目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

漏洞赏金情报

数据来源:HackerOne 公开披露报告 · 每 6 小时更新

浏览 HackerOne 平台公开披露的漏洞赏金报告,按严重程度、漏洞类型或目标项目筛选,关联 CVE 编号。

已披露报告
12,262
关联 CVE
1,866
参与项目数
343
近 7 天新增
0
项目筛选:slack
Data exports stored on S3 can be scraped easily
Slack Improper Authentication - Generic (CWE-287)
Unknown
2014-12-09
Unknown
2014-10-03
Password Policy issue (Weak Protect)
Slack Violation of Secure Design Principles (CWE-657)
Unknown
2014-09-04
Unknown
2014-09-03
URL redirection flaw
Slack Open Redirect (CWE-601)
Unknown
2014-08-30
Unknown
2014-08-30
Broken Authentication (including Slack OAuth bugs)
Slack Violation of Secure Design Principles (CWE-657)
Unknown
2014-08-30
Unknown
2014-08-25
Content spoofing at Stripe Integrations
Slack Violation of Secure Design Principles (CWE-657)
Unknown
2014-08-25
Deleting Teams implemenation
Slack Improper Authentication - Generic (CWE-287)
Unknown
2014-08-21
Content Spoofing
Slack Violation of Secure Design Principles (CWE-657)
Unknown
2014-08-11
Stored XSS in username.slack.com
Slack Cross-site Scripting (XSS) - Generic (CWE-79)
Unknown
2014-08-07
Unknown
2014-07-26
Unknown
2014-07-08
Stored XSS Found
Slack Cross-site Scripting (XSS) - Generic (CWE-79)
Unknown
2014-06-01
Unknown
2014-05-31
Slack OAuth2 "redirect_uri" Bypass
Slack Improper Authentication - Generic (CWE-287)
Unknown
2014-05-29
Stored XSS in slack.com (integrations)
Slack Cross-site Scripting (XSS) - Generic (CWE-79)
Unknown
2014-05-29
Stored XSS in www.slack-files.com
Slack Cross-site Scripting (XSS) - Generic (CWE-79)
Unknown
2014-05-23
高频漏洞类型
最活跃项目
项目 报告数 最高赏金
U.S. Dept Of Defense 896
Internet Bug Bounty 817 $2,257
HackerOne 609
Nextcloud 584
Shopify 465
curl 464
Node.js third-party modules 307
GitLab 258
X / xAI 250
Uber 239