Unprotected Direct Object Reference
π https://hackerone.com/reports/1536936
πΉ Severity: Critical
πΉ Reported To: MTN Group
πΉ Reported By: #coyemerald
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 5:24pm (UTC)
π https://hackerone.com/reports/1536936
πΉ Severity: Critical
πΉ Reported To: MTN Group
πΉ Reported By: #coyemerald
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 5:24pm (UTC)
Remove Every User, Admin, And Owner Out Of Their Teams on developers.mtn.com via IDOR + Information Disclosure
π https://hackerone.com/reports/1448550
πΉ Severity: Critical
πΉ Reported To: MTN Group
πΉ Reported By: #wallotry
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 5:34pm (UTC)
π https://hackerone.com/reports/1448550
πΉ Severity: Critical
πΉ Reported To: MTN Group
πΉ Reported By: #wallotry
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 5:34pm (UTC)
π±1
Subdomain Takeover at course.oberlo.com
π https://hackerone.com/reports/1690951
πΉ Severity: No Rating
πΉ Reported To: Shopify
πΉ Reported By: #m7mdharoun
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 7:22pm (UTC)
π https://hackerone.com/reports/1690951
πΉ Severity: No Rating
πΉ Reported To: Shopify
πΉ Reported By: #m7mdharoun
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 7:22pm (UTC)
Read/Write arbitrary (non-HttpOnly) cookies on checkout pages via GoogleAnalyticsAdditionalScripts postMessage handler
π https://hackerone.com/reports/1081167
πΉ Severity: Medium | π° 1,600 USD
πΉ Reported To: Shopify
πΉ Reported By: #bored-engineer
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 7:34pm (UTC)
π https://hackerone.com/reports/1081167
πΉ Severity: Medium | π° 1,600 USD
πΉ Reported To: Shopify
πΉ Reported By: #bored-engineer
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 7:34pm (UTC)
Disconnecting an external login provider does not revoke session
π https://hackerone.com/reports/1547684
πΉ Severity: Medium | π° 1,600 USD
πΉ Reported To: Shopify
πΉ Reported By: #attackerbhai
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 7:50pm (UTC)
π https://hackerone.com/reports/1547684
πΉ Severity: Medium | π° 1,600 USD
πΉ Reported To: Shopify
πΉ Reported By: #attackerbhai
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 7:50pm (UTC)
Stored XSS in /admin/product and /admin/collections
π https://hackerone.com/reports/1147433
πΉ Severity: Medium | π° 5,300 USD
πΉ Reported To: Shopify
πΉ Reported By: #ashketchum
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 10:44pm (UTC)
π https://hackerone.com/reports/1147433
πΉ Severity: Medium | π° 5,300 USD
πΉ Reported To: Shopify
πΉ Reported By: #ashketchum
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 10:44pm (UTC)
Authentication bypass in https://nin.mtn.ng
π https://hackerone.com/reports/1747146
πΉ Severity: Critical
πΉ Reported To: MTN Group
πΉ Reported By: #roland_hack
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 1:00pm (UTC)
π https://hackerone.com/reports/1747146
πΉ Severity: Critical
πΉ Reported To: MTN Group
πΉ Reported By: #roland_hack
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 1:00pm (UTC)
XSS in Acronis Cloud Manager Admin Portal
π https://hackerone.com/reports/1388788
πΉ Severity: Medium | π° 100 USD
πΉ Reported To: Acronis
πΉ Reported By: #mooimacow
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 7:48pm (UTC)
π https://hackerone.com/reports/1388788
πΉ Severity: Medium | π° 100 USD
πΉ Reported To: Acronis
πΉ Reported By: #mooimacow
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 7:48pm (UTC)
POST following PUT confusion
π https://hackerone.com/reports/1752146
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #robbotic
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 9:03pm (UTC)
π https://hackerone.com/reports/1752146
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #robbotic
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 9:03pm (UTC)
