Read/Write arbitrary (non-HttpOnly) cookies on checkout pages via GoogleAnalyticsAdditionalScripts postMessage handler
π https://hackerone.com/reports/1081167
πΉ Severity: Medium | π° 1,600 USD
πΉ Reported To: Shopify
πΉ Reported By: #bored-engineer
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 7:34pm (UTC)
π https://hackerone.com/reports/1081167
πΉ Severity: Medium | π° 1,600 USD
πΉ Reported To: Shopify
πΉ Reported By: #bored-engineer
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 7:34pm (UTC)
Disconnecting an external login provider does not revoke session
π https://hackerone.com/reports/1547684
πΉ Severity: Medium | π° 1,600 USD
πΉ Reported To: Shopify
πΉ Reported By: #attackerbhai
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 7:50pm (UTC)
π https://hackerone.com/reports/1547684
πΉ Severity: Medium | π° 1,600 USD
πΉ Reported To: Shopify
πΉ Reported By: #attackerbhai
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 7:50pm (UTC)
Stored XSS in /admin/product and /admin/collections
π https://hackerone.com/reports/1147433
πΉ Severity: Medium | π° 5,300 USD
πΉ Reported To: Shopify
πΉ Reported By: #ashketchum
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 10:44pm (UTC)
π https://hackerone.com/reports/1147433
πΉ Severity: Medium | π° 5,300 USD
πΉ Reported To: Shopify
πΉ Reported By: #ashketchum
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 10:44pm (UTC)
Authentication bypass in https://nin.mtn.ng
π https://hackerone.com/reports/1747146
πΉ Severity: Critical
πΉ Reported To: MTN Group
πΉ Reported By: #roland_hack
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 1:00pm (UTC)
π https://hackerone.com/reports/1747146
πΉ Severity: Critical
πΉ Reported To: MTN Group
πΉ Reported By: #roland_hack
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 1:00pm (UTC)
XSS in Acronis Cloud Manager Admin Portal
π https://hackerone.com/reports/1388788
πΉ Severity: Medium | π° 100 USD
πΉ Reported To: Acronis
πΉ Reported By: #mooimacow
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 7:48pm (UTC)
π https://hackerone.com/reports/1388788
πΉ Severity: Medium | π° 100 USD
πΉ Reported To: Acronis
πΉ Reported By: #mooimacow
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 7:48pm (UTC)
POST following PUT confusion
π https://hackerone.com/reports/1752146
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #robbotic
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 9:03pm (UTC)
π https://hackerone.com/reports/1752146
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #robbotic
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 9:03pm (UTC)
Exposed Cortex API at https://cortex-ingest.shopifycloud.com/
π https://hackerone.com/reports/1258871
πΉ Severity: Medium | π° 6,300 USD
πΉ Reported To: Shopify
πΉ Reported By: #ian
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 10:25pm (UTC)
π https://hackerone.com/reports/1258871
πΉ Severity: Medium | π° 6,300 USD
πΉ Reported To: Shopify
πΉ Reported By: #ian
πΉ State: π’ Resolved
πΉ Disclosed: December 2, 2022, 10:25pm (UTC)
π1
CVE-2022-35260: .netrc parser out-of-bounds access
π https://hackerone.com/reports/1753224
πΉ Severity: Low | π° 480 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #kurohiro
πΉ State: π’ Resolved
πΉ Disclosed: December 3, 2022, 12:20am (UTC)
π https://hackerone.com/reports/1753224
πΉ Severity: Low | π° 480 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #kurohiro
πΉ State: π’ Resolved
πΉ Disclosed: December 3, 2022, 12:20am (UTC)
π1
IDOR in Stats API Endpoint Allows Viewing Equity or Net Profit of Any MT Account
π https://hackerone.com/reports/1644436
πΉ Severity: No Rating | π° 1,000 USD
πΉ Reported To: EXNESS
πΉ Reported By: #ashwarya
πΉ State: π’ Resolved
πΉ Disclosed: December 5, 2022, 3:50pm (UTC)
π https://hackerone.com/reports/1644436
πΉ Severity: No Rating | π° 1,000 USD
πΉ Reported To: EXNESS
πΉ Reported By: #ashwarya
πΉ State: π’ Resolved
πΉ Disclosed: December 5, 2022, 3:50pm (UTC)
π9β€2
[Splatoon 3] Kick other players with NplnLogin message
πΉ Severity: Medium
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Nintendo
πΉ Reported By: alzxk11
πΉ State: π’ Resolved
πΉ Disclosed: July 2, 2026, 1:25am (UTC)
A vulnerability was discovered that allowed players to kick other players from a Splatoon 3 game using an NplnLogin message.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Nintendo
πΉ Reported By: alzxk11
πΉ State: π’ Resolved
πΉ Disclosed: July 2, 2026, 1:25am (UTC)
A vulnerability was discovered that allowed players to kick other players from a Splatoon 3 game using an NplnLogin message.
