🎯 New Report #1668489: CSRF vulnerability allows disabling Gmail contacts link for user referrals
🔺Severity: Medium
👽 Reporter: khaledx
⭐️ Reputation: 1558
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-08-13
⏰ Disclosed: 2025-09-19 06:36:34
📝 Summary: The CSRF vulnerability allowed users to disable Gmail contacts link for user referrals. The vulnerable endpoint did not sufficiently verify that the requests were intentionally performed by the user, allowing an attacker to generate a PoC that could be used to disable the victim's linked account.
📂 Report JSON File: 1668489
@hackeronereports
🔺Severity: Medium
👽 Reporter: khaledx
⭐️ Reputation: 1558
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-08-13
⏰ Disclosed: 2025-09-19 06:36:34
📝 Summary: The CSRF vulnerability allowed users to disable Gmail contacts link for user referrals. The vulnerable endpoint did not sufficiently verify that the requests were intentionally performed by the user, allowing an attacker to generate a PoC that could be used to disable the victim's linked account.
📂 Report JSON File: 1668489
@hackeronereports
🎯 New Report #1387366: elections.k8s.io uses weak session secret key, may place elections at risk
🔺Severity: High
👽 Reporter: ian
⭐️ Reputation: 6661
🛠 State: resolved
💼 Team: Kubernetes
💵 Bounty: 250
🕐 Submitted: 2021-11-01
⏰ Disclosed: 2025-09-19 20:54:04
📝 Summary: The elections.k8s.io application used a weak Flask SECRET KEY, the string "N/A", to sign authentication cookies. This allowed the complete compromise of the application, as the session could be manipulated.
📂 Report JSON File: 1387366
@hackeronereports
🔺Severity: High
👽 Reporter: ian
⭐️ Reputation: 6661
🛠 State: resolved
💼 Team: Kubernetes
💵 Bounty: 250
🕐 Submitted: 2021-11-01
⏰ Disclosed: 2025-09-19 20:54:04
📝 Summary: The elections.k8s.io application used a weak Flask SECRET KEY, the string "N/A", to sign authentication cookies. This allowed the complete compromise of the application, as the session could be manipulated.
📂 Report JSON File: 1387366
@hackeronereports
🎯 New Report #1392262: Stored XSS via LINK Name.
🔺Severity: High
👽 Reporter: xploiterr
⭐️ Reputation: 34724
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2021-11-05
⏰ Disclosed: 2025-09-23 12:17:34
📝 Summary: The LINK NAME was not properly escaped at the Templates page, leading to Stored XSS. The name was reflected in the <script> tag, and due to lack of sanitization, the user could break out of the tag and execute the XSS.
📂 Report JSON File: 1392262
@hackeronereports
🔺Severity: High
👽 Reporter: xploiterr
⭐️ Reputation: 34724
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2021-11-05
⏰ Disclosed: 2025-09-23 12:17:34
📝 Summary: The LINK NAME was not properly escaped at the Templates page, leading to Stored XSS. The name was reflected in the <script> tag, and due to lack of sanitization, the user could break out of the tag and execute the XSS.
📂 Report JSON File: 1392262
@hackeronereports
🎯 New Report #3124517: Arbitrary Read of Another Users private repository without Authorization
🔺Severity: High
👽 Reporter: furbreeze
⭐️ Reputation: 164
🛠 State: resolved
💼 Team: GitHub
💵 Bounty: 10000
🕐 Submitted: 2025-05-03
⏰ Disclosed: 2025-09-23 22:18:14
📝 Summary: An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18, and was fixed in versions 3.14.17, 3.15.12, 3.16.8 and 3.17.5.
📂 Report JSON File: 3124517
@hackeronereports
🔺Severity: High
👽 Reporter: furbreeze
⭐️ Reputation: 164
🛠 State: resolved
💼 Team: GitHub
💵 Bounty: 10000
🕐 Submitted: 2025-05-03
⏰ Disclosed: 2025-09-23 22:18:14
📝 Summary: An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18, and was fixed in versions 3.14.17, 3.15.12, 3.16.8 and 3.17.5.
📂 Report JSON File: 3124517
@hackeronereports
🎯 New Report #2919216: XSS1
🔺Severity: None
👽 Reporter: admin097
⭐️ Reputation: 525
🛠 State: resolved
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-01-01
⏰ Disclosed: 2025-09-24 16:49:59
📝 Summary: The XSS vulnerability was discovered in the search functionality of the Informatica website. The vulnerability allowed an attacker to inject arbitrary JavaScript code into the search results, which could be executed by the user's browser.