Exposed Cortex API at https://cortex-ingest.shopifycloud.com/
π https://hackerone.com/reports/1258871
πΉ Severity: Medium | π° 6,300 USD
πΉ Reported To: Shopify
πΉ Reported By: #ian
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 10:25pm (UTC)
π https://hackerone.com/reports/1258871
πΉ Severity: Medium | π° 6,300 USD
πΉ Reported To: Shopify
πΉ Reported By: #ian
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 10:25pm (UTC)
π1
CVE-2022-35260: .netrc parser out-of-bounds access
π https://hackerone.com/reports/1753224
πΉ Severity: Low | π° 480 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #kurohiro
πΉ State: π’ Resolved
πΉ Disclosed: December 3, 2022, 12:20am (UTC)
π https://hackerone.com/reports/1753224
πΉ Severity: Low | π° 480 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #kurohiro
πΉ State: π’ Resolved
πΉ Disclosed: December 3, 2022, 12:20am (UTC)
π1
IDOR in Stats API Endpoint Allows Viewing Equity or Net Profit of Any MT Account
π https://hackerone.com/reports/1644436
πΉ Severity: No Rating | π° 1,000 USD
πΉ Reported To: EXNESS
πΉ Reported By: #ashwarya
πΉ State: π’ Resolved
πΉ Disclosed: December 5, 2022, 3:50pm (UTC)
π https://hackerone.com/reports/1644436
πΉ Severity: No Rating | π° 1,000 USD
πΉ Reported To: EXNESS
πΉ Reported By: #ashwarya
πΉ State: π’ Resolved
πΉ Disclosed: December 5, 2022, 3:50pm (UTC)
π9β€2
[Splatoon 3] Kick other players with NplnLogin message
πΉ Severity: Medium
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Nintendo
πΉ Reported By: alzxk11
πΉ State: π’ Resolved
πΉ Disclosed: July 2, 2026, 1:25am (UTC)
A vulnerability was discovered that allowed players to kick other players from a Splatoon 3 game using an NplnLogin message.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Nintendo
πΉ Reported By: alzxk11
πΉ State: π’ Resolved
πΉ Disclosed: July 2, 2026, 1:25am (UTC)
A vulnerability was discovered that allowed players to kick other players from a Splatoon 3 game using an NplnLogin message.
π Read full report
β€1
admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed
πΉ Severity: None
πΉ Reported To: Shopify
πΉ Reported By: abahack
πΉ State: βͺοΈ Informative
πΉ Disclosed: July 3, 2026, 6:50pm (UTC)
π Read full report
πΉ Severity: None
πΉ Reported To: Shopify
πΉ Reported By: abahack
πΉ State: βͺοΈ Informative
πΉ Disclosed: July 3, 2026, 6:50pm (UTC)
π Read full report
Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity
πΉ Severity: Medium | π° 287 USD
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Basecamp
πΉ Reported By: zerodaysec_xyz
πΉ State: π’ Resolved
πΉ Disclosed: July 4, 2026, 11:05am (UTC)
A vulnerability was discovered in the Basecamp Android app that allowed any installed app to force immediate logout and persistent denial-of-service of authenticated Basecamp sessions. The vulnerability was due to the `com.basecamp.bc4.app.main.start.StartActivity` being declared as exported without any permission guard. This allowed any app to launch it with an explicit intent, terminating the current session andβ¦
π Read full report
πΉ Severity: Medium | π° 287 USD
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Basecamp
πΉ Reported By: zerodaysec_xyz
πΉ State: π’ Resolved
πΉ Disclosed: July 4, 2026, 11:05am (UTC)
A vulnerability was discovered in the Basecamp Android app that allowed any installed app to force immediate logout and persistent denial-of-service of authenticated Basecamp sessions. The vulnerability was due to the `com.basecamp.bc4.app.main.start.StartActivity` being declared as exported without any permission guard. This allowed any app to launch it with an explicit intent, terminating the current session andβ¦
π Read full report
OS Command Injection in `aws-cdk-lib` NodejsFunction via Unsanitized `OsCommand` Helper (Supply Chain RCE)
πΉ Severity: High
πΉ Weakness: OS Command Injection
πΉ Reported To: AWS VDP
πΉ Reported By: kaporia
πΉ State: π’ Resolved
πΉ Disclosed: July 6, 2026, 5:48pm (UTC)
