Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

HackerOne — Vulnerabilities & Security Advisories 470

Browse all 470 CVE security advisories affecting HackerOne. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HackerOne operates a crowdsourced vulnerability disclosure platform, connecting organizations with ethical hackers to identify and remediate security flaws before malicious exploitation. The platform’s extensive record of 470 CVEs highlights a diverse attack surface, with historically common vulnerability classes including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation. These defects often stem from complex API integrations and web application logic errors inherent in its SaaS infrastructure. Notable security characteristics involve its reliance on third-party researchers, which introduces both robust coverage and potential insider threat vectors. While major public incidents have been relatively contained, the platform’s role as a central hub for vulnerability data makes it a high-value target for attackers seeking to disrupt the disclosure ecosystem or harvest sensitive intelligence. Maintaining strict access controls and transparent reporting mechanisms remains critical for preserving trust and ensuring the integrity of the bug bounty process across its global user base.

CVE ID Title CVSS Severity Published
CVE-2017-0938 Ubiquiti Networks airMAX和EdgeMAX 输入验证错误漏洞 — airMAX, EdgeMAX CWE-400 7.5 - 2019-02-12
CVE-2018-16479 http-live-simulator 路径遍历漏洞 — http-live-simulator CWE-22 7.5 - 2019-02-01
CVE-2018-16480 public module 跨站脚本漏洞 — public CWE-79 6.1 - 2019-02-01
CVE-2018-16481 html-page 跨站脚本漏洞 — html-pages CWE-79 6.1 - 2019-02-01
CVE-2018-16482 node module mcstatic 路径遍历漏洞 — mcstatic CWE-22 7.5 - 2019-02-01
CVE-2018-16483 express-cart 访问控制错误漏洞 — express-cart 8.8 - 2019-02-01
CVE-2018-16484 m-server 跨站脚本漏洞 — m-server CWE-79 5.4 - 2019-02-01
CVE-2018-16485 m-server 路径遍历漏洞 — m-server CWE-22 7.5 - 2019-02-01
CVE-2018-16486 defaults-deep 注入漏洞 — defaults-deep CWE-400 9.8 - 2019-02-01
CVE-2018-16487 lodash 资源管理错误漏洞 — lodash CWE-400 6.5 - 2019-02-01
CVE-2018-16489 just-extend 注入漏洞 — just-extend CWE-400 9.8 - 2019-02-01
CVE-2018-16490 mpath module 注入漏洞 — mpath CWE-400 9.4 - 2019-02-01
CVE-2018-16491 node.extend 注入漏洞 — node.extend CWE-400 9.8 - 2019-02-01
CVE-2018-16492 extend module 注入漏洞 — extend CWE-400 9.8 - 2019-02-01
CVE-2018-16493 static-resource-server 路径遍历漏洞 — static-resource-server CWE-548 7.5 - 2019-02-01
CVE-2018-16469 merge package 输入验证错误漏洞 — merge CWE-400 7.5 - 2018-10-30
CVE-2018-3787 simplehttpserver 路径遍历漏洞 — simplehttpserver CWE-22 7.5 - 2018-08-31
CVE-2018-3776 Nextcloud Server 输入验证漏洞 — Nextcloud Server CWE-20 4.3 - 2018-08-12
CVE-2018-3775 Nextcloud Server 授权问题漏洞 — Nextcloud Server CWE-287 8.8 - 2018-08-12
CVE-2018-3774 url-parse 安全漏洞 — url-parse CWE-425 9.1 - 2018-08-12
CVE-2018-3779 active-support ruby gem 安全漏洞 — active-support ruby gem CWE-77 9.8 - 2018-08-10
CVE-2018-3778 aedes 安全漏洞 — aedes CWE-285 5.3 - 2018-08-08
CVE-2018-3771 statics-server 跨站脚本漏洞 — statics-server CWE-79 6.1 - 2018-07-20
CVE-2018-3770 markdown-pdf 路径遍历漏洞 — markdown-pdf CWE-22 5.5 - 2018-07-20
CVE-2018-3760 Sprockets 信息泄露漏洞 — Sprockets CWE-22 7.5 - 2018-06-26
CVE-2018-3759 private_address_check ruby gem 竞争条件漏洞 — private_address_check ruby gem CWE-362 5.9 - 2018-06-13
CVE-2018-3758 express-cart 安全漏洞 — express-cart CWE-22 7.2 - 2018-06-07
CVE-2017-16127 pandora-doomsday 安全漏洞 — pandora-doomsday node module CWE-509 9.1 - 2018-06-07
CVE-2017-16124 node-server-forfront 路径遍历漏洞 — node-server-forfront node module CWE-22 7.5 - 2018-06-07
CVE-2017-16125 rtcmulticonnection-client 路径遍历漏洞 — rtcmulticonnection-client node module CWE-22 7.5 - 2018-06-07

This page lists every published CVE security advisory associated with HackerOne. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.