🎯 New Report #3334165: Nextcloud Tables v1 Share Enumeration Without Authorization (Regression of CVE-2024-52507)
🔺Severity: Low
👽 Reporter: 0x0doteth
⭐️ Reputation: 524
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2025-09-11
⏰ Disclosed: 2025-12-05 08:10:11
📝 Summary: A vulnerability was discovered in Nextcloud Tables v1 that allowed unauthorized users to enumerate shares. The vulnerability was a regression of a previously addressed issue, CVE-2024-52507.
📂 Report JSON File: 3334165
@hackeronereports
🔺Severity: Low
👽 Reporter: 0x0doteth
⭐️ Reputation: 524
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2025-09-11
⏰ Disclosed: 2025-12-05 08:10:11
📝 Summary: A vulnerability was discovered in Nextcloud Tables v1 that allowed unauthorized users to enumerate shares. The vulnerability was a regression of a previously addressed issue, CVE-2024-52507.
📂 Report JSON File: 3334165
@hackeronereports
🎯 New Report #3357808: Stored XSS Vulnerability via SVG File
🔺Severity: Medium
👽 Reporter: aptroom
⭐️ Reputation: 122
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 150
🕐 Submitted: 2025-09-25
⏰ Disclosed: 2025-12-05 10:33:23
📝 Summary: A stored XSS vulnerability was discovered in Nextcloud related to the handling of SVG files. The vulnerability allowed the execution of arbitrary JavaScript code.
📂 Report JSON File: 3357808
@hackeronereports
🔺Severity: Medium
👽 Reporter: aptroom
⭐️ Reputation: 122
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 150
🕐 Submitted: 2025-09-25
⏰ Disclosed: 2025-12-05 10:33:23
📝 Summary: A stored XSS vulnerability was discovered in Nextcloud related to the handling of SVG files. The vulnerability allowed the execution of arbitrary JavaScript code.
📂 Report JSON File: 3357808
@hackeronereports
🎯 New Report #3452015: Unauthenticated GraphQL access by prepending schema to private operations
🔺Severity: Medium
👽 Reporter: pwnie
⭐️ Reputation: 1844
🛠 State: resolved
💼 Team: Enjin
💵 Bounty: null
🕐 Submitted: 2025-12-04
⏰ Disclosed: 2025-12-05 15:10:45
📝 Summary: A security vulnerability was identified in the GraphQL schema of the Enjin Platform. The vulnerability allowed unauthorized access to the GraphQL schema by prepending " schema" to private operations. The vulnerability was discovered and reported by a security researcher. The specific location of the vulnerability within the platform-core repository was identified, and a fix was subsequently implemented to address the issue.
📂 Report JSON File: 3452015
@hackeronereports
🔺Severity: Medium
👽 Reporter: pwnie
⭐️ Reputation: 1844
🛠 State: resolved
💼 Team: Enjin
💵 Bounty: null
🕐 Submitted: 2025-12-04
⏰ Disclosed: 2025-12-05 15:10:45
📝 Summary: A security vulnerability was identified in the GraphQL schema of the Enjin Platform. The vulnerability allowed unauthorized access to the GraphQL schema by prepending " schema" to private operations. The vulnerability was discovered and reported by a security researcher. The specific location of the vulnerability within the platform-core repository was identified, and a fix was subsequently implemented to address the issue.
📂 Report JSON File: 3452015
@hackeronereports
🎯 New Report #3407352: curl built with GnuTLS backend defaults to weak crypto parameters
🔺Severity: None
👽 Reporter: nyymi
⭐️ Reputation: 1257
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-10-31
⏰ Disclosed: 2025-12-08 10:45:24
📝 Summary: null
📂 Report JSON File: 3407352
@hackeronereports
🔺Severity: None
👽 Reporter: nyymi
⭐️ Reputation: 1257
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-10-31
⏰ Disclosed: 2025-12-08 10:45:24
📝 Summary: null
📂 Report JSON File: 3407352
@hackeronereports
🎯 New Report #3455037: Certificate Hostname Validation Bypass via Leading Dot in Hostname
🔺Severity: Medium
👽 Reporter: 4bccc
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-06
⏰ Disclosed: 2025-12-09 23:29:46
📝 Summary: null
📂 Report JSON File: 3455037
@hackeronereports
🔺Severity: Medium
👽 Reporter: 4bccc
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-06
⏰ Disclosed: 2025-12-09 23:29:46
📝 Summary: null
📂 Report JSON File: 3455037
@hackeronereports
🎯 New Report #3316910: Second-Order XSS via javascript protocol in MCP Server Portal Apps leads to ATO
🔺Severity: Low
👽 Reporter: matured kazama
⭐️ Reputation: 2312
🛠 State: resolved
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: null
🕐 Submitted: 2025-08-27
⏰ Disclosed: 2025-12-16 09:47:20
📝 Summary: The vulnerability in the MCP Server Portal Apps was caused by missing sanitization of the redirect uri parameter, leading to a second-order XSS vulnerability. An attacker could craft a malicious redirect uri containing JavaScript code, obtain a client id for this URI, and reuse it when a victim had an active session on the /authorize endpoint to execute arbitrary JavaScript.
