Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

HackerOne — Vulnerabilities & Security Advisories 470

Browse all 470 CVE security advisories affecting HackerOne. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HackerOne operates a crowdsourced vulnerability disclosure platform, connecting organizations with ethical hackers to identify and remediate security flaws before malicious exploitation. The platform’s extensive record of 470 CVEs highlights a diverse attack surface, with historically common vulnerability classes including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation. These defects often stem from complex API integrations and web application logic errors inherent in its SaaS infrastructure. Notable security characteristics involve its reliance on third-party researchers, which introduces both robust coverage and potential insider threat vectors. While major public incidents have been relatively contained, the platform’s role as a central hub for vulnerability data makes it a high-value target for attackers seeking to disrupt the disclosure ecosystem or harvest sensitive intelligence. Maintaining strict access controls and transparent reporting mechanisms remains critical for preserving trust and ensuring the integrity of the bug bounty process across its global user base.

CVE ID Title CVSS Severity Published
CVE-2015-9243 hapi node模块安全漏洞 — hapi node module CWE-284 6.8 - 2018-05-29
CVE-2015-9244 mysql node模块SQL注入漏洞 — mysql node module CWE-89 9.8 - 2018-05-29
CVE-2016-10525 hapi-auth-jwt2 安全漏洞 — hapi-auth-jwt2 node module 9.8 - 2018-05-29
CVE-2016-10551 waterline-sequel 安全漏洞 — waterline-sequel node module CWE-89 9.8 - 2018-05-29
CVE-2016-10556 sequelize SQL注入漏洞 — sequelize node module CWE-89 9.1 - 2018-05-29
CVE-2016-10558 aerospike 安全漏洞 — aerospike node module CWE-311 8.1 - 2018-05-29
CVE-2016-10559 selenium-download 安全漏洞 — selenium-download node module CWE-311 8.1 - 2018-05-29
CVE-2016-10566 install-nw 安全漏洞 — install-nw node module CWE-311 8.1 - 2018-05-29
CVE-2016-10567 install-nw 安全漏洞 — product-monitor node module CWE-311 8.1 - 2018-05-29
CVE-2016-10568 geoip-lite-country 安全漏洞 — geoip-lite-country node module CWE-311 8.1 - 2018-05-29
CVE-2016-10570 pngcrush-installer 安全漏洞 — pngcrush-installer node module CWE-311 8.1 - 2018-05-29
CVE-2016-10573 baryton-saxophone 安全漏洞 — baryton-saxophone node module CWE-311 8.1 - 2018-05-29
CVE-2016-10577 ibm_db 安全漏洞 — ibm_db node module CWE-311 8.1 - 2018-05-29
CVE-2016-10578 unicode 安全漏洞 — unicode node module CWE-311 8.1 - 2018-05-29
CVE-2016-10584 dalek-browser-chrome-canary 安全漏洞 — dalek-browser-chrome-canary node module CWE-311 8.1 - 2018-05-29
CVE-2016-10586 macaca-chromedriver 安全漏洞 — macaca-chromedriver node module CWE-311 8.1 - 2018-05-29
CVE-2016-10589 selenium-binaries 安全漏洞 — selenium-binaries node module CWE-311 8.1 - 2018-05-29
CVE-2016-10590 cue-sdk-node 安全漏洞 — cue-sdk-node node module CWE-311 8.1 - 2018-05-29
CVE-2016-10591 Prince 安全漏洞 — prince node module CWE-311 8.1 - 2018-05-29
CVE-2016-10593 ibapi 安全漏洞 — ibapi node module CWE-311 8.1 - 2018-05-29
CVE-2016-10601 webdrvr 安全漏洞 — webdrvr node module CWE-311 8.1 - 2018-05-29
CVE-2016-10611 strider-sauce 安全漏洞 — strider-sauce node module CWE-311 8.1 - 2018-05-29
CVE-2016-10627 scala-bin 安全漏洞 — scala-bin node module CWE-311 8.1 - 2018-05-29
CVE-2016-10635 broccoli-closure 安全漏洞 — broccoli-closure node module CWE-311 8.1 - 2018-05-29
CVE-2016-10650 ntfserver 安全漏洞 — ntfserver node module CWE-311 8.1 - 2018-05-29
CVE-2016-10658 native-opencv 安全漏洞 — native-opencv node module CWE-311 8.1 - 2018-05-29
CVE-2016-10659 poco 安全漏洞 — poco node module CWE-311 8.1 - 2018-05-29
CVE-2016-10666 tomita-parser 安全漏洞 — tomita-parser node module CWE-311 8.1 - 2018-05-29
CVE-2016-10674 limbus-buildgen 安全漏洞 — limbus-buildgen node module CWE-311 8.1 - 2018-05-29
CVE-2016-10679 selenium-standalone-painful 安全漏洞 — selenium-standalone-painful node module CWE-311 8.1 - 2018-05-29

This page lists every published CVE security advisory associated with HackerOne. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.