π Read full report
β€1
admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed
πΉ Severity: None
πΉ Reported To: Shopify
πΉ Reported By: abahack
πΉ State: βͺοΈ Informative
πΉ Disclosed: July 3, 2026, 6:50pm (UTC)
π Read full report
πΉ Severity: None
πΉ Reported To: Shopify
πΉ Reported By: abahack
πΉ State: βͺοΈ Informative
πΉ Disclosed: July 3, 2026, 6:50pm (UTC)
π Read full report
Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity
πΉ Severity: Medium | π° 287 USD
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Basecamp
πΉ Reported By: zerodaysec_xyz
πΉ State: π’ Resolved
πΉ Disclosed: July 4, 2026, 11:05am (UTC)
A vulnerability was discovered in the Basecamp Android app that allowed any installed app to force immediate logout and persistent denial-of-service of authenticated Basecamp sessions. The vulnerability was due to the `com.basecamp.bc4.app.main.start.StartActivity` being declared as exported without any permission guard. This allowed any app to launch it with an explicit intent, terminating the current session andβ¦
π Read full report
πΉ Severity: Medium | π° 287 USD
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Basecamp
πΉ Reported By: zerodaysec_xyz
πΉ State: π’ Resolved
πΉ Disclosed: July 4, 2026, 11:05am (UTC)
A vulnerability was discovered in the Basecamp Android app that allowed any installed app to force immediate logout and persistent denial-of-service of authenticated Basecamp sessions. The vulnerability was due to the `com.basecamp.bc4.app.main.start.StartActivity` being declared as exported without any permission guard. This allowed any app to launch it with an explicit intent, terminating the current session andβ¦
π Read full report
OS Command Injection in `aws-cdk-lib` NodejsFunction via Unsanitized `OsCommand` Helper (Supply Chain RCE)
πΉ Severity: High
πΉ Weakness: OS Command Injection
πΉ Reported To: AWS VDP
πΉ Reported By: kaporia
πΉ State: π’ Resolved
πΉ Disclosed: July 6, 2026, 5:48pm (UTC)
A vulnerability was discovered in the "aws-cdk-lib" NodejsFunction that allowed for OS command injection through the unsanitized "OsCommand" helper. The vulnerability was caused by the lack of proper escaping of user-controlled data when constructing shell commands during Docker-based bundling. This could have potentially led to arbitrary code execution within the Docker container, which had access to the hostβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: OS Command Injection
πΉ Reported To: AWS VDP
πΉ Reported By: kaporia
πΉ State: π’ Resolved
πΉ Disclosed: July 6, 2026, 5:48pm (UTC)
A vulnerability was discovered in the "aws-cdk-lib" NodejsFunction that allowed for OS command injection through the unsanitized "OsCommand" helper. The vulnerability was caused by the lack of proper escaping of user-controlled data when constructing shell commands during Docker-based bundling. This could have potentially led to arbitrary code execution within the Docker container, which had access to the hostβ¦
π Read full report
Kiro IDE Stores Auth Tokens with World-Readable Permissions (0644)
πΉ Severity: Medium
πΉ Weakness: Incorrect Default Permissions
πΉ Reported To: AWS VDP
πΉ Reported By: mistercloudsec
πΉ State: π’ Resolved
πΉ Disclosed: July 9, 2026, 3:31pm (UTC)
The Kiro IDE (version 0.11.107) wrote authentication tokens (access token and refresh token) to a file with world-readable permissions (0644). The file contained sensitive information, including the access token, refresh token, and profile ARN. This exposed the credentials to potential unauthorized access by local processes or users.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Incorrect Default Permissions
πΉ Reported To: AWS VDP
πΉ Reported By: mistercloudsec
πΉ State: π’ Resolved
πΉ Disclosed: July 9, 2026, 3:31pm (UTC)
The Kiro IDE (version 0.11.107) wrote authentication tokens (access token and refresh token) to a file with world-readable permissions (0644). The file contained sensitive information, including the access token, refresh token, and profile ARN. This exposed the credentials to potential unauthorized access by local processes or users.
