Bug Bounty Channel(@bug_bounty_channel)是 TGbox 收录的 Telegram 开发编程频道,目前有 14,787 名订阅者,创建于 2016年8月20日,活跃度为非常活跃,内容以英语为主。
频道简介与描述
All bug bounties here.
本頁有繁體中文版。
切換到繁體中文This page is available in English.
Switch to EnglishBug Bounty Channel@bug_bounty_channel
直达Bug Bounty Channel(@bug_bounty_channel)是 TGbox 收录的 Telegram 开发编程频道,目前有 14,787 名订阅者,创建于 2016年8月20日,活跃度为非常活跃,内容以英语为主。
All bug bounties here.
成员数据正在积累,过几天再来看看。
🏦 AWS VDP Report ⚠️ Title: Incomplete Input Sanitization in CodeInterpreter install\_packages Allows Command Injection via pip Flags 🔍 Reporter: mistercloudsec (Sergio Garcia) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: High └ 🎯 CWE: OS Command Injection └ 🔢 CVE: CVE-2026-12530 ⏰ Timeline: └ 🔓 Disclosed: 2026-09-16 20:57:22 UTC └ 📝 Created: 2026-03-28 01:16:16 UTC

🏦 Nextcloud Report 📝 Title: Team membership information returned on API level based on ID 🔍 Reporter: milou (Melanie) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Low └ 🎯 CWE: Insecure Direct Object Reference \(IDOR\) └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 05:49:15 UTC └ 📝 Created: 2026-01-02 09:03:48 UTC

🏦 Nextcloud Report ⚡ Title: Unauthenticated blind SSRF in Circles signature verification bypasses Nextcloud local-address protections 🔍 Reporter: 0x0doteth (Balvant Chavda) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Server-Side Request Forgery \(SSRF\) └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 06:22:37 UTC └ 📝 Created: 2025-08-18 10:24:22 UTC

🏦 Nextcloud Report ⚡ Title: Arbitrary Board Preference Injection via Deck Config API 🔍 Reporter: vidang04 (Dang Hung Vi) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Improper Access Control - Generic └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 10:20:08 UTC └ 📝 Created: 2026-03-12 07:10:09 UTC

🏦 Nextcloud Report 📝 Title: Public collectives allow to create pages 🔍 Reporter: yoyomiski (_dha) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Low └ 🎯 CWE: Improper Access Control - Generic └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 10:16:22 UTC └ 📝 Created: 2026-02-01 08:02:16 UTC

🏦 Nextcloud Report ⚡ Title: Critical broken access control: API-only delegated admin can enumerate all Team Folders and grant access to arbitrary groups 🔍 Reporter: qloo (qloo) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Improper Access Control - Generic └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 10:41:04 UTC └ 📝 Created: 2026-04-15 10:09:16 UTC

🏦 Nextcloud Report ⚡ Title: Approval app's file-freshness check can be bypassed by omitting the etag parameter, allowing approval of unreviewed file changes 🔍 Reporter: vidang04 (Dang Hung Vi) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Business Logic Errors └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 10:34:47 UTC └ 📝 Created: 2026-03-17 08:32:35 UTC

🏦 Nextcloud Report ⚡ Title: Shared smart albums in the Photos app can expose files outside the album owner's configured source folders 🔍 Reporter: suul (Joseph Semaan) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Improper Access Control - Generic └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 10:48:18 UTC └ 📝 Created: 2026-01-11 16:52:24 UTC

🏦 Nextcloud Report ⚡ Title: Cross-User Lock/Unlock via Absolute DAV Path 🔍 Reporter: 0x0doteth (Balvant Chavda) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Improper Authentication - Generic └ 🔢 CVE: CVE-2026-45283 ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 13:09:01 UTC └ 📝 Created: 2025-08-16 06:04:54 UTC

🏦 Monero Report ⚠️ Title: sign\_multisig crashes monero-wallet-rpc on a malformed but decryptable multisig txset 🔍 Reporter: helping_bro (0xbro) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: High └ 🎯 CWE: Not Specified └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 17:45:03 UTC └ 📝 Created: 2026-04-19 18:43:26 UTC

🏦 Monero Report ⚡ Title: Restricted ZMQ RPC bypasses HTTP restricted-mode resource checks 🔍 Reporter: helping_bro (0xbro) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Not Specified └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 17:42:05 UTC └ 📝 Created: 2026-04-19 18:10:11 UTC

🏦 Monero Report ⚡ Title: ZMQ get\_output\_distribution duplicate amount DoS 🔍 Reporter: helping_bro (0xbro) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Not Specified └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 17:38:21 UTC └ 📝 Created: 2026-04-18 10:54:41 UTC

🏦 DuckDuckGo Report ⚡ Title: SSRF with bypass leads to client side hosting / vulnerabilities \( XSS and others \) 🔍 Reporter: ferreiraklet_ (Daniel Ferreira) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Server-Side Request Forgery \(SSRF\) └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 22:54:11 UTC └ 📝 Created: 2026-01-23 17:35:56 UTC