📂 Report JSON File: 3316910
@hackeronereports
🔺Severity: Low
👽 Reporter: matured kazama
⭐️ Reputation: 2312
🛠 State: resolved
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: null
🕐 Submitted: 2025-08-27
⏰ Disclosed: 2025-12-16 09:47:20
📝 Summary: The vulnerability in the MCP Server Portal Apps was caused by missing sanitization of the redirect uri parameter, leading to a second-order XSS vulnerability. An attacker could craft a malicious redirect uri containing JavaScript code, obtain a client id for this URI, and reuse it when a victim had an active session on the /authorize endpoint to execute arbitrary JavaScript.
📂 Report JSON File: 3316910
@hackeronereports
🎯 New Report #3458235: [RCE Remote Code Execution via React Server Components Vulnerability CVE-2025-55182](https://hackerone.com/reports/3458235)
🔺Severity: Critical
👽 Reporter: kanon4
⭐️ Reputation: 965
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-12-09
⏰ Disclosed: 2025-12-18 16:17:43
📝 Summary: null
📂 Report JSON File: 3458235
@hackeronereports
🔺Severity: Critical
👽 Reporter: kanon4
⭐️ Reputation: 965
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-12-09
⏰ Disclosed: 2025-12-18 16:17:43
📝 Summary: null
📂 Report JSON File: 3458235
@hackeronereports
🎯 New Report #1068477: RXSS in https://jp.mcafee.com/apps/mdm/jp/3.0 asp/
🔺Severity: Medium
👽 Reporter: lemonoftroy
⭐️ Reputation: 5514
🛠 State: resolved
💼 Team: Trellix
💵 Bounty: null
🕐 Submitted: 2020-12-29
⏰ Disclosed: 2025-12-19 11:04:44
📝 Summary: A cross-site scripting (XSS) vulnerability was discovered in https://jp.mcafee.com/apps/mdm/jp/3.0 asp/. The vulnerability was verified in Chrome 87 and Firefox. The vulnerability allowed execution of arbitrary JavaScript code by injecting it into the website's URL.
📂 Report JSON File: 1068477
@hackeronereports
🔺Severity: Medium
👽 Reporter: lemonoftroy
⭐️ Reputation: 5514
🛠 State: resolved
💼 Team: Trellix
💵 Bounty: null
🕐 Submitted: 2020-12-29
⏰ Disclosed: 2025-12-19 11:04:44
📝 Summary: A cross-site scripting (XSS) vulnerability was discovered in https://jp.mcafee.com/apps/mdm/jp/3.0 asp/. The vulnerability was verified in Chrome 87 and Firefox. The vulnerability allowed execution of arbitrary JavaScript code by injecting it into the website's URL.
📂 Report JSON File: 1068477
@hackeronereports
🎯 New Report #3463949: Missing AES-GCM Authentication Tag Validation and Improper Deprecation Handling
🔺Severity: High
👽 Reporter: sideni
⭐️ Reputation: 100
🛠 State: informative
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-12-13
⏰ Disclosed: 2025-12-19 21:03:44
📝 Summary: null
📂 Report JSON File: 3463949
@hackeronereports
🔺Severity: High
👽 Reporter: sideni
⭐️ Reputation: 100
🛠 State: informative
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-12-13
⏰ Disclosed: 2025-12-19 21:03:44
📝 Summary: null
📂 Report JSON File: 3463949
@hackeronereports
🎯 New Report #3445890: Link unfurling calls out to arbitrary URLs and the private-network guard misses link-local addresses
🔺Severity: Medium
👽 Reporter: brumbelow
⭐️ Reputation: 323
🛠 State: resolved
💼 Team: Basecamp
💵 Bounty: null
🕐 Submitted: 2025-12-01
⏰ Disclosed: 2025-12-22 17:43:51
📝 Summary: A vulnerability was discovered in the application that allowed authenticated users to supply a URL that the server would fetch for OpenGraph data. The "private network" guard only blocked certain IP ranges, but ignored link-local addresses, enabling server-side requests to be made to those hosts. This could have potentially allowed access to internal resources, such as cloud metadata services, depending on the server's network configuration.