📂 Report JSON File: 2919216
@hackeronereports
🔺Severity: None
👽 Reporter: admin097
⭐️ Reputation: 525
🛠 State: resolved
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-01-01
⏰ Disclosed: 2025-09-24 16:49:59
📝 Summary: The XSS vulnerability was discovered in the search functionality of the Informatica website. The vulnerability allowed an attacker to inject arbitrary JavaScript code into the search results, which could be executed by the user's browser.
📂 Report JSON File: 2919216
@hackeronereports
🎯 New Report #2311179: Information Exposure Through Directory Listing
🔺Severity: Medium
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-01-10
⏰ Disclosed: 2025-09-29 15:53:50
📝 Summary: The web server was configured to display a list of files contained in the directory. This is not recommended as the directory may have contained files that were not normally exposed through links on the website.
📂 Report JSON File: 2311179
@hackeronereports
🔺Severity: Medium
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-01-10
⏰ Disclosed: 2025-09-29 15:53:50
📝 Summary: The web server was configured to display a list of files contained in the directory. This is not recommended as the directory may have contained files that were not normally exposed through links on the website.
📂 Report JSON File: 2311179
@hackeronereports
🎯 New Report #2305880: Email not verified when changing afterwards on apps.nextcloud.com
🔺Severity: Low
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-01-06
⏰ Disclosed: 2025-09-29 15:50:37
📝 Summary: The email verification bypass vulnerability was discovered in the web application apps.nextcloud.com. The vulnerability allowed attackers to create accounts with any email address without verification, effectively taking over victim accounts.
📂 Report JSON File: 2305880
@hackeronereports
🔺Severity: Low
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-01-06
⏰ Disclosed: 2025-09-29 15:50:37
📝 Summary: The email verification bypass vulnerability was discovered in the web application apps.nextcloud.com. The vulnerability allowed attackers to create accounts with any email address without verification, effectively taking over victim accounts.
📂 Report JSON File: 2305880
@hackeronereports
🎯 New Report #2778441: Exposing debug.log file leads to server full path disclosure
🔺Severity: Medium
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-10-12
⏰ Disclosed: 2025-09-29 15:50:22
📝 Summary: The debug.log file on the nextcloud.com website was publicly accessible and contained sensitive information, including the server's full directory path. This type of information disclosure could have assisted attackers in understanding the internal structure of the server.
📂 Report JSON File: 2778441
@hackeronereports
🔺Severity: Medium
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-10-12
⏰ Disclosed: 2025-09-29 15:50:22
📝 Summary: The debug.log file on the nextcloud.com website was publicly accessible and contained sensitive information, including the server's full directory path. This type of information disclosure could have assisted attackers in understanding the internal structure of the server.
📂 Report JSON File: 2778441
@hackeronereports
🎯 New Report #3211031: `use-mcp`'s oauth2 process uses a window.open call with untrusted mcp server provided data allowing for code execution under the page using it
🔺Severity: Medium
👽 Reporter: null smashmaster0045
⭐️ Reputation: 225
🛠 State: resolved
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: 550
🕐 Submitted: 2025-06-19
⏰ Disclosed: 2025-09-30 08:15:45
📝 Summary: The
📂 Report JSON File: 3211031
@hackeronereports
🔺Severity: Medium
👽 Reporter: null smashmaster0045
⭐️ Reputation: 225
🛠 State: resolved
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: 550
🕐 Submitted: 2025-06-19
⏰ Disclosed: 2025-09-30 08:15:45
📝 Summary: The
authorizeEndpoint parameter from use-mcp version was susceptible to XSS. Sanitization of that parameter was added in version 0.0.10 of use-mcp. A skilled attacker was able to turn this XSS into code execution on the client.📂 Report JSON File: 3211031
@hackeronereports
🎯 New Report #1920908: Access to the personal emails of Rockstar Support agents through the support platform
🔺Severity: Low
👽 Reporter: gavinmartinwv
⭐️ Reputation: 176
🛠 State: resolved
💼 Team: Rockstar Games
💵 Bounty: 550
🕐 Submitted: 2023-03-28
⏰ Disclosed: 2025-10-02 18:08:44
📝 Summary: The researcher identified a flaw in the Zendesk configuration on the Rockstar Games support platform that could allow users to access the business emails of support agents as well as other non-customer facing information. The issue was resolved earlier this year when the support site was overhauled.