🏦 Essity Report 🔥 Title: Unauthenticated API allows reading, writing to and deleting any user's private chat history on ████████ 🔍 Reporter: agusnicco (Juan Agustin Niccolini) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Critical └ 🎯 CWE: Misconfiguration └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-18 06:04:10 UTC └ 📝 Created: 2026-09-11 04:52:49 UTC

🏦 curl Report ❓ Title: Socket API drops expired timeouts for transfers queued behind a connection limit 🔍 Reporter: giant_anteater (Anteater) 📋 Details: └ 📊 Status: informative └ ⚡ Severity: Not Specified └ 🎯 CWE: Not Specified └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-18 06:33:39 UTC └ 📝 Created: 2026-09-11 15:25:57 UTC

🏦 Nextcloud Report 📋 Title: Persistent SMTP header injection via identity \`organization\` / \`name\` 🔍 Reporter: dogeshark (No name) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: None └ 🎯 CWE: Buffer Under-read └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-18 13:24:05 UTC └ 📝 Created: 2026-08-03 15:23:00 UTC

🏦 Nextcloud Report ⚡ Title: files\_lock: a write-share collaborator can place a TYPE\_TOKEN lock that permanently denies the file owner, survives share revocation and account delet 🔍 Reporter: rz1027 (rz1027) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Improper Access Control - Generic └ 🔢 CVE: CVE-2021-22906 ⏰ Timeline: └ 🔓 Disclosed: 2026-09-18 15:36:09 UTC └ 📝 Created: 2026-05-29 21:54:59 UTC

🏦 curl Report ⚡ Title: HTTP/1.1 response framing violation and unsafe connection reuse when transfer decoding is disabled 🔍 Reporter: thatcyberguyrich (Richard Payne) 📋 Details: └ 📊 Status: informative └ ⚡ Severity: Medium └ 🎯 CWE: HTTP Request Smuggling └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-19 08:36:37 UTC └ 📝 Created: 2026-09-12 20:59:25 UTC

🏦 curl Report ⚡ Title: Use-after-free of the internal multi->admin easy handle via the documented CURLMOPT\_NOTIFYFUNCTION callback 🔍 Reporter: fengxiao (FengXiao) 📋 Details: └ 📊 Status: informative └ ⚡ Severity: Medium └ 🎯 CWE: Use After Free └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-19 08:36:27 UTC └ 📝 Created: 2026-09-16 09:18:57 UTC

🏦 curl Report ❓ Title: TELNET control and environment data bypass HTTPS-proxy TLS 🔍 Reporter: giant_anteater (Anteater) 📋 Details: └ 📊 Status: informative └ ⚡ Severity: Not Specified └ 🎯 CWE: Not Specified └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-19 08:36:16 UTC └ 📝 Created: 2026-09-11 15:29:48 UTC

暂无简介
在这里,我们宣布了Android Java、iOS Swift、JS、C/C++中的Telegram编码比赛。
关于 Telegram Bot API 的官方消息来源. https://core.telegram.org/bots
News and info from the Linux world 🐧 📨 linuxgr4m@gmail.com 📨 💸 If you want to support Linuxgram❤️ 🐧 - BTC: 15aVLQeNY18VAaoBXPgLFA4wfwJnecbjC1
这个测试商店拥有最异国情调的想象性商品,没有钱可以买到,所以你可以测试Telegram Payments 2.0如何工作,而不花一分钱。
VPS新闻频道,VPS信号旗是即时发布简要讯息的小组织,关注VPS和通信自由。为你甄选最具价值的信息,提供业界热点新闻调查。 🌞 讨论群组:https://t.me/vpsxinhaoqi 🏛 评论规则:https://t.me/xhq_rule 🙋 投稿交谈:https://t.me/PandasChatBot
Every day, we change the world. 本群提倡有意义的发言,分享有价值的信息,例如技术讨论、安全资讯、新手教程等。 无用消息将被删除,离题请适度。 禁止交易、招募、求师收徒,提防上当受骗; 禁止社工、黑产、广告、政治、开车等,包括用户名和简介; 禁止 有问题不直接问、在吗有人吗有大佬吗、求求带带、拉我加我、懂的来、打招呼 等糟粕用语和行为; 禁止随意私聊他人; 禁止滥用机器人。 如有违反,将删除、警告或封禁。谢谢配合。 通用水群: @coder_ot
adguard.com 官方网站链接。AdGuard信息反馈意见。中文! 报告错误: agrd.io/report AdGuard微博:https://weibo.com/u/7457831289 加入AdGuard官方群!(最新消息、官方公告、更新发布时间等等) 请大家注意! 请勿使用外语, 中文群仅使用汉语。 严禁NSFW、广告、灰产、政治话题等。 入群请提前私聊 @WatchdogVerifyBot 验证