/161217 | wddx_deserialize null dereference in php_wddx_pop_element
  1246. https://hackerone.com/reports/161301 | READ .svg files by changing .svg into .png extension
  1247. https://hackerone.com/reports/161485 | Non-secure requests to www.lahitapiola.fi are not automatically upgraded to HTTPS
  1248. https://hackerone.com/reports/161710 | Possible to steal any protected files on Android
  1249. https://hackerone.com/reports/162822 | Fetch private list metadata and any user's personal name
  1250. https://hackerone.com/reports/162955 | Code Injection in Slack's Windows Desktop Client leads to Privilege Escalation
  1251. https://hackerone.com/reports/163067 | Stealing users password (Limited Scenario)
  1252. https://hackerone.com/reports/163087 | use of uninitialized variables in operator.methodcaller
  1253. https://hackerone.com/reports/163307 | WordPress Authentication Denial of Service
  1254. https://hackerone.com/reports/163459 | potential memory corruption in or/buffers.c (particularly on 32 bit)
  1255. https://hackerone.com/reports/163464 | User Information sent to client through websockets
  1256. https://hackerone.com/reports/163467 | User Information leak allows user to bypass email verification.
  1257. https://hackerone.com/reports/163476 | Information Disclosure in AWS S3 Bucket
  1258. https://hackerone.com/reports/163491 | CORS (Cross-Origin Resource Sharing)
  1259. https://hackerone.com/reports/163676 | Legal | Application is Missing CSP(Content Security Policy) Header
  1260. https://hackerone.com/reports/164027 | Reflected Self-XSS Vulnerability in the Comment section of Files Information
  1261. https://hackerone.com/reports/164137 | Possible content spoofing due to missing error page
  1262. https://hackerone.com/reports/164152 | [ibank.qiwi.ru] XSS via Request-URI
  1263. https://hackerone.com/reports/164224 | Urgent: Server side template injection via Smarty template allows for RCE
  1264. https://hackerone.com/reports/164515 | Project Manager can approve pending reports(Access control Issue)
  1265. https://hackerone.com/reports/164546 | CSRF bypass on Submit Time sheet for Approval
  1266. https://hackerone.com/reports/164578 | Reflected XSS in www.lahitapiola.fi (/cs/Satellite) using Oracle WebCenter -page
  1267. https://hackerone.com/reports/164581 | Oracle WebCenter Sites Support Tools available and Information disclosure (/cs/Satellite)
  1268. https://hackerone.com/reports/164649 | [Studio.twitter.com] See someone else pics
  1269. https://hackerone.com/reports/164656 | [contact-sys.com] XSS via Request-URI
  1270. https://hackerone.com/reports/164662 | [wallet.rapida.ru] XSS Cookie flashcookie
  1271. https://hackerone.com/reports/164674 | CSV Injection in Camptix
  1272. https://hackerone.com/reports/164684 | [lk.contact-sys.com] SQL Injection reset_password FP_LK_USER_LOGIN
  1273. https://hackerone.com/reports/164704 | [contact-sys.com] XSS /ajax/transfer/status trn param
  1274. https://hackerone.com/reports/164739 | SQL Injection on /cs/Satellite path
  1275. https://hackerone.com/reports/164821 | OX Guard: DOM Based Cross-Site Scripting (#2)
  1276. https://hackerone.com/reports/164833 | Hyperlink Injection in Friend Invitation Emails
  1277. https://hackerone.com/reports/164916 | Same origin policy bypass on e.mail.ru via Cross-Site Flashing
  1278. https://hackerone.com/reports/164933 | [lk.contact-sys.com] LKlang Path Traversal
  1279. https://hackerone.com/reports/164945 | [contact-sys.com] SQL Injection████ limit param
  1280. https://hackerone.com/reports/165046 | Open redirect allows changing iframe content in *.myshopify.com/admin/themes//editor
  1281. https://hackerone.com/reports/165102 | urllib HTTP header injection CVE-2016-5699
  1282. https://hackerone.com/reports/165131 | Seemingly sensitive information at /api/v2/zones
  1283. https://hackerone.com/reports/165154 | Additional information for CVE-2016-5699
  1284. https://hackerone.com/reports/165219 | [id.rapida.ru] Full Path Disclosure
  1285. https://hackerone.com/reports/165229 | Nextcloud 10.0 privilege escalation issue - Normal user can mask external storage shared by admin
  1286. https://hackerone.com/reports/165275 | OX (Guard): Stored Cross-Site Scripting via Email Attachment
  1287. https://hackerone.com/reports/165324 | XSS on expenses attachments
  1288. https://hackerone.com/reports/165570 | Race Condition in account survey
  1289. https://hackerone.com/reports/165686 | Reflected XSS in Gallery App
  1290. https://hackerone.com/reports/165727 | Rate-limit bypass
  1291. https://hackerone.com/reports/165862 | Invoices can be added to any retainers - even closs-platform
  1292. https://hackerone.com/reports/165930 | PHP info page disclosure on http://www.day.dk/
  1293. https://hackerone.com/reports/166080 | null pointer dereference in set_conversion_mode due uncheck _ctypes_conversion_errors
  1294. https://hackerone.com/reports/166265 | Verification of E-Mail address possible on https://biz.yelp.com/login and https://biz.yelp.com/forgot
  1295. https://hackerone.com/reports/166629 | Cross-protocol attack on TLS using SSLv2 (DROWN) (CVE-2016-0800)
  1296. https://hackerone.com/reports/166634 | SSLv2 doesn't block disabled ciphers (CVE-2015-3197)
  1297. https://hackerone.com/reports/166661 | Arbitrary heap overread in strscan on 32 bit Ruby, patch included
  1298. https://hackerone.com/reports/166682 | Denial of Service through set_preference.json
  1299. https://hackerone.com/reports/166709 | Self-XSS via location cookie city field when getting suggestions for a new location
  1300. https://hackerone.com/reports/166826 | Potential Subdomain Takeover Possible
  1301. https://hackerone.com/reports/166871 | Instance of Apache Vulnerable to Several Issues
  1302. https://hackerone.com/reports/166887 | Unsanitized Location Name in POS Channel can lead to XSS in Orders Timeline
  1303. https://hackerone.com/reports/166942 | leaking Digits OAuth authorization to third party websites
  1304. https://hackerone.com/reports/167075 | XSS in SHOPIFY: Unsanitized Supplier Name can lead to XSS in Transfers Timeline
  1305. https://hackerone.com/reports/167489 | Bybass The Closing of the account and logged again to your account
  1306. https://hackerone.com/reports/167688 | msilib.OpenDatabase Type Confusion
  1307. https://hackerone.com/reports/167731 | Make victim buy in attacker's account without any idea - http://www.booztlet.com/
  1308. https://hackerone.com/reports/167846 | Deleted Post and Administrative Function Access in eCommerce Forum
  1309. https://hackerone.com/reports/167888 | Uninitialized Thumbail Data Leads To Memory Leakage in exif_process_IFD_in_TIFF
  1310. https://hackerone.com/reports/167895 | Out of bound when verify signature of zip phar in phar_parse_zipfile
  1311. https://hackerone.com/reports/167896 | Out of bound when verify signature of tar phar in phar_parse_tarfile
  1312. https://hackerone.com/reports/167901 | integer overflow in pg_escape_string caused heap corruption
  1313. https://hackerone.com/reports/167902 | integer overflow in php_ldap_do_escape caused heap corruption
  1314. https://hackerone.com/reports/167903 | integer overflow in str_pad caused heap corruption
  1315. https://hackerone.com/reports/167904 | heap overflow in substr_replace
  1316. https://hackerone.com/reports/167905 | integer overflow in pg_escape_bytea caused heap corruption
  1317. https://hackerone.com/reports/167906 | integer overflow in imap_binary caused heap corruption
  1318. https://hackerone.com/reports/167907 | integer overflow in preg_quote caused heap corruption
  1319. https://hackerone.com/reports/167908 | integer overflow in fgets cause heap corruption
  1320. https://hackerone.com/reports/167909 | integer overflow in recode_string caused heap corruption
  1321. https://hackerone.com/reports/167910 | memory corruption in wordwrap function
  1322. https://hackerone.com/reports/167911 | integer overflow in fgetcsv caused heap corruption
  1323. https://hackerone.com/reports/167921 | integer overflow in xml_utf8_encode
  1324. https://hackerone.com/reports/167931 | Memory Corruption in During Deserialized-object Destruction
  1325. https://hackerone.com/reports/167977 | Missing type check when unserializing SplArray
  1326. https://hackerone.com/reports/168027 | gzdecode does NOT check output string size which leads to an overflow
  1327. https://hackerone.com/reports/168028 | gzuncompress does NOT check output string size which leads to an overflow
  1328. https://hackerone.com/reports/168029 | ldap_escape could produce string larger than 2Gb
  1329. https://hackerone.com/reports/168116 | Insufficient validation on Digits bridge
  1330. https://hackerone.com/reports/168458 | Stored XSS in https://productreviews.shopifyapps.com/proxy/v4/reviews/product
  1331. https://hackerone.com/reports/168476 | Incoming email hijacking on sc-cdn.net
  1332. https://hackerone.com/reports/168485 | Exposed, outdated nginx server (v1.4.6) potentially vulnerable to heap-based buffer overflow & RCE
  1333. https://hackerone.com/reports/168538 | Twitter iOS fails to validate server certificate and sends oauth token
  1334. https://hackerone.com/reports/169699 | CSRF in the "Add restaurant picture" function
  1335. https://hackerone.com/reports/169759 | Open redirect in bulk edit
  1336. https://hackerone.com/reports/170138 | SEH buffer overflow msgfmt_format_message
  1337. https://hackerone.com/reports/170144 | wddx_deserialize use-after-free
  1338. https://hackerone.com/reports/170161 | Password reset token not expiring
  1339. https://hackerone.com/reports/170260 | imap_rfc822_parse_headers GS Violation
  1340. https://hackerone.com/reports/170310 | Bypass rate limiting on /users/password (possibly site-wide rate limit bypass?)
  1341. https://hackerone.com/reports/170548 | Ruby OpenSSL Library - IV Reuse in GCM Mode
  1342. https://hackerone.com/reports/170618 | CVE-2016-7418 PHP Out-Of-Bounds Read in php_wddx_push_element
  1343. https://hackerone.com/reports/170619 | PHP Integer Overflow in gdImageWebpCtx
  1344. https://hackerone.com/reports/170894 | Facebook and twitter page claimed of maximum.com [important]
  1345. https://hackerone.com/reports/171205 | No rate limit for Referral Program
  1346. https://hackerone.com/reports/172115 | Multiple use after frees in obj2ast_* methods
  1347. https://hackerone.com/reports/172137 | Authentication bypass on sso.ubnt.com via subdomain takeover of ping.ubnt.com
  1348. https://hackerone.com/reports/172227 | Stored XSS in photo comment functionality
  1349. https://hackerone.com/reports/172289 | HackerOne Integrations Design Issue
  1350. https://hackerone.com/reports/172403 | Python 2.7 32-bit JSON encoding heap corruption
  1351. https://hackerone.com/reports/172411 | Heap overflow caused by type confusion vulnerability in merge_param()
  1352. https://hackerone.com/reports/172545 | IDOR - Ability to view unlisted products
  1353. https://hackerone.com/reports/172549 | Possible Blind Writing to S3 Bucket
  1354. https://hackerone.com/reports/172562 | LZMADecompressor.decompress Use After Free
  1355. https://hackerone.com/reports/172574 | Follow Button XSS
  1356. https://hackerone.com/reports/172595 | Reflected XSS in LTContactFormReceiver (/cs/Satellite)
  1357. https://hackerone.com/reports/172698 | Subdomain take over signup.websummit
  1358. https://hackerone.com/reports/172711 | Content Spoofing in udemy
  1359. https://hackerone.com/reports/172733 | Add signature to transactions without any permission
  1360. https://hackerone.com/reports/172780 | out of date disqus shortname usage in the web app source code
  1361. https://hackerone.com/reports/172837 | password less login token expiration issue
  1362. https://hackerone.com/reports/172843 | DOM based reflected XSS in rockstargames.com/newswire/tags through cross domain ajax request
  1363. https://hackerone.com/reports/172933 | IDNs displayed in unicode in messages/about/talk sections (Homograph Attack)
  1364. https://hackerone.com/reports/173043 | Bypassing "You've requested your data the maximum number of times today." + "Please Verify an email address with snapchat to continue"
  1365. https://hackerone.com/reports/173681 | [CRITICAL]-Taking over entire subdomain of romit.io
  1366. https://hackerone.com/reports/173811 | Git available containing passwords.
  1367. https://hackerone.com/reports/173969 | Full access to any list
  1368. https://hackerone.com/reports/174069 | Buffer overflow in HTTP parse_hostinfo(), parse_userinfo() and parse_scheme()
  1369. https://hackerone.com/reports/174328 | CSRF in github integration
  1370. https://hackerone.com/reports/174474 | Cookie Injection at 'harvestapp.com'
  1371. https://hackerone.com/reports/174632 | Information disclosure in mmap module - python 2.7.12
  1372. https://hackerone.com/reports/174645 | Existence of Folder path by guessing the path through response
  1373. https://hackerone.com/reports/174668 | No rate-limit in SERVER_SECURITY_CHECK
  1374. https://hackerone.com/reports/174721 | View liked twits of private account via publish.twitter.com
  1375. https://hackerone.com/reports/174871 | Linking Invoice to uninvited project.
  1376. https://hackerone.com/reports/174882 | Requesting Show CheckIn Alert for Non Friend User
  1377. https://hackerone.com/reports/175070 | Subdomain takeover on rider.uber.com due to non-existent distribution on Cloudfront
  1378. https://hackerone.com/reports/175091 | chain.setstate Type Confusion
  1379. https://hackerone.com/reports/175168 | [ecommerce.shopify.com] Invalidated redirection
  1380. https://hackerone.com/reports/175260 | missing NULL check in dom_document_save_html
  1381. https://hackerone.com/reports/175262 | NULL pointer dereference in SimpleXMLElement::asXML()
  1382. https://hackerone.com/reports/175263 | crash in openssl_random_pseudo_bytes function
  1383. https://hackerone.com/reports/175264 | heap overflow in php_ereg_replace function
  1384. https://hackerone.com/reports/175286 | Homograph attack
  1385. https://hackerone.com/reports/175310 | Write out-of-bounds at number_format
  1386. https://hackerone.com/reports/175311 | memcpy negative size parameter in php_resolve_path
  1387. https://hackerone.com/reports/175312 | memcpy negative parameter _bc_new_num_ex
  1388. https://hackerone.com/reports/175315 | Illegal write access through Locale methods
  1389. https://hackerone.com/reports/175316 | stack-buffer-overflow through "ResourceBundle" methods
  1390. https://hackerone.com/reports/175320 | 2 Directory Listing on ledger.brave.com & vault-staging.brave.com
  1391. https://hackerone.com/reports/175403 | [website] Script injection in newsletter signup https://brave.com/brave_youth_program_signup.html
  1392. https://hackerone.com/reports/175490 | Able to Login deactivated staff account in shopify app mobile
  1393. https://hackerone.com/reports/175529 | URI Obfuscation
  1394. https://hackerone.com/reports/175587 | Stack Buffer Overflow in GD dynamicGetbuf
  1395. https://hackerone.com/reports/175779 | Address Bar Spoofing - Already resolved - Retroactive report
  1396. https://hackerone.com/reports/175958 | [iOS/Android] Address Bar Spoofing Vulnerability
  1397. https://hackerone.com/reports/175979 | Access to local file system using javascript
  1398. https://hackerone.com/reports/175982 | Use-after-free in unserialize()
  1399. https://hackerone.com/reports/176065 | [Android] HTML Injection in BatterySaveArticleRenderer WebView
  1400. https://hackerone.com/reports/176066 | Denial of service attack on Brave Browser.
  1401. https://hackerone.com/reports/176197 | Denial of service attack(window object) on brave browser
  1402. https://hackerone.com/reports/176226 | CachingIterator null dereference when convert to string
  1403. https://hackerone.com/reports/176279 | Heap overflow in mysqlnd related to BIT fields (CVE-2016-7412)
  1404. https://hackerone.com/reports/176308 | Wordpress.com REST API oauth bypass via Cross Site Flashing
  1405. https://hackerone.com/reports/176754 | Cross-site scripting (reflected)
  1406. https://hackerone.com/reports/176899 | Editing a project (LIMITED)
  1407. https://hackerone.com/reports/176929 | [ios] Address bar spoofing in Brave for iOS
  1408. https://hackerone.com/reports/176979 | Authentication Issue
  1409. https://hackerone.com/reports/177472 | CSRF: add item to victim's cart automatically (starbucks.com - updatecart)
  1410. https://hackerone.com/reports/177508 | Reflected XSS by exploiting CSRF vulnerability on teavana.com wishlist comment module. (wishlist-comments)
  1411. https://hackerone.com/reports/177624 | Unvalidated redirect on team.badoo.com
  1412. https://hackerone.com/reports/177635 | CSRF vulnerability in saving payment card on store.starbucks.com (COBilling -AddCreditCard)
  1413. https://hackerone.com/reports/177639 | CSRF exploit | Adding/Editing comment of wishlist items (teavana.com - Wishlist-Comments)
  1414. https://hackerone.com/reports/177757 | Stored XSS in Restoring Archived Tasks
  1415. https://hackerone.com/reports/178049 | Ра�крытие балан�а на //kopilka.qiwi.com
  1416. https://hackerone.com/reports/178094 | php_snmp_parse_oid integer overflow in memory allocation
  1417. https://hackerone.com/reports/178144 | imagecropauto out-of-bounds access
  1418. https://hackerone.com/reports/178184 | SSRF in https://cards-dev.twitter.com/validator
  1419. https://hackerone.com/reports/178284 | [vitrina.contact-sys.com] Full Path Disclosure
  1420. https://hackerone.com/reports/178293 | Misconfiguration in Two Factor Authorisation
  1421. https://hackerone.com/reports/178506 | Access private list metadata
  1422. https://hackerone.com/reports/178567 | Arbitrary modification value "session" (Cookie) in badoo.com
  1423. https://hackerone.com/reports/178742 | Leave inaccessible messaging system with a message (https://us1.badoo.com)
  1424. https://hackerone.com/reports/178831 | CSRF on signup endpoint (auto-api.yelp.com)
  1425. https://hackerone.com/reports/179164 | Stored XSS in community.ubnt.com
  1426. https://hackerone.com/reports/179328 | Open Redirect (verkkopalvelu.lahitapiola.fi)
  1427. https://hackerone.com/reports/179426 | Reflected XSS on blockchain.info
  1428. https://hackerone.com/reports/179559 | Stored XSS in Template Documents
  1429. https://hackerone.com/reports/179568 | Tab nabbing via window.opener
  1430. https://hackerone.com/reports/179695 | XSS via unicode characters in upload filename
  1431. https://hackerone.com/reports/179751 | SQL Injection on /webApp/omatalousuk (viestinta.lahitapiola.fi)
  1432. https://hackerone.com/reports/179763 | Suspicious browser fingerprinting(?) scripts on http://www.lahitapiola.fi/ redirector
  1433. https://hackerone.com/reports/180037 | Selecting encryption for email with drive attachment overrides the drive email password
  1434. https://hackerone.com/reports/180109 | crash in gzcompress and 3 other compress functions
  1435. https://hackerone.com/reports/180110 | crash in implode() function
  1436. https://hackerone.com/reports/180111 | crash in bzcompress function
  1437. https://hackerone.com/reports/180112 | iconv() function missing string length check
  1438. https://hackerone.com/reports/180113 | crash in get_icu_value_internal function
  1439. https://hackerone.com/reports/180115 | crash in locale_get_keywords() when keyword value in locale string too long
  1440. https://hackerone.com/reports/180116 | another crash in locale_get_keywords function
  1441. https://hackerone.com/reports/180253 | Reflected Cross-Site Scripting due to vulnerable Flash component (Flashmediaelement.swf)
  1442. https://hackerone.com/reports/180434 | cURL / libcURL - CVE-2016-8624 invalid URL parsing with '#'
  1443. https://hackerone.com/reports/180538 | X.509 certificate validation fails on international vanity domains
  1444. https://hackerone.com/reports/180562 | Memory corruption in _php_math_number_format_ex()
  1445. https://hackerone.com/reports/180563 | Heap overflow due to integer overflow in bzdecompress() function
  1446. https://hackerone.com/reports/180572 | Memory corruption due to missing check size in _php_math_number_format_ex()
  1447. https://hackerone.com/reports/180582 | Heap overflow due to integer overflow in php_escape_html_entities_ex() function
  1448. https://hackerone.com/reports/180584 | Heap overflow due to integer overflow in pg_escape_string() function
  1449. https://hackerone.com/reports/180588 | Invalid memory access in zend_strtod() function
  1450. https://hackerone.com/reports/180589 | crash in simplestring_addn function
  1451. https://hackerone.com/reports/180590 | Invalid memory access in spl_filesystem_dir_open function
  1452. https://hackerone.com/reports/180591 | Invalid memory access in php_basename function
  1453. https://hackerone.com/reports/180592 | Invalid memory access in spl_filesystem_info_set_filename function
  1454. https://hackerone.com/reports/180695 | ruby DoS https://www.mruby.science
  1455. https://hackerone.com/reports/180814 | crash in locale_compose() function
  1456. https://hackerone.com/reports/180908 | NULL Pointer Dereference in WDDX Packet Deserialization with PDORow
  1457. https://hackerone.com/reports/180909 | Use-after-free in ArrayObject Deserialization
  1458. https://hackerone.com/reports/180977 | Exception cause SIGABRT
  1459. https://hackerone.com/reports/181073 | malloc negative size parameter
  1460. https://hackerone.com/reports/181088 | Window.opener bug at www.coinbase.com
  1461. https://hackerone.com/reports/181210 | Incorrect detection of onion URLs
  1462. https://hackerone.com/reports/181225 | Missing rel=noopener noreferrer in target=_blank links (Phishing attack)
  1463. https://hackerone.com/reports/181232 | Denial of Service in mruby due to null pointer dereference
  1464. https://hackerone.com/reports/181319 | Memory disclosure in mruby String#lines method
  1465. https://hackerone.com/reports/181321 | Use after free vulnerability in mruby Array#to_h causing DOS possible RCE
  1466. https://hackerone.com/reports/181558 | [DOS] denial of service using code snippet on brave browser
  1467. https://hackerone.com/reports/181594 | Error Page Content Spoofing or Text Injection (viestinta.lahitapiola.fi)
  1468. https://hackerone.com/reports/181642 | libtiff 4.0.6 heap bufer overflow / out of bounds read (CVE-2016-9273)
  1469. https://hackerone.com/reports/181665 | Subdomain Takeover (moderator.ubnt.com)
  1470. https://hackerone.com/reports/181677 | NULL pointer dereference when parsing ternary operators
  1471. https://hackerone.com/reports/181685 | Range#initialize_copy null pointer dereference
  1472. https://hackerone.com/reports/181686 | [DOS] Browser hangs on loading the code snippet
  1473. https://hackerone.com/reports/181695 | Undefined method_missing null pointer dereference
  1474. https://hackerone.com/reports/181748 | [IDOR][translate.twitter.com] Opportunity to change any comment at the forum
  1475. https://hackerone.com/reports/181768 | Poodle attack SSLv3 Support (viestinta.lahitapiola.fi)
  1476. https://hackerone.com/reports/181803 | SQL Injection /webApp/oma_conf ctx parameter (viestinta.lahitapiola.fi)
  1477. https://hackerone.com/reports/181810 | HTML Injection in email /webApp/lahti (viestinta.lahitapiola.fi)
  1478. https://hackerone.com/reports/181826 | SQL Injection /webApp/sijoitustalous_peruutus locId parameter (viestinta.lahitapiola.fi)
  1479. https://hackerone.com/reports/181828 | Segfault in mruby, mruby_engine and the parent MRI Ruby due to null pointer dereference
  1480. https://hackerone.com/reports/181842 | Multiple Reflected XSS /webApp/lahti (viestinta.lahitapiola.fi)
  1481. https://hackerone.com/reports/181871 | DoS: type confusion in mrb_no_method_error
  1482. https://hackerone.com/reports/181874 | SIGSEGV when invalid argument on remove_method
  1483. https://hackerone.com/reports/181879 | Struct type confusion RCE
  1484. https://hackerone.com/reports/181893 | TOCTTOU bug in mrb_str_setbyte leading the memory corruption
  1485. https://hackerone.com/reports/181910 | Range constructor type confusion DoS
  1486. https://hackerone.com/reports/182027 | SIGSEV on mrb_ary_splice
  1487. https://hackerone.com/reports/182104 | Completed Compromise & Source Code Disclosure via Exposed Jenkins Dashboard at https://jenkins101.udemy.com
  1488. https://hackerone.com/reports/182140 | libtiff 4.0.6 segfault / read outside of buffer (CVE-2016-9297)
  1489. https://hackerone.com/reports/182160 | XSS in IE11 on portswigger.net via Flash
  1490. https://hackerone.com/reports/182169 | Type confusion in FutureIter_throw() which may potentially lead to an arbitrary code execution
  1491. https://hackerone.com/reports/182265 | Option method enabled (viestinta.lahitapiola.fi)
  1492. https://hackerone.com/reports/182274 | Null pointer dereference due to TOCTTOU bug in mrb_time_initialize
  1493. https://hackerone.com/reports/182358 | Partial disclosure of report activity through new "Export as .zip" feature
  1494. https://hackerone.com/reports/182420 | Illegal write/read access caused by gdImageAALine overflow
  1495. https://hackerone.com/reports/182467 | Email Spoofing
  1496. https://hackerone.com/reports/182474 | Use After Free in PHP7 unserialize()
  1497. https://hackerone.com/reports/182484 | Broken handling of maximum number of method call arguments leads to segfault
  1498. https://hackerone.com/reports/182670 | Email link poisoning / Host header attack
  1499. https://hackerone.com/reports/183231 | SIGSEGV on mruby mrb_str_modify() (Invalid memory access)
  1500. https://hackerone.com/reports/183239 | SIGSEGV on mruby's mark_tbl() (Invalid memory access)
  1501. https://hackerone.com/reports/183356 | Segfault and/or potential unwanted (byte)code execution with "break" and "||=" inside a loop
  1502. https://hackerone.com/reports/183405 | Null target_class DoS
  1503. https://hackerone.com/reports/183425 | Segmentation fault when a Ruby method is invoked by a C method via Object#send
  1504. https://hackerone.com/reports/183548 | SMTP configuration vulnerability viestinta.lahitapiola.fi
  1505. https://hackerone.com/reports/183568 | [Buddypress] Arbitrary File Deletion through bp_avatar_set
  1506. https://hackerone.com/reports/183796 | XSS and open redirect in verkkopalvelu.lahitapiola.fi
  1507. https://hackerone.com/reports/184452 | Disclosure of IBM Websphere page
  1508. https://hackerone.com/reports/184661 | mruby-time: Crash host with uninitialized Time obj
  1509. https://hackerone.com/reports/184698 | Eavesdropping on private Slack calls
  1510. https://hackerone.com/reports/184712 | Denial of service due to invalid memory access in mrb_ary_concat
  1511. https://hackerone.com/reports/184715 | Read after free in mrb_vm_exec with OP_ARYCAT reading R(B)
  1512. https://hackerone.com/reports/184857 | Crash: calling Proc::initialize_copy with a Proc instance where initialize never ran leads to a crash
  1513. https://hackerone.com/reports/185041 | Type confusion in mrb_exc_set leading to memory corruption
  1514. https://hackerone.com/reports/185051 | Type confusion in wrap_decimal leading to memory corruption
  1515. https://hackerone.com/reports/185387 | Null pointer dereference regression in parse.y
  1516. https://hackerone.com/reports/185775 | Crash: Initialize Decimal with itself triggers an assertion
  1517. https://hackerone.com/reports/185794 | Crash: mrb_any_to_s can't handle NilClass, Symbol and Fixnum
  1518. https://hackerone.com/reports/185826 | XSS in my.shopify.com in widget
  1519. https://hackerone.com/reports/185833 | Incomplete or No Cache-control and Pragma HTTP Header Set
  1520. https://hackerone.com/reports/185862 | Twitter for android is exposing user's location to any installed android app
  1521. https://hackerone.com/reports/185899 | Invalid memory write caused by incorrect upper bound in array_copy
  1522. https://hackerone.com/reports/185907 | unchecked unserialize usage in WordPress-Functionality-Plugin-Skeleton/functionality-plugin-skeleton.php
  1523. https://hackerone.com/reports/185909 | unchecked unserialize usages in audit-trail-extension/audit-trail-extension.php
  1524. https://hackerone.com/reports/185914 | constant cache_page_secret in regolith
  1525. https://hackerone.com/reports/185957 | Crash: A call to Symbol.new leads to a crash when inspecting the resulting object
  1526. https://hackerone.com/reports/186230 | Internal attachments can be exported via "Export as .zip" feature
  1527. https://hackerone.com/reports/186352 | Fetching binaries (for software installation) over HTTP without verification (RCE as ROOT by MITM)
  1528. https://hackerone.com/reports/186462 | Stored XSS at 'Buy Button' page
  1529. https://hackerone.com/reports/186554 | Stored XSS in Adress Book (starbucks.com/account/profile)
  1530. https://hackerone.com/reports/186723 | Crash: Overwriting NoMethodError with a builtin class crashes/corrupts memory
  1531. https://hackerone.com/reports/186766 | Subdomain takeover on happymondays.starbucks.com due to non-used AWS S3 DNS record
  1532. https://hackerone.com/reports/187305 | Invalid handling of zero-length heredoc identifiers leads to infinite loop in the sandbox
  1533. https://hackerone.com/reports/187410 | Store XSS
  1534. https://hackerone.com/reports/187520 | Wordpress 4.7 - CSRF -> HTTP SSRF any private ip:port and basic-auth
  1535. https://hackerone.com/reports/187536 | Null pointer derefence due to bug in codegen with negation without using value
  1536. https://hackerone.com/reports/187542 | Brave Browser unexpectedly allows to send arbitrary IPC messages
  1537. https://hackerone.com/reports/187714 | Vine - overwrite account associated with email via android application
  1538. https://hackerone.com/reports/188086 | Sending arbitrary IPC messages via overriding Function.prototype.apply
  1539. https://hackerone.com/reports/188102 | 3 heap corruptions in PHP
  1540. https://hackerone.com/reports/188185 | Dom Based Xss DIV.innerHTML parameters store.starbucks*
  1541. https://hackerone.com/reports/188313 | Segmentation fault due to bad memory access in kh_get_mt
  1542. https://hackerone.com/reports/188326 | Buffer overflow in mrb_time_asctime
  1543. https://hackerone.com/reports/188661 | Invalid read when wddx decodes empty boolean element
  1544. https://hackerone.com/reports/188719 | Information Disclosure in /skills call
  1545. https://hackerone.com/reports/188972 | Persistent XSS in www.starbucks.com
  1546. https://hackerone.com/reports/189378 | Unauthenticated Stored XSS on .myshopify.com via checkout page
  1547. https://hackerone.com/reports/189633 | Certain inputs cause tight C-level recursion leading to process stack overflow
  1548. https://hackerone.com/reports/189726 | Websites opened from reports can change url of report page
  1549. https://hackerone.com/reports/189768 | [controlsyou.quora.com] 429 Too Many Requests Error-Page XSS
  1550. https://hackerone.com/reports/189793 | [Android] XSS via start ContentActivity
  1551. https://hackerone.com/reports/190133 | Segfault when passing invalid values to values_at
  1552. https://hackerone.com/reports/190188 | Open Redirect bypass and cookie leakage on www.lahitapiola.com
  1553. https://hackerone.com/reports/190798 | Reflected XSS on teavana.com (Locale-Change)
  1554. https://hackerone.com/reports/190863 | imagefilltoborder stackoverflow on truecolor images
  1555. https://hackerone.com/reports/190933 | Invalid parameter in memcpy function trough openssl_pbkdf2
  1556. https://hackerone.com/reports/190951 | XSS on manually entering Postal codes
  1557. https://hackerone.com/reports/191095 | Reflected XSS on sankarikoulutus (viestinta.lahitapiola.fi)
  1558. https://hackerone.com/reports/191146 | SQL Injection in lapsuudenturva (viestinta.lahitapiola.fi)
  1559. https://hackerone.com/reports/191323 | Sub Domain Takeover at mk.prd.vine.co
  1560. https://hackerone.com/reports/191328 | Invalid memory access in mrb_str_format
  1561. https://hackerone.com/reports/191380 | CRLF and XSS stored on ton.twitter.com
  1562. https://hackerone.com/reports/191387 | Reflected XSS and Open Redirect in several parameters (viestinta.lahitapiola.fi)
  1563. https://hackerone.com/reports/191601 | SQL Injection on /webApp/sijoitustalousuk email-parameter + potential lack of CSRF Token (viestinta.lahitapiola.fi)
  1564. https://hackerone.com/reports/191689 | Incorrect code generation when result of NODE_NEGATE is not used
  1565. https://hackerone.com/reports/191890 | DOM Based XSS in Discourse Search
  1566. https://hackerone.com/reports/191909 | XSS Vulnerability on Image link parser
  1567. https://hackerone.com/reports/191938 | SIGSEGV on mruby mrb_get_args()
  1568. https://hackerone.com/reports/191994 | SIGSEGV mrb_obj_freeze() Manipulating Register RAX and RSI
  1569. https://hackerone.com/reports/192127 | Buffer underflow in sprintf
  1570. https://hackerone.com/reports/192131 | CSRF Attack on (m.badoo.com)deleting account and erasing imported contacts
  1571. https://hackerone.com/reports/192140 | XSS on postal codes
  1572. https://hackerone.com/reports/192210 | Stored XSS in blog comments through Shopify API
  1573. https://hackerone.com/reports/192223 | XSS vulnerability on Audio and Video parsers
  1574. https://hackerone.com/reports/192235 | Integer Overflow in mrb_ary_set
  1575. https://hackerone.com/reports/192318 | mrb_vformat() heap overflow could lead to code execution
  1576. https://hackerone.com/reports/192362 | Heap Overflow in mrb_arb_splice
  1577. https://hackerone.com/reports/192388 | Unauthorised read Access to Expense Receipt of any user in the company(Vertical Privilege escalation)
  1578. https://hackerone.com/reports/192485 | SIGSEGV on mrb_vm_exec() Null Deref
  1579. https://hackerone.com/reports/192532 | SIGABRT, SIGSEGV mspace_free() and mrb_default_allocf()
  1580. https://hackerone.com/reports/192578 | kh_get_n2s() stack overrun
  1581. https://hackerone.com/reports/192665 | heap-buffer-overflow on mruby
  1582. https://hackerone.com/reports/192734 | SIGSEGV Null Pointer mrb_str_concat()
  1583. https://hackerone.com/reports/192896 | Memory disclosure in timegm
  1584. https://hackerone.com/reports/193056 | Subdomain Takeover at http://gameday.websummit.net
  1585. https://hackerone.com/reports/193075 | SIGSEGV - mrb_check_intern_str() - NullPointer
  1586. https://hackerone.com/reports/193077 | mrb_str_modify try to write to memory not marked for writing
  1587. https://hackerone.com/reports/193081 | Null pointer dereference in mrb_str_prepend
  1588. https://hackerone.com/reports/193143 | Use After Free in str_replace
  1589. https://hackerone.com/reports/193314 | SMTP user enumeration via mail.zendesk.com
  1590. https://hackerone.com/reports/193517 | attempting double-free using the mruby compiler mrbc
  1591. https://hackerone.com/reports/193719 | Double free of filename after codegen error
  1592. https://hackerone.com/reports/193724 | SIGSEGV - kh_resize_iv - Null Deref
  1593. https://hackerone.com/reports/193773 | SIGABRT - mrb_default_allocf
  1594. https://hackerone.com/reports/194017 | Open redirect - user interaction needed (verkkopalvelu.lahitapiola.fi/e2/..) - based on #179328
  1595. https://hackerone.com/reports/194329 | No session logout after changing password & alsoandroid sessions not shown in sessions list so they can be deleted
  1596. https://hackerone.com/reports/194351 | Able to download arbitrary PHP files at yelpblog.com
  1597. https://hackerone.com/reports/194574 | IDOR - Folder names disclosure inside a domain, regardless of user
  1598. https://hackerone.com/reports/194721 | Verification of email addresses possible through https://www.yelp.com/signup/facebook
  1599. https://hackerone.com/reports/194761 | OpenSSL Padding Oracle Attack (CVE-2016-2107) on viestinta.lahitapiola.fi
  1600. https://hackerone.com/reports/194790 | IDOR - Downloading all attachements if having access to a shared link
  1601. https://hackerone.com/reports/194832 | Authentication Bypass on monitoring server
  1602. https://hackerone.com/reports/194884 | Heap use-after-free during range creation
  1603. https://hackerone.com/reports/194906 | Heap overflow due to off-by-one when expanding stack
  1604. https://hackerone.com/reports/195045 | Set Cookie Via SVG
  1605. https://hackerone.com/reports/195156 | CSRF in all API endpoints when authenticated using HTTP Authentication
  1606. https://hackerone.com/reports/195350 | Subdomain takeover on podcasts.slack-core.com
  1607. https://hackerone.com/reports/195580 | Crash (DoS) when parsing a hostile TIFF
  1608. https://hackerone.com/reports/195586 | Memory corruption when parsing a hostile PHAR archive
  1609. https://hackerone.com/reports/195688 | NULL Pointer Dereference while unserialize php object
  1610. https://hackerone.com/reports/195842 | Segmentation fault - mrb_gc_mark
  1611. https://hackerone.com/reports/195950 | Use of uninitialized memory in unserialize()
  1612. https://hackerone.com/reports/196221 | XSS in instacart.com/store/partner_recipe
  1613. https://hackerone.com/reports/196222 | RTLO char allowed in chat
  1614. https://hackerone.com/reports/196380 | SIGSEGV in mrb_vm_exec
  1615. https://hackerone.com/reports/196386 | SIGSEGV - mrb_vm_exec - vm.c in line:1272
  1616. https://hackerone.com/reports/196458 | apps.shopify.com - CSRF token leakage through Google Analytics
  1617. https://hackerone.com/reports/196498 | Segmentation fault on program counter
  1618. https://hackerone.com/reports/196624 | dom xss in https://www.slackatwork.com
  1619. https://hackerone.com/reports/196655 | Disclose any user's private email through API
  1620. https://hackerone.com/reports/196846 | Open redirect / Reflected XSS payload in root that affects all your sites (store.starbucks.* / shop.starbucks.* / teavana.com)
  1621. https://hackerone.com/reports/197443 | XSS in topics because of bandcamp preview engine vulnerability
  1622. https://hackerone.com/reports/197693 | SIGSEGV - mrb_vm_exec - line:1681
  1623. https://hackerone.com/reports/197694 | SIGSEGV - mrb_obj_extend - line:413
  1624. https://hackerone.com/reports/197719 | Still heap overflow in mrb_ary_splice
  1625. https://hackerone.com/reports/197723 | Null pointer dereference in mrb_str_modify
  1626. https://hackerone.com/reports/197789 | [insideok.ru] Database Dump
  1627. https://hackerone.com/reports/197902 | Stored XSS in topics because of whitelisted_generic engine vulnerability
  1628. https://hackerone.com/reports/197914 | Stored XSS in posts because of absence of oembed variables values escaping
  1629. https://hackerone.com/reports/197916 | Crash in print_backtrace
  1630. https://hackerone.com/reports/198249 | [XSS/3dsecure.qiwi.com] 3DSecure XSS
  1631. https://hackerone.com/reports/198251 | [XSS/pay.qiwi.com] Pay SubDomain Hard-Use XSS
  1632. https://hackerone.com/reports/198452 | SIGABRT - mrb_realloc_simple - gc.c - line:201
  1633. https://hackerone.com/reports/198622 | Clickjacking Periscope.tv on Chrome
  1634. https://hackerone.com/reports/198723 | Create an Unexpected Object and Don't Invoke __wakeup() in Deserialization
  1635. https://hackerone.com/reports/198732 | Use After Free in unserialize()
  1636. https://hackerone.com/reports/198733 | Type Confusion in Object Deserialization
  1637. https://hackerone.com/reports/198734 | GMP Deserialization Type Confusion Vulnerability [MyBB <= 1.8.3 RCE Vulnerability]
  1638. https://hackerone.com/reports/198969 | IDOR - Deleting other user's reminders just by id
  1639. https://hackerone.com/reports/199281 | IDOR - Leaking other user's folder names from /appsuite/api/import?action=ICA
  1640. https://hackerone.com/reports/199321 | IDOR - Deleting other user's signature via /appsuite/api/snippet?action=update (although an error is thrown)
  1641. https://hackerone.com/reports/199764 | Aborted - proc.c - line:143
  1642. https://hackerone.com/reports/199779 | Google Analytics could be used as CSP bypass for data exfiltration on hackerone.com
  1643. https://hackerone.com/reports/199804 | Persistent XSS on ForecastApp
  1644. https://hackerone.com/reports/200387 | Incorrect code generation with redo inside NODE_RESCUE.
  1645. https://hackerone.com/reports/200487 | Incomplete HTML sanitization + Session id leaking + private information disclosure
  1646. https://hackerone.com/reports/200576 | Logic flaw enables restricted account to access account license key
  1647. https://hackerone.com/reports/200753 | [nutty.ubnt.com] DOM Based XSS nuttyapp github-btn.html
  1648. https://hackerone.com/reports/200818 | SQL Injection /webApp/cancel_iltakoulu regId parameter (viestinta.lahitapiola.fi)
  1649. https://hackerone.com/reports/200821 | heap-use-after-free /home/operac/testafl/mruby/mrubylast/mruby/src/gc.c
  1650. https://hackerone.com/reports/200826 | [github.algolia.com] DOM Based XSS github-btn.html
  1651. https://hackerone.com/reports/200909 | Out of bounds memory read in unserialize()
  1652. https://hackerone.com/reports/201137 | Reflected XSS on iltakoulu_varkaus (viestinta.lahitapiola.fi)
  1653. https://hackerone.com/reports/201314 | Enumeration in unsubscribe -function of /omatalousuk (viestinta.lahitapiola.fi)
  1654. https://hackerone.com/reports/201346 | CVE-2017-3730: Bad (EC)DHE parameters cause a client crash
  1655. https://hackerone.com/reports/201529 | Can upload files without authentication on AirFibre 3.2
  1656. https://hackerone.com/reports/201723 | Single user DOS on selectedLanguage -cookie (yrityspalvelu.lahitapiola.fi)
  1657. https://hackerone.com/reports/201796 | cloudup Subdomain Takeover That resolves to Desk.com ( CNAME cloudup.desk.com )
  1658. https://hackerone.com/reports/201897 | Recursion causing uninitialized memory reads leading to a segfault
  1659. https://hackerone.com/reports/201901 | Test Page available with Server details on /r/test (viestinta.lahitapiola.fi)
  1660. https://hackerone.com/reports/201905 | SIGSEGV - vm.c - line:1214
  1661. https://hackerone.com/reports/201984 | Wordpress directories/files visible to internet
  1662. https://hackerone.com/reports/202177 | Login with Google Not Authenticated on iOS App
  1663. https://hackerone.com/reports/202354 | Stored XSS / Bypassing .htaccess protection in http://nodebb.ubnt.com/
  1664. https://hackerone.com/reports/202362 | Null pointer dereference in mrb_random_initialize
  1665. https://hackerone.com/reports/202425 | Two-factor authentication bypass on Grab Android App
  1666. https://hackerone.com/reports/202499 | User with only Viewing Privilege can send message to Room
  1667. https://hackerone.com/reports/202501 | Restricted user is able to delete filter sets of admin users in https://infrastructure.newrelic.com/accounts/{{ACC#}}/settings/filterSets
  1668. https://hackerone.com/reports/202582 | Denial of service (segfault) due to null pointer dereference in mrb_obj_instance_eval
  1669. https://hackerone.com/reports/202584 | Denial of service (segfault) due to null pointer dereference in mrb_vm_exec
  1670. https://hackerone.com/reports/202767 | Subdomain takeover at info.hacker.one
  1671. https://hackerone.com/reports/202960 | CVE-2017-5204: The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print()
  1672. https://hackerone.com/reports/202965 | CVE-2017-5341 The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print()
  1673. https://hackerone.com/reports/202967 | CVE-2017-5484 The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print()
  1674. https://hackerone.com/reports/202968 | CVE-2017-5342 In tcpdump before 4.9.0 a bug in multiple protocol parsers could cause a buffer overflow in print-ether.c:ether_print()
  1675. https://hackerone.com/reports/202969 | CVE-2017-5482 The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print().
  1676. https://hackerone.com/reports/203002 | Incorrect GC behavior in xxlimited could lead to use-after-free
  1677. https://hackerone.com/reports/203042 | Find whether a video has been favourited or not, for any user [via YouPorn Mobile API]
  1678. https://hackerone.com/reports/203513 | SIGSEGV - mrb_vm_exec - line:1312
  1679. https://hackerone.com/reports/203515 | Wordpress 4.7.2 - Two XSS in Media Upload when file too large.
  1680. https://hackerone.com/reports/203595 | forgot to add the patch
  1681. https://hackerone.com/reports/203673 | AirFibre products vulnerable to HTTP Header injection
  1682. https://hackerone.com/reports/203726 | Open Redirect in .greenhouse.io
  1683. https://hackerone.com/reports/204047 | Segmentation fault while printing backtrace
  1684. https://hackerone.com/reports/204208 | High server resource usage on captcha (viestinta.lahitapiola.fi)
  1685. https://hackerone.com/reports/204421 | Heap buffer oveflow with many arguments
  1686. https://hackerone.com/reports/204513 | Infrastructure - Photon - SSRF
  1687. https://hackerone.com/reports/204628 | segafult in mruby's sprintf - mrb_str_format
  1688. https://hackerone.com/reports/204774 | A crash when an exception is caught in a caller and the receiver returned from ensure
  1689. https://hackerone.com/reports/204802 | pam-ussh may be tricked into using another logged in user's ssh-agent
  1690. https://hackerone.com/reports/204984 | IDOR - Accessing other user's attachements via PUT /appsuite/api/files?action=saveAs
  1691. https://hackerone.com/reports/205000 | Authorization bypass using login by phone option+horizontal escalation possible on Grab Android App
  1692. https://hackerone.com/reports/205284 | SIGABRT - method_missing - mark_context_stack
  1693. https://hackerone.com/reports/205481 | Wordpress unzip_file path traversal
  1694. https://hackerone.com/reports/205884 | Interger overflow in str_substr leading to read/write out of bound memory
  1695. https://hackerone.com/reports/205953 | CSRF - Adding unlimited number of saved items via GET request
  1696. https://hackerone.com/reports/206109 | mruby heap use-after-free
  1697. https://hackerone.com/reports/206227 | Remote Code Execution on Git.imgur-dev.com
  1698. https://hackerone.com/reports/206319 | Persistent CSRF in /GiftCert-AddToBasket prevents purchases on eCommerce sites
  1699. https://hackerone.com/reports/206650 | Broken Authentication - Security token gets captured via man in the middle attack
  1700. https://hackerone.com/reports/206653 | Captcha bypass for the most important function - At en.instagram-brand.com
  1701. https://hackerone.com/reports/206894 | SSRF at iris.lystit.com
  1702. https://hackerone.com/reports/207042 | Stealing contact form data on www.hackerone.com using Marketo Forms XSS with postMessage frame-jumping and jQuery-JSONP
  1703. https://hackerone.com/reports/207053 | Writable RubyCi Amazon s3 bucket
  1704. https://hackerone.com/reports/207266 | Information leakage via CSV when content is valid JavaScript
  1705. https://hackerone.com/reports/207321 | Controlled address leak due to type confusion - ASLR bypass
  1706. https://hackerone.com/reports/207576 | Subdomain takeover on s3.shopify.com
  1707. https://hackerone.com/reports/207710 | Heap use-after-free in mrb_vm_exec
  1708. https://hackerone.com/reports/207983 | read outside of buffer (heap buffer overflow) in S_regmatch - regexec.c:6057
  1709. https://hackerone.com/reports/208237 | Brute force unsubscription on /webApp/unsub_sb (viestinta.lahitapiola.fi)
  1710. https://hackerone.com/reports/208363 | Memory corrouption in mrb_gc_mark
  1711. https://hackerone.com/reports/208480 | Site configured improperly at subdomain of lyst.co.uk
  1712. https://hackerone.com/reports/208526 | Null pointer dereference in mark_context_stack
  1713. https://hackerone.com/reports/208622 | Reflected cross-site scripting (XSS) vulnerability in scores.ubnt.com allows attackers to inject arbitrary web script via p parameter.
  1714. https://hackerone.com/reports/208719 | Subdomain Takeover at Landing.udemy.com
  1715. https://hackerone.com/reports/208734 | CSRF @ configuration
  1716. https://hackerone.com/reports/209004 | Subdomain takeover #2 at info.hacker.one
  1717. https://hackerone.com/reports/209008 | Authentication Bypass - Chaining two vulnerabilities leads to account takeover at en.instagram-brand.com
  1718. https://hackerone.com/reports/209223 | Open S3 Bucket WriteAble To Any Aws User
  1719. https://hackerone.com/reports/209251 | public report - Reproducible - Writable RubyCi Amazon s3 bucket[207053]
  1720. https://hackerone.com/reports/209352 | Cross Domain leakage of sensitive information - Leading to Account Takeover at Instagram Brand
  1721. https://hackerone.com/reports/209368 | [wallet.rapida.ru] Mass SMS flood
  1722. https://hackerone.com/reports/209398 | HTML Injection in email from http://www.lahitapiola.fi/henkilo/sivut/tonttutesti
  1723. https://hackerone.com/reports/209449 | Heap buffer overflow with long array assignment
  1724. https://hackerone.com/reports/209736 | DOM XSS on teavana.com via "pr_zip_location" parameter
  1725. https://hackerone.com/reports/209765 | Heap buffer overflow in mruby value_move
  1726. https://hackerone.com/reports/209917 | javascript: and mailto: links are allowed in JIRA integration settings
  1727. https://hackerone.com/reports/209937 | SIGSEGV - mark_context_stack
  1728. https://hackerone.com/reports/209949 | Arbitrary heap exposure in JSON.generate
  1729. https://hackerone.com/reports/210190 | Transitioning a Private Program to Public Does Not Clear Previously Private Updates to Hackers
  1730. https://hackerone.com/reports/210331 | SSLv3 POODLE Vulnerability
  1731. https://hackerone.com/reports/210354 | RTLO character in file names
  1732. https://hackerone.com/reports/210429 | mrb_vm_exec - null ptr dereference
  1733. https://hackerone.com/reports/210572 | Full path Disclosure in Rockstargames.com██████████
  1734. https://hackerone.com/reports/210779 | [Urgent] Invalidating OAuth2 Bearer token makes TweetDeck unavailable
  1735. https://hackerone.com/reports/210875 | use of unsafe host header leads to open redirect
  1736. https://hackerone.com/reports/210908 | XSS on 3rd party service Localtapiola is using
  1737. https://hackerone.com/reports/211149 | Inadequate/dangerous jQuery behavior
  1738. https://hackerone.com/reports/211418 | Source Code Disclosure (CGI)
  1739. https://hackerone.com/reports/211477 | Stealing users' facebook access tokens - kitcrm.com
  1740. https://hackerone.com/reports/212067 | An “algobot�-s GitHub access token was leaked
  1741. https://hackerone.com/reports/212074 | SIGSEGV - mrb_yield_with_class
  1742. https://hackerone.com/reports/212107 | Null pointer dereference in mrb_class
  1743. https://hackerone.com/reports/212239 | sprintf gem - format string combined attack
  1744. https://hackerone.com/reports/212241 | sprintf combined format string attack
  1745. https://hackerone.com/reports/212456 | SIGSEGV - kh_get_n2s - in /src/symbol.c:37
  1746. https://hackerone.com/reports/212508 | Single User DOS on SelectedLocale -cookie (verkkopalvelu.tapiola.fi)
  1747. https://hackerone.com/reports/212696 | RCE by command line argument injection to gm convert in /edit/process?a=crop
  1748. https://hackerone.com/reports/212721 | IE 11 Self-XSS on Jira Integration Preview Base Link
  1749. https://hackerone.com/reports/212882 | SIGABRT in only mirb
  1750. https://hackerone.com/reports/213255 | SIGSEGV in str_buf_cat
  1751. https://hackerone.com/reports/213261 | Use-after-free leading to an invalid pointer dereference
  1752. https://hackerone.com/reports/213418 | User able to access company details in yrityspalvelu without proper permissions
  1753. https://hackerone.com/reports/213437 | Critical vulnerability in JSON Web Encryption (JWE) - RFC 7516 Invalid Curve attack
  1754. https://hackerone.com/reports/213558 | Arbitrary Local-File Read from Admin - Restore From Backup due to Symlinks
  1755. https://hackerone.com/reports/213779 | SIGSEGV - mrb_obj_value
  1756. https://hackerone.com/reports/213942 | Differential "Show Raw File" feature exposes generated files to unauthorised users
  1757. https://hackerone.com/reports/214000 | SIGABRT - mirb and mruby
  1758. https://hackerone.com/reports/214001 | File access controls incorrectly enforced for files shared via QuickLink - Unshared files can be accessed
  1759. https://hackerone.com/reports/214022 | Admin Command Injection via username in user_archive ExportCsvFile
  1760. https://hackerone.com/reports/214044 | Stored XSS in [shop].myshopify.com/admin/orders/[id]
  1761. https://hackerone.com/reports/214087 | Clickjacking Vulnerability found on Yelp
  1762. https://hackerone.com/reports/214571 | Login form on non-HTTPS page
  1763. https://hackerone.com/reports/214576 | SIGABRT - mirb - Double Free
  1764. https://hackerone.com/reports/214581 | Stored passive XSS at scheduled posts (kitcrm.com)
  1765. https://hackerone.com/reports/214681 | Null pointer dereference in ary_concat
  1766. https://hackerone.com/reports/214845 | SIGSEGV in mrb_vm_exec
  1767. https://hackerone.com/reports/215044 | [iOS] URL can be replaceState by blob URL in iOS Brave
  1768. https://hackerone.com/reports/215381 | CSRF on Periscope Web OAuth authorization endpoint
  1769. https://hackerone.com/reports/215447 | SIGSEGV in mrb_class
  1770. https://hackerone.com/reports/215625 | A HackerOne employee's GitHub personal access token exposed in Travis CI build logs
  1771. https://hackerone.com/reports/215854 | Garbage collector crash
  1772. https://hackerone.com/reports/215891 | Null pointer dereference in mrb_class
  1773. https://hackerone.com/reports/215967 | SIGABRT in mrb_debug_info_append_file
  1774. https://hackerone.com/reports/216151 | Use-after-free in _asyncio_Future_remove_done_callback
  1775. https://hackerone.com/reports/216615 | Crash in ary_concat()
  1776. https://hackerone.com/reports/216700 | heap use-after-free in mrb_vm_exec()
  1777. https://hackerone.com/reports/216725 | SIGABRT - in free
  1778. https://hackerone.com/reports/216746 | Phabricator is vulnerable to padding oracle attacks and chosen-ciphertext attacks.
  1779. https://hackerone.com/reports/216812 | Reflected XSS in error pages (NC-SA-2017-008)
  1780. https://hackerone.com/reports/216840 | OCSP Status Request extension unbounded memory growth (CVE-2016-6304)
  1781. https://hackerone.com/reports/217007 | Stored XSS in e.mail.ru (payload affect multiple users)
  1782. https://hackerone.com/reports/217083 | SIGSEGV in mrb_str_inum
  1783. https://hackerone.com/reports/217097 | SIGSEGV in mrb_vm_exec
  1784. https://hackerone.com/reports/217358 | Subdomain takeover #3 at info.hacker.one
  1785. https://hackerone.com/reports/217555 | Possible to unsubscribe from activities using CSRF @ mijn.werkenbijdefensie.nl
  1786. https://hackerone.com/reports/217558 | Possible to view and takeover other user's education and courses @ mijn.werkenbijdefensie.nl
  1787. https://hackerone.com/reports/217610 | kh_put_iv SEGFAULT - mruby 1.2.0
  1788. https://hackerone.com/reports/217745 | XSS in $shop$.myshopify.com/admin/ via "Button Objects" in malicious app
  1789. https://hackerone.com/reports/217790 | XSS in $shop$.myshopify.com/admin/ via twine template injection in "Shopify.API.Modal.input" method when using a malicious app
  1790. https://hackerone.com/reports/218088 | Request Hijacking Vulnerability in RubyGems 2.6.11 and earlier
  1791. https://hackerone.com/reports/218226 | Stored XSS in comments on https://www.starbucks.co.uk/blog/*
  1792. https://hackerone.com/reports/218233 | Null pointer dereference in OP_ENTER
  1793. https://hackerone.com/reports/218287 | In App purchase Hack
  1794. https://hackerone.com/reports/218451 | [Gnip Blogs] Reflected XSS via "plupload.flash.swf" component vulnerable to SOME
  1795. https://hackerone.com/reports/218465 | [staging-engineering.gnip.com] Publicly accessible GIT directory
  1796. https://hackerone.com/reports/218567 | SIGSEGV in array_copy - array.c:71
  1797. https://hackerone.com/reports/218570 | Invalid pointer dereference in OP_ENTER
  1798. https://hackerone.com/reports/218680 | [buy.coinbase.com]Content Injection
  1799. https://hackerone.com/reports/218803 | SIGABRT in sym_validate_len - symbol.c:44
  1800. https://hackerone.com/reports/219170 | XSS
  1801. https://hackerone.com/reports/219192 | Resend invitation to members by Read only user(Privilege Escalation)
  1802. https://hackerone.com/reports/219197 | [██████████.gnip.com] .htpasswd disclosure
  1803. https://hackerone.com/reports/219205 | Authentication bypass on auth.uber.com via subdomain takeover of saostatic.uber.com
  1804. https://hackerone.com/reports/219215 | Client can redirect payment, causing payment discrepancy between Harvest and PayPal
  1805. https://hackerone.com/reports/219607 | Dovecot authentication is vulnerable to timing attacks.
  1806. https://hackerone.com/reports/219821 | XSS
  1807. https://hackerone.com/reports/219870 | mirb only: stack-buffer-overflow (OOB write) in main()
  1808. https://hackerone.com/reports/220002 | Subdomain takeover #4 at info.hacker.one
  1809. https://hackerone.com/reports/220009 | Lack of input sanitization in Marketo form leads to execution of HTML in lead emails
  1810. https://hackerone.com/reports/220385 | Delete All Data of Any User
  1811. https://hackerone.com/reports/220494 | [GitHub Extension] Unsanitised HTML leading to XSS on GitHub.com
  1812. https://hackerone.com/reports/220615 | Expired SSL certificate
  1813. https://hackerone.com/reports/220737 | Tabnabbing via Window.Opener @Mavenlink
  1814. https://hackerone.com/reports/220864 | Unauthorized access to attachments details of Private Calendar appointments (Access control issue)
  1815. https://hackerone.com/reports/220874 | Critical : View/Edit access to private appointments of calendar folder by read only user (Vertical privilege escalation)
  1816. https://hackerone.com/reports/220903 | Authenticated Cross-site Scripting in Template Name
  1817. https://hackerone.com/reports/221251 | heap-buffer-overflow (read outside of buffer) in mrb_vm_exec()
  1818. https://hackerone.com/reports/221328 | HTTP 401 response injection on "amp.twimg.com/amplify-web-player/prod/source.html" through "image_src" parameter
  1819. https://hackerone.com/reports/221558 | Private Grab Messages on Android App can be accessed and cached by Search Engines
  1820. https://hackerone.com/reports/221785 | OOB write in MDC2_Update() (CVE-2016-6303)
  1821. https://hackerone.com/reports/221787 | Malformed SHA512 ticket DoS (CVE-2016-6302)
  1822. https://hackerone.com/reports/221788 | OOB write in BN_bn2dec() (CVE-2016-2182)
  1823. https://hackerone.com/reports/221789 | OOB read in TS_OBJ_print_bio() (CVE-2016-2180)
  1824. https://hackerone.com/reports/221790 | Certificate message OOB reads (CVE-2016-6306)
  1825. https://hackerone.com/reports/221791 | Excessive allocation of memory in tls_get_message_header() (CVE-2016-6307)
  1826. https://hackerone.com/reports/221792 | Excessive allocation of memory in dtls1_preprocess_fragment() (CVE-2016-6308)
  1827. https://hackerone.com/reports/221893 | XSS in the search bar of mercantile.wordpress.org
  1828. https://hackerone.com/reports/222020 | Mercurial can be tricked into granting authorized users access to the Python debugger
  1829. https://hackerone.com/reports/222040 | Reflected XSS at https://da.wordpress.org/themes/?s= via "s=" parameter
  1830. https://hackerone.com/reports/222224 | Stored but [SELF] XSS in mercantile.wordpress.org
  1831. https://hackerone.com/reports/222252 | Дубликат: https://hackerone.com/reports/219171 (до�туп к аккаунту, через �бро� парол�)
  1832. https://hackerone.com/reports/222294 | heap-use-after-free in mrb_vm_exec - vm.c:1247
  1833. https://hackerone.com/reports/222692 | plugins.trac.wordpress.org likely vulnerable to Cross Site Tracing (xst), TRACE HTTP method should be disabled
  1834. https://hackerone.com/reports/222870 | IRC-Bot exposes information
  1835. https://hackerone.com/reports/223203 | SVG Server Side Request Forgery (SSRF)
  1836. https://hackerone.com/reports/223363 | Escape sequence injection vulnerability in WEBrick BasicAuth
  1837. https://hackerone.com/reports/223625 | Subdomain Takeover (and Stored XSS) via Trailing Dot at https://coding-exercises.udemy.com
  1838. https://hackerone.com/reports/223906 | Dropbox Paper - Markdown XSS
  1839. https://hackerone.com/reports/225243 | phone number exposure for riders/drivers given email/uuid
  1840. https://hackerone.com/reports/225831 | Extract Billing admin email address using random team id
  1841. https://hackerone.com/reports/225897 | Throttling Bypass - ws1.dashlane.com
  1842. https://hackerone.com/reports/226191 | Android MailRu Email: Thirdparty can access private data files with small user interaction
  1843. https://hackerone.com/reports/226199 | Changing Victim's JIRA Integration Settings Through Multiple Bugs
  1844. https://hackerone.com/reports/226200 | OP_SCALL in LHS of a OP_ASGN resulting in arbitrary memory write
  1845. https://hackerone.com/reports/226203 | Cross-site-Scripting
  1846. https://hackerone.com/reports/226335 | Escape sequence injection in "summary" field
  1847. https://hackerone.com/reports/226418 | HackerOne reports escalation to JIRA is CSRF vulnerable
  1848. https://hackerone.com/reports/226428 | Reflected XSS in .myshopify.com through theme preview
  1849. https://hackerone.com/reports/226783 | HTML Injection on airlink.ubnt.com
  1850. https://hackerone.com/reports/226960 | [platform.harvestapp.com] Reflected XSS in Error Message via URL parameters
  1851. https://hackerone.com/reports/227181 | Xss в https://e.mail.ru/
  1852. https://hackerone.com/reports/227486 | XSS on https://www.starbucks.co.uk (can lead to credit card theft) (/shop/paymentmethod)
  1853. https://hackerone.com/reports/227522 | IDOR in editing courses
  1854. https://hackerone.com/reports/227663 | [https://www.dashlane.com] Test Panel Disclosure
  1855. https://hackerone.com/reports/227762 | Heap Overflow in fiber_switch triggered from Fiber.transfer
  1856. https://hackerone.com/reports/227809 | XSS at in instacart.com/store/partner_recipe
  1857. https://hackerone.com/reports/227833 | Reverse Tab-nabbing at www.instacart.com/store/partner_recipe?recipe_url=
  1858. https://hackerone.com/reports/228006 | Cross-site Scripting (XSS) on [maximum.nl]
  1859. https://hackerone.com/reports/228112 | Directory Disclose,Email Disclose Zendmail vulnerability
  1860. https://hackerone.com/reports/228377 | SSRF in upload IMG through URL
  1861. https://hackerone.com/reports/228399 | Any authenticated user can download full list of users, including email
  1862. https://hackerone.com/reports/228531 | Xss в https://e.mail.ru/
  1863. https://hackerone.com/reports/228648 | WannaCrypt “Killswitch�
  1864. https://hackerone.com/reports/229498 | Host header injection/redirection via newsletter signup
  1865. https://hackerone.com/reports/229619 | Ability to verify any email address you don't own - accounts.shopify.com
  1866. https://hackerone.com/reports/229622 | Directory traversal at https://nightly.ubnt.com
  1867. https://hackerone.com/reports/230232 | Stored self-XSS in mercantile.wordpress.org checkout
  1868. https://hackerone.com/reports/230234 | [mercantile.wordpress.org] Reflected XSS via AngularJS Template Injection
  1869. https://hackerone.com/reports/230435 | DOM Based XSS In mercantile.wordpress.org
  1870. https://hackerone.com/reports/231053 | XSS on any Shopify shop via abuse of the HTML5 structured clone algorithm in postMessage listener on "/:id/digital_wallets/dialog"
  1871. https://hackerone.com/reports/231917 | Shared file link - password protection bypass under certain conditions
  1872. https://hackerone.com/reports/232150 | heap-buffer-overflow (READ of size 11) in Perl 5.25.x
  1873. https://hackerone.com/reports/232174 | XSS on $shop$.myshopify.com/admin/ and partners.shopify.com via whitelist bypass in SVG icon for sales channel applications
  1874. https://hackerone.com/reports/232347 | [FG-VD-17-063] NextCloud Insufficient Attack Protection Vulnerability Notification
  1875. https://hackerone.com/reports/232432 | Universal Cross-Site Scripting in Keybase Chrome extension
  1876. https://hackerone.com/reports/232463 | Possible sweet32 lahitapiola.fi
  1877. https://hackerone.com/reports/232653 | CSRF. Удаление адре�ной книги, добавление контактов
  1878. https://hackerone.com/reports/233099 | CSRF in Report Lost or Stolen Page https://www.starbucks.com/account/card
  1879. https://hackerone.com/reports/233440 | heap-buffer-overflow (READ of size 61) in Perl_re_intuit_start()
  1880. https://hackerone.com/reports/235200 | Cross-origin resource sharing misconfig | steal user information
  1881. https://hackerone.com/reports/235866 | Cross-site Scripting (XSS) in /updates-pro/archive/
  1882. https://hackerone.com/reports/236552 | Unauthenticated RCE in Vaultpress
  1883. https://hackerone.com/reports/237184 | Session fixation in password protected public download.
  1884. https://hackerone.com/reports/237357 | CRLF Injection at vpn.bitstrips.com
  1885. https://hackerone.com/reports/237381 | SSRF and local file disclosure in https://wordpress.com/media/videos/ via FFmpeg HLS processing
  1886. https://hackerone.com/reports/237915 | PHP mbstring / Oniguruma multiple remote heap/stack corruptions
  1887. https://hackerone.com/reports/238260 | Uninstalling Slack for Windows (64-bit), then reinstalling keeps you logged in without authentication
  1888. https://hackerone.com/reports/239359 | Timing attack woocommerce, simplify commerce gateway
  1889. https://hackerone.com/reports/239503 | Open Redirect & Information Disclosure [mijn.werkenbijdefensie.nl]
  1890. https://hackerone.com/reports/240083 | Updating payout preference to CurrencyCloud doesn't notify user via email
  1891. https://hackerone.com/reports/240821 | Ability To Takeover any account by Emaill.
  1892. https://hackerone.com/reports/240886 | Multiple File Manipulation bugs in WP Super Cache
  1893. https://hackerone.com/reports/241008 | Stored XSS in *.myshopify.com
  1894. https://hackerone.com/reports/241202 | Unsafe arithmetic in PyString_DecodeEscape
  1895. https://hackerone.com/reports/241323 | woocommerce - prevent_caching() bug / bypass
  1896. https://hackerone.com/reports/241610 | ap_find_token() Buffer Overread
  1897. https://hackerone.com/reports/241619 | DOM-based XSS in store.starbucks.co.uk on IE 11
  1898. https://hackerone.com/reports/242314 | Open redirect on https://werkenbijdefensie.nl/
  1899. https://hackerone.com/reports/242354 | Null pointer dereference with send/method_missing
  1900. https://hackerone.com/reports/242727 | Android content provider exposes password-protected share password hashes
  1901. https://hackerone.com/reports/242765 | Any user with invite capabilities can take-over any account on Discourse
  1902. https://hackerone.com/reports/243058 | XSS bypass Script execute,Read any file,execute any javascript code--UXSS
  1903. https://hackerone.com/reports/243094 | Paragonie Airship Admin CSRF on Extensions Pages
  1904. https://hackerone.com/reports/243156 | Installing a crafted gem package may create or overwrite files
  1905. https://hackerone.com/reports/243943 | IDOR [partners.shopify.com] - User with ONLY Manage apps permission is able to get shops info and staff names from inside the shop
  1906. https://hackerone.com/reports/244504 | Possible SOP bypass in www.starbucks.com due to insecure crossdomain.xml
  1907. https://hackerone.com/reports/244904 | Use after free in mruby-mpdecimal
  1908. https://hackerone.com/reports/245172 | Double Stored Cross-Site scripting in the admin panel
  1909. https://hackerone.com/reports/245228 | Object Injection in Woocommerce / Handle PDT Responses from PayPal
  1910. https://hackerone.com/reports/245296 | Persistent XSS on keybase.io via "payload" field in /user/sigchain_signature.toffee template
  1911. https://hackerone.com/reports/245833 | The user, who was deleted from Github Organization, still can access all functions of federalist, in case he didn't do logout
  1912. https://hackerone.com/reports/245872 | [IDOR] The authenticated user can restart website build or view build logs on any another Federalist account
  1913. https://hackerone.com/reports/245956 | Use-after-free in PHP7's unserialize()
  1914. https://hackerone.com/reports/246794 | XSS on "widgets.shopifyapps.com" via "stripping" attribute and "shop" parameter
  1915. https://hackerone.com/reports/246801 | Captcha Bypass in Coinbase SignUp Form
  1916. https://hackerone.com/reports/246803 | [spectacles.com] Bypassing quantity limit in orders
  1917. https://hackerone.com/reports/246897 | Open Redirect
  1918. https://hackerone.com/reports/247246 | Dom based xss affecting all pages from https://www.grab.com/.
  1919. https://hackerone.com/reports/247628 | Reading redacted data via hackbot's answers
  1920. https://hackerone.com/reports/247680 | SSRF in imgur video GIF conversion
  1921. https://hackerone.com/reports/248560 | [parcel.grab.com] DOM XSS at /assets/bower_components/lodash/perf/
  1922. https://hackerone.com/reports/248599 | Information disclosure same issue #176002
  1923. https://hackerone.com/reports/248601 | PHP INI Parsing Stack Buffer Overflow Vulnerability
  1924. https://hackerone.com/reports/248609 | PHP OpenSSL zif_openssl_seal() heap overflow (wild memcpy)
  1925. https://hackerone.com/reports/248659 | PHP WDDX Deserialization Heap OOB Read in timelib_meridian()
  1926. https://hackerone.com/reports/248668 | XXE on sms-be-vip.twitter.com in SXMP Processor
  1927. https://hackerone.com/reports/248693 | Git repository found
  1928. https://hackerone.com/reports/249131 | Ability to create own account UUID leads to stored XSS
  1929. https://hackerone.com/reports/249234 | Posting to Twitter CSRF on php/post_twitter_authenticate.php
  1930. https://hackerone.com/reports/249319 | Race condition on the Federalist API endpoints can lead to the Denial of Service attack
  1931. https://hackerone.com/reports/249798 | Intercom chat session information persists after logout
  1932. https://hackerone.com/reports/250386 | CSRF Проверить �вл�ет�� ли пользователь админом группы.
  1933. https://hackerone.com/reports/250688 | The Federalsit session cookie (federalist.sid) is not properly invalidated - backdoor access to the account is possible
  1934. https://hackerone.com/reports/250729 | Content Security Policy not applied to error pages at multiple HackerOne endpoints
  1935. https://hackerone.com/reports/250837 | Stored xss via template injection
  1936. https://hackerone.com/reports/251224 | Blind stored xss [parcel.grab.com] > name parameter
  1937. https://hackerone.com/reports/251572 | Length extension attack leading to HTML injection
  1938. https://hackerone.com/reports/251918 | Flash CSRF: Update Ad Frequency %: [cp-ng.pinion.gg]
  1939. https://hackerone.com/reports/252580 | Scrollbar Width permits detecting browser platform
  1940. https://hackerone.com/reports/252908 | Reflected XSS on https://www.starbucks.co.uk/shop/paymentmethod/ (bypass for 227486)
  1941. https://hackerone.com/reports/253313 | XSS Vulnerability in WooCommerce Product Vendors plugin
  1942. https://hackerone.com/reports/253429 | Linux TBB SFTP URI allows local IP disclosure
  1943. https://hackerone.com/reports/253934 | Password reset token issue
  1944. https://hackerone.com/reports/254269 | Persistent XSS found on bin.pinion.gg due to outdated FlowPlayer SWF file with Remote File Inclusion vulnerability.
  1945. https://hackerone.com/reports/254285 | Gain access to random information via group chat "about" property
  1946. https://hackerone.com/reports/254588 | Removed staff members who had "Manage shops" permission can still create development stores
  1947. https://hackerone.com/reports/255021 | Profile shows incorrect account creation date
  1948. https://hackerone.com/reports/255100 | No error or notification on Reset password page
  1949. https://hackerone.com/reports/255474 | Profile fields validation bypass
  1950. https://hackerone.com/reports/255651 | Unauthorized update of merchants' information via /php/merchant_details.php
  1951. https://hackerone.com/reports/255668 | Weak Password
  1952. https://hackerone.com/reports/255685 | [New Relic Infrastructure] Restricted User can still integrate with AWS via forced browsing (plus, a few other bugs)
  1953. https://hackerone.com/reports/255978 | Non-Cloudflare IPs allowed to access origin servers
  1954. https://hackerone.com/reports/255991 | URL Spoof / Brave Shield Bypass
  1955. https://hackerone.com/reports/256647 | Simple CSS line-height identifies platform
  1956. https://hackerone.com/reports/257305 | [www.boozt.com] - Authentication bypass
  1957. https://hackerone.com/reports/257335 | ssh: unprivileged users may hijack due to backdated ssh version open port found(███.unikrn.com)
  1958. https://hackerone.com/reports/257942 | languagechange event fires simultaneously on all tabs
  1959. https://hackerone.com/reports/258084 | Access to all files of remote user through shared file
  1960. https://hackerone.com/reports/258198 | The Custom Emoji Page has a Reflected XSS
  1961. https://hackerone.com/reports/258201 | Overwrite Drafts of Everyone
  1962. https://hackerone.com/reports/258237 | [et.mail.ru] ssrf 2
  1963. https://hackerone.com/reports/258260 | Accessing Private Files Shared in message of other users
  1964. https://hackerone.com/reports/258318 | filin.mail.ru user's e-mail address disclosure
  1965. https://hackerone.com/reports/258460 | [Quora Android] Possible to steal arbitrary files from mobile device
  1966. https://hackerone.com/reports/258578 | application/x-brave-tab should not be readable.
  1967. https://hackerone.com/reports/258585 | OS username disclosure
  1968. https://hackerone.com/reports/258710 | Download attribute allows downloading local files
  1969. https://hackerone.com/reports/258876 | XSS when clicking "Share to Twitter" at quora.com/widgets/embed_iframe?path=...
  1970. https://hackerone.com/reports/259100 | XSS through __e2e_action_id delivered by JSONP
  1971. https://hackerone.com/reports/259390 | Use-after-free in XML::LibXML::Node::replaceChild
  1972. https://hackerone.com/reports/259400 | Issues with Forgot password Error Handling
  1973. https://hackerone.com/reports/259415 | Lengthy manual entry of 2FA secret
  1974. https://hackerone.com/reports/259416 | Incorrect email content when disabling 2FA
  1975. https://hackerone.com/reports/259742 | Incorrect error message
  1976. https://hackerone.com/reports/260005 | RCE via ssh:// URIs in multiple VCS
  1977. https://hackerone.com/reports/260278 | TabNabbing issue (due to taget=_blank)
  1978. https://hackerone.com/reports/260420 | [dev-nightly.ubnt.com] Local File Reading
  1979. https://hackerone.com/reports/260632 | Improper validation of parameters while creating issues
  1980. https://hackerone.com/reports/260662 | No length limit in invite_code can cause server degradation
  1981. https://hackerone.com/reports/260697 | CSRF-tokens on pages without no-cache headers, resulting in ATO when using CloudFlare proxy (Web Cache Deception)
  1982. https://hackerone.com/reports/260744 | [dev.twitter.com] XSS and Open Redirect
  1983. https://hackerone.com/reports/260755 | https://secure.gravatar.com
  1984. https://hackerone.com/reports/260938 | Homograph IDNs displayed in Description
  1985. https://hackerone.com/reports/261221 | Participation of expired account holders in Projects can occure financial loss to Mavenlink
  1986. https://hackerone.com/reports/261335 | Heap Use After Free Read in unserialize()
  1987. https://hackerone.com/reports/261336 | Out of Bounds Memory Read in unserialize()
  1988. https://hackerone.com/reports/261338 | Heap Use After Free in unserialize()
  1989. https://hackerone.com/reports/261592 | Open Redirection Found in users.whisper.sh
  1990. https://hackerone.com/reports/261734 | Индек�аци� почты/логинов пользователей
  1991. https://hackerone.com/reports/262004 | HTML injection in email in unikrn.com
  1992. https://hackerone.com/reports/262230 | Tinymce 2.4.0
  1993. https://hackerone.com/reports/262649 | Information disclosure (system username) in the x-amz-meta-s3cmd-attrs response header on federation.data.gov
  1994. https://hackerone.com/reports/262830 | Rate-limit protection get executed in the last stage of the registration process, allowing enumeration of existing account.
  1995. https://hackerone.com/reports/263010 | Improper validation at Phone verification (possible cost increase + SMS SPAM attack)
  1996. https://hackerone.com/reports/263109 | Buddypress 2.9.1 - Exceeding the maximum upload size - XSS leading to potential RCE.
  1997. https://hackerone.com/reports/263226 | HTML injection (with XSS possible) on the https://www.data.gov/issue/ using media_url attribute
  1998. https://hackerone.com/reports/263684 | [qiwi.com] XSS on payment form
  1999. https://hackerone.com/reports/263760 | Opportunity to obtain private tweets through search widget preview caches
  2000. https://hackerone.com/reports/263876 | Stored XSS Deleting Menu Links in the Shopify Admin
  2001. https://hackerone.com/reports/264177 | XSS when replying / forwarding to a malicious email on iOS
  2002. https://hackerone.com/reports/264494 | Subdomain Takeover at creatorforum.roblox.com
  2003. https://hackerone.com/reports/264832 | xss filter bypass [polldaddy]
  2004. https://hackerone.com/reports/265050 | Blind SSRF in emblem editor (2)
  2005. https://hackerone.com/reports/265528 | Reflected XSS on the data.gov (WAF bypass+ Chrome XSS Auditor bypass+ works in all browsers)
  2006. https://hackerone.com/reports/265740 | [Cross Domain Referrer Leakage] Password Reset Token Leaking to Third party Sites.
  2007. https://hackerone.com/reports/265775 | Password reset token issue
  2008. https://hackerone.com/reports/267177 | stored xss in invited team member via email parameter
  2009. https://hackerone.com/reports/267570 | Stored XSS through Facebook Page Connection
  2010. https://hackerone.com/reports/267636 | [NR Synthetics] (IDOR) Ability to see full name associated with other New Relic accounts through workaround of #255894
  2011. https://hackerone.com/reports/267783 | Stored XSS and html injection in biz.mail.ru
  2012. https://hackerone.com/reports/268228 | A manager of a determinate group of users still might have access to any user account from any group that he doesn't administrate anymore.
  2013. https://hackerone.com/reports/268245 | XSS in biz.mail.ru/error
  2014. https://hackerone.com/reports/268382 | Nginx misconfiguration leading to direct PHP source code download
  2015. https://hackerone.com/reports/268541 | [Synthetics/Infrastructure/everything] Individual account permissions are not properly managed and inherited on sub accounts
  2016. https://hackerone.com/reports/268803 | CVE-2017-12985: The IPv6 parser in tcpdump before 4.9.2 has a buffer over-read in ip6_print()
  2017. https://hackerone.com/reports/268804 | CVE-2017-12986 The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().
  2018. https://hackerone.com/reports/268805 | CVE-2017-13008 The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().
  2019. https://hackerone.com/reports/268806 | CVE-2017-13009 The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_print().
  2020. https://hackerone.com/reports/268807 | CVE-2017-13010 The BEEP parser in tcpdump before 4.9.2 has a buffer over-read in print-beep.c:l_strnstart().
  2021. https://hackerone.com/reports/268808 | CVE-2017-13038 The PPP parser in tcpdump before 4.9.2 has a buffer over-read in print-ppp.c:handle_mlppp().
  2022. https://hackerone.com/reports/268888 | Sensitive Information Disclosure https://cards-dev.twitter.com
  2023. https://hackerone.com/reports/268984 | Homograph Attack Bypass [ Tested on Linux & Windows ]
  2024. https://hackerone.com/reports/269230 | Emails of invited collaborators are disclosed in full in payload for report participants
  2025. https://hackerone.com/reports/269279 | SQL injection in partner id field on https://www.teavana.com (Sign-up form)
  2026. https://hackerone.com/reports/269349 | XSS on https://account.mail.ru/login via postMessage
  2027. https://hackerone.com/reports/269458 | XSS в пи�ьме, в теле пи�ьма.
  2028. https://hackerone.com/reports/269568 | Optionsbleed / CVE-2017-9798
  2029. https://hackerone.com/reports/270060 | Reflected Swf XSS In ( plugins.svn.wordpress.org )
  2030. https://hackerone.com/reports/270072 | Unpacker improperly validates symlinks, allowing gems writes to arbitrary locations
  2031. https://hackerone.com/reports/270993 | resolved bugs in a program are public despite the program settings
  2032. https://hackerone.com/reports/271007 | [app.simplenote.com] Stored XSS via Markdown SVG filter bypass
  2033. https://hackerone.com/reports/271176 | Bypassing one-time checkout router page (revealing payment information)
  2034. https://hackerone.com/reports/271324 | Homograph fix Bypass
  2035. https://hackerone.com/reports/271330 | Format string implementation vulnerability, resulting in code execution
  2036. https://hackerone.com/reports/271506 | Banned researcher gets email updates on a private program.
  2037. https://hackerone.com/reports/271533 | Bruteforcing password reset tokens, could lead to account takeover
  2038. https://hackerone.com/reports/271765 | Stored XSS in partners dashboard
  2039. https://hackerone.com/reports/272095 | SSRF/XSPA in labs.data.gov/dashboard/validate
  2040. https://hackerone.com/reports/272497 | Perl $ENV Key Stack Buffer Overflow
  2041. https://hackerone.com/reports/272588 | CSRF in Raffles Ticket Purchasing
  2042. https://hackerone.com/reports/272839 | Weak Session ID Implementation - No Session change on Password change
  2043. https://hackerone.com/reports/273099 | User with removed manage shops permissions is still able to make changes to a shop
  2044. https://hackerone.com/reports/273557 | ability to install paid themes for free
  2045. https://hackerone.com/reports/273805 | Improper access control lead To delete anyone comment
  2046. https://hackerone.com/reports/273946 | www.drivegrab.com SQL injection
  2047. https://hackerone.com/reports/273998 | CSRF token does not valided during blog comment
  2048. https://hackerone.com/reports/274541 | Invited user to a Author profile can remove the owner of that Author
  2049. https://hackerone.com/reports/274844 | Stored XSS when you read eamils. <style>
  2050. https://hackerone.com/reports/274868 | Xss on community.imgur.com
  2051. https://hackerone.com/reports/274990 | Remote code execution on rubygems.org
  2052. https://hackerone.com/reports/275186 | Get all instacart emails - missing rate limit on /accounts/register
  2053. https://hackerone.com/reports/275269 | Gem signature forgery
  2054. https://hackerone.com/reports/275386 | Stored XSS Using Media
  2055. https://hackerone.com/reports/275515 | Stored XSS in dev-ucrm-billing-demo.ubnt.com In Client Custom Attribute
  2056. https://hackerone.com/reports/275518 | Blind XSS in Mobpub Marketplace Admin Production | Sentry via demand.mopub.com (User-Agent)
  2057. https://hackerone.com/reports/275714 | Subdomain takeover on developer.openapi.starbucks.com
  2058. https://hackerone.com/reports/277163 | XSS в теле пи�ьма, в блочных �тил�х.
  2059. https://hackerone.com/reports/277502 | [BuddyPress 2.9.1] Open Redirect via "wp_http_referer" parameter on "bp-profile-edit" endpoint
  2060. https://hackerone.com/reports/277525 | Formula injection via CSV exports in WordCamp Talks plugin
  2061. https://hackerone.com/reports/277534 | Timing Attack in Google Authenticator - Per User Prompt
  2062. https://hackerone.com/reports/278095 | Invalid Host detection at https://hackerone.com/redirect
  2063. https://hackerone.com/reports/278191 | Listing of Amazon S3 Bucket accessible to any amazon authenticated user (metrics.pscp.tv)
  2064. https://hackerone.com/reports/279932 | Users Unable to login using Gmail/Facebook on https://boozt-stage1.booztx.com/login
  2065. https://hackerone.com/reports/280748 | High server resource usage on captcha (viestinta.lahitapiola.fi)
  2066. https://hackerone.com/reports/280912 | apache access.log leakage via long request on https://rapida.ru/
  2067. https://hackerone.com/reports/282176 | Unauthenticated hidden groups disclosure via Ajax groups search
  2068. https://hackerone.com/reports/282748 | Detecting Tor Browser UI Language
  2069. https://hackerone.com/reports/283058 | [IRCCloud Android] Opening arbitrary URLs/XSS in SAMLAuthActivity
  2070. https://hackerone.com/reports/283063 | [IRCCloud Android] XSS in ImageViewerActivity
  2071. https://hackerone.com/reports/283460 | Open Redirect Protection Bypass
  2072. https://hackerone.com/reports/283644 | Out-Of-Bounds Read in timelib_meridian()
  2073. https://hackerone.com/reports/284346 | Download attachments with traversal path into any sdcard directory (incomplete fix 106097)
  2074. https://hackerone.com/reports/285432 | IDOR - setAttribute action of user object in API
  2075. https://hackerone.com/reports/286667 | Self-XSS in password reset functionality
  2076. https://hackerone.com/reports/286740 | Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse
  2077. https://hackerone.com/reports/287789 | IDOR to view User Order Information
  2078. https://hackerone.com/reports/287837 | 217.147.95.145 NFS Exposed with Zeus Server configs
  2079. https://hackerone.com/reports/288219 | Open Redirection while saving User account Settings
  2080. https://hackerone.com/reports/288704 | Command injection on Phabricator instance with an evil hg branch name
  2081. https://hackerone.com/reports/288955 | [IRCCloud Android] Theft of arbitrary files leading to token leakage
  2082. https://hackerone.com/reports/288966 | POODLE SSLv3 bug on multiple twitter smtp servers (mx3.twitter.com,199.59.148.204,199.16.156.108 and 199.59.148.204)
  2083. https://hackerone.com/reports/288993 | SSL_peek() hang on empty record (CVE-2016-6305)
  2084. https://hackerone.com/reports/289246 | Following links are vulnerable to clickjacking
  2085. https://hackerone.com/reports/289568 | Program profile metrics endpoint contains mean time to triage, even when turned off
  2086. https://hackerone.com/reports/289823 | Improper markup sanitization.
  2087. https://hackerone.com/reports/291057 | MySQL username and password leaked in developer.valvesoftware.com via source code dislosure
  2088. https://hackerone.com/reports/291522 | XSS on account.mail.ru/login
  2089. https://hackerone.com/reports/291539 | [Simplenote for Windows] Client RCE via External JavaScript Inclusion leveraging Electron
  2090. https://hackerone.com/reports/291683 | Crafted frame injection leading to form-based UI redressing.
  2091. https://hackerone.com/reports/291750 | Link filter protection bypass
  2092. https://hackerone.com/reports/291764 | SQL Injection found in NextCloud Android App Content Provider
  2093. https://hackerone.com/reports/292457 | Reflected XSS in www.dota2.com
  2094. https://hackerone.com/reports/292463 | Exposed authentication (/cs/Satellite)
  2095. https://hackerone.com/reports/292636 | session_id is not being validated at email invitation endpoint
  2096. https://hackerone.com/reports/292797 | ActionController::Parameters .each returns an unsafe hash
  2097. https://hackerone.com/reports/293016 | CSRF log victim into the attacker account
  2098. https://hackerone.com/reports/293105 | XSS в личных �ообщени�х
  2099. https://hackerone.com/reports/293299 | Validation message in Bounty award endpoint can be used to determine program balances
  2100. https://hackerone.com/reports/293490 | [www.zomato.com] Leaking Email Addresses of merchants via reset password feature
  2101. https://hackerone.com/reports/293689 | Query parameter reordering causes redirect page to render unsafe URL
  2102. https://hackerone.com/reports/293743 | [public-api.wordpress.com] Stored XSS via Crafted Developer App Description
  2103. https://hackerone.com/reports/293845 | [IDOR] Deleting other people's tasks
  2104. https://hackerone.com/reports/293847 | SSRF in /appsuite/api/autoconfig
  2105. https://hackerone.com/reports/294147 | Mercurial git subrepo lead to arbritary command injection
  2106. https://hackerone.com/reports/294201 | subdomain takeover at news-static.semrush.com
  2107. https://hackerone.com/reports/294232 | Adding external participants to unaccessible appointments
  2108. https://hackerone.com/reports/294462 | NET::Ftp allows command injection in filenames
  2109. https://hackerone.com/reports/294505 | Cross-site scripting in "Contact customer" form
  2110. https://hackerone.com/reports/294867 | Improper Host Detection During Team Up on tweetdeck.twitter.com
  2111. https://hackerone.com/reports/295276 | heap-use-after-free in OP_RESCUE
  2112. https://hackerone.com/reports/295330 | code.wordpress.net subdomain Takeover
  2113. https://hackerone.com/reports/295380 | heap-buffer-overflow in OP_R_BREAK
  2114. https://hackerone.com/reports/295540 | [XSS] Portal Widget Mail
  2115. https://hackerone.com/reports/295680 | Invalid read leading to a segfault
  2116. https://hackerone.com/reports/295841 | Blind SQL injection in Hall of Fap
  2117. https://hackerone.com/reports/296045 | SSRF in VCARD photo upload functionality
  2118. https://hackerone.com/reports/296198 | SEGV on ary_concat
  2119. https://hackerone.com/reports/297181 | Common response suggestion is sent to Google Analytics when user accepts duplicate comment Genius suggestion
  2120. https://hackerone.com/reports/297203 | Reflected XSS using Header Injection
  2121. https://hackerone.com/reports/297339 | PHPMYADMIN Setup is accessible without authentication on https://lml.lahitapiola.fi/
  2122. https://hackerone.com/reports/297359 | No Rate Limit in email leads to huge Mass mailings
  2123. https://hackerone.com/reports/297383 | mruby heredoc notation
  2124. https://hackerone.com/reports/297478 | SQL injection in https://labs.data.gov/dashboard/datagov/csv_to_json via User-agent
  2125. https://hackerone.com/reports/297547 | Improper markup sanitisation in Simplenote Android application.