A vulnerability was discovered in the "aws-cdk-lib" NodejsFunction that allowed for OS command injection through the unsanitized "OsCommand" helper. The vulnerability was caused by the lack of proper escaping of user-controlled data when constructing shell commands during Docker-based bundling. This could have potentially led to arbitrary code execution within the Docker container, which had access to the hostβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: OS Command Injection
πΉ Reported To: AWS VDP
πΉ Reported By: kaporia
πΉ State: π’ Resolved
πΉ Disclosed: July 6, 2026, 5:48pm (UTC)
A vulnerability was discovered in the "aws-cdk-lib" NodejsFunction that allowed for OS command injection through the unsanitized "OsCommand" helper. The vulnerability was caused by the lack of proper escaping of user-controlled data when constructing shell commands during Docker-based bundling. This could have potentially led to arbitrary code execution within the Docker container, which had access to the hostβ¦
π Read full report
Kiro IDE Stores Auth Tokens with World-Readable Permissions (0644)
πΉ Severity: Medium
πΉ Weakness: Incorrect Default Permissions
πΉ Reported To: AWS VDP
πΉ Reported By: mistercloudsec
πΉ State: π’ Resolved
πΉ Disclosed: July 9, 2026, 3:31pm (UTC)
The Kiro IDE (version 0.11.107) wrote authentication tokens (access token and refresh token) to a file with world-readable permissions (0644). The file contained sensitive information, including the access token, refresh token, and profile ARN. This exposed the credentials to potential unauthorized access by local processes or users.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Incorrect Default Permissions
πΉ Reported To: AWS VDP
πΉ Reported By: mistercloudsec
πΉ State: π’ Resolved
πΉ Disclosed: July 9, 2026, 3:31pm (UTC)
The Kiro IDE (version 0.11.107) wrote authentication tokens (access token and refresh token) to a file with world-readable permissions (0644). The file contained sensitive information, including the access token, refresh token, and profile ARN. This exposed the credentials to potential unauthorized access by local processes or users.
π Read full report
π1
Unauthenticated Access to MMGIS Webhooks
πΉ Severity: High
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: oversudo
πΉ State: π’ Resolved
πΉ Disclosed: July 7, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: High
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: oversudo
πΉ State: π’ Resolved
πΉ Disclosed: July 7, 2026
π Source: Bugcrowd
π Read full report
Unauthenticated Disclosure of NASA Organizer Email Addresses via The Events Calendar REST API (CVE-2025-9808)
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: ARTanvir76
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 9, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: ARTanvir76
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 9, 2026
π Source: Bugcrowd
π Read full report
[Atlas Browser] Fullscreen Toast Can Be Hidden by Repeated Constraint Validation Popups
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: jodyritonga
πΉ State: π’ Resolved
πΉ Disclosed: July 9, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: jodyritonga
πΉ State: π’ Resolved
πΉ Disclosed: July 9, 2026
π Source: Bugcrowd
π Read full report
π Hey hunters!
The channel just leveled up β disclosed reports now pull from two sources: HackerOne & Bugcrowd ππ₯
More features are on the way π And you get a say β which platform should we plug in next? React to vote π
π₯ β Immunefi (web3)
π β huntr (open source)
π€ β something else (tell us in comments)
The channel just leveled up β disclosed reports now pull from two sources: HackerOne & Bugcrowd ππ₯
More features are on the way π And you get a say β which platform should we plug in next? React to vote π
π₯ β Immunefi (web3)
π β huntr (open source)
π€ β something else (tell us in comments)
β€5π₯3π2π€2