🎯 New Report #3091390: Reflected Cross-Site Scripting (XSS) in Revive Adserver 5.5.2
🔺Severity: Medium
👽 Reporter: env bak
⭐️ Reputation: 104
🛠 State: resolved
💼 Team: Revive Adserver
💵 Bounty: null
🕐 Submitted: 2025-04-14
⏰ Disclosed: 2025-10-22 09:54:05
📝 Summary: null
📂 Report JSON File: 3091390
@hackeronereports
🔺Severity: Medium
👽 Reporter: env bak
⭐️ Reputation: 104
🛠 State: resolved
💼 Team: Revive Adserver
💵 Bounty: null
🕐 Submitted: 2025-04-14
⏰ Disclosed: 2025-10-22 09:54:05
📝 Summary: null
📂 Report JSON File: 3091390
@hackeronereports
🎯 New Report #3393539: Memory leak in Curl auth create ntlm type3 message
🔺Severity: Low
👽 Reporter: tjbecker theori
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-10-21
⏰ Disclosed: 2025-10-28 14:48:40
📝 Summary: null
📂 Report JSON File: 3393539
@hackeronereports
🔺Severity: Low
👽 Reporter: tjbecker theori
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-10-21
⏰ Disclosed: 2025-10-28 14:48:40
📝 Summary: null
📂 Report JSON File: 3393539
@hackeronereports
🎯 New Report #268221: No Confirmation Email For Email Change
🔺Severity: Low
👽 Reporter: craxermgr
⭐️ Reputation: 105
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-09-14
⏰ Disclosed: 2025-10-31 17:38:56
📝 Summary: null
📂 Report JSON File: 268221
@hackeronereports
🔺Severity: Low
👽 Reporter: craxermgr
⭐️ Reputation: 105
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-09-14
⏰ Disclosed: 2025-10-31 17:38:56
📝 Summary: null
📂 Report JSON File: 268221
@hackeronereports
🎯 New Report #268224: Information Disclosure
🔺Severity: Medium
👽 Reporter: craxermgr
⭐️ Reputation: 105
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-09-14
⏰ Disclosed: 2025-10-31 17:34:26
📝 Summary: null
📂 Report JSON File: 268224
@hackeronereports
🔺Severity: Medium
👽 Reporter: craxermgr
⭐️ Reputation: 105
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-09-14
⏰ Disclosed: 2025-10-31 17:34:26
📝 Summary: null
📂 Report JSON File: 268224
@hackeronereports
🎯 New Report #300164: REDIRECTION VULNERABILITY/HOST HEADER INJECTION VULNERABILITY
🔺Severity: Medium
👽 Reporter: vyshnav nk
⭐️ Reputation: 50
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-12-23
⏰ Disclosed: 2025-10-31 17:33:52
📝 Summary: null
📂 Report JSON File: 300164
@hackeronereports
🔺Severity: Medium
👽 Reporter: vyshnav nk
⭐️ Reputation: 50
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-12-23
⏰ Disclosed: 2025-10-31 17:33:52
📝 Summary: null
📂 Report JSON File: 300164
@hackeronereports
🎯 New Report #304073: Missing restriction on string size of Full Name at browser.blockstack.org
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-01-11
⏰ Disclosed: 2025-10-31 17:33:31
📝 Summary: null
📂 Report JSON File: 304073
@hackeronereports
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-01-11
⏰ Disclosed: 2025-10-31 17:33:31
📝 Summary: null
📂 Report JSON File: 304073
@hackeronereports
🎯 New Report #377565: Can view all username leaked in https://core.blockstack.org
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-07-05
⏰ Disclosed: 2025-10-31 17:32:59
📝 Summary: null
📂 Report JSON File: 377565
@hackeronereports
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-07-05
⏰ Disclosed: 2025-10-31 17:32:59
📝 Summary: null
📂 Report JSON File: 377565
@hackeronereports
🎯 New Report #716647: Invalidate active sessions after password change
🔺Severity: Low
👽 Reporter: droop3r
⭐️ Reputation: 251
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-10-17
⏰ Disclosed: 2025-10-31 17:32:49
📝 Summary: null
📂 Report JSON File: 716647
@hackeronereports
🔺Severity: Low
👽 Reporter: droop3r
⭐️ Reputation: 251