  2126. https://hackerone.com/reports/297751 | Registered users can change app password permissions for any user
  2127. https://hackerone.com/reports/297803 | [crm.unikrn.com] Open Redirect
  2128. https://hackerone.com/reports/297968 | Persistent DOM-based XSS in https://help.twitter.com via localStorage
  2129. https://hackerone.com/reports/298176 | SQL injection in MilestoneFinder order method
  2130. https://hackerone.com/reports/298246 | controlled buffer under-read in pack_unpack_internal()
  2131. https://hackerone.com/reports/298265 | HTTP Parameter Pollution using semicolons in iframe element at hackerone.com/careers allows loading external Greenhouse forms
  2132. https://hackerone.com/reports/298873 | Command injection by overwriting authorized_keys file through GitLab import
  2133. https://hackerone.com/reports/299009 | Single Sing On - Clickjacking
  2134. https://hackerone.com/reports/299130 | SSRF - RSS feed, blacklist bypass (IP Formatting)
  2135. https://hackerone.com/reports/299135 | SSRF - RSS feed, blacklist bypass (301 re-direct)
  2136. https://hackerone.com/reports/299403 | Domain spoofing in redirect page using RTLO
  2137. https://hackerone.com/reports/299424 | Bypass Filter and get Stored Xss
  2138. https://hackerone.com/reports/299466 | [XSS] Mail <style> v2.0
  2139. https://hackerone.com/reports/299473 | Evaluating Ruby code by injecting Rescue job on the system_hook_push queue through web hook
  2140. https://hackerone.com/reports/299552 | Information disclosure on https://paycard.rapida.ru
  2141. https://hackerone.com/reports/299728 | Markdown parsing issue enables insertion of malicious tags and event handlers
  2142. https://hackerone.com/reports/299835 | Link poisoning on https://secure.login.gov/ login page
  2143. https://hackerone.com/reports/300099 | [www.zomato.com] Privilege Escalation - Control reviews - /████dashboard_handler.php
  2144. https://hackerone.com/reports/300179 | User uploaded portfolio files can be accessed by any user even after deleted
  2145. https://hackerone.com/reports/300181 | Torrent Viewer extension web service available on all interfaces
  2146. https://hackerone.com/reports/300270 | Stored XSS in learnboost.com via the lesson[goals] parameter.
  2147. https://hackerone.com/reports/300305 | Ability to bypass partner email confirmation to take over any store given an employee email
  2148. https://hackerone.com/reports/300391 | The parameter in the POST query allows to control size of returned page which in turn can lead to the potential DOS attack
  2149. https://hackerone.com/reports/300454 | [www.zomato.com] Privilege Escalation - /php/restaurant_menus_handler.php
  2150. https://hackerone.com/reports/300812 | Stored XSS in www.learnboost.com via ZIP codes.
  2151. https://hackerone.com/reports/300879 | User to Admin privilege escalation in Infrastructure Conditions - /v2/accounts/1835740/alerts/conditions
  2152. https://hackerone.com/reports/300881 | Account members can re-add themselve after has been deleted by administrator
  2153. https://hackerone.com/reports/301137 | GitHub import allows user to create child group under existing namespace
  2154. https://hackerone.com/reports/301432 | GitLab CI runner can read and poison cache of all other projects
  2155. https://hackerone.com/reports/301458 | Remote Code Execution in Wordpress Desktop
  2156. https://hackerone.com/reports/301526 | Invitation token leaks to https://bat.bing.com
  2157. https://hackerone.com/reports/301680 | Reflected XSS Vulnerability in https://www.lahitapiola.fi/cs/Satellite
  2158. https://hackerone.com/reports/301718 | https://fundl.qiwi.com CSRF на подтверждении sms
  2159. https://hackerone.com/reports/301862 | Path traversal leading to limited CSRF on GET requests on two endpoints
  2160. https://hackerone.com/reports/301919 | CSRF Add user templates
  2161. https://hackerone.com/reports/302253 | �чень же�тка� XSS в личных �ообщени�х m.ok.ru
  2162. https://hackerone.com/reports/302298 | Unintentional file creation caused at Tempfile with directory traversal
  2163. https://hackerone.com/reports/302338 | The possibility that unintended file operation may be performed because some methods of Dir do not check NULL characters.
  2164. https://hackerone.com/reports/302485 | IDOR allow to extract all registered email
  2165. https://hackerone.com/reports/302651 | Leak of Platform Authentication credentials via Repeater
  2166. https://hackerone.com/reports/302885 | ImageMagick GIF coder vulnerability leading to memory disclosure
  2167. https://hackerone.com/reports/302997 | Unix domain socket and a path containing a null character
  2168. https://hackerone.com/reports/303061 | RCE using bash command injection on /system/images (toimitilat.lahitapiola.fi)
  2169. https://hackerone.com/reports/303378 | SSRF - Blacklist bypass for mail account addition
  2170. https://hackerone.com/reports/303522 | Zomato.com Reflected Cross Site Scripting
  2171. https://hackerone.com/reports/303632 | Fastify denial-of-service vulnerability with large JSON payloads
  2172. https://hackerone.com/reports/303730 | Defacement of catalog.data.gov via web cache poisoning to stored DOMXSS
  2173. https://hackerone.com/reports/303744 | Arbitrary local system file read on open-xchange server
  2174. https://hackerone.com/reports/304098 | [XSS/CSRF] filter content-type bypass in Files
  2175. https://hackerone.com/reports/304240 | Unrestricted access to Eureka server on ██████
  2176. https://hackerone.com/reports/304386 | Unrestricted access to https://██████.█████myteksi.net/
  2177. https://hackerone.com/reports/304679 | XSS ( Работа � пи�ьмами )
  2178. https://hackerone.com/reports/304708 | Information exposure via error pages (www.lahitapiola.fi Tomcat)
  2179. https://hackerone.com/reports/305082 | Query string parameter modifications returned in page
  2180. https://hackerone.com/reports/305128 | ClickJacking on IMPORTANT Functions of Yelp
  2181. https://hackerone.com/reports/305237 | Malicious file upload (secure.lahitapiola.fi)
  2182. https://hackerone.com/reports/305972 | Potential infinite loop in gdImageCreateFromGifCtx!
  2183. https://hackerone.com/reports/305973 | Inappropriately parsing HTTP response leads to PHP segment fault!
  2184. https://hackerone.com/reports/305974 | Inappropriate URL parsing may cause security risk!
  2185. https://hackerone.com/reports/305978 | Urllib connects to a wrong host
  2186. https://hackerone.com/reports/306414 | Window.opener protection Bypass
  2187. https://hackerone.com/reports/307670 | Difference in query string parameter processing between Hacker News and Keybase Chrome extension spawns chat to incorrect user
  2188. https://hackerone.com/reports/307672 | Keybase extension hostname-validation regular expression issue.
  2189. https://hackerone.com/reports/307675 | Claiming ownership of GitHub handles via forked GitHub gists.
  2190. https://hackerone.com/reports/308489 | wpjobmanager - unserialize of user input
  2191. https://hackerone.com/reports/308610 | Read Access to all comments on unauthorized forums' discussions! IDOR!
  2192. https://hackerone.com/reports/309058 | Open Redirect on the nl.wordpress.net
  2193. https://hackerone.com/reports/310105 | Disclosure of 152 cookie names via crafted input
  2194. https://hackerone.com/reports/310185 | Removing a user from a private group doesn't remove him from group's project, if his project's role was changed
  2195. https://hackerone.com/reports/310280 | [Informational] Possible SQL Injection in inc/ajax-actions-frontend.php
  2196. https://hackerone.com/reports/310946 | The request tells the number of private programs, the new system of authorization /invite/token
  2197. https://hackerone.com/reports/311326 | ms5 debug page exposing internal info (internal IPs, headers)
  2198. https://hackerone.com/reports/311330 | Open Redirect
  2199. https://hackerone.com/reports/311639 | Reflected XSS on https://www.zomato.com
  2200. https://hackerone.com/reports/311776 | Securemail server used to internal spam and resource exhaustion
  2201. https://hackerone.com/reports/312118 | Using GitLab to monitor and hijack domains in mass quantity.
  2202. https://hackerone.com/reports/312543 | XXE in Site Audit function exposing file and directory contents
  2203. https://hackerone.com/reports/312548 | XSS via Cookie in e.mail.ru
  2204. https://hackerone.com/reports/312647 | Gaining access to private topics using quoting feature
  2205. https://hackerone.com/reports/313050 | IDOR in treat subscriptions
  2206. https://hackerone.com/reports/313250 | Xss was found by exploiting the URL markdown on http://store.steampowered.com
  2207. https://hackerone.com/reports/314126 | Blind XSS - Report review - Admin panel
  2208. https://hackerone.com/reports/314204 | [XSS] Style/Event Filter Bypass v3.0
  2209. https://hackerone.com/reports/314518 | Reflected XSS+CSRF on secure.lahitapiola.fi
  2210. https://hackerone.com/reports/314808 | Full account takeover
  2211. https://hackerone.com/reports/314814 | [oauth token leak] at oauth.semrush.com
  2212. https://hackerone.com/reports/315205 | Debug information disclosure on oauth-redirector.services.greenhouse.io
  2213. https://hackerone.com/reports/315837 | blind XXE in autodiscover parser
  2214. https://hackerone.com/reports/316319 | XSS on redirection page( Bypassed)
  2215. https://hackerone.com/reports/316713 | Ad Builder Display Ads Path Traversal
  2216. https://hackerone.com/reports/316810 | Can read features from any user
  2217. https://hackerone.com/reports/317005 | Subdomain Takeover due to unclaimed domain pointing to AWS
  2218. https://hackerone.com/reports/317243 | Window.opener fix bypass
  2219. https://hackerone.com/reports/317321 | Delete directory using symlink when decompressing tar
  2220. https://hackerone.com/reports/317476 | Account Takeover in Periscope TV
  2221. https://hackerone.com/reports/317711 | twofactor_auth bypassable if provider fails to load
  2222. https://hackerone.com/reports/317931 | Bypassing Homograph Attack Using /@ [ Tested On Windows ]
  2223. https://hackerone.com/reports/318068 | SSH server compatible with several vulnerable cryptographic algorithms
  2224. https://hackerone.com/reports/318099 | Registration enabled on ███grab.com
  2225. https://hackerone.com/reports/318399 | Program profile_metrics.json contains time to triage for deptofdefense even it's turned off
  2226. https://hackerone.com/reports/318571 | Imformation Disclosure on id.rapida.ru
  2227. https://hackerone.com/reports/318603 | Sitemap causing strain on your Lahitapiola.fi server
  2228. https://hackerone.com/reports/318751 | Access to Private Photos of Apps in App section(IDOR)
  2229. https://hackerone.com/reports/320200 | [NR Alerts/Synthetics?] User with no Synthetics permissions can view synthetic monitor details through /internal_api/ endpoint
  2230. https://hackerone.com/reports/320222 | memory corruption while parsing HTTP response
  2231. https://hackerone.com/reports/320355 | myshopify.com domain takeover
  2232. https://hackerone.com/reports/320376 | Open Redirection in index.php page
  2233. https://hackerone.com/reports/320679 | [growth.grab.com] Reflected XSS via Base64-encoded "q" param on "my.html" Valentine's microsite
  2234. https://hackerone.com/reports/320689 | [NR Synthetics] Restricted user can view synthetics monitors and user permissions through .json endpoint at /permissions/securablemetadata/{GROUP ID}
  2235. https://hackerone.com/reports/321029 | HTML Injection inside Slack promotional emails
  2236. https://hackerone.com/reports/321249 | Forum Users Information Disclosure
  2237. https://hackerone.com/reports/321410 | A user can create an event in a group without being in it http://littleguy.vanillastaging.com/
  2238. https://hackerone.com/reports/321420 | xss reflected in littleguy.vanillastaging.com
  2239. https://hackerone.com/reports/321444 | Fix bypass of different processing of usernames on Hackernews
  2240. https://hackerone.com/reports/321725 | A user can comment in private discussions without having permission to access the discussion
  2241. https://hackerone.com/reports/321938 | [www.zomato.com] Getting a complimentary dessert [Zomato Treats] on ordering a Meal at no cost
  2242. https://hackerone.com/reports/321980 | [XSS/CSRF] filter content-type bypass in Files v2.0
  2243. https://hackerone.com/reports/322661 | Replace other user files in Inbox messages
  2244. https://hackerone.com/reports/322935 | Exim off-by-one RCE vulnerability
  2245. https://hackerone.com/reports/323005 | CSRF leads to a stored self xss
  2246. https://hackerone.com/reports/323975 | CSRF in Inviting users
  2247. https://hackerone.com/reports/324005 | Server-Side Request Forgery on SAML Application - Import via URL
  2248. https://hackerone.com/reports/324006 | SaaS admin can modify/delete/get user information.
  2249. https://hackerone.com/reports/324136 | XSS *.myshopify.com/collections/vendors?q=
  2250. https://hackerone.com/reports/324423 | Reflected XSS (myynti.lahitapiolarahoitus.fi)
  2251. https://hackerone.com/reports/324442 | Reflected XSS on bbe_open_htmleditor_popup.php of BBE Theme via "value"-GET-parameter
  2252. https://hackerone.com/reports/325040 | xmlrpc.php FILE IS enable it will used for bruteforce attack and denial of service
  2253. https://hackerone.com/reports/325336 | Subdomain takeover on svcgatewayus.starbucks.com
  2254. https://hackerone.com/reports/325510 | Stored-XSS with user interaction on [sandbox.open-xchange.com] via inserted link in mail
  2255. https://hackerone.com/reports/326434 | Able to Select Every Poll Option[http://tedwebers-famous-loudspeakers.vanillacommunities.com]
  2256. https://hackerone.com/reports/326639 | DoS through cache poisoning using invalid HTTP parameters
  2257. https://hackerone.com/reports/327088 | Extra program metrics disclosed via /PROGRAM_NAME json response
  2258. https://hackerone.com/reports/327200 | disclosure of email by sending a message.
  2259. https://hackerone.com/reports/327512 | Potential command injection in Shell#[] and Shell#test
  2260. https://hackerone.com/reports/327671 | Error Page Content Spoofing or Text Injection
  2261. https://hackerone.com/reports/327674 | Invitation reminder emails contain insecure links
  2262. https://hackerone.com/reports/328337 | IDOR widget.support.my.com
  2263. https://hackerone.com/reports/328486 | [Zomato Android/iOS] Theft of user session
  2264. https://hackerone.com/reports/329209 | Making further registrations difficult on Vanilla forum
  2265. https://hackerone.com/reports/329791 | Internal IP Address Disclosure at https://www.lahitapiolarahoitus.fi/wp-json/wp/v2/pages
  2266. https://hackerone.com/reports/329798 | h1-202 leaderboard photo discloses local wifi password
  2267. https://hackerone.com/reports/329862 | Stored xss in shop name @ lp.reverb.com
  2268. https://hackerone.com/reports/329957 | Tracking of users on third-party websites using the Twitter cookie, due to a flaw in authenticating image requests
  2269. https://hackerone.com/reports/330008 | [dev.twitter.com] XSS and Open Redirect Protection Bypass
  2270. https://hackerone.com/reports/330135 | S3 bucket unnecessarily discloses permissions
  2271. https://hackerone.com/reports/330716 | F5 BIG-IP Cookie Remote Information Disclosure
  2272. https://hackerone.com/reports/331223 | Order notifications being sent for a deactivated staff account
  2273. https://hackerone.com/reports/331302 | Improper protection of FileContentProvider
  2274. https://hackerone.com/reports/331489 | Extremly simple way to bypass Nextcloud-Client PIN/Fingerprint lock
  2275. https://hackerone.com/reports/331691 | Email Forwarding invitations for Drafts are not marked as accepted, allowing multiple users to join a program after disabling Email Forwarding
  2276. https://hackerone.com/reports/331975 | [XSS] Pasting bootstrap in mail compose
  2277. https://hackerone.com/reports/332381 | Internal API endpoint discloses full account name of email address associated with unconfirmed user
  2278. https://hackerone.com/reports/332632 | (Possible) staff account takeover via reset token bruteforce at helpdesk.bistudio.com
  2279. https://hackerone.com/reports/333008 | Persistent XSS in https://sandbox.reverb.com/item/
  2280. https://hackerone.com/reports/333419 | TURN server allows TCP and UDP proxying to internal network, localhost and meta-data services
  2281. https://hackerone.com/reports/333507 | Stored XSS in "post last edited" option
  2282. https://hackerone.com/reports/333767 | IDOR to view other user folder name
  2283. https://hackerone.com/reports/334139 | CSRF Trial 14 days express subscription
  2284. https://hackerone.com/reports/334143 | [NR Synthetics] Restricted User can add/modify alert conditions on monitors without any synthetics privileges
  2285. https://hackerone.com/reports/334205 | Harvesting all private invites using leave program fast-tracked invitation and security@ email forwarding feature
  2286. https://hackerone.com/reports/334253 | CSRF at [Apply to this program] that lead to submit your request automatic with out any validations
  2287. https://hackerone.com/reports/334488 | Blind XXE via Powerpoint files
  2288. https://hackerone.com/reports/334709 | Cache poisoning using NULL bytes and long URLs
  2289. https://hackerone.com/reports/335123 | Invalid Phabricator API token revealed through error message when escalating a report
  2290. https://hackerone.com/reports/335177 | DoS of www.lahitapiolarahoitus.fi via CVE-2018-6389 exploitation
  2291. https://hackerone.com/reports/335330 | Subdomain Takeover to Authentication bypass
  2292. https://hackerone.com/reports/335341 | Disclosure of Users Information via Wordpress API (?rest_route)
  2293. https://hackerone.com/reports/335427 | WordPress username enumeration (/author)
  2294. https://hackerone.com/reports/335481 | [Zomato's Blog] POST based XSS on https://www.zomato.com/blog/wp-admin/admin-ajax.php?td_theme_name=Newspaper&v=8.2
  2295. https://hackerone.com/reports/335607 | [XSS] select/onchange in TinyMCE via set body
  2296. https://hackerone.com/reports/335735 | Reflected XSS of bbe-child-starter Theme via "value"-GET-parameter
  2297. https://hackerone.com/reports/335779 | User Information Disclosure via Json response
  2298. https://hackerone.com/reports/335990 | Flash-based XSS on mediaelement-flash-audio-ogg.swf of www.lahitapiolarahoitus.fi
  2299. https://hackerone.com/reports/336131 | Potential to abuse pricing errors in saved carts
  2300. https://hackerone.com/reports/337488 | [XSS] Forgot password link
  2301. https://hackerone.com/reports/337680 | burp does not validate the common name of the presented collaborator server certificate
  2302. https://hackerone.com/reports/337986 | CVE-2018-6797: A crafted regular expression can cause a heap buffer write overflow in Perl 5 giving a remote attacker control over bytes written
  2303. https://hackerone.com/reports/339137 | XSS при добавлении в чат пользовател�
  2304. https://hackerone.com/reports/339237 | [web.icq.com] Stored XSS in link when sending message
  2305. https://hackerone.com/reports/339352 | CSRF logs the victim into attacker's account
  2306. https://hackerone.com/reports/339483 | "Bad Protocols Validation" Bypass in "wp_kses_bad_protocol_once" using HTML-encoding without trailing semicolons
  2307. https://hackerone.com/reports/340926 | [XSS] Parameter Theme
  2308. https://hackerone.com/reports/341876 | SSRF in Exchange leads to ROOT access in all instances
  2309. https://hackerone.com/reports/341884 | api.icq.com / возможно�ть при�оединить�� к л�бому чату (даже закрытому).
  2310. https://hackerone.com/reports/341908 | XSS via Direct Message deeplinks
  2311. https://hackerone.com/reports/341925 | invalid handling of redirect_uri at o2.mail.ru/jsapi/button
  2312. https://hackerone.com/reports/342610 | [XSS] Style/Event Filter Bypass v4.0
  2313. https://hackerone.com/reports/342693 | Password reset token leakage via referer
  2314. https://hackerone.com/reports/342976 | Referer in /servlet/TestServlet
  2315. https://hackerone.com/reports/342978 | Team object in GraphQL disclosed total number of whitelisted hackers
  2316. https://hackerone.com/reports/343464 | Team object in GraphQL discloses team group names and permissions
  2317. https://hackerone.com/reports/343752 | lootdog.io XSS
  2318. https://hackerone.com/reports/344035 | Heap Buffer Overflow (READ: 1786) in exif_iif_add_value
  2319. https://hackerone.com/reports/344049 | XSS touch.mail.ru compose Body
  2320. https://hackerone.com/reports/344112 | XSS account.mail.ru in state JSON script
  2321. https://hackerone.com/reports/344145 | [www.zomato.com] IDOR - Gold Subscription Details, Able to view "Membership ID" and "Validity Details" of other Users
  2322. https://hackerone.com/reports/344228 | Stored xss в пере�ланном �ообщении.
  2323. https://hackerone.com/reports/344309 | Adding a new user discloses their full name in the "Users" section of NR Alerts notification channels page
  2324. https://hackerone.com/reports/344468 | User is able to access and create private synthetics locations without upgrading (regression of #276157)
  2325. https://hackerone.com/reports/345152 | Publicly Accessible Datadog link
  2326. https://hackerone.com/reports/346219 | XSS e.mail.ru fixSpecialSymbols
  2327. https://hackerone.com/reports/347282 | Linux kernel: CVE-2017-6074: DCCP double-free vulnerability
  2328. https://hackerone.com/reports/347296 | Docker Registry HTTP API v2 exposed in HTTP without authentication leads to docker images dumping and poisoning
  2329. https://hackerone.com/reports/347439 | [synthetics.newrelic.com] SMTP header injection leads to (mass) arbitrary email sending
  2330. https://hackerone.com/reports/347665 | Permissions leaks the full name of other NR accounts - Regression of #267636
  2331. https://hackerone.com/reports/347693 | Program metrics disclosed response_efficiency_percentage via /program_name json response despite the team decided not to show on their profile
  2332. https://hackerone.com/reports/347748 | Improper session handling on web browsers
  2333. https://hackerone.com/reports/348076 | Stored XSS in Brower name field reflected in two pages
  2334. https://hackerone.com/reports/348443 | Snippet JS template allows attacker to read a user's private snippets
  2335. https://hackerone.com/reports/349291 | IDOR via internal_api "users" endpoint
  2336. https://hackerone.com/reports/350847 | Bypass of request line length limit to DoS via cache poisoning
  2337. https://hackerone.com/reports/351014 | Malformed .BSP Access Violation in CS:GO can lead to Remote Code Execution
  2338. https://hackerone.com/reports/351016 | Malformed Skybox .TGA in Half-Life (GoldSRC) leads to Access Violation
  2339. https://hackerone.com/reports/351106 | resetreportedcount & updatetags doesn't verify appid param
  2340. https://hackerone.com/reports/351171 | Stored XXS @ https://steamcommunity.com/search/users/#text= via Profile Name
  2341. https://hackerone.com/reports/351275 | DOM Based XSS charting_library
  2342. https://hackerone.com/reports/351361 | Administrator can create user without entering high security mode
  2343. https://hackerone.com/reports/351376 | XSS in main search, use class tag to imitate Reverb.com core functionality, create false login window
  2344. https://hackerone.com/reports/351519 | Improper access check by Kit leads to controlling attributes of store & getting analytics by deleted Store member via dual messenger A/C
  2345. https://hackerone.com/reports/351555 | Disclosure of all uploads to Cloudinary via hardcoded api secret in Android app
  2346. https://hackerone.com/reports/352869 | Subdomain Takeover Via Insecure CloudFront Distribution cdn.grab.com
  2347. https://hackerone.com/reports/353293 | XSS in buying and selling pages, can created spoofed content (false login message)
  2348. https://hackerone.com/reports/353310 | People who interviewed for HackerOne security analyst position can be enumerated and their personal email address may be exposed
  2349. https://hackerone.com/reports/353784 | Vanilla SQL Injection Vulnerability
  2350. https://hackerone.com/reports/354650 | [CVE-2018-6913] heap-buffer-overflow in S_pack_rec
  2351. https://hackerone.com/reports/355773 | XSS on support.wordcamp.org in ajax-quote.php
  2352. https://hackerone.com/reports/355859 | CRITICAL-CLICKJACKING at Yelp Reservations Resulting in exposure of victim Private Data (Email info) + Victim Credit Card MissUse.
  2353. https://hackerone.com/reports/356047 | Wordpress Users Disclosure (/wp-json/wp/v2/users/)
  2354. https://hackerone.com/reports/356566 | HackerOne support disclosing report state without checking user identity
  2355. https://hackerone.com/reports/356586 | [XSS] content_disposition=inline in files
  2356. https://hackerone.com/reports/357485 | Hacktivity of a private program visible to banned user if he gets invited to a program by hackbot
  2357. https://hackerone.com/reports/357665 | DoS in Brave browser for iOS
  2358. https://hackerone.com/reports/357929 | Items bought for free due to lacks of quantity controls
  2359. https://hackerone.com/reports/358007 | Compromising the user ID
  2360. https://hackerone.com/reports/358049 | RCE via Print function [Simplenote 1.1.3 - Desktop app]
  2361. https://hackerone.com/reports/358339 | File access control rules not enforced on image files
  2362. https://hackerone.com/reports/358570 | A SQL injection vulnerability in Vanilla
  2363. https://hackerone.com/reports/360171 | Multiple Bugs in api.data.gov/signup endpoint leads to send custom messages to Anyone
  2364. https://hackerone.com/reports/360191 | [account.mail.ru] XSS на �транице удалени� аккаунта через backUrl
  2365. https://hackerone.com/reports/360787 | [account.mail.ru] XSS на �транице во��тановлени� парол�
  2366. https://hackerone.com/reports/360811 | Information Leak - Github - JMS Information
  2367. https://hackerone.com/reports/361287 | DOMXSS in redirect param
  2368. https://hackerone.com/reports/361793 | [SSRF] PDF documentconverterws
  2369. https://hackerone.com/reports/361938 | [XSS] RSS Feed Widget
  2370. https://hackerone.com/reports/361951 | Exploiting JSONP callback on /username/charts.json endpoint leads to information disclosure despite user's privacy settings
  2371. https://hackerone.com/reports/361957 | Unsanitized input in email field
  2372. https://hackerone.com/reports/361960 | Insufficient validation of sides/modifiers quantity
  2373. https://hackerone.com/reports/362129 | XSS https://health.mail.ru/my/ через внешнее им� аккаунта
  2374. https://hackerone.com/reports/363636 | DoS through PeerExplorer
  2375. https://hackerone.com/reports/363971 | Insecure Infrastructure Integrations YML Loading leads to Windows Privilege Escalation
  2376. https://hackerone.com/reports/364843 | OLO Total price manipulation using negative quantities
  2377. https://hackerone.com/reports/364964 | Client DoS due to large DH parameter (CVE-2018-0732)
  2378. https://hackerone.com/reports/365093 | XSS https://agent.postamat.tech/ в профиле + ди�клоз �екретной информации
  2379. https://hackerone.com/reports/365271 | Remote code execution on Basecamp.com
  2380. https://hackerone.com/reports/365504 | Comment restriction in subsection "Workshop" of domain "steamcommunity.com" can be bypassed using IDOR
  2381. https://hackerone.com/reports/365853 | Subdomain Takeover - https://competition.shopify.com/
  2382. https://hackerone.com/reports/367581 | Basic auth details is still work on report ( 351555 )
  2383. https://hackerone.com/reports/367966 | FileUpload Plugin: CSRF (delete all attached files)
  2384. https://hackerone.com/reports/368119 | [engineering.udemy.com] - Subdomain Takeover (ghost.io)
  2385. https://hackerone.com/reports/369086 | URL spoofing in Brave for macOS
  2386. https://hackerone.com/reports/369185 | Unsafe handling of protocol handlers
  2387. https://hackerone.com/reports/369218 | Navigation to restricted origins via "Open in new tab"
  2388. https://hackerone.com/reports/369451 | SSRF in CI after first run
  2389. https://hackerone.com/reports/370094 | Вывод значений переменных Nginx в теле �траницы
  2390. https://hackerone.com/reports/370777 | [affiliates.udemy.com] Wordpress user admin information discloure
  2391. https://hackerone.com/reports/371135 | CVE-2018-12882: heap-use-after-free in PHP 7.2 through 7.2.6, possible 7.2.7
  2392. https://hackerone.com/reports/373721 | URL spoofing using protocol handlers
  2393. https://hackerone.com/reports/374106 | Lack of quarantine meta-attribute for downloaded files leads to GateKeeper bypass
  2394. https://hackerone.com/reports/374737 | Blind SSRF on errors.hackerone.net due to Sentry misconfiguration
  2395. https://hackerone.com/reports/374907 | Root user disclosure in data.gov domain though x-amz-meta-s3cmd-attrs header
  2396. https://hackerone.com/reports/374919 | Content spoofing and potential Cross-Site Scripting vulnerability on www.hackerone.com
  2397. https://hackerone.com/reports/374969 | Navigation to protocol handler URL from the opened page displayed as a request from this page.
