首页 > 专栏 > HackerOne Hacker Activity HackerOne Hacker Activity 共 248 条资讯 [$200] Nextcloud: Team membership information returned on API level based on ID 2026-06-27 17:36:26 Nextcloud: Unauthenticated blind SSRF in Circles signature verification bypasses Nextcloud local-address protections 2026-06-27 17:36:26 Nextcloud: Public collectives allow to create pages 2026-06-27 17:36:26 Nextcloud: Arbitrary Board Preference Injection via Deck Config API 2026-06-27 17:36:26 Nextcloud: Approval app's file-freshness check can be bypassed by omitting the etag parameter, allowing approval of unreviewed file changes 2026-06-27 17:36:26 Nextcloud: Critical broken access control: API-only delegated admin can enumerate all Team Folders and grant access to arbitrary groups 2026-06-27 17:36:26 Nextcloud: Shared smart albums in the Photos app can expose files outside the album owner's configured source folders 2026-06-27 17:36:26 Nextcloud: Cross-User Lock/Unlock via Absolute DAV Path 2026-06-27 17:36:26 Monero: ZMQ get_output_distribution duplicate amount DoS 2026-06-27 17:36:26 Monero: Restricted ZMQ RPC bypasses HTTP restricted-mode resource checks 2026-06-27 17:36:26 Monero: sign_multisig crashes monero-wallet-rpc on a malformed but decryptable multisig txset 2026-06-27 17:36:26 [$500] DuckDuckGo: SSRF with bypass leads to client side hosting / vulnerabilities ( XSS and others ) 2026-06-27 17:36:26 Monero: Authenticated `unsigned_txset` change spoof lets a malicious hot wallet steal cold-signer change 2026-06-27 17:36:26 curl: 37: `curl_mprintf` `%F` format specifier not consumed, causing variadic argument desynchronization 2026-06-27 17:36:26 curl: 10: CURLOPT_MAXLIFETIME_CONN bypass on active HTTP/2 connections 2026-06-27 17:36:26 curl: 56: IBM i CL wrapper `parse_command_line()` never enters quote mode 2026-06-27 17:36:26 curl: 53: HTTP/1 CONNECT chunked-407 trailers bypass CURLOPT_SUPPRESS_CONNECT_HEADERS and lose CURLH_CONNECT classification 2026-06-27 17:36:26 curl: Heap-use-after-free in CURLOPT_REFERER when passed a CURLINFO_REFERER pointer 2026-06-27 17:36:26 curl: OpenSSL ENGINE selection omitted from mTLS connection matching 2026-06-27 17:36:26 curl: TLS session resumption client cert bypass with CURLOPT_SSL_CTX_FUNCTION 2026-06-27 17:36:26 « 上一页1234…13下一页 » 相关分类 #!/slash/note #UNTAG (B)(F)uzzing on my world (Hi)story (IN)SECURE Magazine Notification (gdb) break *0x972 - 带鱼博客 BeltfishBlog - ./kwaa.dev .NET Blog .Trash /home/rook1e 00's Adventure 0kami's Blog 0x41414141 in ?? () 0x7f Blog 0xRick Owned Root ! 0xd00's blog 1 Byte 1A23 Blog 1A23 Studio 1Link.Fun 1stwebdesigner 251 2BAB 的工程博客 2ch中文网 360 CERT 360 Netlab Blog - Network Securi 38号车评中心 3o米的微博 404 Media