π Read full report
π1
Unauthenticated Access to MMGIS Webhooks
πΉ Severity: High
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: oversudo
πΉ State: π’ Resolved
πΉ Disclosed: July 7, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: High
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: oversudo
πΉ State: π’ Resolved
πΉ Disclosed: July 7, 2026
π Source: Bugcrowd
π Read full report
Unauthenticated Disclosure of NASA Organizer Email Addresses via The Events Calendar REST API (CVE-2025-9808)
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: ARTanvir76
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 9, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: ARTanvir76
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 9, 2026
π Source: Bugcrowd
π Read full report
[Atlas Browser] Fullscreen Toast Can Be Hidden by Repeated Constraint Validation Popups
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: jodyritonga
πΉ State: π’ Resolved
πΉ Disclosed: July 9, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: jodyritonga
πΉ State: π’ Resolved
πΉ Disclosed: July 9, 2026
π Source: Bugcrowd
π Read full report
π Hey hunters!
The channel just leveled up β disclosed reports now pull from two sources: HackerOne & Bugcrowd ππ₯
More features are on the way π And you get a say β which platform should we plug in next? React to vote π
π₯ β Immunefi (web3)
π β huntr (open source)
π€ β something else (tell us in comments)
The channel just leveled up β disclosed reports now pull from two sources: HackerOne & Bugcrowd ππ₯
More features are on the way π And you get a say β which platform should we plug in next? React to vote π
π₯ β Immunefi (web3)
π β huntr (open source)
π€ β something else (tell us in comments)
β€5π₯3π2π€2
Unauthenticated Error-Based SQL Injection in HEASARC W3Browse w3hdprods.pl
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Anon0x0
πΉ State: π’ Resolved
πΉ Disclosed: July 13, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Anon0x0
πΉ State: π’ Resolved
πΉ Disclosed: July 13, 2026
π Source: Bugcrowd
π Read full report
SELECT ... INTO OUTFILE does not enforce the FILE WRITE privilege unprivileged arbitrary file write on the server
πΉ Severity: High
πΉ Weakness: Missing Authorization
πΉ Reported To: SingleStore
πΉ Reported By: bisht-ji
πΉ State: π’ Resolved
πΉ Disclosed: July 13, 2026, 7:35pm (UTC)
π Source: HackerOne
A security vulnerability was reported in SingleStore's self-managed database server where the SELECT...INTO OUTFILE command did not properly enforce the FILE WRITE privilege. This allowed any authenticated user, including those with only USAGE privileges, to write arbitrary files to the aggregator host at any path, written as the engine OS user. The vulnerability affected default-configuration self-managedβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Missing Authorization
πΉ Reported To: SingleStore
πΉ Reported By: bisht-ji
πΉ State: π’ Resolved
πΉ Disclosed: July 13, 2026, 7:35pm (UTC)
π Source: HackerOne
A security vulnerability was reported in SingleStore's self-managed database server where the SELECT...INTO OUTFILE command did not properly enforce the FILE WRITE privilege. This allowed any authenticated user, including those with only USAGE privileges, to write arbitrary files to the aggregator host at any path, written as the engine OS user. The vulnerability affected default-configuration self-managedβ¦
π Read full report
π1
One-Click Data Exfiltration via rovoChatPrompt URL Parameter (Confluence / Rovo)
πΉ Severity: High
πΉ Reported To: Atlassian
πΉ Reported By: loacker
πΉ State: π’ Resolved
πΉ Disclosed: July 14, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: High
πΉ Reported To: Atlassian
πΉ Reported By: loacker
πΉ State: π’ Resolved
πΉ Disclosed: July 14, 2026
π Source: Bugcrowd
π Read full report