  2398. https://hackerone.com/reports/375259 | Cross-origin page stays focused before/after downloading + uninformative modal window for download
  2399. https://hackerone.com/reports/375329 | Local files reading using link[rel="import"]
  2400. https://hackerone.com/reports/375352 | Post Based XSS On Upload Via CK Editor [semrush.com]
  2401. https://hackerone.com/reports/378122 | HackerOne customer submitted sensitive link to VirusTotal, exposing confidential information
  2402. https://hackerone.com/reports/378805 | Navigation to chrome-extension:// origin (internal pages) from the web
  2403. https://hackerone.com/reports/380045 | Stored XSS in the guide's GameplayVersion (www.dota2.com)
  2404. https://hackerone.com/reports/380102 | Missing memory corruption protection on Windows release built
  2405. https://hackerone.com/reports/380158 | svcardproxydevus.starbucks.com Subdomain take over
  2406. https://hackerone.com/reports/380317 | Team object exposes amount of participants in a private program to non-invited users
  2407. https://hackerone.com/reports/380354 | Reflected XSS through multiple inputs in the issue collector on Jira
  2408. https://hackerone.com/reports/380413 | Restricted user can bypass permissions restriction to create NR Alert policies
  2409. https://hackerone.com/reports/380873 | Prototype pollution attack (lodash / constructor.prototype)
  2410. https://hackerone.com/reports/381129 | SSRF in api.slack.com, using slash commands and bypassing the protections.
  2411. https://hackerone.com/reports/381192 | Preview bar: Incomplete message origin validation results in XSS
  2412. https://hackerone.com/reports/381237 | CSRF | Ban or unban users in broadcast's chat
  2413. https://hackerone.com/reports/381356 | Client-Side Race Condition using Marketo, allows sending user to data-protocol in Safari when form without onSuccess is submitted on www.hackerone.com
  2414. https://hackerone.com/reports/382625 | Stored XSS in '' Section and WAF Bypass
  2415. https://hackerone.com/reports/383564 | Subdomain takeover on svcgatewaydevus.starbucks.com and svcgatewayloadus.starbucks.com
  2416. https://hackerone.com/reports/384101 | Go.imgur.com can be used to phish for account information
  2417. https://hackerone.com/reports/384112 | xss - reflected
  2418. https://hackerone.com/reports/384214 | heap-buffer-overflow (READ of size 48) in exif_read_data()
  2419. https://hackerone.com/reports/384477 | Int Overflow lead to Heap OverFlow in exif_thumbnail_extract of exif.c
  2420. https://hackerone.com/reports/384569 | Bypassing the Trusted Link Alert System
  2421. https://hackerone.com/reports/384719 | linkinfo - openbasedir bypass on Windows PHP
  2422. https://hackerone.com/reports/384782 | User Information Disclosure via the REST API - /?_method=GET
  2423. https://hackerone.com/reports/384839 | DoS for HTTP/2 connections by crafted requests (CVE-2018-1333)
  2424. https://hackerone.com/reports/384905 | F5 BigIP Backend Cookie Disclosure
  2425. https://hackerone.com/reports/384962 | jsConnect Plugin: Takeover of existing account
  2426. https://hackerone.com/reports/385145 | Homograph attack on redirect URL (https://chaturbate.com/external_link/?url)
  2427. https://hackerone.com/reports/385239 | Add non-existent room moderator
  2428. https://hackerone.com/reports/385372 | Homograph attack on redirect URL
  2429. https://hackerone.com/reports/385381 | Rate limit missing at room login
  2430. https://hackerone.com/reports/385407 | store xss in calendar via upload filename
  2431. https://hackerone.com/reports/386112 | [allhiphop.vanillacommunities.com] XSS Request-URI
  2432. https://hackerone.com/reports/386116 | CSV Injection with the CSV export feature
  2433. https://hackerone.com/reports/386292 | Bypass of the SSRF protection in Event Subscriptions parameter.
  2434. https://hackerone.com/reports/386334 | CSS Injection on /embed/ via bgcolor parameter leaks user's CSRF token and allows for XSS
  2435. https://hackerone.com/reports/386340 | Reflected XSS on ssl-ccstatic.highwebmedia.com via player.swf
  2436. https://hackerone.com/reports/386556 | [NR Alerts] Internal API exposes Synthetics monitor details to a restricted user without view monitor permissions
  2437. https://hackerone.com/reports/386596 | Email Not Completely Deleted after Deleting an account
  2438. https://hackerone.com/reports/386735 | Login form on non-HTTPS page on http://stream.highwebmedia.com/auth/login/
  2439. https://hackerone.com/reports/386997 | Private program policy page still accessible after user left the program
  2440. https://hackerone.com/reports/387007 | [idp.fr.cloud.gov] Open Redirect
  2441. https://hackerone.com/reports/387250 | OpenSSL::X509::Name Equality Check Does Not Work, Patch included
  2442. https://hackerone.com/reports/387279 | App messaging can be hijacked by third-party websites
  2443. https://hackerone.com/reports/387544 | Admin bar: Incomplete message origin validation results in XSS
  2444. https://hackerone.com/reports/388506 | Stored XSS in Email attachment file name
  2445. https://hackerone.com/reports/388622 | Subdomain takeover on wfmnarptpc.starbucks.com
  2446. https://hackerone.com/reports/388743 | [NR Insights] Data app permissions setting does not fully prevent other users from modifying/changing changing data related to your data app
  2447. https://hackerone.com/reports/389076 | open-url command allows opening unlimited number of tabs pointing to arbitrary URLs
  2448. https://hackerone.com/reports/389108 | Handling of tracking command allows making arbitrary blind requests with user's cookies from Grammarly Extension's origin
  2449. https://hackerone.com/reports/389454 | Backup Source Code Detected
  2450. https://hackerone.com/reports/389592 | [theacademy.upserve.com] Reflected XSS Query-String
  2451. https://hackerone.com/reports/389600 | TeamProfile exposes partially sensitive information through GraphQL
  2452. https://hackerone.com/reports/390013 | Local files reading from the web using brave://
  2453. https://hackerone.com/reports/390362 | Local files reading from the "file://" origin through brave://
  2454. https://hackerone.com/reports/390429 | Reflected XSS on help.steampowered.com
  2455. https://hackerone.com/reports/391385 | Unauthorized Use of Victim Credit Card
  2456. https://hackerone.com/reports/391390 | Stored XSS on activity
  2457. https://hackerone.com/reports/392728 | Possibility to freeze/crash the host system of all Slack Desktop users easily
  2458. https://hackerone.com/reports/394016 | Web Cache Deception Attack (XSS)
  2459. https://hackerone.com/reports/394253 | Validation bypass for queries generated for PostgreSQL
  2460. https://hackerone.com/reports/395729 | socket command allows sending data over WebSockets to arbitrary origins from Grammarly Extension
  2461. https://hackerone.com/reports/395737 | chrome://brave available for navigation in Release build [-> RCE] + navigation to chrome://* using tab_helper ["Open in new tab"]
  2462. https://hackerone.com/reports/396370 | XSS: Group search terms
  2463. https://hackerone.com/reports/396467 | Github Token Leaked publicly for https://github.sc-corp.net
  2464. https://hackerone.com/reports/396493 | Reflected DOM XSS on www.starbucks.co.uk
  2465. https://hackerone.com/reports/396954 | Attacker can add arbitrary data to the blockchain without paying gas
  2466. https://hackerone.com/reports/397031 | Disclosure of top 10 vulnerability types for programs that haven't enabled the Insights feature
  2467. https://hackerone.com/reports/397088 | Stored XSS on buy button
  2468. https://hackerone.com/reports/397130 | Unauthenticated access to Zendesk tickets through athena-flex-production.shopifycloud.com Okta bypass
  2469. https://hackerone.com/reports/397478 | Privilege Escalation via Keybase Helper
  2470. https://hackerone.com/reports/397483 | [NR Infrastructure] Restricted user can update integration provider account name via integrations API
  2471. https://hackerone.com/reports/397508 | Web cache deception attack - expose token information
  2472. https://hackerone.com/reports/397527 | Leaking sensitive information on Github lead full access to all Grab Slack channels
  2473. https://hackerone.com/reports/397545 | Malformed .BMP file in Counter-Strike 1.6 may cause shellcode injection
  2474. https://hackerone.com/reports/398054 | DOM Based XSS in www.hackerone.com via PostMessage
  2475. https://hackerone.com/reports/398316 | CSRF combined with IDOR within Document Converter exposes files
  2476. https://hackerone.com/reports/398797 | DVR default username and password
  2477. https://hackerone.com/reports/398799 | Unauthenticated blind SSRF in OAuth Jira authorization controller
  2478. https://hackerone.com/reports/399174 | Access MoPub Reports Data even after Company removed you from their MoPub Account.
  2479. https://hackerone.com/reports/399382 | XSS in e.mail.ru
  2480. https://hackerone.com/reports/400982 | Open redirect in securegatewayaccess.com / secure.chaturbate.com via prejoin_data parameter
  2481. https://hackerone.com/reports/401483 | [chaturbate.com] - CSRF Vulnerability on image upload
  2482. https://hackerone.com/reports/402362 | RCE due to ImageTragick v2
  2483. https://hackerone.com/reports/402410 | Ра�шифровка в�ех типов шифрованных ID
  2484. https://hackerone.com/reports/402473 | Arbitrary File Download as Shopmanager
  2485. https://hackerone.com/reports/402753 | Stored XSS in Jetpack's Simple Payment Module by Contributors / Authors
  2486. https://hackerone.com/reports/403039 | WooCommerce Blacklist in 'map_meta_cap' leads to Privilege Escalation of Shopmanagers
  2487. https://hackerone.com/reports/403083 | Authenticated Code Execution through Phar deserialization in CSV Importer as Shop manager in WooCommerce
  2488. https://hackerone.com/reports/403402 | Public Jenkins instance with /script enabled
  2489. https://hackerone.com/reports/403417 | Remote Code Execution on www.semrush.com/my_reports on Logo upload
  2490. https://hackerone.com/reports/403602 | Attachments may be hijacked via AppCache+CookieBombing trick (bc3_production_blobs bucket)
  2491. https://hackerone.com/reports/403783 | [www.zomato.com] Tampering with Order Quantity and paying less amount then actual amount, leads to business loss
  2492. https://hackerone.com/reports/404797 | IDOR to delete images from other stores
  2493. https://hackerone.com/reports/405342 | Clickjacking at ylands.com
  2494. https://hackerone.com/reports/406289 | Stored XSS on Broken Themes via filename
  2495. https://hackerone.com/reports/406614 | Resource Consumption DOS on Edgemax v1.10.6
  2496. https://hackerone.com/reports/406704 | XSS @ store.steampowered.com via agecheck path name
  2497. https://hackerone.com/reports/407355 | Subdomain Takeover on demo.greenhouse.io pointing to unbouncepages
  2498. https://hackerone.com/reports/407552 | Vanilla Forums Gdn_Format unserialize() Remote Code Execution Vulnerability
  2499. https://hackerone.com/reports/409370 | Denial of service via cache poisoning
  2500. https://hackerone.com/reports/409395 | Bypass of GitLab CI runner slash fix in YAML validation
  2501. https://hackerone.com/reports/409512 | mod_userdir CRLF injection (CVE-2016-4975)
  2502. https://hackerone.com/reports/409518 | "More on Wikipedia" link disclose "Referrer" and leak window.opener reference for arbitrary websites
  2503. https://hackerone.com/reports/409701 | SSRF in hatchful.shopify.com
  2504. https://hackerone.com/reports/409850 | XSS in steam react chat client
  2505. https://hackerone.com/reports/409973 | Some store settings/data are accessible to "No Access" permission users on GraphQL LiveView operation
  2506. https://hackerone.com/reports/409986 | Improper handling of Chunked data request in sapi_apache2.c leads to Reflected XSS
  2507. https://hackerone.com/reports/410015 | Discrepancy in hacker profile report count may reveal existence of a private program by publishing a report
  2508. https://hackerone.com/reports/410212 | Vanilla Forums Xenforo password splitHash Unserialize Remote Code Execution Vulnerability
  2509. https://hackerone.com/reports/410237 | Vanilla Forums ImportController index file_exists Unserialize Remote Code Execution Vulnerability
  2510. https://hackerone.com/reports/410451 | User login page doesn't implement any form of rate limiting
  2511. https://hackerone.com/reports/410882 | Vanilla Forums domGetImages getimagesize Unserialize Remote Code Execution Vulnerability (critical)
  2512. https://hackerone.com/reports/411075 | Abusing "Report as abuse" functionality to delete any user's post.
  2513. https://hackerone.com/reports/411140 | Vanilla Forums AddonManager getSingleIndex Directory Traversal File Inclusion Remote Code Execution Vulnerability
  2514. https://hackerone.com/reports/411329 | code injection, steam chat client
  2515. https://hackerone.com/reports/411337 | Forget password link not expiring after email change.
  2516. https://hackerone.com/reports/411519 | DNS SRV lookup of file:// sources enables local hijacking of gems
  2517. https://hackerone.com/reports/411679 | View Failed Approval and Pending videos other users
  2518. https://hackerone.com/reports/411690 | Stored xss in address field in billing activity at https://shop.aaf.com/Order/step1/index.cfm
  2519. https://hackerone.com/reports/411723 | Open redirection at https://chaturbate.com/auth/login/
  2520. https://hackerone.com/reports/411822 | Password protected rooms total number of viewers disclosure to unauthorized members
  2521. https://hackerone.com/reports/411865 | Blind SSRF at https://chaturbate.com/notifications/update_push/
  2522. https://hackerone.com/reports/411930 | User with privilege to maintain External Programs can update certain churned HackerOne programs
  2523. https://hackerone.com/reports/412526 | No rate limit in stats api token endpoint
  2524. https://hackerone.com/reports/412988 | Hacker can request mediation for published reports
  2525. https://hackerone.com/reports/413426 | Open redirect on chaturbate.com (tipping/purchase_success)
  2526. https://hackerone.com/reports/413442 | [chatws25.stream.highwebmedia.com] - Reflected XSS in c parameter
  2527. https://hackerone.com/reports/413505 | No rate limit in affiliate statsapi endpoint
  2528. https://hackerone.com/reports/413759 | Race condition at create new Location
  2529. https://hackerone.com/reports/413828 | Persistent XSS via Signatures
  2530. https://hackerone.com/reports/415139 | Reflected xss on theacademy.upserve.com
  2531. https://hackerone.com/reports/415178 | chrome://brave can still be navigated to, leading to RCE
  2532. https://hackerone.com/reports/415238 | [Admin Panel] CSRF to resume/pause runner
  2533. https://hackerone.com/reports/415258 | RCE: DnDing shortcut files to chrome://brave allows loading HTML files in Muon's context
  2534. https://hackerone.com/reports/415272 | Linux Desktop application slack executable does not use pie / no ASLR
  2535. https://hackerone.com/reports/415398 | Chaturbate "/chat_ignore_list/" endpoint does not check for Account status: Disabled before adding Ignore via POST
  2536. https://hackerone.com/reports/415484 | Stored xss
  2537. https://hackerone.com/reports/415622 | PII disclosure -- Past team members & their email ID(personal email) can be viewed by Staff member with no permissions on Partner Dashboard
  2538. https://hackerone.com/reports/415967 | chrome://brave navigation from web
  2539. https://hackerone.com/reports/416040 | Field Day With Protocol Handlers
  2540. https://hackerone.com/reports/416682 | CSRF on change video thumbnail at https://chaturbate.com
  2541. https://hackerone.com/reports/416906 | Missing Rate Limitation at /apps/upload_app/
  2542. https://hackerone.com/reports/416978 | H1514 CSRF in Domain transfer allows adding your domain to other user's account
  2543. https://hackerone.com/reports/416983 | H1514 Removed Staff members who had "Apps" permission can still modify flow app connections
  2544. https://hackerone.com/reports/417170 | Using GraphQL, STAFF with NO explicit permissions on Store can retrieve Shopify Payments Balance.
  2545. https://hackerone.com/reports/417382 | Revoking user session in https://hackerone.com/settings/sessions does not revoke the GraphQL query session
  2546. https://hackerone.com/reports/417839 | H1514 Lack of access control on edit packing slip template
  2547. https://hackerone.com/reports/418145 | No rate limiting in changing room subject.
  2548. https://hackerone.com/reports/418151 | No rate limiting in starting up a bot.
  2549. https://hackerone.com/reports/418254 | Unrestricted POST request size on roomlogin endpoint
  2550. https://hackerone.com/reports/418474 | Disclosing a private program in an external link if program is paused
  2551. https://hackerone.com/reports/418767 | Hacker can bypass 2FA requirement and reporter blacklist through embedded submission form
  2552. https://hackerone.com/reports/418823 | Reflected XSS on developers.zomato.com
  2553. https://hackerone.com/reports/419875 | [NR Alerts/Synthetics] IDOR through /policies.json with Synthetics exposes full name of other NR users
  2554. https://hackerone.com/reports/419883 | H1514 [beerify.shopifycloud.com] GraphQL discloses internal beer consumption
  2555. https://hackerone.com/reports/420115 | Crash in mrb_ary_push
  2556. https://hackerone.com/reports/420459 | H1514 Stored XSS in Return Magic App portal content
  2557. https://hackerone.com/reports/421009 | H1514 Deanonymizing Exchange Marketplace private listings
  2558. https://hackerone.com/reports/421859 | H1514 [*.(my)shopify.com] - Viewing Password Protected Content
  2559. https://hackerone.com/reports/422043 | H1514 DOMXSS on Embedded SDK via Shopify.API.setWindowLocation abusing cookie Stuffing
  2560. https://hackerone.com/reports/422279 | H1514 Simple phishing using auto-created modal with weak URL-pattern check in incontext_app_link
  2561. https://hackerone.com/reports/422331 | attacker can book unlimited tickets in free at https://aaf.com/checkout/order-received/21237/?key=wc_order_5bbef48fa35b2
  2562. https://hackerone.com/reports/422698 | Update Chat Allowed By Option ( without age verification )
  2563. https://hackerone.com/reports/422707 | Reflected XSS on $Any$.myshopify.com/admin
  2564. https://hackerone.com/reports/422944 | H1514 Remote Code Execution on kitcrm using bulk customer update of Priority Products
  2565. https://hackerone.com/reports/423022 | Account takeover at https://try.discourse.org due to no CSRF protection in connecting Yahoo account
  2566. https://hackerone.com/reports/423073 | Improper UUID validation results in bypass of #419896
  2567. https://hackerone.com/reports/423136 | H1514 Session Fixation on multiple shopify-built apps on *.shopifycloud.com and *.shopifyapps.com
  2568. https://hackerone.com/reports/423198 | H1514 Ability to Edit Packaging Slip Templates and View Product & Shipping Information by a low privileged staff in a Sandbox Store
  2569. https://hackerone.com/reports/423218 | H1514 DOM XSS on checkout.shopify.com via postMessage handler on /:id/sandbox/google_maps
  2570. https://hackerone.com/reports/423388 | H1514 Get access to non public information by pivoting with graphql queries
  2571. https://hackerone.com/reports/423454 | H1514 Stored XSS on Wholesale sales channel allows cross-organization data leakage
  2572. https://hackerone.com/reports/423467 | H1514 Ability to MiTM Shopify PoS Session to Takeover Communications
  2573. https://hackerone.com/reports/423496 | H1514 Bypass Wholesale account signup restrictions
  2574. https://hackerone.com/reports/423506 | H1514 Extract information about other sites (new sites) through Affiliate/Referral pages
  2575. https://hackerone.com/reports/423541 | H1514 Server Side Template Injection in Return Magic email templates?
  2576. https://hackerone.com/reports/423546 | H1514 Wholesale customer without checkout permission can complete purchases
  2577. https://hackerone.com/reports/424447 | Integer overflow leading to buffer overflow
  2578. https://hackerone.com/reports/424669 | Subdomain Takeover Via unclaimed Heroku Instance tim-exclusive.shopify.com
  2579. https://hackerone.com/reports/425048 | Stored XSS on chaturbate.com (wish list)
  2580. https://hackerone.com/reports/425200 | XSS [flow] - on www.paypal.com/paypalme/my/landing (requires user interaction)
  2581. https://hackerone.com/reports/425314 | API request signature can be reused with other parameters/data than the original in certain cases
  2582. https://hackerone.com/reports/425719 | Disclosure of Github Issues
  2583. https://hackerone.com/reports/426165 | [www.zomato.com] CORS Misconfiguration, could lead to disclosure of sensitive information
  2584. https://hackerone.com/reports/426547 | Missing Rate Limitation at /photo_videos/photoset/create
  2585. https://hackerone.com/reports/426944 | Linux privilege escalation via trusted $PATH in keybase-redirector
  2586. https://hackerone.com/reports/427502 | Proper verification is not done before sending invitations to researchers for certain private programs with rules e.g. "Participants must be US-based"
  2587. https://hackerone.com/reports/427835 | Server-Side request forgery in New-Subscription feature of the calendar app
  2588. https://hackerone.com/reports/428010 | Talk / spreed: Disclosure of Room names and participants for password protected rooms
  2589. https://hackerone.com/reports/428660 | Gallery: No feedback for invalid password
  2590. https://hackerone.com/reports/429026 | Race condition in performing retest allows duplicated payments
  2591. https://hackerone.com/reports/429298 | Stored XSS in chat topic due to insecure emoticon parsing on any message type
  2592. https://hackerone.com/reports/429617 | Reverse Proxy misroute leading to steal X-Shopify-Access-Token header
  2593. https://hackerone.com/reports/429679 | POST-based XSS on apps.shopify.com
  2594. https://hackerone.com/reports/430463 | Keybase client: downloaded executables lack "com.apple.quarantine" meta-attribute [macOS]
  2595. https://hackerone.com/reports/430854 | Kaspersky Password Manager allows websites to access user's address data
  2596. https://hackerone.com/reports/431561 | Specially constructed multi-part requests cause multi-second response times; vulnerable to DoS
  2597. https://hackerone.com/reports/431633 | Order Creation Webhooks can be edited/deleted by STAFF with Settings only permission
  2598. https://hackerone.com/reports/434116 | Exposing voting results on the Slowvote application without actually voting
  2599. https://hackerone.com/reports/434715 | No session expiry after log-out and session id exposed in URL
  2600. https://hackerone.com/reports/434763 | Incorrect details on OAuth permissions screen allows DMs to be read without permission
  2601. https://hackerone.com/reports/435457 | Ability to login to the Nexus Repo Manager from https://nexus.imgur.com/
  2602. https://hackerone.com/reports/435618 | Kaspersky Password Manager is vulnerable to HTML injection in the browser action pop-up via user name
  2603. https://hackerone.com/reports/435648 | TOTP Key is shorter than RFC 4226 recommended minimum
  2604. https://hackerone.com/reports/436928 | RCE as Admin defeats WordPress hardening and file permissions
  2605. https://hackerone.com/reports/437142 | Instant open redirect on Live preview WEB Ide opening
  2606. https://hackerone.com/reports/437800 | Passive mixed content issues on the site https://*.fanduel.com
  2607. https://hackerone.com/reports/438240 | Reflected Cross site Scripting (XSS) on www.starbucks.com
  2608. https://hackerone.com/reports/439729 | Add and Access to Labels of any Private Projects/Groups of Gitlab(IDOR)
  2609. https://hackerone.com/reports/439828 | Event privacy level does not work in Thunderbird
  2610. https://hackerone.com/reports/439912 | Stored XSS on demo app link
  2611. https://hackerone.com/reports/440749 | [Mail.Ru Android] Typo in permission name allows to write contacts without user knowledge
  2612. https://hackerone.com/reports/442843 | Notifications sent due to "Transfer report" functionality may be sent to users who are no longer authorized to see the report
  2613. https://hackerone.com/reports/446238 | EXIF metadata not stripped from JPG group logos
  2614. https://hackerone.com/reports/446271 | CRLF injection
  2615. https://hackerone.com/reports/446585 | Exfiltrate and mutate repository and project data through injected templated service
  2616. https://hackerone.com/reports/446593 | GitLab's GitHub integration is vulnerable to SSRF vulnerability
  2617. https://hackerone.com/reports/447494 | Share recipient can modify a share's expiration date
  2618. https://hackerone.com/reports/447975 | Upgrade menu exposes the mobile application token meant to only be visible to administrators
  2619. https://hackerone.com/reports/448078 | A user can request a report to be retested even though the program has not been verified by HackerOne
  2620. https://hackerone.com/reports/449351 | IE only: stored Cross-Site Scripting (XSS) vulnerability through Program Asset identifier
  2621. https://hackerone.com/reports/449482 | Command injection in Pathname
  2622. https://hackerone.com/reports/449617 | Null character at fnmatch
  2623. https://hackerone.com/reports/452959 | A user can bypass approval step in Hacker Publishing feature, allowing them to publish reports immediately
  2624. https://hackerone.com/reports/452973 | Inline banner on Report page discloses whether organization runs a private program
  2625. https://hackerone.com/reports/454949 | Race Condition in Flag Submission
  2626. https://hackerone.com/reports/455858 | [p2p.qiwi.com] nginx alias traversal
  2627. https://hackerone.com/reports/456333 | [auth2.zomato.com] Reflected XSS at oauth2/fallbacks/error | ORY Hydra an OAuth 2.0 and OpenID Connect Provider
  2628. https://hackerone.com/reports/456727 | null pointer dereference in imap_mail
  2629. https://hackerone.com/reports/458842 | Malformed save files (.sav) allow to write files with arbitrary extensions and content in GoldSrc-based games.
  2630. https://hackerone.com/reports/459286 | protocol & Ports are not shown in third-party site redirect warning page
  2631. https://hackerone.com/reports/459443 | [NR Insights] IDOR - Modify the filter settings for any NR Insights dashboard through internal_api endpoint
  2632. https://hackerone.com/reports/460428 | The impossibility of inclusion of the trial (BROWSER)
  2633. https://hackerone.com/reports/460815 | Milestones leaked via search API
  2634. https://hackerone.com/reports/460911 | [FG-VD-18-165] Wordpress Cross-Site Scripting Vulnerability Notification II
  2635. https://hackerone.com/reports/460920 | Response program can create bounty table
  2636. https://hackerone.com/reports/461272 | [www.zomato.com] Blind XSS in one of the admin dashboard
  2637. https://hackerone.com/reports/461308 | Remote attacker can impersonate Social users via ActivityPub API
  2638. https://hackerone.com/reports/462321 | Ability to view monitor names of other NR accounts through internal API (v3) via "monitor_id" parameter
  2639. https://hackerone.com/reports/462503 | Claiming package names in GitLab's automatic package referencer.
  2640. https://hackerone.com/reports/463828 | Submitting report through Embedded Submission form gives user indefinite access to a profile
  2641. https://hackerone.com/reports/463915 | URL Advisor component in KIS products family is vulnerable to Universal XSS
  2642. https://hackerone.com/reports/464426 | account takeover https://idea.qiwi.com/
  2643. https://hackerone.com/reports/469372 | Web protection component in Anti-Virus products family uses predictable links for certificate warnings
  2644. https://hackerone.com/reports/469803 | Open redirect at https://inventory.upserve.com/http://google.com/
  2645. https://hackerone.com/reports/470003 | Privilege Escalation via Keybase Helper (incomplete security fix)
  2646. https://hackerone.com/reports/470067 | DoS on the Issue page by exploiting Mermaid.
  2647. https://hackerone.com/reports/470206 | Reflected XSS in *.myshopify.com/account/register
  2648. https://hackerone.com/reports/470398 | Local privilege escalation bug using Keybase redirector on macOS
  2649. https://hackerone.com/reports/470519 | Kaspersky Protection extension for Google Chrome is vulnerable to abuse its features
  2650. https://hackerone.com/reports/470520 | RCE on Steam Client via buffer overflow in Server Info
  2651. https://hackerone.com/reports/470544 | Unauthorized command execution in Web protection component of Anti-Virus products family
  2652. https://hackerone.com/reports/470547 | Unauthorized command execution in Web protection component of Anti-Virus products family [IE]
  2653. https://hackerone.com/reports/470553 | Unauthorized command execution in Web protection component of Anti-Virus products family [FF, Chrome]
  2654. https://hackerone.com/reports/470637 | User-assisted RCE in Slack for macOS (from official site) due to improper quarantine meta-attribute handling for downloaded files
  2655. https://hackerone.com/reports/471265 | unuse domain still in using at wechat by Starbucks East China
  2656. https://hackerone.com/reports/471739 | macOS privilege escalation via keybase install
  2657. https://hackerone.com/reports/472013 | Changing email address on Twitter for Android unsets "Protect your Tweets"
  2658. https://hackerone.com/reports/472026 | The auto login link does not expire on changing email id
  2659. https://hackerone.com/reports/472651 | Private key "tron" leaked via Travis CI Log
  2660. https://hackerone.com/reports/473252 | Privilege Escalation through Keybase Installer via Helper
  2661. https://hackerone.com/reports/473888 | RCE which may occur due to ActiveSupport::MessageVerifier or ActiveSupport::MessageEncryptor (especially Active storage)
  2662. https://hackerone.com/reports/473950 | XSS on Desktop Client
  2663. https://hackerone.com/reports/474262 | XSS due to incomplete JS escaping
  2664. https://hackerone.com/reports/474656 | Cross-site Scripting (XSS) on HackerOne careers page
  2665. https://hackerone.com/reports/475499 | heap buffer overflow in phar_detect_phar_fname_ext
  2666. https://hackerone.com/reports/475660 | Response program can display "eligible for bounty" in scope area in program policy
  2667. https://hackerone.com/reports/476168 | Heap overflow in utf32be_mbc_to_code
  2668. https://hackerone.com/reports/476178 | Negative size parameter in mb_split
  2669. https://hackerone.com/reports/476179 | Buffer over-write in finfo_open with malformed magic file.