📂 Report JSON File: 3445890
@hackeronereports
🔺Severity: Medium
👽 Reporter: brumbelow
⭐️ Reputation: 323
🛠 State: resolved
💼 Team: Basecamp
💵 Bounty: null
🕐 Submitted: 2025-12-01
⏰ Disclosed: 2025-12-22 17:43:51
📝 Summary: A vulnerability was discovered in the application that allowed authenticated users to supply a URL that the server would fetch for OpenGraph data. The "private network" guard only blocked certain IP ranges, but ignored link-local addresses, enabling server-side requests to be made to those hosts. This could have potentially allowed access to internal resources, such as cloud metadata services, depending on the server's network configuration.
📂 Report JSON File: 3445890
@hackeronereports
🎯 New Report #2902856: [nextcloud/mail Blind SSRF to Internal Network via "List-Unsubscribe" SMTP Header when allow local remote servers is allowed](https://hackerone.com/reports/2902856)
🔺Severity: Medium
👽 Reporter: lauritz
⭐️ Reputation: 2388
🛠 State: informative
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-12-16
⏰ Disclosed: 2025-12-23 07:11:19
📝 Summary: null
📂 Report JSON File: 2902856
@hackeronereports
🔺Severity: Medium
👽 Reporter: lauritz
⭐️ Reputation: 2388
🛠 State: informative
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-12-16
⏰ Disclosed: 2025-12-23 07:11:19
📝 Summary: null
📂 Report JSON File: 2902856
@hackeronereports
🎯 New Report #3367676: tabnabbing in roundcube webmail
🔺Severity: null
👽 Reporter: waloodi109
⭐️ Reputation: 62
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2025-10-02
⏰ Disclosed: 2025-12-24 08:36:49
📝 Summary: A tab nabbing vulnerability was discovered in Roundcube webmail. This vulnerability allowed a malicious website opened in a new tab to access the initial tab and change its location. This could be exploited to perform phishing attacks.
📂 Report JSON File: 3367676
@hackeronereports
🔺Severity: null
👽 Reporter: waloodi109
⭐️ Reputation: 62
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2025-10-02
⏰ Disclosed: 2025-12-24 08:36:49
📝 Summary: A tab nabbing vulnerability was discovered in Roundcube webmail. This vulnerability allowed a malicious website opened in a new tab to access the initial tab and change its location. This could be exploited to perform phishing attacks.
📂 Report JSON File: 3367676
@hackeronereports
🎯 New Report #3470073: Heap Buffer Over-Read via Malicious SMB Server READ ANDX Response
🔺Severity: Medium
👽 Reporter: strokep
⭐️ Reputation: 65
🛠 State: duplicate
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-18
⏰ Disclosed: 2025-12-25 16:54:32
📝 Summary: null
📂 Report JSON File: 3470073
@hackeronereports
🔺Severity: Medium
👽 Reporter: strokep
⭐️ Reputation: 65
🛠 State: duplicate
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-18
⏰ Disclosed: 2025-12-25 16:54:32
📝 Summary: null
📂 Report JSON File: 3470073
@hackeronereports
🎯 New Report #3479203: HTTP/3 Protocol Smuggling and Header Injection via CRLF in QPACK value conversion
🔺Severity: Critical
👽 Reporter: 0x0000nosfu
⭐️ Reputation: 87
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-26
⏰ Disclosed: 2025-12-27 22:06:14
📝 Summary: null
📂 Report JSON File: 3479203
@hackeronereports
🔺Severity: Critical
👽 Reporter: 0x0000nosfu
⭐️ Reputation: 87
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-26
⏰ Disclosed: 2025-12-27 22:06:14
📝 Summary: null
📂 Report JSON File: 3479203
@hackeronereports
❤1
🎯 New Report #3480039: WebSocket Logic Error: Control Frame (PING/PONG) Starvation causes Connection Drop (DoS) during large transfers
🔺Severity: Medium
👽 Reporter: efrsxcv
⭐️ Reputation: null
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-27
⏰ Disclosed: 2025-12-28 21:29:00
📝 Summary: null
📂 Report JSON File: 3480039
@hackeronereports
🔺Severity: Medium
👽 Reporter: efrsxcv
⭐️ Reputation: null
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-27
⏰ Disclosed: 2025-12-28 21:29:00
📝 Summary: null
📂 Report JSON File: 3480039
@hackeronereports
🎯 New Report #3480712: Telnet Suboption Buffer Pointer Underflow in lib/telnet.c leads to Out-of-Bounds Read
🔺Severity: Low
👽 Reporter: stif
⭐️ Reputation: 148
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-28
⏰ Disclosed: 2025-12-29 15:46:46
📝 Summary: null
📂 Report JSON File: 3480712
@hackeronereports
🔺Severity: Low
👽 Reporter: stif
⭐️ Reputation: 148
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-28
⏰ Disclosed: 2025-12-29 15:46:46
📝 Summary: null
📂 Report JSON File: 3480712
@hackeronereports
🎯 New Report #3463045: Remote Code Execution identified on IBM endpoint.