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-10-17
⏰ Disclosed: 2025-10-31 17:32:49
📝 Summary: null
📂 Report JSON File: 716647
@hackeronereports
🎯 New Report #910732: blockstack.org - is vulnerable to (CVE-2016-2183, CVE-2016-6329)
🔺Severity: None
👽 Reporter: 0x1 aulia
⭐️ Reputation: 93
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2020-06-29
⏰ Disclosed: 2025-10-31 17:32:21
📝 Summary: null
📂 Report JSON File: 910732
@hackeronereports
🔺Severity: None
👽 Reporter: 0x1 aulia
⭐️ Reputation: 93
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2020-06-29
⏰ Disclosed: 2025-10-31 17:32:21
📝 Summary: null
📂 Report JSON File: 910732
@hackeronereports
🎯 New Report #541760: Blockstack Browser For Mac leaks "Core API Password" to 3rd parties
🔺Severity: Low
👽 Reporter: frozensolid
⭐️ Reputation: 673
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-04-18
⏰ Disclosed: 2025-10-31 17:32:08
📝 Summary: null
📂 Report JSON File: 541760
@hackeronereports
🔺Severity: Low
👽 Reporter: frozensolid
⭐️ Reputation: 673
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-04-18
⏰ Disclosed: 2025-10-31 17:32:08
📝 Summary: null
📂 Report JSON File: 541760
@hackeronereports
🎯 New Report #3062299: Logout Bypass Vulnerability in Hiro.so
🔺Severity: Medium
👽 Reporter: anonymous--1000
⭐️ Reputation: 97
🛠 State: informative
💼 Team: Hiro
💵 Bounty: 150
🕐 Submitted: 2025-03-27
⏰ Disclosed: 2025-10-31 17:31:10
📝 Summary: null
📂 Report JSON File: 3062299
@hackeronereports
🔺Severity: Medium
👽 Reporter: anonymous--1000
⭐️ Reputation: 97
🛠 State: informative
💼 Team: Hiro
💵 Bounty: 150
🕐 Submitted: 2025-03-27
⏰ Disclosed: 2025-10-31 17:31:10
📝 Summary: null
📂 Report JSON File: 3062299
@hackeronereports
🎯 New Report #3243860: Microsoft `x-apikey` Exposed in Mozilla CI Public Logs
🔺Severity: Medium
👽 Reporter: xhacking z
⭐️ Reputation: 358
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: 200
🕐 Submitted: 2025-07-09
⏰ Disclosed: 2025-11-03 10:34:21
📝 Summary: A Microsoft telemetry API key (x-apikey) was found exposed in publicly accessible Mozilla CI logs. The key appeared in HTTP POST requests sent to Microsoft's telemetry endpoint during automated Firefox testing and was captured via mitmproxy logs. The security impact was considered minimal as the telemetry API key had limited functionality. The report was accepted and a bonus was paid as recognition of the reporter's efforts.
📂 Report JSON File: 3243860
@hackeronereports
🔺Severity: Medium
👽 Reporter: xhacking z
⭐️ Reputation: 358
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: 200
🕐 Submitted: 2025-07-09
⏰ Disclosed: 2025-11-03 10:34:21
📝 Summary: A Microsoft telemetry API key (x-apikey) was found exposed in publicly accessible Mozilla CI logs. The key appeared in HTTP POST requests sent to Microsoft's telemetry endpoint during automated Firefox testing and was captured via mitmproxy logs. The security impact was considered minimal as the telemetry API key had limited functionality. The report was accepted and a bonus was paid as recognition of the reporter's efforts.
📂 Report JSON File: 3243860
@hackeronereports
🎯 New Report #3371414: Improper Authorization Leads to Editor can toggle admin-only workspace features (Lovable Cloud)
🔺Severity: Low
👽 Reporter: d0maxploit
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-05
⏰ Disclosed: 2025-11-04 20:32:59
📝 Summary: A vulnerability was discovered where an account with the Editor role could call an API endpoint that disabled workspace-wide admin-only features. This was due to a lack of server-side role checks, allowing a vertical privilege escalation.