  2670. https://hackerone.com/reports/476958 | IDOR allows accounts to view full name of other accounts based on email through share notes feature
  2671. https://hackerone.com/reports/477073 | ZeroMQ libzmq remote code execution
  2672. https://hackerone.com/reports/477222 | Last build status and coverage leaked to unauthorized users
  2673. https://hackerone.com/reports/477344 | Heap Buffer Overflow (READ: 4) in phar_parse_pharfile
  2674. https://hackerone.com/reports/477896 | Use after free and out of bounds read in xmlrpc_decode()
  2675. https://hackerone.com/reports/477897 | buffer overread in base64 code of the xmlrpc module
  2676. https://hackerone.com/reports/478367 | efree() on uninitialized Heap data in imagescale leads to use-after-free
  2677. https://hackerone.com/reports/478368 | imagecolormatch Out Of Bounds Write on Heap
  2678. https://hackerone.com/reports/478957 | Stored XSS/HTML injection in autocomplete suggestions for sharing
  2679. https://hackerone.com/reports/479135 | GET request to accounts.json on support site leaks the root account license key and the browser license key to a restricted user
  2680. https://hackerone.com/reports/479139 | Bypass of #447975 - view mobile application token though "Application Information" sidebar on Installation page
  2681. https://hackerone.com/reports/480778 | Heap-buffer-overflow in Perl__byte_dump_string (utf8.c) could lead to memory leak
  2682. https://hackerone.com/reports/480883 | Stack overflow in XML Parsing
  2683. https://hackerone.com/reports/480928 | Username restriction bypass with SSL client authentication
  2684. https://hackerone.com/reports/480984 | Stack overflow affecting "ext" field on stylers.xml configuration file
  2685. https://hackerone.com/reports/481335 | Security check failure or stack buffer overrun (crash)
  2686. https://hackerone.com/reports/481360 | Stored XSS in vanilla
  2687. https://hackerone.com/reports/481472 | URL link spoofing
  2688. https://hackerone.com/reports/481532 | heap-use-after-free (READ of size 8) in main()
  2689. https://hackerone.com/reports/482200 | puttygen: heap-buffer-overflow in mp_get_decimal()
  2690. https://hackerone.com/reports/483572 | [FG-VD-19-009] Intel(R) Trace Analyzer and Collector 2019 Memory Corruption Vulnerability Notification
  2691. https://hackerone.com/reports/484398 | Buffer overflow in libavi_plugin memmove() call
  2692. https://hackerone.com/reports/484434 | Stored XSS on imgur profile
  2693. https://hackerone.com/reports/484615 | Unsanitized user photo paths allow local file read
  2694. https://hackerone.com/reports/484664 | ICQ for macOS: lack of com.apple.quarantine meta-attribute on downloaded files leads to GateKeeper/Quarantine bypass for downloaded executables
  2695. https://hackerone.com/reports/484930 | puttygen: 160MB memory leak while trying to extract openssh public key from crafted key file
  2696. https://hackerone.com/reports/485407 | From nobody to somebody
  2697. https://hackerone.com/reports/485748 | Stored XSS on reports.
  2698. https://hackerone.com/reports/486629 | Improper validation allows user to unlock Zomato Gold multiple times at the same restaurant within one day
  2699. https://hackerone.com/reports/487008 | Arbitrary file read via ffmpeg HLS parser at https://www.flickr.com/photos/upload
  2700. https://hackerone.com/reports/487081 | Stored XSS in Private Message component (BuddyPress)
  2701. https://hackerone.com/reports/488643 | Disclosure of h1 challenges name through the calendar
  2702. https://hackerone.com/reports/488923 | No Rate Limit on CrowdSignal Polls when Adding Comment
  2703. https://hackerone.com/reports/488985 | Race condition in claiming program credentials
  2704. https://hackerone.com/reports/489102 | VLC 4.0.0 - Stack Buffer Overflow (SEH)
  2705. https://hackerone.com/reports/489146 | Confidential data of users and limited metadata of programs and reports accessible via GraphQL
  2706. https://hackerone.com/reports/489284 | Access to Employee calendar disclosing internal presentation and meetings
  2707. https://hackerone.com/reports/490782 | Mssing Authorization on Private Message replies (BuddyPress)
  2708. https://hackerone.com/reports/490946 | Bypassing lock protection
  2709. https://hackerone.com/reports/490960 | macOS privilege escalation
  2710. https://hackerone.com/reports/491023 | XSS Reflected on my_report
  2711. https://hackerone.com/reports/491473 | Protected tweets exposure through the URL
  2712. https://hackerone.com/reports/491753 | DMARC RECORD MISSING
  2713. https://hackerone.com/reports/492512 | [bower] Arbitrary File Write through improper validation of symlinks while package extraction
  2714. https://hackerone.com/reports/492841 | Web cache poisoning attack leads to user information and more
  2715. https://hackerone.com/reports/493324 | Privilege escalation from any user (including external) to gitlab admin when admin impersonates you
  2716. https://hackerone.com/reports/494979 | Insufficient sanitizing can lead to arbitrary commands execution
  2717. https://hackerone.com/reports/495382 | No SearchEngine sanatizing can lead to command injection
  2718. https://hackerone.com/reports/495495 | CVE-2019-5736: Escape from Docker and Kubernetes containers to root on host
  2719. https://hackerone.com/reports/495497 | Know whether private project name exists or not within a group using link comments
  2720. https://hackerone.com/reports/495508 | Assertion `len == 1' failed, process aborted while streaming ouput from remote server
  2721. https://hackerone.com/reports/495515 | Reflected XSS: Taxonomy Converter via tax parameter
  2722. https://hackerone.com/reports/495525 | XSSI: Quick Navigation Interface - leak of private page/post titles
  2723. https://hackerone.com/reports/495583 | [FG-VD-19-022] Wordpress WooCommerce Cross-Site Scripting Vulnerability Notification
  2724. https://hackerone.com/reports/495793 | Malformed .MDL triggers an Access Violation on GoldSRC (hl.exe)
  2725. https://hackerone.com/reports/496113 | Crash
  2726. https://hackerone.com/reports/496285 | Ubuntu Linux privilege escalation (dirty_sock)
  2727. https://hackerone.com/reports/496375 | Reflected XSS in https://www.starbucks.co.jp/store/search/
  2728. https://hackerone.com/reports/496405 | Stored XSS in vanilla
  2729. https://hackerone.com/reports/496973 | Persistent XSS via e-mail when creating merge requests
  2730. https://hackerone.com/reports/497047 | Blocked user Git access through CI/CD token
  2731. https://hackerone.com/reports/497255 | A stack buffer overflow in BabyGrid.cpp can lead to program crashes via a malicious localization file
  2732. https://hackerone.com/reports/497312 | Command injection by setting a custom search engine
  2733. https://hackerone.com/reports/497724 | Stored XSS in Post Preview as Contributor
  2734. https://hackerone.com/reports/498052 | Password theft login.newrelic.com via Request Smuggling
  2735. https://hackerone.com/reports/498964 | Full access to internal Gitlab instances at redash.gitlab.com, dashboards.gitlab.com, prometheus.gitlab.com
  2736. https://hackerone.com/reports/499030 | DOM Based XSS in www.hackerone.com via PostMessage (bypass of #398054)
  2737. https://hackerone.com/reports/499348 | Twitter lite(Android): Vulnerable to local file steal, Javascript injection, Open redirect
  2738. https://hackerone.com/reports/500348 | URL filter bypass in Enterprise Grid
  2739. https://hackerone.com/reports/500436 | DOM based CSS Injection on grammarly.com
  2740. https://hackerone.com/reports/500515 | XXE at ecjobs.starbucks.com.cn/retail/hxpublic_v6/hxdynamicpage6.aspx
  2741. https://hackerone.com/reports/500686 | url that twitter mobile site can not load
  2742. https://hackerone.com/reports/501672 | Restricted user can view all account invoices, payment method details, PII of account owner through zoura_api endpoints
  2743. https://hackerone.com/reports/502593 | Attacker is able to access commit title and team member comments which are supposed to be private
  2744. https://hackerone.com/reports/502816 | Access Violation Reading in libfaad_plugin
  2745. https://hackerone.com/reports/503208 | Access Violation Reading EXPLOITABLE_0228
  2746. https://hackerone.com/reports/503283 | Real Time Error Logs Through Debug Information
  2747. https://hackerone.com/reports/503298 | Multiple XSS on account settings that can hijack any users in the company.
  2748. https://hackerone.com/reports/503300 | █████████ on CRM server without authorization
  2749. https://hackerone.com/reports/503804 | Path Disclosure Vulnerability http://crm.******.com
  2750. https://hackerone.com/reports/503821 | Assertion `col >= 0 && col < line->cols' failed, process aborted while streaming ouput from remote server
  2751. https://hackerone.com/reports/504751 | Open Redirect
  2752. https://hackerone.com/reports/504759 | Uploading large avatar images cause excessive CPU usage
  2753. https://hackerone.com/reports/504761 | phar_tar_writeheaders_int() buffer overflow
  2754. https://hackerone.com/reports/504782 | CSRF at adding new role (user-management.service.newrelic.com)
  2755. https://hackerone.com/reports/504951 | Malformed playlist.txt in GoldSrc games leads to Access Violation & arbitrary code execution
  2756. https://hackerone.com/reports/505007 | [Twitter Open Source] Releases were & are built/executed/tested/released in the context of insecure/untrusted code
  2757. https://hackerone.com/reports/505173 | Malformed map detailed texture files in GoldSrc games lead to Remote Code Execution
  2758. https://hackerone.com/reports/505278 | DOS in stream filters
  2759. https://hackerone.com/reports/505424 | Twitter ID exposure via error-based side-channel attack
  2760. https://hackerone.com/reports/506040 | ChaCha20-Poly1305 with long nonces
  2761. https://hackerone.com/reports/506161 | Build fetches jars over HTTP
  2762. https://hackerone.com/reports/506646 | Webshell via File Upload on ecjobs.starbucks.com.cn
  2763. https://hackerone.com/reports/507012 | bypass Claudflare access crm.mautic.com
  2764. https://hackerone.com/reports/507097 | Open AWS S3 bucket leaks all Images uploaded to Zomato chat
  2765. https://hackerone.com/reports/507132 | Stored XSS in notes (charts) because of insecure chart data JSON generation
  2766. https://hackerone.com/reports/507139 | DOM based XSS in the WooCommerce plugin
  2767. https://hackerone.com/reports/507172 | Able to bypass "Device credentials" Lock
  2768. https://hackerone.com/reports/507525 | DoS attacks utilizing camo.stream.highwebmedia.com
  2769. https://hackerone.com/reports/507957 | Stored XSS on www.starbucks.com.sg/careers/career-center/career-landing-*
  2770. https://hackerone.com/reports/508184 | Persistent XSS in Note objects
  2771. https://hackerone.com/reports/508459 | SSRF in webhooks leads to AWS private keys disclosure
  2772. https://hackerone.com/reports/508490 | Nextcloud domain and name of every user leaked to lookup server
  2773. https://hackerone.com/reports/508493 | Group admins can remove arbitrary data from "data" directory (including admin data)
  2774. https://hackerone.com/reports/509574 | Invited team member can disclosure slack channels
  2775. https://hackerone.com/reports/509924 | JSON serialization of any Project model results in all Runner tokens being exposed through Quick Actions
  2776. https://hackerone.com/reports/509930 | Potential unprivileged Stored XSS through wp_targeted_link_rel
  2777. https://hackerone.com/reports/510025 | Invalid Read on exif_process_SOFn
  2778. https://hackerone.com/reports/510336 | Uninitialized read in exif_process_IFD_in_TIFF
  2779. https://hackerone.com/reports/510887 | [CVE-2018-18312] regcomp: heap-buffer-overflow write / reg_node overrun
  2780. https://hackerone.com/reports/510888 | [CVE-2018-18313] regcomp: heap-buffer-overflow read in S_grok_bslash_N
  2781. https://hackerone.com/reports/511044 | [www.zomato.com] Availing Zomato Gold membership for free by tampering plan id(s)
  2782. https://hackerone.com/reports/511381 | All functions that allow users to specify color code are vulnerable to ReDoS
  2783. https://hackerone.com/reports/511440 | credentials leakage in public lead to view dev websites
  2784. https://hackerone.com/reports/512102 | CSRF at acknowledging an incident
  2785. https://hackerone.com/reports/513154 | Unchecked weapon id in WeaponList message parser on client leads to RCE
  2786. https://hackerone.com/reports/514224 | SSRF in Search.gov via ?url= parameter
  2787. https://hackerone.com/reports/514451 | Deprecated Hacker101 coursework repository mentions Heroku App that is susceptible to takeover
  2788. https://hackerone.com/reports/514897 | Possible to enumerate Addresses of users using AddressId and guessing the delivery_subzone
  2789. https://hackerone.com/reports/515484 | [Reflected XSS] In Request URL
  2790. https://hackerone.com/reports/515574 | Unclaimed Github Repository Takeover on https://www.data.gov/labs
  2791. https://hackerone.com/reports/516237 | Uninitialized read in exif_process_IFD_in_MAKERNOTE
  2792. https://hackerone.com/reports/518669 | SQLi allow query restriction bypass on exposed FileContentProvider
  2793. https://hackerone.com/reports/519059 | Protected Tweets setting overridden by Android app
  2794. https://hackerone.com/reports/519220 | File writing by Directory traversal at actionpack-page_caching and RCE by it
  2795. https://hackerone.com/reports/519367 | Attacker can read password from log data
  2796. https://hackerone.com/reports/520518 | Full name of other accounts exposed through NR API Explorer (another workaround of #476958)
  2797. https://hackerone.com/reports/520630 | (Prerelease UI) Stored XSS via role name in JSON chart
  2798. https://hackerone.com/reports/520717 | Old WebKit HTML agent in Template Preview function has multiple known vulnerabilities leading to RCE
  2799. https://hackerone.com/reports/520903 | Apache HTTP [2.4.17-2.4.38] Local Root Privilege Escalation
  2800. https://hackerone.com/reports/526265 | DOM XSS on app.starbucks.com via ReturnUrl
  2801. https://hackerone.com/reports/526325 | Stored XSS in Wiki pages
  2802. https://hackerone.com/reports/526570 | Bypassing push rules via MRs created by Email
  2803. https://hackerone.com/reports/527042 | CVE-2019-0196: mod_http2 with scoreboard Use-After-Free (Read)
  2804. https://hackerone.com/reports/528940 | STAFF member with NO Explicit permissions can view ActivityFeed via GraphQL
  2805. https://hackerone.com/reports/530458 | Stored XSS in Rich editor via Embed datetime
  2806. https://hackerone.com/reports/530464 | Stored XSS in Profile Comments
  2807. https://hackerone.com/reports/530499 | WooCommerce: Persistent XSS via customer address (state/county)
  2808. https://hackerone.com/reports/530511 | Stored XSS at APM applications listing
  2809. https://hackerone.com/reports/530853 | Stored XSS in embedded posts containing images
  2810. https://hackerone.com/reports/530871 | Stored XSS firing if the error occurs when trying to delete the APM app
  2811. https://hackerone.com/reports/530881 | Hidden Stored XSS in nested post embeds
  2812. https://hackerone.com/reports/530974 | Server-Side Request Forgery using Javascript allows to exfill data from Google Metadata
  2813. https://hackerone.com/reports/531032 | Slack DTLS uses a private key that is in the public domain, which may lead to SRTP stream hijack
  2814. https://hackerone.com/reports/531042 | Reflected XSS in https://www.starbucks.com/account/create/redeem/MCP131XSR via xtl_amount, xtl_coupon_code, xtl_amount_type parameters
  2815. https://hackerone.com/reports/532667 | Server Side JavaScript Code Injection
  2816. https://hackerone.com/reports/534450 | Account takeover through the combination of cookie manipulation and XSS
  2817. https://hackerone.com/reports/534541 | Combination of content provider allows private data disclosure
  2818. https://hackerone.com/reports/534554 | Unpublished Product Images can be disclosed
  2819. https://hackerone.com/reports/534711 | Stored XSS at APM apps labels autocomplete dropdown (apps listing)
  2820. https://hackerone.com/reports/534794 | Importing GitLab project archives can replace uploads of other users
  2821. https://hackerone.com/reports/534908 | CSRF at https://chatstory.pixiv.net/imported
  2822. https://hackerone.com/reports/535827 | Buffer overflow in yywarning_s
  2823. https://hackerone.com/reports/536669 | "Test target" of the "HTTP target" extension can unintentionally send username and password in the Authorization header
  2824. https://hackerone.com/reports/536853 | Unreleased CTF Levels are Revealed on /group/user/ID1?user=USERID endpoint
  2825. https://hackerone.com/reports/537550 | Memory corruption in imap-parser.c
  2826. https://hackerone.com/reports/538008 | Add users to groups who have restricted group invites
  2827. https://hackerone.com/reports/540301 | Wordpress VIP leaks email of the test a/c
  2828. https://hackerone.com/reports/540711 | Access Projects And create projects in gitlab pre production server
  2829. https://hackerone.com/reports/541020 | GetGlobalAchievementPercentagesForApp is missing the same release checks as GetSchemaForGame
  2830. https://hackerone.com/reports/541169 | GitLab::UrlBlocker validation bypass leading to full Server Side Request Forgery
  2831. https://hackerone.com/reports/541606 | [Privilege Escalation] Shopify Admin -- Permission from Settings to Customer
  2832. https://hackerone.com/reports/541862 | Open redirect protection (https://www.pixiv.net/jump.php) is broken for novels
  2833. https://hackerone.com/reports/542180 | Malformed NAV file leads to buffer overflow and code execution in Left4Dead2.exe
  2834. https://hackerone.com/reports/544329 | IDOR and statistics leakage in Orders
  2835. https://hackerone.com/reports/544928 | Privilege Escalation From user to SYSTEM via unauthenticated command execution
  2836. https://hackerone.com/reports/546644 | Two heap use-after-free errors in IMAP operations
  2837. https://hackerone.com/reports/547630 | An integer overflow found in /lib/urlapi.c
  2838. https://hackerone.com/reports/549040 | Clientside resource Exhausting by exploiting gitlab math rendering
  2839. https://hackerone.com/reports/549084 | Stored XSS firing at transaction map (applicationName field)
  2840. https://hackerone.com/reports/549364 | Account recovery text message is sending a wrong domain to users.
  2841. https://hackerone.com/reports/549831 | External Storage - WebDAV - New user has access to storage from deleted user (same user-ID)
  2842. https://hackerone.com/reports/550696 | Heap Buffer Overflow at lib/tftp.c
  2843. https://hackerone.com/reports/550937 | Insufficient DKIM record with RSA 512-bit key used on WordPress.com
  2844. https://hackerone.com/reports/557154 | DoS attack via comment on Issue
  2845. https://hackerone.com/reports/563268 | Spoofing the redirect process using RTLO
  2846. https://hackerone.com/reports/564196 | help.shopify.com Cross Site Scripting
  2847. https://hackerone.com/reports/565736 | View HackerOne challenge scope before challenge begins
  2848. https://hackerone.com/reports/565883 | Bypass Email Verification -- Able to Access Internal Gitlab Services that use Login with Gitlab and Perform Check on email domain
  2849. https://hackerone.com/reports/566400 | Stored XSS firing at the "Add chart to note" popup
  2850. https://hackerone.com/reports/567468 | Stored XSS at APM key transactions list
  2851. https://hackerone.com/reports/568832 | No rate limit on app.crowdsignal.com (Finish quiz)
  2852. https://hackerone.com/reports/574639 | Reports Modal in app.mopub.com Disclose by any user
  2853. https://hackerone.com/reports/574962 | Verify any unused email address
  2854. https://hackerone.com/reports/575562 | Blind Stored XSS on iOS App due to Unsanitized Webview
  2855. https://hackerone.com/reports/576288 | Testnet address being sent in cleartext as http://rinkeby.chain.link/ is missing SSL certificate
  2856. https://hackerone.com/reports/576532 | DOM XSS via Shopify.API.remoteRedirect
  2857. https://hackerone.com/reports/577920 | login csrf in analytics.mopub.com
  2858. https://hackerone.com/reports/578119 | Privilege escalation due to insecure use of logrotate
  2859. https://hackerone.com/reports/582349 | Last pipeline status for MR leaked
  2860. https://hackerone.com/reports/583819 | cookie injection allow dos attack to periscope.tv
  2861. https://hackerone.com/reports/583987 | Periscope android app deeplink leads to CSRF in follow action
  2862. https://hackerone.com/reports/587829 | CSTI at Plugin page leading to active stored XSS (Publisher name)
  2863. https://hackerone.com/reports/587854 | Local files could be overwritten in GitLab, leading to remote command execution
  2864. https://hackerone.com/reports/587910 | Password not checked when disabling 2FA on HackerOne
  2865. https://hackerone.com/reports/588562 | Memory Leak in OCUtil.dll library in Desktop client can lead to DoS
  2866. https://hackerone.com/reports/590020 | CRLF Injection in urllib
  2867. https://hackerone.com/reports/590319 | Linux client is vulnerable to directory traversal when downloading files
  2868. https://hackerone.com/reports/591295 | Potential pre-auth RCE on Twitter VPN
  2869. https://hackerone.com/reports/591302 | Denial of service to WP-JSON API by cache poisoning the CORS allow origin header
  2870. https://hackerone.com/reports/591432 | Twitter Periscope Clickjacking Vulnerability
  2871. https://hackerone.com/reports/591786 | XSS on services.shopify.com
  2872. https://hackerone.com/reports/592090 | IDOR in sending support email upon Verifying user business domain
  2873. https://hackerone.com/reports/592316 | Stored XSS on byddypress Plug-in via groups name
  2874. https://hackerone.com/reports/592803 | Gaining unlimited bonus points on websites with WooCommerce Points and Rewards
  2875. https://hackerone.com/reports/592885 | multiple vulnerabilities on your mautic server
  2876. https://hackerone.com/reports/593229 | Out-of-bounds read in iconv.c:_php_iconv_mime_decode() due to integer overflow
  2877. https://hackerone.com/reports/593712 | Web cache deception attack on https://open.vanillaforums.com/messages/all
  2878. https://hackerone.com/reports/593893 | CSRF in generating developer api_key
  2879. https://hackerone.com/reports/602527 | Urgent! Stored XSS at plugin's violations leading to account takeover
  2880. https://hackerone.com/reports/602767 | DOM XSS via Shopify.API.Modal.initialize
  2881. https://hackerone.com/reports/603764 | DOM Based XSS via postMessage at https://inventory.upserve.com/login/
  2882. https://hackerone.com/reports/604534 | Race Condition leads to undeletable group member
  2883. https://hackerone.com/reports/604560 | �бход коми��ии на переводы
  2884. https://hackerone.com/reports/605608 | [information disclosure] Validate existence of a private project.
  2885. https://hackerone.com/reports/605720 | Team member with Program permission only can escalate to Admin permission
  2886. https://hackerone.com/reports/605845 | Stored admin-to-owner XSS at infrastructure alerts runbook URL leading to account takeover by malicious admin
  2887. https://hackerone.com/reports/605915 | Reflected XSS / Markup Injection in index.php/svg/core/logo/logo parameter color
  2888. https://hackerone.com/reports/608577 | Windows Privilege Escalation: Malicious OpenSSL Engine
  2889. https://hackerone.com/reports/608656 | Disabled account can still use GraphQL endpoint
  2890. https://hackerone.com/reports/612231 | Github Token Leaked publicly for https://github.com/mopub
  2891. https://hackerone.com/reports/614355 | GraphQL query "namespace" leaks data
  2892. https://hackerone.com/reports/614947 | Site-wide clickjacking at IE11
  2893. https://hackerone.com/reports/615840 | Blind Stored XSS In "Report a Problem" on www.data.gov/issue/
  2894. https://hackerone.com/reports/617896 | Bypass Email Verification using Salesforce -- Reproducible in gitlab.com
  2895. https://hackerone.com/reports/618031 | Stored XSS in Discounts section
  2896. https://hackerone.com/reports/619484 | User with read-only access to a share can gain write access to sub-folders in the share
  2897. https://hackerone.com/reports/621308 | NULL pointer dereference in mrb_check_frozen
  2898. https://hackerone.com/reports/622170 | Arbitrary code execution in desktop client via OpenSSL config
  2899. https://hackerone.com/reports/623588 | Uninitialized read in gdImageCreateFromXbm
  2900. https://hackerone.com/reports/625546 | Open Redirection leads to redirect Users to malicious website
  2901. https://hackerone.com/reports/626082 | Stored XSS via "my recent queries" selector in NRQL dashboard builder
  2902. https://hackerone.com/reports/629087 | No Valid SPF Records.
  2903. https://hackerone.com/reports/629745 | Reflected cross-site scripting on multiple Starbucks assets.
  2904. https://hackerone.com/reports/629892 | Lack of CSRF header validation at https://g-mail.grammarly.com/profile
  2905. https://hackerone.com/reports/630462 | Heap overflow happen when receiving short length key from ssh server using ssh protocol 1
  2906. https://hackerone.com/reports/631227 | Some HTML Tags are Getting Executed in com.nextcloud.client
  2907. https://hackerone.com/reports/631956 | Panorama UI XSS leads to Remote Code Execution via Kick/Disconnect Message
  2908. https://hackerone.com/reports/632017 | Self-Stored XSS - Chained with login/logout CSRF
  2909. https://hackerone.com/reports/632101 | Server Side Request Forgery mitigation bypass
  2910. https://hackerone.com/reports/633001 | Private System Note Disclosure using GraphQL
  2911. https://hackerone.com/reports/633231 | pre-auth Stored XSS in comments via javascript: url when administrator edits user supplied comment
  2912. https://hackerone.com/reports/633245 | Delete permission can be added on reshare
  2913. https://hackerone.com/reports/633266 | Code injection in macOS Desktop Client
  2914. https://hackerone.com/reports/633607 | Invalid read in str_replace_partial
  2915. https://hackerone.com/reports/634488 | Broken Authentication and Session Management Flaw After Change Password and Logout
  2916. https://hackerone.com/reports/634692 | Stored XSS Via NRQL chartbuilder JSON view
  2917. https://hackerone.com/reports/635597 | Wrong Interpretation of URL encoded characters, showing different punny code leads to redirection on different domain
  2918. https://hackerone.com/reports/636560 | Project Milestones Disclosed Via Groups When the Victim disabled milestones access in project settings
  2919. https://hackerone.com/reports/637194 | Bypass of biometrics security functionality is possible in Android application (com.shopify.mobile)
  2920. https://hackerone.com/reports/638401 | Private Key exposed in Travis Log can Compromise all the test servers.
  2921. https://hackerone.com/reports/638685 | Restricted user can add and delete tags of APM key transactions
  2922. https://hackerone.com/reports/640488 | Total bounties paid amount is disclosed because of redesign of the Program Profiles
  2923. https://hackerone.com/reports/642281 | Stored XSS in https://app.mopub.com
  2924. https://hackerone.com/reports/642515 | User can delete data in shared folders he's not autorized to access
  2925. https://hackerone.com/reports/643274 | Viral Direct Message Clickjacking via link truncation leading to capture of both Google credentials & installation of malicious 3rd party Twitter App
  2926. https://hackerone.com/reports/643622 | SSRF In Get Video Contents
  2927. https://hackerone.com/reports/643882 | Developper's websites are easily accessibles leading to massive information disclosure
  2928. https://hackerone.com/reports/643908 | Stored XSS Vulnerability
  2929. https://hackerone.com/reports/645264 | Program Email Nofication settings ignored when being added as an external contributor
  2930. https://hackerone.com/reports/646505 | ██████ DOM XSS via Shopify.API.remoteRedirect
  2931. https://hackerone.com/reports/647130 | Stored XSS in "Create Groups"
  2932. https://hackerone.com/reports/649533 | Enable 2FA without verifying the email
  2933. https://hackerone.com/reports/651518 | OS Command Injection via egrep in Rake::FileList
  2934. https://hackerone.com/reports/653125 | Git flag injection leading to file overwrite and potential remote code execution
  2935. https://hackerone.com/reports/654198 | Manipulate hacker profile and private program hacktivity to expose your name as researchers who is actively submitting reports with resolve status
  2936. https://hackerone.com/reports/658013 | Git flag injection - local file overwrite to remote code execution
  2937. https://hackerone.com/reports/659419 | Reflected XSS on https://make.wordpress.org via 'channel' parameter
  2938. https://hackerone.com/reports/661051 | Message Authentication Codes calculated by the Default Encryption Module allow an attacker to silently overwrite blocks in a file
  2939. https://hackerone.com/reports/661722 | WEBrick::HTTPAuth::DigestAuth authentication is vulnerable to regular expression denial of service (ReDoS)
  2940. https://hackerone.com/reports/661751 | Subdomain takeover of d02-1-ag.productioncontroller.starbucks.com
  2941. https://hackerone.com/reports/661978 | IDOR bug to See hidden slowvote of any user even when you dont have access right
  2942. https://hackerone.com/reports/662083 | Inject page in admin panel via Shopify.API.pushState
  2943. https://hackerone.com/reports/662204 | Persistent XSS via filename in projects
  2944. https://hackerone.com/reports/662218 | Talk - Leak of password-protected room name via already existent resource addition
  2945. https://hackerone.com/reports/662287 | Cross-site Scripting (XSS) - Stored in RDoc wiki pages
  2946. https://hackerone.com/reports/663729 | [Brave browser] WebTorrent has DNS rebinding vulnerability
  2947. https://hackerone.com/reports/664038 | protected Tweet settings overwritten by other settings
  2948. https://hackerone.com/reports/665330 | Out of Bounds Memory Read in php_jpg_get16
  2949. https://hackerone.com/reports/665398 | Subdomain takeover of datacafe-cert.starbucks.com
  2950. https://hackerone.com/reports/665651 | Stealing Users OAuth Tokens through redirect_uri parameter
  2951. https://hackerone.com/reports/665722 | “email� MFA mode allows bypassing MFA from victim’s device when the device trust is not expired
  2952. https://hackerone.com/reports/665798 | Earn free DAI interest (inflation) through instant CDP+DSR in one tx
  2953. https://hackerone.com/reports/666632 | Delete direct message history without access the proper conversation_id
  2954. https://hackerone.com/reports/666722 | Email enumeration at SignUp page
  2955. https://hackerone.com/reports/667188 | Stored Self XSS on https://app.crowdsignal.com (in Photo Insert App) + Stored XSS on https://your-subdomain.survey.fm
  2956. https://hackerone.com/reports/667408 | Head pipeline leaked to unauthorized users via blocking merge request feature
  2957. https://hackerone.com/reports/667739 | Previously created sessions continue being valid after MFA activation
  2958. https://hackerone.com/reports/667770 | Stored XSS at APM transaction map (transactionName field)
  2959. https://hackerone.com/reports/668439 | IDOR leading to downloading of any attachment
  2960. https://hackerone.com/reports/669438 | [Bypass #645264] Report title disclosure despite the program settings for email notification is set to "No Content"
  2961. https://hackerone.com/reports/669776 | Disclosure of Program email Title Report when being removed as contributor. Bypass for Report #645264
  2962. https://hackerone.com/reports/670572 | Uncontrolled Resource Consumption in any Markdown field using Mermaid
  2963. https://hackerone.com/reports/672245 | Use After Free in GC with Certain Destructors
  2964. https://hackerone.com/reports/672487 | Business Logic Flaw - A non premium user can change/update retailers to get cashback on all the retailers associated with Curve
  2965. https://hackerone.com/reports/672623 | Username and Access Token Disclousure
  2966. https://hackerone.com/reports/672664 | Steal collateral during end process, by earning DSR interest after flow.
