Early access: the directory is still filling out, and every rating here is a reported experience.

Attack surface intelligence

See which programs are heating up before the crowd does.

BugRater reads the whole bug bounty field as a live market: which programs are heating up as reports pour in, which are under-hunted while intake is still healthy, and what their surface is exposing right now. Stop guessing where to spend the night.

Where to hunt tonight live
1 Stripe ↑ +17% 6.8/day under-hunted · 331
2 Flutter UK&I ↑ +16% 2.5/day busy · 500
3 Flickr ↑ +14% 1.0/day under-hunted · 181
4 Spotify ↑ +13% 10.4/day crowded · 993
5 Basecamp ↑ +13% 5.4/day busy · 413
153 rated · board, drill-downs, API, digests Open the board →

Signal intelligence

See what's exposed right now

We enumerate each program's surface and flag what deserves a second look. Not findings, leads: the exposed thing worth the first hour of your night.

The signal feed →
17,926

Exposed configs and secrets

Config files, env dumps, and keys reachable on the live surface.

502

Staging and pre-prod high

The softer builds behind a program, where controls slip.

132

Login and admin panels

Auth surfaces and consoles worth a closer look.

2,114

Live-probed hosts

Across 3,049 subdomains enumerated so far.

Freshest exposures

Exposed config 89.••••••• Semmle 🔒
Exposed config 82.••••••• Hilton 🔒
Exposed config 62.••••••• Hilton 🔒
Exposed config 121.••••••• Hilton 🔒
Exposed config 82.••••••• Hilton 🔒
Exposed config 89.••••••• Semmle 🔒

Hosts unlock with a subscription. See what's inside →

Three ways in

However you hunt, the intel meets you there

Pricing →

The board

Scan it in your browser

The full rated board, every program's drill-down, and the live exposure feed. Where to hunt tonight, no setup.

Open the board →

The API

Pull it into your recon

Ten endpoints, metered by the call, with $200 of usage included every month. Wire the intel into your own tooling.

Read the API docs →

Daily digests

Wake up to your shortlist

A quiz picks your programs and the asset types you care about, then a personalized brief lands each morning. Preferences rolling out.

Included · see the offer →

The public record

Your name is already in the file

Every vendor security release names the researchers behind it. We index every line, CVEs and the recognitions that carry no CVE at all, with an identifier you can quote.

Search the record →
Security release credits as of 23 Sep 2026 indexing
CVE-2026-86882 Accelerate Framework Peter Malone Apple
CVE-2026-43664 Accessibility Stuart Wallace Apple
CVE-2026-43664 Accessibility Ilya Andr (andrd3v) Apple
CVE-2026-43664 Accessibility Rosyna Keller of Totally Not Malicious Software Apple
CVE-2026-43664 Accessibility CJ Vana Apple
CVE-2026-43664 Accessibility David Strnadel Apple
CVE-2026-43664 Accessibility Daniel Febrero Apple
CVE-2026-43664 Accessibility Asaf Cohen Apple
CVE-2026-43664 Accessibility Gongyu Ma (@Mezone0) Apple
CVE-2026-43664 Accessibility Jian Lee (@speedyfriend433) Apple
CVE-2026-84523 APFS Cem Onat Karagun Apple
CVE-2026-86888 App Store Zhongcheng Li (CK01) Apple
CVE-2026-65407 AppleAVD Franco Belman at Blackwing Intelligence Apple
CVE-2026-65339 Audio Mustafa Calap (@ordinal0, dbg.re) Apple
CVE-2026-65339 Audio Meta Red Team X - Nik Tsytsarkin Apple
CVE-2026-84583 AuthKit Zhongcheng Li from IES Red Team Apple
CVE-2026-65410 AVEVideoEncoder Calif.io in collaboration with Claude and Anthropic Research Apple
CVE-2026-84616 AVEVideoEncoder Peter Malone Apple
CVE-2026-84607 AVEVideoEncoder Ruslan Dautov Apple
CVE-2026-65406 BackgroundAssets Ye Zhang (@VAR10CK) of Baidu Security Apple
CVE-2026-86895 CloudKit Stanislav Jelezoglo Apple
CVE-2026-86893 CloudKit Heiner Gerdes Apple
CVE-2026-65344 CoreMedia Siyeong kim Apple
CVE-2026-43737 CoreMotion Stuart Wallace Apple
11,675credit lines
4,167researchers
3,101carry no CVE
Find your line →

