Open-source vulnerability disclosure and bug bounty program database
-
Updated
Jul 13, 2026 - Python
Open-source vulnerability disclosure and bug bounty program database
Tools, data, and contact lists relevant to The disclose.io Project.
176 vulnerabilities in Samsung preinstalled Android apps
Independent research white paper by Jon “GainSec” Gaines examining the security posture of a connected public safety technology ecosystem.
The First Open Source Bug Bounty Platform
Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations
Misc bounty and vulndisc things
Agent-assisted maintainership and development framework for Apache projects — Triage, Mentoring, Drafting (agent-authored fixes with human review), and Pairing (developer-side dev-cycle) skills shipping; Agentic Autonomous (auto-merge) on the roadmap.
Open-source vulnerability disclosure policy templates.
Vulnerability analysis and proof of concepts
A standard allowing organizations to nominate security contact points and policies via DNS TXT records.
Vultron is a protocol for Coordinated Vulnerability Disclosure
A Python client for the Global CVE Allocation System.
Content for the CERT Guide to Coordinated Vulnerability Disclosure
A free, open-source, multi-lingual, template-based VDP policy, safe harbor clause, securitytxt, and DNS Security TXT generator.
A collection of templates for generating vulnerability disclosure policies. (NOTE: As of 2024, these templates are now part of the CERT Guide to Coordinated Vulnerability Disclosure, see link in README.)
The Disclose.io Status best practice seal.
Open protocol for signed, verifiable machine decisions. Ed25519 receipts, hash-chained audit trails, in-toto predicate type. 3 IETF Internet-Drafts. Apache-2.0.
Exploit and report for CVE-2023-23396.
Vulnerability research on Tesla Model 3/Y infotainment systems. 6 vulnerabilities, 4 CVEs (CVE-2022-42005 through CVE-2022-42008). Root shell, persistent access, insurance telemetry spoofing.
Add a description, image, and links to the vulnerability-disclosure topic page so that developers can more easily learn about it.
To associate your repository with the vulnerability-disclosure topic, visit your repo's landing page and select "manage topics."