  2967. https://hackerone.com/reports/673724 | Circle email-members have still access to a shared folder/file after they are removed from the circle
  2968. https://hackerone.com/reports/674195 | Stealing data from customers.gitlab.com without user interaction
  2969. https://hackerone.com/reports/674426 | XSS For Profile Name
  2970. https://hackerone.com/reports/674540 | mod_remoteip stack buffer overflow and NULL pointer dereference
  2971. https://hackerone.com/reports/674757 | Total Paid Bounty Paid can be disclose
  2972. https://hackerone.com/reports/674774 | AppLovin API Key hardcoded in a Github repo
  2973. https://hackerone.com/reports/674866 | Conversation API Leaks Details Of UnAuthorized Conversations
  2974. https://hackerone.com/reports/675578 | Out of Bounds Memory Read in exif_scan_thumbnail
  2975. https://hackerone.com/reports/675580 | Out of Bounds Memory Read in exif_process_user_comment
  2976. https://hackerone.com/reports/676581 | Use Github pack with Coda employee github account (search code of Coda's private repositories)
  2977. https://hackerone.com/reports/676976 | Container scanning and Dependency scanning report leaked to unauthorized users
  2978. https://hackerone.com/reports/677557 | mod_http2, memory corruption on early pushes (CVE-2019-10081)
  2979. https://hackerone.com/reports/679907 | Malformed string sent through FireServer leads to server freezing/hanging
  2980. https://hackerone.com/reports/679969 | CSS Injection to disable app & potential message exfil
  2981. https://hackerone.com/reports/680240 | Stored XSS at Synthetics private locations (planted through location label or description)
  2982. https://hackerone.com/reports/680415 | mod_http2, read-after-free in h2 connection shutdown (CVE-2019-10082)
  2983. https://hackerone.com/reports/682442 | Git flag injection - Search API with scope 'blobs'
  2984. https://hackerone.com/reports/682774 | Arbitrary file creation with semi-controlled content (leads to DoS, EoP and others) at Steam Windows Client
  2985. https://hackerone.com/reports/683298 | XSS and Open Redirect on MoPub Login
  2986. https://hackerone.com/reports/683318 | Windows builds with insecure path defaults (CVE-2019-1552)
  2987. https://hackerone.com/reports/683792 | XSS through chat messages
  2988. https://hackerone.com/reports/684092 | Steal ALL collateral during liquidation by exploiting lack of validation in flip.kick
  2989. https://hackerone.com/reports/684099 | Periscope-all Firebase database takeover
  2990. https://hackerone.com/reports/684152 | Steal all MKR from flap during liquidation by exploiting lack of validation in flap.kick
  2991. https://hackerone.com/reports/684603 | Heap buffer overflow in TFTP when using small blksize
  2992. https://hackerone.com/reports/685007 | Password Reset Link not expiring after changing the email Leads To Account Takeover
  2993. https://hackerone.com/reports/685552 | XSS in desktop client via invalid server address on login form
  2994. https://hackerone.com/reports/685909 | Searching from Hacktivity returns hits for words in limited disclosure reports that are not visible
  2995. https://hackerone.com/reports/686823 | krb5: double-free in read_data() after realloc() fail
  2996. https://hackerone.com/reports/687908 | Found Origin IP's Lead To Access To [ Grafana Instance , PgHero Instance [ Can SQL Injection ]
  2997. https://hackerone.com/reports/689245 | SSRF In plantuml (on plantuml.pre.gitlab.com)
  2998. https://hackerone.com/reports/689314 | Project Template functionality can be used to copy private project data, such as repository, confidential issues, snippets, and merge requests
  2999. https://hackerone.com/reports/689997 | Disclosure of Email title report in quick award paypout email (no content mode)
  3000. https://hackerone.com/reports/690536 | Passive stored XSS at Synthetics job result page (View resource)
  3001. https://hackerone.com/reports/691611 | XSS while logging using Google
  3002. https://hackerone.com/reports/692040 | PHP 7.3.3: Heap-use-after-free (READ of size 8) in match_at()
  3003. https://hackerone.com/reports/692252 | Group search leaks private MRs, code, commits
  3004. https://hackerone.com/reports/692352 | XSS on https://app.mopub.com/reports/custom/add/ [new-d1]
  3005. https://hackerone.com/reports/692603 | Privilege escalation in workers container
  3006. https://hackerone.com/reports/694181 | Worker container escape lead to arbitrary file reading in host machine
  3007. https://hackerone.com/reports/694604 | HTTP Request Smuggling on vpn.lob.com
  3008. https://hackerone.com/reports/696266 | "Bounties paid in the last 90 days" discloses the undisclosed bounty amount in program statistics
  3009. https://hackerone.com/reports/697055 | Worker container escape lead to arbitrary file reading in host machine [again]
  3010. https://hackerone.com/reports/697512 | Information Disclosure through Sentry Instance ███████
  3011. https://hackerone.com/reports/697959 | Only the file extensions are checked, not the MIME types as configured
  3012. https://hackerone.com/reports/698416 | Host Header Injection
  3013. https://hackerone.com/reports/698708 | Bypass report #416983 - Removed Staff members who had "Apps" permission can still modify flow app connections
  3014. https://hackerone.com/reports/700051 | Misconfigured s3 Bucket exposure
  3015. https://hackerone.com/reports/700831 | Unauthenticated read and write access to ALL endpoints of a store is possible for removed staff members who had "Apps" permission
  3016. https://hackerone.com/reports/700833 | Race condition на покупке призов за баллы
  3017. https://hackerone.com/reports/701901 | 2FA doesn't work in "https://insider.razer.com"
  3018. https://hackerone.com/reports/702981 | DOM XSS at https://www.thx.com in IE/Edge browser
  3019. https://hackerone.com/reports/702987 | No redirect_uri in the db for web-internal clientKey leads to one-click DoS on gitter.im
  3020. https://hackerone.com/reports/703058 | Insecure redirect rule results in bypassing ban redirect on certain pages
  3021. https://hackerone.com/reports/703759 | SSO through odnoklassniki uses http rather than https
  3022. https://hackerone.com/reports/703894 | View the Starred Projects in a Private Profile
  3023. https://hackerone.com/reports/704266 | DOM XSS at www.forescout.com in Microsoft Edge and IE Browser
  3024. https://hackerone.com/reports/705420 | A reflected XSS in python/Lib/DocXMLRPCServer.py
  3025. https://hackerone.com/reports/706533 | Stored XSS at Mobile (Versions tab)
  3026. https://hackerone.com/reports/706934 | Variant of CVE-2013-0269 (Denial of Service and Unsafe Object Creation Vulnerability in JSON)
  3027. https://hackerone.com/reports/707406 | Team object in GraphQL disclosed of private programs via the industry
  3028. https://hackerone.com/reports/707433 | Disclosure of payment_transactions for programs via GraphQL query
  3029. https://hackerone.com/reports/707720 | Stored XSS vulnerability in comments on *.wordpress.com
  3030. https://hackerone.com/reports/708013 | StoreFront API allows for a brute force attack on customer login by not timing out ALL attempts
  3031. https://hackerone.com/reports/708589 | Unsafe charts embedding implementation leads to cross-account stored XSS and SSRF
  3032. https://hackerone.com/reports/708820 | Group search with Elastic search enable leaks unrelated data
  3033. https://hackerone.com/reports/708917 | Rate Limit Misconfiguration on tumblr login .
  3034. https://hackerone.com/reports/709336 | Reflective Cross-site Scripting via Newsletter Form
  3035. https://hackerone.com/reports/709883 | Cross-account stored XSS at embedded charts
  3036. https://hackerone.com/reports/710006 | Elasticsearch leaks data through the notes scope
  3037. https://hackerone.com/reports/710535 | Cross-account stored XSS at notes (through "swf" note parameter)
  3038. https://hackerone.com/reports/712065 | Prototype pollution attack (lodash)
  3039. https://hackerone.com/reports/712979 | Creating malformed URLs via new line character in-between two URLs leads to misrepresented hyperlinks in Tweets/DMs
  3040. https://hackerone.com/reports/713006 | Keybase client (Windows 10): Write files anywhere in userland using relative path in "download attachement" feature
  3041. https://hackerone.com/reports/713285 | http request smuggling in pscp.tv and periscope.tv
  3042. https://hackerone.com/reports/713407 | ActiveStorage throws exception when using whitespace as filename, may lead to denial of service of multiple pages
  3043. https://hackerone.com/reports/715192 | Private program disclosure via vpn_suspended GraphQL query
  3044. https://hackerone.com/reports/716292 | JumpCloud API Key leaked via Open Github Repository.
  3045. https://hackerone.com/reports/716761 | WAF bypass via double encoded non standard ASCII chars permitted a reflected XSS on response page not found pages - (629745 bypass)
  3046. https://hackerone.com/reports/716976 | Open redirect in semrush.com
  3047. https://hackerone.com/reports/719426 | File-drop content is visible through the gallery app
  3048. https://hackerone.com/reports/720306 | Docker image with FPM is vulnerable to CVE-2019-11043
  3049. https://hackerone.com/reports/722327 | CVE-2019-11043: a buffer underflow in fpm_main.c can lead to RCE in php-fpm
  3050. https://hackerone.com/reports/723060 | Reflected XSS at https://pay.gold.razer.com escalated to account takeover
  3051. https://hackerone.com/reports/723118 | [IDOR] API endpoint leaking sensitive user information
  3052. https://hackerone.com/reports/723175 | De-anonymization Attack: Cross Site Information Leakage
  3053. https://hackerone.com/reports/723707 | Code injection in https://www.semrush.com
  3054. https://hackerone.com/reports/724217 | tcpdump: CVE-2018-14879 - buffer overflow in tcpdump.c:get_next_file()
  3055. https://hackerone.com/reports/724243 | Tcpdump before 4.9.3 has a buffer over-read in print-802_11.c (CVE-2018-16227)
  3056. https://hackerone.com/reports/724253 | Tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option() (CVE-2018-16229)
  3057. https://hackerone.com/reports/724944 | latest_activity_id and latest_activity_at may disclose information about internal activities to unauthorized users
  3058. https://hackerone.com/reports/725307 | Unchecked URL in attachment datasource
  3059. https://hackerone.com/reports/725569 | [IDOR] Attacker user can Approve/Decline AFK on the behalf of other users
  3060. https://hackerone.com/reports/726117 | SMB access smuggling via FILE URL on Windows
  3061. https://hackerone.com/reports/726773 | HTTP Request Smuggling on https://labs.data.gov
  3062. https://hackerone.com/reports/727870 | [www.yoti.com] Wordpress user admin information discloure
  3063. https://hackerone.com/reports/728664 | Cache poisoning DoS to various TTS assets
  3064. https://hackerone.com/reports/729040 | Shopify's SF and LA offices Dashboard Information disclosed via Public Gist
  3065. https://hackerone.com/reports/729424 | Stored XSS in private message
  3066. https://hackerone.com/reports/730779 | HTTP header values do not have trailing OWS trimmed
  3067. https://hackerone.com/reports/731878 | An implementation flaw in Mail.ru can be exploited for DKIM signature spoofing and email spoofing
  3068. https://hackerone.com/reports/732415 | The authenticity_token can be reversed and used to forge valid per_form_csrf_tokens for arbitrary routes
  3069. https://hackerone.com/reports/733248 | Stored XSS in wordpress.com
  3070. https://hackerone.com/reports/735748 | HTTP request smuggling using malformed Transfer-Encoding header
  3071. https://hackerone.com/reports/736800 | IP address can be leaked on Image preview in ICQ for Android chat
  3072. https://hackerone.com/reports/736867 | SSRF protection bypass
  3073. https://hackerone.com/reports/737140 | Mass account takeovers using HTTP Request Smuggling on https://slackb.com/ to steal session cookies
  3074. https://hackerone.com/reports/737161 | SSRF - URL Attachments - 725307 bypass
  3075. https://hackerone.com/reports/737163 | SSRF - Image Sources in HTML Snippets - 727234 bypass
  3076. https://hackerone.com/reports/737315 | 'X-Forwarded-Host' key used in input without sanitation - possible cache poisoning
  3077. https://hackerone.com/reports/738015 | SSRF - Office Documents - Image URL
  3078. https://hackerone.com/reports/738072 | XSS on product comments in transfers
  3079. https://hackerone.com/reports/743545 | Bruteforce password recovery code
  3080. https://hackerone.com/reports/744692 | The login of Hotor Not is Vulnerable to bruteforce.
  3081. https://hackerone.com/reports/745276 | Dragonblood: Design and Implementation Flaws in WPA3 and EAP-pwd
  3082. https://hackerone.com/reports/745324 | Account takeover via leaked session cookie
  3083. https://hackerone.com/reports/745495 | Unauthenticated users can access all food.grammarly.io user's data
  3084. https://hackerone.com/reports/745953 | Camo Image Proxy Bypass with CSS Escape Sequences
  3085. https://hackerone.com/reports/746000 | Subdomain Takeover Via via Dangling NS records on Amazon Route 53 http://api.e2e-kops-aws-canary.test-cncf-aws.canary.k8s.io
  3086. https://hackerone.com/reports/746733 | Remotely trigger an assertion on a TLS server with a malformed certificate string
  3087. https://hackerone.com/reports/746786 | Disclosure of locally served nerdpacks due to nr-local.net CORS policy misconfiguration
  3088. https://hackerone.com/reports/748375 | Transferring a public group to a private group doesn't remove code from the Elastichsearch API search result
  3089. https://hackerone.com/reports/751577 | IDOR allow access to payments data of any user
  3090. https://hackerone.com/reports/751604 | No Rate Limit On Forgot Password Page Of NordVPN
  3091. https://hackerone.com/reports/751699 | NR-wide cross account access through misconfigured CORS-policy of multiple endpoints
  3092. https://hackerone.com/reports/751729 | THX Tuneup Survey feedback disclosure via Google cached content for apps.thx.com
  3093. https://hackerone.com/reports/751876 | Version problem in wordpress leads to the many vulnearability
  3094. https://hackerone.com/reports/752010 | DoS of https://nordvpn.com/ via CVE-2018-6389 exploitation
  3095. https://hackerone.com/reports/752073 | xmlrpc.php FILE IS enable it will used for Bruteforce attack and Denial of Service(DoS)
  3096. https://hackerone.com/reports/753399 | Open redirect
  3097. https://hackerone.com/reports/753491 | DoS of https://blog.yelp.com/ and other WP instances via CVE-2018-6389
  3098. https://hackerone.com/reports/753602 | Staging Rabbitmq instance is exposed to the internet with default credentials
  3099. https://hackerone.com/reports/753725 | Disclosure of User Information
  3100. https://hackerone.com/reports/753868 | Insecure Storage and Overly Permissive API Keys in Android App
  3101. https://hackerone.com/reports/753939 | HTTP SMUGGLING EXPOSED HMAC/DOS
  3102. https://hackerone.com/reports/755679 | Timeline Editor Self-XSS (Previous Fix #738072 Incomplete)
  3103. https://hackerone.com/reports/756149 | Blind SSRF on debug.nordvpn.com due to misconfigured sentry instance
  3104. https://hackerone.com/reports/756182 | Potential leak of server side software at repogohi.nordvpn.com
  3105. https://hackerone.com/reports/756729 | Stored XSS in Shopify Chat
  3106. https://hackerone.com/reports/757957 | Restricted user can manage the NerdGraph entities' tags
  3107. https://hackerone.com/reports/758002 | Markdown parsing issue enables insertion of malicious tags
  3108. https://hackerone.com/reports/759247 | Race Condition allows to redeem multiple times gift cards which leads to free "money"
  3109. https://hackerone.com/reports/759454 | Helpdesk Takeover at dmc.datastax.com
  3110. https://hackerone.com/reports/761218 | Adds CodeQL query to check for insecure RequestValidationMode in ASP.NET
  3111. https://hackerone.com/reports/761219 | CodeQL query to detect pages with validationRequest disabled
  3112. https://hackerone.com/reports/761220 | CodeQL query to detect insecure MaxLengthRequest values in ASP.NET applications
  3113. https://hackerone.com/reports/761222 | Netty HTTP Response Splitting (CRLF Injection) due to disabled header validation
  3114. https://hackerone.com/reports/761480 | User password left in memory in plain text after GUI launch
  3115. https://hackerone.com/reports/761726 | SOP bypass using browser cache
  3116. https://hackerone.com/reports/761975 | Keychain data persistence may lead to account takeover
  3117. https://hackerone.com/reports/762271 | Guest users can change the confidentiality attribute on those issues that have been assigned to them
  3118. https://hackerone.com/reports/763994 | Disclose Any Store products, Files, Purchase Orders Via Email through Shopify Stocky APP
  3119. https://hackerone.com/reports/764243 | API - Amazon S3 bucket misconfiguration
  3120. https://hackerone.com/reports/764434 | profile-picture name parameter with large value lead to DoS for other users and programs on the platform
  3121. https://hackerone.com/reports/765355 | Modify account details by exploiting clickjacking vulnerability on refer.wordpress.com
  3122. https://hackerone.com/reports/765955 | Clickjacking at join.nordvpn.com
  3123. https://hackerone.com/reports/766145 | Restricted user can remove NerdStorage documents/collections scoped to ACCOUNT or ENTITY
  3124. https://hackerone.com/reports/766578 | Absence of Token expiry leads to Unauthorized login Access
  3125. https://hackerone.com/reports/766633 | XSS reflected on [https://www.pixiv.net]
  3126. https://hackerone.com/reports/767348 | Java (Maven): Use of insecure protocol to download/upload artifacts
  3127. https://hackerone.com/reports/767458 | User input validation can lead to DOS
  3128. https://hackerone.com/reports/768110 | Race condition (TOCTOU) in NordVPN can result in local privilege escalation
  3129. https://hackerone.com/reports/768677 | lack of input validation that can lead Denial of Service (DOS)
  3130. https://hackerone.com/reports/769058 | CORS misconfiguration which leads to the disclosure of certain data concerning the user.
  3131. https://hackerone.com/reports/770209 | Unauthorized user can obtain report_sources attribute through Team GraphQL object
  3132. https://hackerone.com/reports/770349 | Reflected XSS in twitterflightschool.com
  3133. https://hackerone.com/reports/770504 | Bypass Password Authentication for updating email and phone number - Security Vulnerability
  3134. https://hackerone.com/reports/771666 | Stealing Zomato X-Access-Token: in Bulk using HTTP Request Smuggling on api.zomato.com
  3135. https://hackerone.com/reports/771694 | An attacker can buy marketplace articles for lower prices as it allows for negative quantity values leading to business loss
  3136. https://hackerone.com/reports/772886 | Password Reset Link Works Multiple Times
  3137. https://hackerone.com/reports/774050 | No rate limiting for confirmation email lead to email flooding
  3138. https://hackerone.com/reports/774896 | Kubelet resource exhaustion attack via metric label cardinality explosion from unauthenticated requests
  3139. https://hackerone.com/reports/776017 | Half-Blind SSRF found in kube/cloud-controller-manager can be upgraded to complete SSRF (fully crafted HTTP requests) in vendor managed k8s service.
  3140. https://hackerone.com/reports/776449 | Restricted user can update Apdex target for applications by leveraging the GraphQL mutation
  3141. https://hackerone.com/reports/776634 | [H1-415 2020] CTF Writeup
  3142. https://hackerone.com/reports/777942 | Unrestricted access to any "connected pack" on docs
  3143. https://hackerone.com/reports/777984 | Denial of Service with Cookie Bomb
  3144. https://hackerone.com/reports/778803 | Compromise of auth via subset/superset namespace names.
  3145. https://hackerone.com/reports/778834 | OOB read in php_strip_tags_ex
  3146. https://hackerone.com/reports/779442 | Subdomain takeover of storybook.lystit.com
  3147. https://hackerone.com/reports/780632 | Html Injection and Possible XSS in main nordvpn.com domain
  3148. https://hackerone.com/reports/781325 | Out-of-bounds Read in php_strip_tags_ex
  3149. https://hackerone.com/reports/781673 | Accepting error message on twitter sends you to attacker site
  3150. https://hackerone.com/reports/781880 | CodeQL query to detect weak (duplicated) encryption keys for ASP.NET Telerik Upload
  3151. https://hackerone.com/reports/782703 | Account owner/admin can't actually delete personal users' API keys
  3152. https://hackerone.com/reports/783258 | 2-factor authentication can be disabled when logged in without confirming account password
  3153. https://hackerone.com/reports/783356 | The password limit is not set, [DoS].
  3154. https://hackerone.com/reports/783688 | Ability to buy PRO subscriptions by arbitrary reduced prices
  3155. https://hackerone.com/reports/783708 | IDOR in semrush academy
  3156. https://hackerone.com/reports/783877 | Remote Code Execution in Slack desktop apps + bonus
  3157. https://hackerone.com/reports/784186 | napi_get_value_string_X allow various kinds of memory corruption
  3158. https://hackerone.com/reports/784676 | iOS app crashed by specially crafted direct message reactions
  3159. https://hackerone.com/reports/784714 | Relative Path Vulnerability Results in Arbitrary Command Execution/Privilege Escalation
  3160. https://hackerone.com/reports/785120 | CodeQL query for finding CSRF vulnerabilities in Spring applications
  3161. https://hackerone.com/reports/785243 | Twitter Source Label allow 'mongolian vowel separator' U+180E (app name)
  3162. https://hackerone.com/reports/785785 | [Web ICQ Client] XSS-inj in polls
  3163. https://hackerone.com/reports/786044 | [windows10.hi-tech.mail.ru] Blind SQL Injection
  3164. https://hackerone.com/reports/786301 | Stored XSS in Name of Team Member Invitation
  3165. https://hackerone.com/reports/786745 | [API] ICQ user's avatar can be manipulated remotely
  3166. https://hackerone.com/reports/786822 | [Web ICQ Client] XSS у�звимо�ть в имени пользовател�
  3167. https://hackerone.com/reports/787113 | CodeQL query for finding LDAP Injection (CWE-90) vulnerabilities in Java
  3168. https://hackerone.com/reports/788257 | "Secure View" aka "Hide Download" can be bypassed easily
  3169. https://hackerone.com/reports/788691 | XSS - Guard - Insufficient escaping of User-IDs from PGP Keys
  3170. https://hackerone.com/reports/789260 | Past payments using the Direct Debit method keep subscriptions active even if payments fail
  3171. https://hackerone.com/reports/789579 | ActiveStorage direct upload fails to sign content-length header for S3 service
  3172. https://hackerone.com/reports/790005 | 3igames.mail.ru SQL Injection
  3173. https://hackerone.com/reports/790786 | Members from parent group keep their access level on a subgroup transfer and are invisible
  3174. https://hackerone.com/reports/790854 | NO username used in authenthication to www.mopub.com leading to direct password submission which has unlimited submission rate.
  3175. https://hackerone.com/reports/790876 | Dynamic reflection class
  3176. https://hackerone.com/reports/791775 | Email Confirmation Bypass in myshop.myshopify.com that Leads to Full Privilege Escalation to Any Shop Owner by Taking Advantage of the Shopify SSO
  3177. https://hackerone.com/reports/792295 | On Singing up with a Phone number , The 4 digit OTP does not expires for a long time leading to an easy attack and make a verified account easilty
  3178. https://hackerone.com/reports/792927 | Email address of any user can be queried on Report Invitation GraphQL type when username is known
  3179. https://hackerone.com/reports/792953 | SSRF - Guard - Unchecked HKP servers
  3180. https://hackerone.com/reports/792960 | SSRF - Guard - Unchecked WKS servers
  3181. https://hackerone.com/reports/792998 | 404-response contains debug-information with all headers
  3182. https://hackerone.com/reports/796808 | [Part II] Email Confirmation Bypass in myshop.myshopify.com that Leads to Full Privilege Escalation
  3183. https://hackerone.com/reports/796956 | Able to Takeover Merchants Accounts Even They Have Already Setup SSO, After Bypassing the Email Confirmation
  3184. https://hackerone.com/reports/797159 | PHP builded for Windows with TS support does not resolve relalative paths with drive letter correctly
  3185. https://hackerone.com/reports/797685 | IDOR in marketing calendar tool
  3186. https://hackerone.com/reports/798301 | FileZilla 3.46.3 - 'Scale factor' Buffer Overflow
  3187. https://hackerone.com/reports/798599 | xss stored
  3188. https://hackerone.com/reports/798686 | x-request-id header reflected in server response without sanitization
  3189. https://hackerone.com/reports/798742 | open redirect in eb9f.pivcac.prod.login.gov
  3190. https://hackerone.com/reports/798744 | Null Pointer Dereference in PHP Session Upload Progress
  3191. https://hackerone.com/reports/799072 | Slowloris, body parsing
  3192. https://hackerone.com/reports/800109 | An invite-only's program submission state is accessible to users no longer part of the program
  3193. https://hackerone.com/reports/800140 | Malformed HTTP/2 SETTINGS frame leads to reachable assert
  3194. https://hackerone.com/reports/801230 | CodeQL query for finding ReDoS and Regex Injection vulnerabilities in Java
  3195. https://hackerone.com/reports/802011 | Grafana Improper authorization
  3196. https://hackerone.com/reports/803141 | Unauthorized User Can Delete Any User Account
  3197. https://hackerone.com/reports/805010 | PHP link() silently truncates after a null byte on Windows
  3198. https://hackerone.com/reports/805013 | DirectoryIterator class silently truncates after a null byte
  3199. https://hackerone.com/reports/805073 | Periscope iOS app CSRF in follow action due to deeplink
  3200. https://hackerone.com/reports/806571 | Stored XSS in blob viewer
  3201. https://hackerone.com/reports/806577 | Arbitrary Set-Cookie via "?coupon=" due to semi-colon not encoded
  3202. https://hackerone.com/reports/807440 | Java (Maven): Actually fix the use of insecure protocol to download/upload artifacts
  3203. https://hackerone.com/reports/807448 | Customer private program can disclose email any users through invited via username
  3204. https://hackerone.com/reports/807924 | CSRF on connecting Paypal as Payment Provider
  3205. https://hackerone.com/reports/808287 | Unrestricted file upload on the image of contacts
  3206. https://hackerone.com/reports/808762 | Exposed Slinky Instance Admin Panel
  3207. https://hackerone.com/reports/809248 | SSRF into Shared Runner, by replacing dockerd with malicious server in Executor
  3208. https://hackerone.com/reports/809816 | Organization Takeover
  3209. https://hackerone.com/reports/810320 | Read-only user can delete higher privileged members using open DELETE /api/memberships/ endpoint
  3210. https://hackerone.com/reports/810880 | Account takeover w/o interaction for a user that doesn't have 2fa enabled via 2fa linking and improper auth at /api/2fa/verify
  3211. https://hackerone.com/reports/811502 | Node.js: TLS session reuse can lead to hostname verification bypass
  3212. https://hackerone.com/reports/812754 | Denial of Service by requesting to reset a password
  3213. https://hackerone.com/reports/813159 | Cleartext Transmission of Sensitive Information Leads to administrator access
  3214. https://hackerone.com/reports/813421 | Account deletion requests not entirely honoured. Misinformation even after seeking clarification from customer support.
  3215. https://hackerone.com/reports/816086 | Remote Code Execution on contactws.contact-sys.com via SQL injection in TCertObject operation "Delete"
  3216. https://hackerone.com/reports/816254 | SQL injection on contactws.contact-sys.com in TScenObject action ScenObjects leads to remote code execution
  3217. https://hackerone.com/reports/816560 | SQL injection on contactws.contact-sys.com in TRateObject.AddForOffice in USER_ID parameter leads to remote code execution
  3218. https://hackerone.com/reports/819088 | character limitation bypass can lead to DoS on Twitter App and 500 Internal Server Error
  3219. https://hackerone.com/reports/819278 | Open S3 Bucket Accessible by any Aws User
  3220. https://hackerone.com/reports/819807 | Missing ownership check on remote wipe endpoint
  3221. https://hackerone.com/reports/819821 | Initial mirror user can be assigned by other user even if the mirror was removed
  3222. https://hackerone.com/reports/819863 | XSS in PDF Viewer
  3223. https://hackerone.com/reports/819930 | Ability to bruteforce mopub account’s password due to lack of rate limitation protection using {ip rotation techniques}
  3224. https://hackerone.com/reports/820146 | PHPUnit is included in groupfolders release package potentially causing RCE
  3225. https://hackerone.com/reports/824689 | Send arbitrary PUT requests when user clicks on a link
  3226. https://hackerone.com/reports/824909 | Subdomain Takeover uptime
  3227. https://hackerone.com/reports/824925 | XPath Injection query in java
  3228. https://hackerone.com/reports/824926 | CWE-094 ScriptEngine in java
  3229. https://hackerone.com/reports/826026 | Use-After-Free In IPV6_2292PKTOPTIONS leading To Arbitrary Kernel R/W Primitives
  3230. https://hackerone.com/reports/826176 | program_analytics_benchmarks query shows information not visible in public
  3231. https://hackerone.com/reports/826361 | SSRF on project import via the remote_attachment_url on a Note
  3232. https://hackerone.com/reports/827051 | Use after free in smtp_server_connection_handle_command
  3233. https://hackerone.com/reports/827052 | Arbitrary file read via the UploadsRewriter when moving and issue
  3234. https://hackerone.com/reports/827484 | Missing rate limit for current password field (Password Change) Account Takeover
  3235. https://hackerone.com/reports/827729 | Null pointer dereference in SMTP server function smtp_string_parse
  3236. https://hackerone.com/reports/827816 | Missing server side controls when editing the board’s sharing permissions per user
  3237. https://hackerone.com/reports/831290 | Null pointer dereference in SMTP server function smtp_command_parse_data_with_size
  3238. https://hackerone.com/reports/831962 | XSS on Issue reference numbers
  3239. https://hackerone.com/reports/832227 | Buffer over-reads in i_stream_zlib_read
  3240. https://hackerone.com/reports/832858 | SSRF via 3d.cs.money/pasteLinkToImage
  3241. https://hackerone.com/reports/833080 | Tricking the "Create snippet" feature into displaying the wrong filetype can lead to RCE on Slack users
  3242. https://hackerone.com/reports/833782 | Allow authenticated users can edit, trash,and add new in BuddyPress Emails function
  3243. https://hackerone.com/reports/833856 | DoS for GCSArtifact.RealAll
  3244. https://hackerone.com/reports/834366 | Login CSRF vulnerability on hackerone.com
  3245. https://hackerone.com/reports/835005 | Organization Takeover via invitation API
  3246. https://hackerone.com/reports/836036 | Multiple buffer over reads in mbox_from_parse
  3247. https://hackerone.com/reports/836045 | Buffer overread in parse_angle_addr called from message_address_parse_path
  3248. https://hackerone.com/reports/836187 | CSRF in Profile Fields allows deleting any field in BuddyPress
  3249. https://hackerone.com/reports/836649 | Stored XSS in markdown when redacting references
  3250. https://hackerone.com/reports/837018 | Privilege Escalation in BuddyPress core allows Moderate to Administrator
  3251. https://hackerone.com/reports/837256 | Improper Access Control in Buddypress core allows reply,delete any user's activity
  3252. https://hackerone.com/reports/837729 | Session works after logout from Shopify account and password of online store is displayed
  3253. https://hackerone.com/reports/838127 | mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full (CVE-2020-7065)
  3254. https://hackerone.com/reports/838685 | Use of uninitialized value in ftp_getrc_msg method of mod_proxy_ftp.c
  3255. https://hackerone.com/reports/838855 | [www.zomato.com] Blind SQL Injection in /php/geto2banner
  3256. https://hackerone.com/reports/840598 | Possible denial of service when entering a loooong password
  3257. https://hackerone.com/reports/840759 | Reflected XSS on www.hackerone.com and resources.hackerone.com
  3258. https://hackerone.com/reports/843421 | Hyperlink Injection on Email Invitation
  3259. https://hackerone.com/reports/844327 | Java/CWE-036: Calling openStream on URLs created from remote source can lead to file disclosure
  3260. https://hackerone.com/reports/844428 | [www.zomato.com] Abusing LocalParams (city) to Inject SOLR query
  3261. https://hackerone.com/reports/845677 | Sourcemaps and Unminified Source Code Exposed on Pages
  3262. https://hackerone.com/reports/845729 | CPP: Out of order Linux permission dropping without checking return codes
  3263. https://hackerone.com/reports/846338 | Reflected XSS on https://www.glassdoor.com/employers/sem-dual-lp/
  3264. https://hackerone.com/reports/848625 | None permission staff member can identify installed application and products attached to it
  3265. https://hackerone.com/reports/850022 | CSRF on launchpad.37signals.com OAuth2 authorization endpoint
  3266. https://hackerone.com/reports/850114 | SSRF in notifications.server configuration
  3267. https://hackerone.com/reports/850447 | gitlab-workhorse bypass in Gitlab::Middleware::Multipart allowing files in allowed_paths to be read
  3268. https://hackerone.com/reports/851807 | Code injection possible with malformed Nextcloud Talk chat commands
  3269. https://hackerone.com/reports/852103 | Out-of-Bound Read in urldecode() [CVE-2020-7067]
  3270. https://hackerone.com/reports/852316 | Go/CWE-643: XPath Injection Query in Go
  3271. https://hackerone.com/reports/852349 | CPP: Out of order Linux permission dropping without checking return codes
  3272. https://hackerone.com/reports/852841 | Reduced purmations on encryption
  3273. https://hackerone.com/reports/853130 | IDOR on stocky application-Low Stock-Varient-Settings-Columns
  3274. https://hackerone.com/reports/853355 | Unauthorized access to private project security dashboard
  3275. https://hackerone.com/reports/854299 | Self XSS in Timeline
  3276. https://hackerone.com/reports/854424 | æš´åŠ›ç ´è§£ç”¨æˆ·å¯†ç �没有速ç�‡æ�§åˆ¶
  3277. https://hackerone.com/reports/854439 | Initial websocket support for Javascript (SockJS)
  3278. https://hackerone.com/reports/854793 | No rate limiting for confirmation email lead to email flooding and leads to enumeration of emails in publishers.basicattentiontoken.org
  3279. https://hackerone.com/reports/855276 | Injection of http.<url>.* git config settings leading to SSRF
  3280. https://hackerone.com/reports/855618 | Account takeover intercepting magic link for Arrive app
  3281. https://hackerone.com/reports/856554 | Stored XSS on the job page
  3282. https://hackerone.com/reports/856836 | Stored XSS on PyPi simple API endpoint
  3283. https://hackerone.com/reports/858650 | CRLF injection on www.starbucks.com
  3284. https://hackerone.com/reports/858671 | Insufficient Type Check on GraphQL leading to Maintainer delete repository
  3285. https://hackerone.com/reports/858854 | Recursor accepts unsigned, empty NXDOMAINs in secure zones
  3286. https://hackerone.com/reports/858915 | CircleCI token in github repo allows for access to sensitive build information
  3287. https://hackerone.com/reports/859333 | Stored XSS in group issue list
  3288. https://hackerone.com/reports/860197 | A staff without export customers permissions can still export customers CSV file
  3289. https://hackerone.com/reports/860348 | Staff member with no permission can delete POS staff from account settings
  3290. https://hackerone.com/reports/861170 | Attacker with an Old account might still be able to DoS ctf.hacker101.com by sending a Crafted request
  3291. https://hackerone.com/reports/861521 | Cookie injection leads to complete DoS over whole domain *.mackeeper.com. Injection point accountstage.mackeeper.com/
  3292. https://hackerone.com/reports/861940 | OAuth redirect_uri bypass using IDN homograph attack resulting in user's access token leakage
  3293. https://hackerone.com/reports/863551 | Subdomain takeover of resources.hackerone.com
  3294. https://hackerone.com/reports/863553 | SSRF protection bypass in /appsuite/api/oxodocumentfilter addfile action
  3295. https://hackerone.com/reports/863979 | Compromise of node can lead to compromise of pods on other nodes
  3296. https://hackerone.com/reports/864701 | Prototype Pollution lodash 4.17.15
  3297. https://hackerone.com/reports/865115 | unpermitted user can change the device name of admin account
  3298. https://hackerone.com/reports/865195 | reading the stack data of the imap process
  3299. https://hackerone.com/reports/865652 | Blind SSRF in /appsuite/api/oxodocumentfilter&action=addfile
  3300. https://hackerone.com/reports/866271 | Lack of Input sanitization leads to database Character encoding configuration Disclosure
  3301. https://hackerone.com/reports/866597 | Pre-auth buffer over-read in Dovecot NTLM implementation
  3302. https://hackerone.com/reports/866605 | Pre-auth Denial-of-Service in Dovecot RPA implementation
  3303. https://hackerone.com/reports/867052 | Access Control: Inject tasks into other users decks
  3304. https://hackerone.com/reports/867249 | The hacker has access to the administrative part of the management reports in publish report
  3305. https://hackerone.com/reports/867513 | Takeover an account that doesn't have a Shopify ID and more
  3306. https://hackerone.com/reports/867577 | Unauthenticated request smuggling on launchpad.37signals.com
  3307. https://hackerone.com/reports/867699 | Node disk DOS by writing to container /etc/hosts
  3308. https://hackerone.com/reports/867952 | HTTP request Smuggling
  3309. https://hackerone.com/reports/868615 | Inject page in admin panel via Shopify.API.pushState with protocol invalid
  3310. https://hackerone.com/reports/868834 | Denial of Service by resource exhaustion CWE-400 due to unfinished HTTP/1.1 requests
  3311. https://hackerone.com/reports/869831 | XSS within Shopify Email App - Admin
  3312. https://hackerone.com/reports/869888 | Path Traversal in App Proxy
  3313. https://hackerone.com/reports/870001 | access permission is not revoked even if the email has been deleted or changed on the partner account -partners.shopify-
  3314. https://hackerone.com/reports/871142 | Disclosure of the name of a program that has a private part with an external link
  3315. https://hackerone.com/reports/871749 | Unauthorized access to metadata of undisclosed reports that were retested
  3316. https://hackerone.com/reports/872094 | CodeQL query to detect SSRF in Python
  3317. https://hackerone.com/reports/874574 | Partner's non-verified business email change reflected into Shopify Collaborator Request
  3318. https://hackerone.com/reports/874778 | Partial password leak over DNS on HTTP redirect
  3319. https://hackerone.com/reports/878779 | Full Read SSRF on Gitlab's Internal Grafana
  3320. https://hackerone.com/reports/880089 | Smartsheet employees email disclosure through enpoint after login.
  3321. https://hackerone.com/reports/880099 | Unrestricted file upload leads to Stored XSS
  3322. https://hackerone.com/reports/880187 | Near to Infinite loop when changing Group's name that has API token as Team Member
  3323. https://hackerone.com/reports/880863 | Todos are not redacted when membership changes - Access to (confidential) issues and merge requests
  3324. https://hackerone.com/reports/881115 | Cross-Site Scripting (XSS) on www.starbucks.com | .co.uk login pages
  3325. https://hackerone.com/reports/881855 | Arbitrary change of blog's background image via CSRF
  3326. https://hackerone.com/reports/881918 | Authenticated Stored Cross-site Scripting in bbPress
  3327. https://hackerone.com/reports/882412 | OrderListInitial leaks order details
  3328. https://hackerone.com/reports/882546 | DOM-Based XSS in tumblr.com
  3329. https://hackerone.com/reports/882848 | Possibilty to purchase Ultimate - 1 Year (EDU or OSS)
  3330. https://hackerone.com/reports/882923 | DoS for client-go jsonpath func
  3331. https://hackerone.com/reports/883867 | Inject page in admin panel via Shopify.API.pushState [New Payload]
  3332. https://hackerone.com/reports/884159 | Ability to generate shipping labels in another store orders
  3333. https://hackerone.com/reports/885539 | Private list members disclosure via GraphQL
  3334. https://hackerone.com/reports/886287 | Java: CWE-532 sensitive info logging
  3335. https://hackerone.com/reports/887462 | curl overwrite local file with -J
  3336. https://hackerone.com/reports/887879 | xss stored in https://your store.myshopify.com/admin/
  3337. https://hackerone.com/reports/888666 | Add check for disabled HTTPOnly setting in Tomcat
  3338. https://hackerone.com/reports/888729 | Read-Only user can delete users
  3339. https://hackerone.com/reports/888930 | SAML Response Reuse on hackerone.com/users/saml/auth
  3340. https://hackerone.com/reports/888986 | [CVE-2020-10543] Buffer overflow caused by a crafted regular expression
  3341. https://hackerone.com/reports/889243 | Re-Sharing allows increase of privileges
  3342. https://hackerone.com/reports/890747 | PIN OK attack
  3343. https://hackerone.com/reports/890793 | Panic: Input stream data unexpectedly has references
  3344. https://hackerone.com/reports/890798 | Panic in file smtp-address.c: line 684 (smtp_address_write): assertion failed: (smtp_char_is_qpair(*p))
  3345. https://hackerone.com/reports/891069 | null dereference in sieve_address_do_validate (or redundant null check)
  3346. https://hackerone.com/reports/891080 | Null pointer deference in call to mail_get_flags
  3347. https://hackerone.com/reports/891265 | gagliardetto: Query to detect incorrect conversion between numeric types
  3348. https://hackerone.com/reports/891266 | CodeQL query to detect open Spring Boot actuator endpoints
  3349. https://hackerone.com/reports/891267 | CPP: Missing/incomplete TLS server certificate hostname validation
  3350. https://hackerone.com/reports/891268 | [Java] CWE-939 - Address improper URL authorization
  3351. https://hackerone.com/reports/892289 | self-xss with ClickJacking can leads to account takeover in Firefox
  3352. https://hackerone.com/reports/892465 | CodeQL query to detect JNDI injections
  3353. https://hackerone.com/reports/892466 | Golang : Add Email Content Injection query
  3354. https://hackerone.com/reports/892615 | [www.werkenbijbakertilly.nl] Denial of service due to incorrect server return can result in total denial of service.
  3355. https://hackerone.com/reports/892904 | Ability to link a Google account to another staff account/store owner that isn't linked yet
  3356. https://hackerone.com/reports/894446 | Null dereference in mcht_relational_validate ext-relational-common.c:136
  3357. https://hackerone.com/reports/894569 | An attacker can run pipeline jobs as arbitrary user
  3358. https://hackerone.com/reports/894870 | CodeQL query for MVEL injections
  3359. https://hackerone.com/reports/894871 | CodeQL query for unsafe TLS versions
  3360. https://hackerone.com/reports/894872 | CodeQL query to detect Server-Side Template Injections (JavaScript)
  3361. https://hackerone.com/reports/894876 | XSS through image upload of contacts using svg file
  3362. https://hackerone.com/reports/894915 | XSS on opening a malicious OpenOffice text document
  3363. https://hackerone.com/reports/894918 | XSS on opening malicious OpenOffice presentation document
  3364. https://hackerone.com/reports/894919 | XSS on opening malicious OpenOffice presentation document
  3365. https://hackerone.com/reports/895696 | Blind SSRF on https://labs.data.gov/dashboard/Campaign/json_status/ Endpoint
  3366. https://hackerone.com/reports/895972 | Limited LFI
  3367. https://hackerone.com/reports/896298 | CodeQL query for SpEL injections
  3368. https://hackerone.com/reports/896299 | Java: CWE-297 Insecure JavaMail SSL configuration
  3369. https://hackerone.com/reports/896522 | Reflected XSS when renaming a file with a vulnerable name which results in an error
  3370. https://hackerone.com/reports/897385 | 2FA bypass by sending blank code
  3371. https://hackerone.com/reports/898693 | Out of memory with combination of test_config_set and test_config_reload
  3372. https://hackerone.com/reports/898841 | Password reset link not expired at Stocky App
  3373. https://hackerone.com/reports/900548 | Buffer over read from smtp_command_parse_parameters
  3374. https://hackerone.com/reports/901775 | Get analytics token using only apps permission
  3375. https://hackerone.com/reports/902733 | Sensitive Info Leak - An Attacker Can Retrieve All the Users Mobile Numbers at https://website-api.production.curve.app/api/waitlist/us
  3376. https://hackerone.com/reports/902970 | [Java]: CWE-523 Insecure HSTS configuration
  3377. https://hackerone.com/reports/903521 | Fastify uses allErrors: true ajv configuration by default which is susceptible to DoS
  3378. https://hackerone.com/reports/903740 | Denial of Service | twitter.com & mobile.twitter.com
  3379. https://hackerone.com/reports/904059 | Open Redirect (6.0.0 < rails < 6.0.3.2)
  3380. https://hackerone.com/reports/905015 | Long filenames cause OOM and temp files are not cleaned
  3381. https://hackerone.com/reports/905607 | [cs.money] Open Redirect Leads to Account Takeover
  3382. https://hackerone.com/reports/905816 | No Rate Limit when accessing "Password protection" enabled surveys leads to bypassing passwords via "pd-pass_surveyid" cookie
  3383. https://hackerone.com/reports/906201 | XSS / SELF XSS
  3384. https://hackerone.com/reports/906433 | Android WebViews in Twitter app are vulnerable to UXSS due to configuration and CVE-2020-6506
  3385. https://hackerone.com/reports/906907 | IDOR with Geolocation data not stripped from images
  3386. https://hackerone.com/reports/908162 | Acronis True Image Local Privilege Escalation via insecure folder permissions
  3387. https://hackerone.com/reports/908894 | Null dereference or redundant null check in mail_crypt_load_global_private_key for plugin mail-crypt
  3388. https://hackerone.com/reports/909374 | Java : CWE-548 - J2EE server directory listing enabled
  3389. https://hackerone.com/reports/909375 | Golang : Add MongoDb NoSQL injection sinks
  3390. https://hackerone.com/reports/909863 | Low privileged user can create high privileged user's KITCRM authorization token and can read and write message to KIT
  3391. https://hackerone.com/reports/910300 | Email Confirmation Bypass in your-store.myshopify.com which leads to privilege escalation
  3392. https://hackerone.com/reports/911857 | increased privileges on staff account
  3393. https://hackerone.com/reports/915110 | No Email Checking at Invitation Confirmation Link leads to Account Takeover without User Interaction at CrowdSignal
  3394. https://hackerone.com/reports/915114 | IDOR when editing users leads to Account Takeover without User Interaction at CrowdSignal
  3395. https://hackerone.com/reports/915127 | IDOR when moving contents at CrowdSignal
  3396. https://hackerone.com/reports/915133 | IDOR at 'media_code' when addings media to questions
  3397. https://hackerone.com/reports/915140 | Users can bypass page restrictions via Export feature at "Share" feature in CrowdSignal
  3398. https://hackerone.com/reports/915756 | [tumblr.com] 69< Firefox Only XSS Reflected
  3399. https://hackerone.com/reports/915940 | Script Editor preview token still working with uninstalled application, even for unpublished script
  3400. https://hackerone.com/reports/916704 | Access control missing while viewing the attachments in the "All boards"
  3401. https://hackerone.com/reports/917250 | Stored XSS on recruit.innogames.de
  3402. https://hackerone.com/reports/917453 | CodeQL query for disabled revocation checking
  3403. https://hackerone.com/reports/917454 | Java: CWE-273 Unsafe certificate trust
  3404. https://hackerone.com/reports/917455 | CodeQL query to detect OGNL injections
  3405. https://hackerone.com/reports/917456 | [Java] CWE-295 - Incorrect Hostname Verification - MitM
  3406. https://hackerone.com/reports/917875 | STAFF "No-Permissions" on the Store can retrieve the details Order via exchangeReceiptSend
  3407. https://hackerone.com/reports/919175 | HTTP request smuggling on Basecamp 2 allows web cache poisoning
  3408. https://hackerone.com/reports/920005 | Stored XSS on app.crowdsignal.com + your-subdomain.survey.fm via Embed Media
  3409. https://hackerone.com/reports/920285 | [javascript] CWE-020: CodeQL query to detect missing origin validation in cross-origin communication via postMessage
  3410. https://hackerone.com/reports/920357 | Captcha checker "pd-captcha_form_SURVEYID" cookie is accepting any value
  3411. https://hackerone.com/reports/921286 | Denial of Service [Chrome]
  3412. https://hackerone.com/reports/921704 | Denial-of- service By Cache Poisoning The Cross-Origin Resource Sharing Misconfiguration Allow Origin Header
  3413. https://hackerone.com/reports/921709 | Clickjacking on donation page
  3414. https://hackerone.com/reports/922456 | Ability to bypass email verification for OAuth grants results in accounts takeovers on 3rd parties
  3415. https://hackerone.com/reports/922597 | HTTP Request Smuggling due to CR-to-Hyphen conversion
  3416. https://hackerone.com/reports/926221 | Improper use of "path" parameter can be used to trick testers into leaking their Front-End PoC
  3417. https://hackerone.com/reports/927567 | Ability to publish a paid theme without purchasing it.
  3418. https://hackerone.com/reports/927661 | Ability to manipulate price with a max threshold of <1 Rupee in support rider parameter
  3419. https://hackerone.com/reports/928255 | Ability To Delete User(s) Account Without User Interaction
  3420. https://hackerone.com/reports/929288 | Java: CWE-939 - Address improper URL authorization
  3421. https://hackerone.com/reports/942859 | Stored XSS in Post title (PoC)
  3422. https://hackerone.com/reports/944359 | Python : Add query to detect Server Side Template Injection
  3423. https://hackerone.com/reports/944735 | Arbitrary DLL injection in mmsminisrv (Acronis Managed Machine Service Mini)
  3424. https://hackerone.com/reports/945122 | Arbitrary file creation via symlink attack on syncagentsrv (Acronis Sync Agent Service)
  3425. https://hackerone.com/reports/945990 | Safe Redirect Bypass
  3426. https://hackerone.com/reports/946053 | Stored XSS in my staff name fired in another your internal panel
  3427. https://hackerone.com/reports/946409 | RCE on build server via misconfigured pip install
  3428. https://hackerone.com/reports/946728 | SafeParamsHelper::safe_params is not so safe
  3429. https://hackerone.com/reports/947728 | staff can able to extend shopify trial period without admin permission
  3430. https://hackerone.com/reports/947790 | Reflected XSS on a Atavist theme
  3431. https://hackerone.com/reports/948876 | Connect-only connections can use the wrong connection
  3432. https://hackerone.com/reports/948929 | Blind Stored XSS Via Staff Name
  3433. https://hackerone.com/reports/949382 | DOM-Based XSS in tumblr.com
  3434. https://hackerone.com/reports/949513 | XSS by file (Active Storage Proxying)
  3435. https://hackerone.com/reports/949823 | XSS DI BIODATA
  3436. https://hackerone.com/reports/950190 | Store-XSS in error message of build-dependencies
  3437. https://hackerone.com/reports/950299 | Use after free vulnerability in phar_parse_zipfile
  3438. https://hackerone.com/reports/950845 | Reflected XSS at /category/ on a Atavis theme
  3439. https://hackerone.com/reports/950881 | IDOR when editing email leads to Account Takeover on Atavist
  3440. https://hackerone.com/reports/951230 | Can buy Atavist Magazine subscription for free
  3441. https://hackerone.com/reports/951292 | Site-wide CSRF at Atavist
  3442. https://hackerone.com/reports/952035 | Admin web sessions remain active after logout of Shopify ID
  3443. https://hackerone.com/reports/952771 | CVE-2019-11250 remains in effect.
  3444. https://hackerone.com/reports/953083 | Ability to publish a paid theme without purchasing it.
  3445. https://hackerone.com/reports/953219 | SMTP interaction theft via MITM
  3446. https://hackerone.com/reports/953579 | [api.tumblr.com] Exploiting clickjacking vulnerability to trigger self DOM-based XSS
  3447. https://hackerone.com/reports/955016 | GitLab-Runner on Windows DOCKER_AUTH_CONFIG container host Command Injection
  3448. https://hackerone.com/reports/955286 | Graphql: Sorting the reports by jira_status field resulted to different value
  3449. https://hackerone.com/reports/956295 | LDAP injection vulnerability in Java
  3450. https://hackerone.com/reports/956296 | Golang : Improvements to Golang SSRF query
  3451. https://hackerone.com/reports/956967 | Java: CWE-798 - Hardcoded AWS credentials
  3452. https://hackerone.com/reports/957829 | Sending thousands of notifications with single request
  3453. https://hackerone.com/reports/957874 | Adding your account to victim's app via deeplink
  3454. https://hackerone.com/reports/958374 | Pentester can obtain information about other pentesters who applied for the same test, but weren't accepted
  3455. https://hackerone.com/reports/960244 | Insufficient Type Check leading to Developer ability to delete Project, Repository, Group, ...
  3456. https://hackerone.com/reports/961757 | Twitter Media Studio Source Information Disclosure With Analyst Role
  3457. https://hackerone.com/reports/961841 | Recently added 'Country' field doesn't send email notification when changed
  3458. https://hackerone.com/reports/961929 | Ability to see password protected content by bypassing the password page of shopify preview URL for new development stores (as of August 17, 2020)
  3459. https://hackerone.com/reports/962462 | Unauthorized user is able to access schedule pipeline variables and values
  3460. https://hackerone.com/reports/962604 | Revoked User can still view the Merge Request created by him via API
  3461. https://hackerone.com/reports/962895 | Stocky App Administrator can create a backdoor admin account by using an existing POS User
  3462. https://hackerone.com/reports/963774 | Premium Email Address Check Bypass - Hey
  3463. https://hackerone.com/reports/963815 | Java: CWE-522 Insecure basic authentication
  3464. https://hackerone.com/reports/963816 | [javascript] CWE-117: CodeQL query to detect Log Injection
  3465. https://hackerone.com/reports/965267 | Potential HTTP Request Smuggling in ruby webrick
  3466. https://hackerone.com/reports/965510 | Password protection can be removed for newly created development store
  3467. https://hackerone.com/reports/965782 | Failed assert in mail_index_transaction_lookup
  3468. https://hackerone.com/reports/965790 | Assert failed in edit_mail_istream_read
  3469. https://hackerone.com/reports/965881 | Null dereference in cmd_denotify_operation_execute
  3470. https://hackerone.com/reports/965914 | fs.realpath.native on darwin may cause buffer overflow
  3471. https://hackerone.com/reports/966383 | secret leaks in vsphere cloud controller manager log
  3472. https://hackerone.com/reports/966494 | True Image 2021 - LPE via XPC service communication
  3473. https://hackerone.com/reports/966834 | Incomplete fix for CVE-2020-12673 : Specially crafted NTML message leads to buffer over read
  3474. https://hackerone.com/reports/967457 | Buffer overread off by one in rpa_read_buffer, incomplete fix for CVE-2020-12674
  3475. https://hackerone.com/reports/968690 | DOM based XSS in store.acronis.com//purl-corporate-standard-IT [cfg parameter]
  3476. https://hackerone.com/reports/970157 | Bypass Password Authentication to Update the Password
  3477. https://hackerone.com/reports/970760 | Pixel Flood Attack leads to Application level DoS
  3478. https://hackerone.com/reports/972355 | Able to leak private email of any user given his/her username via graphql
  3479. https://hackerone.com/reports/972561 | kubeadm logs tokens before deleting them
  3480. https://hackerone.com/reports/972601 | Open Redirect at https://oauth.secure.pixiv.net
  3481. https://hackerone.com/reports/974222 | IDOR leads to Edit Anyone's Blogs / Websites
  3482. https://hackerone.com/reports/974271 | Stored XSS on https://app.crowdsignal.com/surveys/[Survey-Id]/question - Bypass
  3483. https://hackerone.com/reports/974368 | CodeQL query to detect XSLT injections
  3484. https://hackerone.com/reports/974369 | Query to find TLS configurations supporting hardcoded insecure versions of the protocol and cipher suites
  3485. https://hackerone.com/reports/974370 | [CATENACYBER]: [CPP] CWE-476 Null Pointer Dereference : Another query to either missing or redundant NULL check
  3486. https://hackerone.com/reports/974892 | Race Condition of Transfer data Credits to Organization Leads to Add Extra free Data Credits to the Organization
  3487. https://hackerone.com/reports/975047 | User sensitive information disclosure
  3488. https://hackerone.com/reports/975827 | Permanent DoS with one click.
  3489. https://hackerone.com/reports/975983 | Site-wide CSRF on Safari due to CORS misconfiguration (not localhost)
  3490. https://hackerone.com/reports/976657 | Reflected XSS on a Atavist theme at external_import.php
  3491. https://hackerone.com/reports/977851 | Cache poisoning via X-Forwarded-Host in www.shopify.com/partners/blog
  3492. https://hackerone.com/reports/978125 | xss triggered in "myshopify.com/admin/product"
  3493. https://hackerone.com/reports/978143 | Team object in GraphQL disclosed private_comment
  3494. https://hackerone.com/reports/978515 | A specially crafted message sent to the local delivery agent (LMTP) causes the LMTP child process to issue a panic (call i_panic)
  3495. https://hackerone.com/reports/978680 | GET based Open redirect on [streamlabs.com/content-hub/streamlabs-obs/search?query=]
  3496. https://hackerone.com/reports/979110 | Internal Path Disclosure
  3497. https://hackerone.com/reports/980511 | A staff member with no permissions can edit Store Customer Email
  3498. https://hackerone.com/reports/980856 | https://publishers.basicattentiontoken.org/favicon.ico is Vulnerable to CVE-2017-7529
  3499. https://hackerone.com/reports/981472 | Undocumented fileCopy GraphQL API
  3500. https://hackerone.com/reports/981796 | Information Disclosure of Garbage Collection Cycle
  3501. https://hackerone.com/reports/981824 | DNS Setup allows sending mail on behalf of other customers
  3502. https://hackerone.com/reports/982291 | HEY.com email stored XSS
  3503. https://hackerone.com/reports/982510 | Self XSS
  3504. https://hackerone.com/reports/983070 | IDOR when creating App on [platform.streamlabs.com/api/v1/store/whitelist] with user_id field
  3505. https://hackerone.com/reports/983867 | Java : add MongoDB injection sinks
  3506. https://hackerone.com/reports/985150 | Privilege Escalation in Point Of Sale Application from POS Manage Staff Role to potentially Store Owner
  3507. https://hackerone.com/reports/986386 | Reflected XSS on www.hackerone.com via Wistia embed code
  3508. https://hackerone.com/reports/988103 | Node.js: use-after-free in TLSWrap
  3509. https://hackerone.com/reports/988272 | stored XSS in hey.com message content
  3510. https://hackerone.com/reports/989415 | Bypass restrict of member subscription to use custom background in https://3d.cs.money without prime subscription
  3511. https://hackerone.com/reports/990838 | Bypass Filter on link of build
  3512. https://hackerone.com/reports/990878 | IDOR in https://3d.cs.money/
  3513. https://hackerone.com/reports/993005 | Server-side denial of service via large payload sent to wiki.cs.money/graphql
  3514. https://hackerone.com/reports/993582 | Application DOS via specially crafted payload on 3d.cs.money
  3515. https://hackerone.com/reports/994504 | authenticity token not verfied leads to change business name
  3516. https://hackerone.com/reports/996899 | LFI to steal /etc/passwd - Bypass filter in the tag via redirect and much more
  3517. https://hackerone.com/reports/997198 | Content Spoofing/Text Injection in https://support.cs.money and JS file not minified and uglyfied which makes it clearly readable
  3518. https://hackerone.com/reports/999765 | Ticket Trick at https://account.acronis.com
  3519. https://hackerone.com/reports/999789 | Getting New Invitations without Leaving Programs
  3520. https://hackerone.com/reports/1000567 | ReDoS at wiki.cs.money graphQL endpoint (AND probably a kind of command injection)
  3521. https://hackerone.com/reports/1001255 | Possible RCE through Windows Custom Protocol on Windows client
  3522. https://hackerone.com/reports/1002188 | Potential HTTP Request Smuggling in nodejs

hackerone-reports's People

Contributors

rcluex avatar

Stargazers

 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.