From the people who worked them

What it is actually like to submit there

Every review answers the same questions: how many reports, what was paid, how long the first reply took, whether they would go back. So two programs can be compared instead of merely described.

MongoDB Bug Bounty MongoDB · HackerOne ★★★☆☆

One click remote code execution - Working as intended. Then reopened

“Triage overall left me relatively disappointed, but by equal measures, relived. I reported a remote code execution to this program in May, the H1 analyst team reviewed and downgraded the severity from critical to high on account of double-counting the UI:R co…”

reports 1 paid $2k – $10k 1st reply Within 3 days resubmit yes
MAMaliq Barnard ✓ verified August 2026
A+ National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program NASA · Bugcrowd ★★★★★

Securing the Cosmos: Earning Hall of Fame with NASA

“Reporting to the NASA Vulnerability Disclosure Program on Bugcrowd is an incredibly rewarding experience. The security team is highly professional, and they genuinely value the efforts of the community in keeping their massive infrastructure secure. Receiving…”

reports 1 paid No payment 1st reply Within 3 days resubmit yes
RARathore August 2026
Apple Security Bounty Apple ★★★★

Authentication Bypass on *.apple.com

“Hunting on Apple requires patience, but verifying a successful fix makes the wait worthwhile. I reported a vulnerability on *.apple.com where a advance client-side response manipulation allowed a complete bypass of the authentication gate. Tracking the status…”

reports 1 1st reply 1–3 months resubmit yes
RARathore August 2026
Google Vulnerability Reward Program Google · Direct / email ★★★★★

The Program with Massive Surface Area, Fair Triage, and Great Scope Alignment

“Majorly I participate in Google VRP mostly as a casual and daily user rather than doing dedicated, aggressive bug hunting. Most of the security flaws I have reported came from normal day to day usage of Google products rather than active deep scanning. The sh…”

1st reply Within 3 days resubmit yes
SSSSP August 2026
Personio Bug Bounty Personio · Intigriti ★★★★

Professional, Transparent, and Responsive.

“I've spent a significant amount of time testing Personio and interacting with their security team through responsible disclosure. Overall, the experience has been positive. The security team is professional, communicates clearly, and is willing to discuss tec…”

1st reply 1–3 months resubmit yes
ANAnonymous researcher August 2026
A+ National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program NASA · Bugcrowd ★★★☆☆

I submitted 3 SSRF findings across the NASA VRP scope - they all went informative

“As the tittle says, I had three. SSRF reports go to NASA's VPR before they were all closed as informative under P5. Which, while unfortunate, had the reports triaged in under 2 days. Which is always a quality I as a research greatly appreciate from programs a…”

reports 3 paid No payment 1st reply Within 3 days resubmit yes
MAMaliq Barnard ✓ verified August 2026
A+ National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program NASA · Bugcrowd ★★★★

NASA's Highly Competitive VDP on Bugcrowd

“NASA VDP is triaged by Bugcrowd team before handing it over to NASA officials for confirmation. I noticed that Bugcrowd's bot such as teapot_bugcrowd tends to mark report submissions as N/A. This was the case with my accepted report that earned me the NASA's …”

resubmit yes
AAaaronamran August 2026
Apple Security Bounty Apple · Direct / email ★★★★

Responsive, fair, and quick.