📂 Report JSON File: 3371414
@hackeronereports
🔺Severity: Low
👽 Reporter: d0maxploit
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-05
⏰ Disclosed: 2025-11-04 20:32:59
📝 Summary: A vulnerability was discovered where an account with the Editor role could call an API endpoint that disabled workspace-wide admin-only features. This was due to a lack of server-side role checks, allowing a vertical privilege escalation.
📂 Report JSON File: 3371414
@hackeronereports
🎯 New Report #3371448: Improper Authorization Leads to Editor can toggle admin-only workspace features (Lovable AI)
🔺Severity: Low
👽 Reporter: d0maxploit
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-05
⏰ Disclosed: 2025-11-04 22:54:23
📝 Summary: The API endpoint /workspaces/<WORKSPACE ID>/tool-preferences/ai gateway/enable did not enforce proper authorization checks. As a result, an account with the Editor role was able to disable the workspace-wide admin-only Lovable AI feature, which powers key AI functionalities across the workspace.
📂 Report JSON File: 3371448
@hackeronereports
🔺Severity: Low
👽 Reporter: d0maxploit
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-05
⏰ Disclosed: 2025-11-04 22:54:23
📝 Summary: The API endpoint /workspaces/<WORKSPACE ID>/tool-preferences/ai gateway/enable did not enforce proper authorization checks. As a result, an account with the Editor role was able to disable the workspace-wide admin-only Lovable AI feature, which powers key AI functionalities across the workspace.
📂 Report JSON File: 3371448
@hackeronereports
🎯 New Report #3355218: CVE-2025-10966: missing SFTP host verification with wolfSSH
🔺Severity: Low
👽 Reporter: giant anteater
⭐️ Reputation: 123
🛠 State: resolved
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-23
⏰ Disclosed: 2025-11-05 21:57:54
📝 Summary: null
📂 Report JSON File: 3355218
@hackeronereports
🔺Severity: Low
👽 Reporter: giant anteater
⭐️ Reputation: 123
🛠 State: resolved
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-23
⏰ Disclosed: 2025-11-05 21:57:54
📝 Summary: null
📂 Report JSON File: 3355218
@hackeronereports
🎯 New Report #3335709: SQL Injection in Django ORM via Unvalidated ` connector` in Q Objects
🔺Severity: Critical
👽 Reporter: cyberstan
⭐️ Reputation: 92
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-09-12
⏰ Disclosed: 2025-11-06 21:09:42
📝 Summary: A critical SQL injection vulnerability was discovered in the Django ORM's handling of Q objects. The internal WhereNode.as sql method used unsafe string formatting to inject the query connector, which could be controlled by an attacker through the connector key when creating a Q object. This allowed arbitrary SQL to be injected into the WHERE clause, bypassing the ORM's parameterization safeguards.
📂 Report JSON File: 3335709
@hackeronereports
🔺Severity: Critical
👽 Reporter: cyberstan
⭐️ Reputation: 92
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-09-12
⏰ Disclosed: 2025-11-06 21:09:42
📝 Summary: A critical SQL injection vulnerability was discovered in the Django ORM's handling of Q objects. The internal WhereNode.as sql method used unsafe string formatting to inject the query connector, which could be controlled by an attacker through the connector key when creating a Q object. This allowed arbitrary SQL to be injected into the WHERE clause, bypassing the ORM's parameterization safeguards.
📂 Report JSON File: 3335709
@hackeronereports
🎯 New Report #3369843: Low-privileged user can enable or disable Lovable AI for new projects in workspace
🔺Severity: Low
👽 Reporter: anxioussick
⭐️ Reputation: 129
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-03
⏰ Disclosed: 2025-11-07 03:52:10
📝 Summary: A vulnerability was discovered that allowed low-privileged users to enable or disable Lovable AI for new projects in a workspace. The vulnerability was caused by improper authorization, which enabled low-privileged users to modify the Lovable AI settings by replaying certain API endpoints.
📂 Report JSON File: 3369843
@hackeronereports
🔺Severity: Low
👽 Reporter: anxioussick
⭐️ Reputation: 129
🛠 State: resolved
💼 Team: Lovable VDP
💵 Bounty: null
🕐 Submitted: 2025-10-03
⏰ Disclosed: 2025-11-07 03:52:10
📝 Summary: A vulnerability was discovered that allowed low-privileged users to enable or disable Lovable AI for new projects in a workspace. The vulnerability was caused by improper authorization, which enabled low-privileged users to modify the Lovable AI settings by replaying certain API endpoints.