🔺Severity: Critical
👽 Reporter: dara 7979
⭐️ Reputation: 94
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-12-12
⏰ Disclosed: 2025-12-31 14:16:34
📝 Summary: A remote code execution vulnerability was identified on an IBM endpoint. The issue was reported to IBM, analyzed, and remediated.
📂 Report JSON File: 3463045
@hackeronereports
🔺Severity: Critical
👽 Reporter: dara 7979
⭐️ Reputation: 94
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-12-12
⏰ Disclosed: 2025-12-31 14:16:34
📝 Summary: A remote code execution vulnerability was identified on an IBM endpoint. The issue was reported to IBM, analyzed, and remediated.
📂 Report JSON File: 3463045
@hackeronereports
🎯 New Report #3484319: MQTT Protocol Violation Integer Overflow in libcurl
🔺Severity: High
👽 Reporter: ssyyaa
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2026-01-01
⏰ Disclosed: 2026-01-01 22:50:02
📝 Summary: null
📂 Report JSON File: 3484319
@hackeronereports
🔺Severity: High
👽 Reporter: ssyyaa
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2026-01-01
⏰ Disclosed: 2026-01-01 22:50:02
📝 Summary: null
📂 Report JSON File: 3484319
@hackeronereports
🎯 New Report #2276148: The role "CI-driven scan initiator" provides excessive read access
🔺Severity: Low
👽 Reporter: osama-hamad
⭐️ Reputation: 5008
🛠 State: resolved
💼 Team: PortSwigger Web Security
💵 Bounty: null
🕐 Submitted: 2023-12-07
⏰ Disclosed: 2026-01-02 09:32:37
📝 Summary: The reporter noticed that all authenticated users were able to access certain non-sensitive information such as metadata about third-party integrations. This was found to be by design, and the documentation was updated to clarify the information available to all authenticated users.
📂 Report JSON File: 2276148
@hackeronereports
🔺Severity: Low
👽 Reporter: osama-hamad
⭐️ Reputation: 5008
🛠 State: resolved
💼 Team: PortSwigger Web Security
💵 Bounty: null
🕐 Submitted: 2023-12-07
⏰ Disclosed: 2026-01-02 09:32:37
📝 Summary: The reporter noticed that all authenticated users were able to access certain non-sensitive information such as metadata about third-party integrations. This was found to be by design, and the documentation was updated to clarify the information available to all authenticated users.
📂 Report JSON File: 2276148
@hackeronereports
🎯 New Report #3483902: PROTOCOL-LEVEL: Persistent UDP Amplification and Cache Poisoning via Alt-Svc Logic Flaw
🔺Severity: High
👽 Reporter: huntsd
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2026-01-01
⏰ Disclosed: 2026-01-02 21:35:02
📝 Summary: null
📂 Report JSON File: 3483902
@hackeronereports
🔺Severity: High
👽 Reporter: huntsd
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2026-01-01
⏰ Disclosed: 2026-01-02 21:35:02
📝 Summary: null
📂 Report JSON File: 3483902
@hackeronereports
🎯 New Report #3040887: Users can modify tags on files that do not belong to them
🔺Severity: Medium
👽 Reporter: rolandsch
⭐️ Reputation: 122
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 150
🕐 Submitted: 2025-03-16
⏰ Disclosed: 2026-01-04 08:00:36
📝 Summary: A vulnerability was discovered in which users could modify tags on files that did not belong to them. This issue has been addressed.
📂 Report JSON File: 3040887
@hackeronereports
🔺Severity: Medium
👽 Reporter: rolandsch
⭐️ Reputation: 122
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 150
🕐 Submitted: 2025-03-16
⏰ Disclosed: 2026-01-04 08:00:36
📝 Summary: A vulnerability was discovered in which users could modify tags on files that did not belong to them. This issue has been addressed.
📂 Report JSON File: 3040887
@hackeronereports