Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Bug Bounty Intelligence

Source: HackerOne public disclosures · updated every 6h

Browse publicly disclosed bug bounty reports from HackerOne. Filter by severity, weakness type, or program. Cross-referenced with CVE IDs where available.

Disclosed Reports
12,221
CVE-linked
1,854
Programs
342
New This Week
5
High
2022-03-03
IDOR delete any Tickets on ads.tiktok.com
TikTok Insecure Direct Object Reference (IDOR) (CWE-639)
High
2022-03-02
████ api key exposed in github.com/███/███
8x8 Cleartext Storage of Sensitive Information (CWE-312)
High
2022-02-22
High
2022-02-21
High
2022-02-18
Broken Authentication
U.S. Dept Of Defense Improper Access Control - Generic (CWE-284)
High
2022-02-14
Widespread CSRF on authenticated POST endpoints
UPchieve Cross-Site Request Forgery (CSRF) (CWE-352)
High
2022-02-13
High
2022-02-11
Reflected xss on ads.tiktok.com using `from` parameter.
TikTok Cross-site Scripting (XSS) - Reflected (CWE-79)
High
2022-02-09
Ruby CVE-2021-41819: Cookie Prefix Spoofing in CGI::Cookie.parse
Internet Bug Bounty Reliance on Cookies without Validation and Integrity Checking in a Security Decision (CWE-784)CVE-2021-41819CVE-2020-8184
High
2022-02-03
High
2022-02-01
Top Weakness Types
Most Active Programs
ProgramReportsMax $
U.S. Dept Of Defense896
Internet Bug Bounty817
HackerOne609
Nextcloud582
Shopify464
curl440
Node.js third-party modules307
GitLab258 $13,950
X / xAI250 $2,500
Uber239