📂 Report JSON File: 3369843
@hackeronereports
🎯 New Report #3378635: Unauthorized Password Reset Allows Account Takeover Across Tenant Boundaries
🔺Severity: High
👽 Reporter: mcdave
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: lemlist
💵 Bounty: null
🕐 Submitted: 2025-10-10
⏰ Disclosed: 2025-11-07 09:33:24
📝 Summary: An authorization issue was discovered in the application that allowed a tenant admin to change the password of another user within the same tenant, including invited agency accounts. The victim had to first accept the invitation before the attacker could proceed. The issue could allow unintended account access within a shared tenant environment, but multi-factor authentication successfully prevented logins when enabled. The issue was reported to the vendor and addressed to ensure stricter access controls for user credential changes.
📂 Report JSON File: 3378635
@hackeronereports
🔺Severity: High
👽 Reporter: mcdave
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: lemlist
💵 Bounty: null
🕐 Submitted: 2025-10-10
⏰ Disclosed: 2025-11-07 09:33:24
📝 Summary: An authorization issue was discovered in the application that allowed a tenant admin to change the password of another user within the same tenant, including invited agency accounts. The victim had to first accept the invitation before the attacker could proceed. The issue could allow unintended account access within a shared tenant environment, but multi-factor authentication successfully prevented logins when enabled. The issue was reported to the vendor and addressed to ensure stricter access controls for user credential changes.
📂 Report JSON File: 3378635
@hackeronereports
🎯 New Report #3414088: SMTP CRLF Command Injection in CURLOPT MAIL FROM and CURLOPT MAIL RCPT
🔺Severity: Medium
👽 Reporter: bau1u
⭐️ Reputation: 116
🛠 State: duplicate
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-06
⏰ Disclosed: 2025-11-10 10:39:03
📝 Summary: null
📂 Report JSON File: 3414088
@hackeronereports
🔺Severity: Medium
👽 Reporter: bau1u
⭐️ Reputation: 116
🛠 State: duplicate
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-06
⏰ Disclosed: 2025-11-10 10:39:03
📝 Summary: null
📂 Report JSON File: 3414088
@hackeronereports
🎯 New Report #3417428: libcurl MQTT `CURLOPT POSTFIELDSIZE LARGE` overflow leads to immediate DoS
🔺Severity: Medium
👽 Reporter: jiyong
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-09
⏰ Disclosed: 2025-11-10 15:00:34
📝 Summary: null
📂 Report JSON File: 3417428
@hackeronereports
🔺Severity: Medium
👽 Reporter: jiyong
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-09
⏰ Disclosed: 2025-11-10 15:00:34
📝 Summary: null
📂 Report JSON File: 3417428
@hackeronereports
🎯 New Report #3079738: Two click Account Takeover
🔺Severity: High
👽 Reporter: fr4via
⭐️ Reputation: 11240
🛠 State: resolved
💼 Team: Basecamp
💵 Bounty: null
🕐 Submitted: 2025-04-06
⏰ Disclosed: 2025-11-11 09:14:15
📝 Summary: A vulnerability was discovered in the HEY Email Android application that allowed for a two-click account takeover. Improper handling of incoming deeplinks led to the application's authorization bearer token being sent to an attacker-controlled server if the user could be tricked into clicking a link and then performing an Undo action.
📂 Report JSON File: 3079738
@hackeronereports
🔺Severity: High
👽 Reporter: fr4via
⭐️ Reputation: 11240
🛠 State: resolved
💼 Team: Basecamp
💵 Bounty: null
🕐 Submitted: 2025-04-06
⏰ Disclosed: 2025-11-11 09:14:15
📝 Summary: A vulnerability was discovered in the HEY Email Android application that allowed for a two-click account takeover. Improper handling of incoming deeplinks led to the application's authorization bearer token being sent to an attacker-controlled server if the user could be tricked into clicking a link and then performing an Undo action.
📂 Report JSON File: 3079738
@hackeronereports