WakaTime: User Email Disclosure via ID-Based Invitation

The issue occurs when inviting a user by their WakaTime ID. If a user has set their email to private, their email address was disclosed when they were invited using their ID. This contradicted the pri ...

Continue Reading
Hemi VDP: VSCode launch.json file exposed on hemi.xyz

A .vscode/launch.json file was published publicly on...Read More ...

Continue Reading
odaah.com Cross Site Scripting vulnerability OBB-4027599

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
jc-motor.com.tw Cross Site Scripting vulnerability OBB-4027582

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
Autodesk: WordPress users Disclosure

Vulnerability description not...Read More ...

Continue Reading
Hemi VDP: Linkedin Broken Link Hijacking on https://hemi.xyz/about

The LinkedIn account link for a team member on the https://hemi.xyz/about page pointed to a non-existent LinkedIn...Read More ...

Continue Reading
silver.fanfreak.net Cross Site Scripting vulnerability OBB-4027588

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
elearning.mta.gov.am Cross Site Scripting vulnerability OBB-4030713

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading

Back to Main

Subscribe for the latest news: