Hacking & Computer Science stuff

Bug Hunting

DateFindingSeverityProfile
2024/04/05Denial of Service (CWE-400)N/A
2024/04/05Improper Access Control - Generic (CWE-284)N/A
2024/04/04Improper Access Control - Generic (CWE-284)N/A
2024/04/04Improper Access Control - Generic (CWE-284)N/A
2024/03/26Improper Access Control - Generic (CWE-284)N/A
2024/03/25Improper Access Control - Generic (CWE-284)N/A
2024/03/21Business Logic Errorshigh
2024/03/20Improper Access Control - Generic (CWE-284)N/A
2024/03/20Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)low
2024/03/13Insecure Direct Object Reference (IDOR) (CWE-639)N/A
2024/03/09Improper Access Control - Generic (CWE-284)N/A
2024/03/08Insecure Direct Object Reference (IDOR) (CWE-639)N/A
2024/03/08Business Logic Errors (CWE-840)N/A
2024/02/23Server-Side Request Forgery (SSRF) (CWE-918)N/A
2024/02/16Business Logic Errors (CWE-840)N/A
2024/02/08Insecure Direct Object Reference (IDOR) (CWE-639)N/A
2024/02/08Business Logic Errors (CWE-840)N/A
2024/02/07Improper Access Control - Generic (CWE-284)N/A
2024/02/07Insecure Direct Object Reference (IDOR) (CWE-639)N/A
2024/02/07Business Logic Errors (CWE-840)N/A
2024/02/06Business Logic Errors (CWE-840)N/A
2024/02/05Open Redirect (CWE-601)N/A
2024/02/05Open Redirect (CWE-601)N/A
2024/02/01Business Logic Errors (CWE-840)N/A
2024/01/30Improper Access Control - Generic (CWE-284)N/A
2024/01/25Business Logic Errors (CWE-840)N/A
2024/01/24Open Redirect (CWE-601)N/A
2024/01/24Open Redirect (CWE-601)N/A
2024/01/24Improper Access Control - Generic (CWE-284)N/A
2023/12/14Improper Access Control - Generic (CWE-284)N/A
2023/12/11Cross-site Scripting (XSS) - Storedhigh
2023/12/11Incorrect Permission Assignment for Critical Resourcemedium
2023/12/04Command Injection - Generic (CWE-77)N/A
2023/11/24Command Injection - Generic (CWE-77)N/A
2023/08/28Cross-site Scripting (XSS) - Stored (CWE-79)N/A
2023/08/21Cross-site Scripting (XSS) - Stored (CWE-79)N/A
2023/08/16Weak Password Mechanism for Forgotten Password (CWE-640)N/A
2023/08/10Improper Access Control - Generic (CWE-284)N/A
2023/08/04Improper Access Control - Generic (CWE-284)N/A
2023/07/30Improper Access Control - Generic (CWE-284)N/A
2023/07/28Improper Access Control - Generic (CWE-284)N/A
2023/07/26Improper Access Control - Generic (CWE-284)N/A
2023/06/19N/AP2
2023/06/06Code Injectioncritical
2023/05/30N/AP3
2023/05/28N/AP2
2023/05/01Improper Access Control - Generichigh
2023/04/08N/AP3
2023/04/05Improper Access Control - Generic (CWE-284)N/A
2023/04/05Improper Access Control - Generic (CWE-284)N/A
2023/03/11N/AP1
2023/03/05Resource Injectionnone
2023/02/27Information Disclosuremedium
2023/02/27Improper Authentication - Generichigh
2023/02/24Information Disclosurelow
2023/02/21N/AP3
2023/02/20Improper Access Control - Generic (CWE-284)N/A
2023/01/12N/AP1
2022/12/26Violation of Secure Design Principles (CWE-657)N/A
2022/11/02Code Injection (CWE-94)N/A
2022/10/27Code Injection (CWE-94)N/A
2022/10/27Improper Access Control - Generic (CWE-284)N/A
2022/10/26Violation of Secure Design Principles (CWE-657)N/A
2022/10/26Code Injection (CWE-94)N/A
2022/10/25Improper Access Control - Generic (CWE-284)N/A
2022/10/19Violation of Secure Design Principles (CWE-657)N/A
2022/10/12Improper Access Control - Generic (CWE-284)N/A
2022/09/10N/AP4
2021/09/11N/AN/A
2021/05/02N/AP4
2021/04/30N/AN/A
2021/03/30N/AP4
2021/03/16N/AP1
2021/02/13N/AP5
2020/10/04N/AP5
2020/09/05N/AP5
2020/06/19N/AP5
2020/06/19N/AN/A
2020/06/02N/AP5
2020/06/02N/AN/A
2020/06/02N/AP4
2020/06/01N/AP4
2020/05/29N/AP4
2020/05/26N/AP5
2020/05/26N/AN/A
2020/05/10Information Exposure Through an Error Messagemedium
2020/05/01Insecure Storage of Sensitive Informationcritical
2020/04/06Information Disclosuremedium
2020/03/26Information Exposure Through Directory Listingmedium

Misc.

IDProductSources
N/A - 2023/04/17 (Unsecured password storage)Agora ProjectHuntr.dev
N/A - 2023/04/17 (Reflected XSS)Agora ProjectHuntr.dev
N/A - 2023/04/17 (Authenticated RCE)Agora ProjectHuntr.dev
N/A - 2023/04/17 (Unrestricted file download)Agora ProjectHuntr.dev
N/A - 2023/04/17 (Missing Access Control)Agora ProjectHuntr.dev
N/A - 2023/04/17 (SQL injection)Agora ProjectHuntr.dev
CVE-2022-28800SonarqubeMitre
CVE-2021-27375TraefikMitre Sonarqube

© Sébastien Copin (cosades) 2024