📂 Report JSON File: 1920908
@hackeronereports
🔺Severity: Low
👽 Reporter: gavinmartinwv
⭐️ Reputation: 176
🛠 State: resolved
💼 Team: Rockstar Games
💵 Bounty: 550
🕐 Submitted: 2023-03-28
⏰ Disclosed: 2025-10-02 18:08:44
📝 Summary: The researcher identified a flaw in the Zendesk configuration on the Rockstar Games support platform that could allow users to access the business emails of support agents as well as other non-customer facing information. The issue was resolved earlier this year when the support site was overhauled.
📂 Report JSON File: 1920908
@hackeronereports
🎯 New Report #3226838: Exceeding the limit of Workspaces via Race Condition
🔺Severity: Medium
👽 Reporter: 4x4
⭐️ Reputation: 446
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-06-27
⏰ Disclosed: 2025-10-06 09:17:21
📝 Summary: The reporter discovered a race condition vulnerability in backend.singlestore.com that allowed free-tier users to bypass the 5-workspace limit by sending multiple simultaneous CreateWorkspace requests. This issue was patched by SingleStore as of October 3rd, 2025.
📂 Report JSON File: 3226838
@hackeronereports
🔺Severity: Medium
👽 Reporter: 4x4
⭐️ Reputation: 446
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-06-27
⏰ Disclosed: 2025-10-06 09:17:21
📝 Summary: The reporter discovered a race condition vulnerability in backend.singlestore.com that allowed free-tier users to bypass the 5-workspace limit by sending multiple simultaneous CreateWorkspace requests. This issue was patched by SingleStore as of October 3rd, 2025.
📂 Report JSON File: 3226838
@hackeronereports
🎯 New Report #3303136: Pending invites remain valid even after the inviter is removed.
🔺Severity: High
👽 Reporter: mantu1738
⭐️ Reputation: 116
🛠 State: resolved
💼 Team: Omise
💵 Bounty: null
🕐 Submitted: 2025-08-18
⏰ Disclosed: 2025-10-08 03:51:16
📝 Summary: The pending invites created by a removed admin remained valid, and members already added by the removed admin remained in the team with admin privileges, even after the inviter was removed.
📂 Report JSON File: 3303136
@hackeronereports
🔺Severity: High
👽 Reporter: mantu1738
⭐️ Reputation: 116
🛠 State: resolved
💼 Team: Omise
💵 Bounty: null
🕐 Submitted: 2025-08-18
⏰ Disclosed: 2025-10-08 03:51:16
📝 Summary: The pending invites created by a removed admin remained valid, and members already added by the removed admin remained in the team with admin privileges, even after the inviter was removed.
📂 Report JSON File: 3303136
@hackeronereports
🎯 New Report #3176157: DNS Rebinding SSRF in Burp Suite MCP Server Enables Internal Network Access via send http1 request Tool
🔺Severity: None
👽 Reporter: farmer
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: PortSwigger Web Security
💵 Bounty: 2000
🕐 Submitted: 2025-06-03
⏰ Disclosed: 2025-10-08 14:26:27
📝 Summary: The Burp Suite MCP (Model Context Protocol) server was vulnerable to a DNS rebinding attack. This allowed malicious websites to connect to the victim's local MCP server, use the send http1 request tool to make arbitrary HTTP requests, and access internal networks, localhost services, and cloud metadata endpoints. The vulnerability was caused by the lack of proper origin validation and CORS protection in the MCP server.
📂 Report JSON File: 3176157
@hackeronereports
🔺Severity: None
👽 Reporter: farmer
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: PortSwigger Web Security
💵 Bounty: 2000
🕐 Submitted: 2025-06-03
⏰ Disclosed: 2025-10-08 14:26:27
📝 Summary: The Burp Suite MCP (Model Context Protocol) server was vulnerable to a DNS rebinding attack. This allowed malicious websites to connect to the victim's local MCP server, use the send http1 request tool to make arbitrary HTTP requests, and access internal networks, localhost services, and cloud metadata endpoints. The vulnerability was caused by the lack of proper origin validation and CORS protection in the MCP server.
📂 Report JSON File: 3176157
@hackeronereports
🎯 New Report #3367292: CSRF allowing unauthorized modification of user Notes on ███████
🔺Severity: Low
👽 Reporter: kanon4
⭐️ Reputation: 742
🛠 State: resolved
💼 Team: Tucows (VDP)
💵 Bounty: null
🕐 Submitted: 2025-10-02
⏰ Disclosed: 2025-10-10 18:37:09
📝 Summary: A CSRF vulnerability was discovered that allowed unauthorized modification of user notes. The vulnerability was present in the endpoint that handled saving the notes. The endpoint did not implement proper CSRF protection, allowing an attacker to craft a malicious link that could be used to modify or delete the victim's notes. The complexity of the attack was that the attacker needed to be a member of the same organization as the victim in order to obtain the victim's correct ID, which was required to carry out the attack.
📂 Report JSON File: 3367292
@hackeronereports
🔺Severity: Low
👽 Reporter: kanon4
⭐️ Reputation: 742
🛠 State: resolved
💼 Team: Tucows (VDP)
💵 Bounty: null
🕐 Submitted: 2025-10-02
⏰ Disclosed: 2025-10-10 18:37:09
📝 Summary: A CSRF vulnerability was discovered that allowed unauthorized modification of user notes. The vulnerability was present in the endpoint that handled saving the notes. The endpoint did not implement proper CSRF protection, allowing an attacker to craft a malicious link that could be used to modify or delete the victim's notes. The complexity of the attack was that the attacker needed to be a member of the same organization as the victim in order to obtain the victim's correct ID, which was required to carry out the attack.
📂 Report JSON File: 3367292
@hackeronereports
🎯 New Report #3255910: Vulnerability: XML-RPC Interface Enabled and Accessible
🔺Severity: null
👽 Reporter: emad2466
⭐️ Reputation: 100
🛠 State: informative
💼 Team: Tucows (VDP)
💵 Bounty: null
🕐 Submitted: 2025-07-16
⏰ Disclosed: 2025-10-10 18:24:26
📝 Summary: null
📂 Report JSON File: 3255910
@hackeronereports
🔺Severity: null
👽 Reporter: emad2466
⭐️ Reputation: 100
🛠 State: informative
💼 Team: Tucows (VDP)
💵 Bounty: null
🕐 Submitted: 2025-07-16
⏰ Disclosed: 2025-10-10 18:24:26
📝 Summary: null
📂 Report JSON File: 3255910
@hackeronereports
🎯 New Report #3253725: SameSite restrictions are lifted, and SameSite:Strict cookie are being sent.
🔺Severity: High
👽 Reporter: mingijung
⭐️ Reputation: 250
🛠 State: resolved
💼 Team: Brave Software
💵 Bounty: 500
🕐 Submitted: 2025-07-15
⏰ Disclosed: 2025-10-15 05:41:30
📝 Summary: A vulnerability was discovered where SameSite=Strict cookies were being sent during cross-site navigations, even though they should have been restricted under the SameSite policy. This was caused by the absence of the Sec-Fetch-Site: cross-site header, which is normally used to prevent such bypasses and protect against CSRF attacks. The issue was reported to have been observed in Brave browser version 1.80.120 during a window operation.
📂 Report JSON File: 3253725
@hackeronereports
🔺Severity: High
👽 Reporter: mingijung
⭐️ Reputation: 250
🛠 State: resolved
💼 Team: Brave Software
💵 Bounty: 500
🕐 Submitted: 2025-07-15
⏰ Disclosed: 2025-10-15 05:41:30
📝 Summary: A vulnerability was discovered where SameSite=Strict cookies were being sent during cross-site navigations, even though they should have been restricted under the SameSite policy. This was caused by the absence of the Sec-Fetch-Site: cross-site header, which is normally used to prevent such bypasses and protect against CSRF attacks. The issue was reported to have been observed in Brave browser version 1.80.120 during a window operation.
📂 Report JSON File: 3253725
@hackeronereports
🎯 New Report #3313408: OneAgent Unprivileged NTLM User Coercion
🔺Severity: Medium
👽 Reporter: remiec
⭐️ Reputation: 122
🛠 State: resolved
💼 Team: Dynatrace
💵 Bounty: 750
🕐 Submitted: 2025-08-25
⏰ Disclosed: 2025-10-15 08:01:47
📝 Summary: null
📂 Report JSON File: 3313408
@hackeronereports
🔺Severity: Medium
👽 Reporter: remiec
⭐️ Reputation: 122
🛠 State: resolved
💼 Team: Dynatrace
💵 Bounty: 750
🕐 Submitted: 2025-08-25
⏰ Disclosed: 2025-10-15 08:01:47
📝 Summary: null
📂 Report JSON File: 3313408
@hackeronereports
🎯 New Report #3249624: Path Traversal Vulnerability in Nextcloud Tables Enables Arbitrary File Exfiltration of Any Files Supported by PhpSpreadsheet Library
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 391
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 750
🕐 Submitted: 2025-07-13
⏰ Disclosed: 2025-10-16 06:52:20
📝 Summary: A path traversal vulnerability was discovered in Nextcloud Tables. This vulnerability allowed the exfiltration of any files supported by the PhpSpreadsheet library.
