h1Disclosed Profile Banner
H1 Disclosed - Public Disclosures Profile
H1 Disclosed - Public Disclosures

@h1Disclosed

Followers
10K
Following
275
Media
2K
Statuses
2K

User friendly unofficial HackerOne public disclosures, keeps you updated about the recently disclosed bugs. Made With ♥ By Hackers For Hackers. - @rohsec

127.0.0.1
Joined September 2022
Don't wanna be here? Send us removal request.
@h1Disclosed
H1 Disclosed - Public Disclosures
3 days
⚡ on the implications of permitting procedural culling .👨🏻‍💻 lyb_unaffiliated ➟ curl .🟨 Low.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
0
7
@h1Disclosed
H1 Disclosed - Public Disclosures
3 days
⚡ curl ASSERTs when accessing an LDAP URL .👨🏻‍💻 cmeister2 ➟ curl .⬜ None.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
0
1
@h1Disclosed
H1 Disclosed - Public Disclosures
3 days
⚡ XSS on Amazon Aquisition: elemental .👨🏻‍💻 muhammad_kasim ➟ AWS VDP .🟥 High.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
1
9
@h1Disclosed
H1 Disclosed - Public Disclosures
3 days
⚡ [CRITICAL] 0-Click Account Takeover via Password Reset [AUTH-3243] /orchestrator/v1/password_rese. 👨🏻‍💻 db3wy ➟ Remitly .🆘 Critical.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
1
7
86
@h1Disclosed
H1 Disclosed - Public Disclosures
7 days
⚡ API Key Exposed in JavaScript File on 1Password Developer Site .👨🏻‍💻 @sudosu01 ➟ 1Password - Enterprise Password Manager .⬜ None.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
2
1
24
@h1Disclosed
H1 Disclosed - Public Disclosures
8 days
⚡ Account takeover of existing HackerOne accounts through SCIM provisioning .👨🏻‍💻 boy_child_ ➟ HackerOne .🟥 High.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
2
18
@h1Disclosed
H1 Disclosed - Public Disclosures
8 days
⚡ Stored Cross-Site Scripting (XSS) in "Add Contact" Name Field – MainWP Plugin .👨🏻‍💻 rishail01 ➟ MainWP .⬜ None.💰 $50.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
1
2
@h1Disclosed
H1 Disclosed - Public Disclosures
8 days
⚡ Reflected XSS in "Create Category" Functionality of Post Creation Module .👨🏻‍💻 rishail01 ➟ MainWP .🟨 Low.💰 $50.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
1
0
11
@h1Disclosed
H1 Disclosed - Public Disclosures
8 days
⚡ Reflected XSS in "Manage Tags" Notes Field .👨🏻‍💻 rishail01 ➟ MainWP .🟨 Low.💰 $50.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
0
6
@h1Disclosed
H1 Disclosed - Public Disclosures
8 days
⚡ Reflected XSS in "Cost Tracker" Notes Field .👨🏻‍💻 rishail01 ➟ MainWP .🟨 Low.💰 $50.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
0
4
@h1Disclosed
H1 Disclosed - Public Disclosures
9 days
⚡ exposure of personal IP address via email. 👨🏻‍💻 micael1 ➟ Weblate .⬜ None.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
0
6
@h1Disclosed
H1 Disclosed - Public Disclosures
9 days
⚡ Windows Device Names (CON, PRN, AUX) Bypass Path Traversal Protection in path.normalize() .👨🏻‍💻 @theoblivionsage ➟ Node.js .🟥 High.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
1
3
15
@h1Disclosed
H1 Disclosed - Public Disclosures
9 days
⚡ HashDoS in V8 .👨🏻‍💻 sharp_edged ➟ Node.js .🟥 High.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
0
1
@h1Disclosed
H1 Disclosed - Public Disclosures
10 days
⚡ Banned user still has access to their deleted account via HackerOne's API using their API key .👨🏻‍💻 @MrMax404 ➟ HackerOne .🟧 Medium.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
1
2
50
@h1Disclosed
H1 Disclosed - Public Disclosures
11 days
⚡ Default Minimum TLS Version Set to TLS v1.0 (Cryptographic Weakness) .👨🏻‍💻 monkey_dee ➟ curl .🟧 Medium.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
0
0
@h1Disclosed
H1 Disclosed - Public Disclosures
11 days
⚡ Leaked reused password for a few Khan Academy users .👨🏻‍💻 @A0xTrojan ➟ Khan Academy .🟥 High.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
2
2
8
@h1Disclosed
H1 Disclosed - Public Disclosures
11 days
⚡ HTTP Request Smuggling Vulnerability Analysis - cURL Security Report .👨🏻‍💻 youssef111 ➟ curl .🟧 Medium.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
1
0
2
@h1Disclosed
H1 Disclosed - Public Disclosures
11 days
⚡ Reflected XSS in "Client Notes" Field .👨🏻‍💻 rishail01 ➟ MainWP .🟨 Low.💰 $50.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
0
12
@h1Disclosed
H1 Disclosed - Public Disclosures
11 days
⚡ Uncontrolled File Write/Arbitrary File Creation .👨🏻‍💻 tryhackplanet ➟ curl .🟥 High.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
0
0
@h1Disclosed
H1 Disclosed - Public Disclosures
11 days
⚡ Not a Vuln: Race Condition Allows Creation of Multiple Organizations with the Same Name .👨🏻‍💻 @calvin_minyate ➟ WakaTime .⬜ None.💰 None.🔗 #bugbounty #bugbountytips #cybersecurity #infosec
Tweet media one
0
3
8