Bug Bounty Channel(@bug_bounty_channel)是 TGbox 收錄的 Telegram 開發編程頻道,目前有 14,787 名訂閱者,創建於 2016年8月20日,活躍度為非常活躍,內容以英文為主。
頻道簡介與描述
All bug bounties here.
本頁有簡體中文版。
切換到簡體中文This page is available in English.
Switch to EnglishBug Bounty Channel@bug_bounty_channel
直達Bug Bounty Channel(@bug_bounty_channel)是 TGbox 收錄的 Telegram 開發編程頻道,目前有 14,787 名訂閱者,創建於 2016年8月20日,活躍度為非常活躍,內容以英文為主。
All bug bounties here.
成員數據正在積累,過幾天再來看看。
🏦 AWS VDP Report ⚠️ Title: Incomplete Input Sanitization in CodeInterpreter install\_packages Allows Command Injection via pip Flags 🔍 Reporter: mistercloudsec (Sergio Garcia) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: High └ 🎯 CWE: OS Command Injection └ 🔢 CVE: CVE-2026-12530 ⏰ Timeline: └ 🔓 Disclosed: 2026-09-16 20:57:22 UTC └ 📝 Created: 2026-03-28 01:16:16 UTC

🏦 Nextcloud Report 📝 Title: Team membership information returned on API level based on ID 🔍 Reporter: milou (Melanie) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Low └ 🎯 CWE: Insecure Direct Object Reference \(IDOR\) └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 05:49:15 UTC └ 📝 Created: 2026-01-02 09:03:48 UTC

🏦 Nextcloud Report ⚡ Title: Unauthenticated blind SSRF in Circles signature verification bypasses Nextcloud local-address protections 🔍 Reporter: 0x0doteth (Balvant Chavda) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Server-Side Request Forgery \(SSRF\) └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 06:22:37 UTC └ 📝 Created: 2025-08-18 10:24:22 UTC

🏦 Nextcloud Report ⚡ Title: Arbitrary Board Preference Injection via Deck Config API 🔍 Reporter: vidang04 (Dang Hung Vi) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Improper Access Control - Generic └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 10:20:08 UTC └ 📝 Created: 2026-03-12 07:10:09 UTC

🏦 Nextcloud Report 📝 Title: Public collectives allow to create pages 🔍 Reporter: yoyomiski (_dha) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Low └ 🎯 CWE: Improper Access Control - Generic └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 10:16:22 UTC └ 📝 Created: 2026-02-01 08:02:16 UTC

🏦 Nextcloud Report ⚡ Title: Critical broken access control: API-only delegated admin can enumerate all Team Folders and grant access to arbitrary groups 🔍 Reporter: qloo (qloo) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Improper Access Control - Generic └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 10:41:04 UTC └ 📝 Created: 2026-04-15 10:09:16 UTC

🏦 Nextcloud Report ⚡ Title: Approval app's file-freshness check can be bypassed by omitting the etag parameter, allowing approval of unreviewed file changes 🔍 Reporter: vidang04 (Dang Hung Vi) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Business Logic Errors └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 10:34:47 UTC └ 📝 Created: 2026-03-17 08:32:35 UTC

🏦 Nextcloud Report ⚡ Title: Shared smart albums in the Photos app can expose files outside the album owner's configured source folders 🔍 Reporter: suul (Joseph Semaan) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Improper Access Control - Generic └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 10:48:18 UTC └ 📝 Created: 2026-01-11 16:52:24 UTC

🏦 Nextcloud Report ⚡ Title: Cross-User Lock/Unlock via Absolute DAV Path 🔍 Reporter: 0x0doteth (Balvant Chavda) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Improper Authentication - Generic └ 🔢 CVE: CVE-2026-45283 ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 13:09:01 UTC └ 📝 Created: 2025-08-16 06:04:54 UTC

🏦 Monero Report ⚠️ Title: sign\_multisig crashes monero-wallet-rpc on a malformed but decryptable multisig txset 🔍 Reporter: helping_bro (0xbro) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: High └ 🎯 CWE: Not Specified └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 17:45:03 UTC └ 📝 Created: 2026-04-19 18:43:26 UTC

🏦 Monero Report ⚡ Title: Restricted ZMQ RPC bypasses HTTP restricted-mode resource checks 🔍 Reporter: helping_bro (0xbro) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Not Specified └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 17:42:05 UTC └ 📝 Created: 2026-04-19 18:10:11 UTC

🏦 Monero Report ⚡ Title: ZMQ get\_output\_distribution duplicate amount DoS 🔍 Reporter: helping_bro (0xbro) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Not Specified └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 17:38:21 UTC └ 📝 Created: 2026-04-18 10:54:41 UTC

🏦 DuckDuckGo Report ⚡ Title: SSRF with bypass leads to client side hosting / vulnerabilities \( XSS and others \) 🔍 Reporter: ferreiraklet_ (Daniel Ferreira) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Server-Side Request Forgery \(SSRF\) └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-17 22:54:11 UTC └ 📝 Created: 2026-01-23 17:35:56 UTC

🏦 Essity Report 🔥 Title: Unauthenticated API allows reading, writing to and deleting any user's private chat history on ████████ 🔍 Reporter: agusnicco (Juan Agustin Niccolini) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Critical └ 🎯 CWE: Misconfiguration └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-18 06:04:10 UTC └ 📝 Created: 2026-09-11 04:52:49 UTC

🏦 curl Report ❓ Title: Socket API drops expired timeouts for transfers queued behind a connection limit 🔍 Reporter: giant_anteater (Anteater) 📋 Details: └ 📊 Status: informative └ ⚡ Severity: Not Specified └ 🎯 CWE: Not Specified └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-18 06:33:39 UTC └ 📝 Created: 2026-09-11 15:25:57 UTC

🏦 Nextcloud Report 📋 Title: Persistent SMTP header injection via identity \`organization\` / \`name\` 🔍 Reporter: dogeshark (No name) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: None └ 🎯 CWE: Buffer Under-read └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-18 13:24:05 UTC └ 📝 Created: 2026-08-03 15:23:00 UTC

🏦 Nextcloud Report ⚡ Title: files\_lock: a write-share collaborator can place a TYPE\_TOKEN lock that permanently denies the file owner, survives share revocation and account delet 🔍 Reporter: rz1027 (rz1027) 📋 Details: └ 📊 Status: resolved └ ⚡ Severity: Medium └ 🎯 CWE: Improper Access Control - Generic └ 🔢 CVE: CVE-2021-22906 ⏰ Timeline: └ 🔓 Disclosed: 2026-09-18 15:36:09 UTC └ 📝 Created: 2026-05-29 21:54:59 UTC

🏦 curl Report ⚡ Title: HTTP/1.1 response framing violation and unsafe connection reuse when transfer decoding is disabled 🔍 Reporter: thatcyberguyrich (Richard Payne) 📋 Details: └ 📊 Status: informative └ ⚡ Severity: Medium └ 🎯 CWE: HTTP Request Smuggling └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-19 08:36:37 UTC └ 📝 Created: 2026-09-12 20:59:25 UTC

🏦 curl Report ⚡ Title: Use-after-free of the internal multi->admin easy handle via the documented CURLMOPT\_NOTIFYFUNCTION callback 🔍 Reporter: fengxiao (FengXiao) 📋 Details: └ 📊 Status: informative └ ⚡ Severity: Medium └ 🎯 CWE: Use After Free └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-19 08:36:27 UTC └ 📝 Created: 2026-09-16 09:18:57 UTC

🏦 curl Report ❓ Title: TELNET control and environment data bypass HTTPS-proxy TLS 🔍 Reporter: giant_anteater (Anteater) 📋 Details: └ 📊 Status: informative └ ⚡ Severity: Not Specified └ 🎯 CWE: Not Specified └ 🔢 CVE: None ⏰ Timeline: └ 🔓 Disclosed: 2026-09-19 08:36:16 UTC └ 📝 Created: 2026-09-11 15:29:48 UTC

暫無簡介
在這裡,我們宣佈了Android Java、iOS Swift、JS、C/C++中的Telegram編碼比賽。
關於 Telegram Bot API 的官方消息來源. https://core.telegram.org/bots
News and info from the Linux world 🐧 📨 linuxgr4m@gmail.com 📨 💸 If you want to support Linuxgram❤️ 🐧 - BTC: 15aVLQeNY18VAaoBXPgLFA4wfwJnecbjC1
這個測試商店擁有最異國情調的想像性商品,沒有錢可以買到,所以你可以測試Telegram Payments 2.0如何工作,而不花一分錢。
VPS新聞頻道,VPS信號旗是即時發佈簡要訊息的小組織,關注VPS和通信自由。為你甄選最具價值的信息,提供業界熱點新聞調查。 🌞 討論群組:https://t.me/vpsxinhaoqi 🏛 評論規則:https://t.me/xhq_rule 🙋 投稿交談:https://t.me/PandasChatBot
Every day, we change the world. 本群提倡有意義的發言,分享有價值的信息,例如技術討論、安全資訊、新手教程等。 無用消息將被刪除,離題請適度。 禁止交易、招募、求師收徒,提防上當受騙; 禁止社工、黑產、廣告、政治、開車等,包括用戶名和簡介; 禁止 有問題不直接問、在嗎有人嗎有大佬嗎、求求帶帶、拉我加我、懂的來、打招呼 等糟粕用語和行為; 禁止隨意私聊他人; 禁止濫用機器人。 如有違反,將刪除、警告或封禁。謝謝配合。 通用水群: @coder_ot
adguard.com 官方網站鏈接。AdGuard信息反饋意見。中文! 報告錯誤: agrd.io/report AdGuard微博:https://weibo.com/u/7457831289 加入AdGuard官方群!(最新消息、官方公告、更新發布時間等等) 請大家注意! 請勿使用外語, 中文群僅使用漢語。 嚴禁NSFW、廣告、灰產、政治話題等。 入群請提前私聊 @WatchdogVerifyBot 驗證