📂 Report JSON File: 3249624
@hackeronereports
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 391
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 750
🕐 Submitted: 2025-07-13
⏰ Disclosed: 2025-10-16 06:52:20
📝 Summary: A path traversal vulnerability was discovered in Nextcloud Tables. This vulnerability allowed the exfiltration of any files supported by the PhpSpreadsheet library.
📂 Report JSON File: 3249624
@hackeronereports
🎯 New Report #3104356: Blu-ray Disc Java Sandbox Escape via two vulnerabilities
🔺Severity: Medium
👽 Reporter: theflow0
⭐️ Reputation: 657
🛠 State: resolved
💼 Team: PlayStation
💵 Bounty: 5000
🕐 Submitted: 2025-04-22
⏰ Disclosed: 2025-10-18 00:35:23
📝 Summary: Two vulnerabilities in Blu-ray Disc Java (bd-j) related to the Inter-Xlet Communication (Ixc) implementation were discovered. The first vulnerability allowed invoking methods in privileged context by registering a remote object that implements an interface extending java.rmi.Remote. The second vulnerability enabled privileged method invocation by setting a custom method in the stub class generated for remote object registration. Together, these vulnerabilities could be exploited to disable the Java sandbox.
📂 Report JSON File: 3104356
@hackeronereports
🔺Severity: Medium
👽 Reporter: theflow0
⭐️ Reputation: 657
🛠 State: resolved
💼 Team: PlayStation
💵 Bounty: 5000
🕐 Submitted: 2025-04-22
⏰ Disclosed: 2025-10-18 00:35:23
📝 Summary: Two vulnerabilities in Blu-ray Disc Java (bd-j) related to the Inter-Xlet Communication (Ixc) implementation were discovered. The first vulnerability allowed invoking methods in privileged context by registering a remote object that implements an interface extending java.rmi.Remote. The second vulnerability enabled privileged method invocation by setting a custom method in the stub class generated for remote object registration. Together, these vulnerabilities could be exploited to disable the Java sandbox.
📂 Report JSON File: 3104356
@hackeronereports
🎯 New Report #3058919: Application Level DoS - Large Markdown Payload in Reply Section Leading to Resource Exhaustion
🔺Severity: High
👽 Reporter: theteatoast
⭐️ Reputation: 356
🛠 State: resolved
💼 Team: Discourse
💵 Bounty: null
🕐 Submitted: 2025-03-25
⏰ Disclosed: 2025-10-18 16:47:02
📝 Summary: A Denial of Service (DoS) vulnerability was identified in the reply section of the web application. Submitting an excessively large markup payload (approximately 800,000 characters) resulted in the server taking 30 seconds to respond before returning an HTTP/2 502 Bad Gateway error, indicating potential resource exhaustion or backend service failure.
📂 Report JSON File: 3058919
@hackeronereports
🔺Severity: High
👽 Reporter: theteatoast
⭐️ Reputation: 356
🛠 State: resolved
💼 Team: Discourse
💵 Bounty: null
🕐 Submitted: 2025-03-25
⏰ Disclosed: 2025-10-18 16:47:02
📝 Summary: A Denial of Service (DoS) vulnerability was identified in the reply section of the web application. Submitting an excessively large markup payload (approximately 800,000 characters) resulted in the server taking 30 seconds to respond before returning an HTTP/2 502 Bad Gateway error, indicating potential resource exhaustion or backend service failure.
📂 Report JSON File: 3058919
@hackeronereports
🎯 New Report #3383095: DNS Rebinding Attack
🔺Severity: Critical
👽 Reporter: newby99
⭐️ Reputation: 178
🛠 State: informative
💼 Team: arkadiyt-projects
💵 Bounty: null
🕐 Submitted: 2025-10-14
⏰ Disclosed: 2025-10-19 21:33:19
📝 Summary: null
📂 Report JSON File: 3383095
@hackeronereports
🔺Severity: Critical
👽 Reporter: newby99
⭐️ Reputation: 178
🛠 State: informative
💼 Team: arkadiyt-projects
💵 Bounty: null
🕐 Submitted: 2025-10-14
⏰ Disclosed: 2025-10-19 21:33:19
📝 Summary: null
📂 Report JSON File: 3383095
@hackeronereports