“I have spent the last 4 months interacting with the Apple security response team (SRT). They have been incredibly thorough with their evaluations, informative closes are almost always accompanied by a detailed explanation as to why it is not applicable. They …”

reports 9 paid $500 – $2k 1st reply Within 3 days resubmit yes
MAMaliq Barnard ✓ verified August 2026

Where credit is recorded in public

Security releases

When a vendor ships a security release it names the researchers behind it: CVEs and additional recognitions alike. We record every line, CVE or not, with a BugRater ID you can quote. If your name is here, the credit is yours to claim: instantly, and durable on your profile.

Top-rated programs

Full rankings →

New · a native Mac app

Give your agents’ findings a permanent trail.

Research Tracker runs on your Mac. Your agents report findings to it over a local API, and each one is appended to a BugRater project: shared, attributed, append-only. On an encrypted project the content is sealed on your machine before it is sent, so a finding becomes evidence of who established what, without handing us the finding itself.

Download for macOS Version 1.4 · Free · Apple-signed · macOS 14+
Research Tracker showing findings with 'in the log' badges tying each to its BugRater entry

Write one

The things you learned the expensive way

See the form →

Every researcher is carrying a set of rules nobody wrote down for them. This program disputes valid scope. That one downgrades every severity. This one is slow but pays above market and will actually argue the technical detail with you. Each of those was paid for with a month of work, or a report that died, or a duplicate filed six hours late.

Writing it down is what turns a private scar into something the next person reads before they spend the month. And because every review answers the same questions, yours does not sit alone as an anecdote. It moves the program's grade, its median response time, and the strengths and concerns other researchers see first.

Post under your handle or anonymously. Either way it is account-backed, so a review here costs something to write. That is exactly why it is worth reading.

What happens after you post

A moderator reads it For abuse and for anything that identifies a person, not for whether it flatters the program. A company cannot have a review of itself taken down.
The grade moves Your ratings recompute the program's letter grade and its median response time. Verified reviews carry double weight, because a verified account has something to lose.
The details stay anonymous Nothing you report is named in an aggregate until 3 reports from 2 different researchers say the same thing. Below that floor it folds into an unnamed residual.
They get one reply, not a veto If the company has claimed its profile it can answer, published under its own name, underneath yours. That is the whole of what claiming buys.
Rate a program: the actual form
sent
resolved
duplicate
n/a · closed
Triage speed★★★★ Communication★★★★★ Payout fairness★★★☆☆ Scope clarity★★★★
Engages on the technical detail Credits researchers Downgrades severity Fair on duplicates Assigns CVEs Slow to first response Silently patched, no credit

14 strengths and 14 concerns, the same list on every program. That is what makes them countable rather than quotable.

Write a review Takes about five minutes. Everything but the headline and the review body is optional.

Who builds this

No program pays us to be rated.

That single fact is the whole design. A platform earns its money from the companies it hosts, so the moment a researcher's account of a program is inconvenient, the platform has a customer to keep and you do not. We have no such customer.

This is built by someone who submits reports and waits, who has had a month's work closed informative in an hour, and who has watched a duplicate land six hours ahead of him. Every decision beside this was made by someone who expected to be on the receiving end of it.

Maliq Barnard

Security researcher · builds and maintains BugRater
3 published CVEs · reviews on this site under the same handle →

  • 01

    A company cannot delete a review of itself

    Claiming a profile buys one thing: a reply, published under the company's name, beneath the review it answers. There is no takedown path, and moderators cannot post in a company's voice either.

  • 02

    We do not hold your unpatched findings

    Private report detail is encrypted at rest with a key that is not in the database. A collaboration project goes further: keys are generated in your browser and we hold ciphertext we have no way to open. Not “will not”: cannot.

  • 03

    Your report cannot be traced back to you through the numbers

    No detail is named in an aggregate until 3 reports from 2 different researchers say it. Below that floor it folds into an unnamed residual, because a statistic of one is a disclosure wearing a percentage sign.

  • 04

    Claiming your own credit does not wait on us

    The vendor printed your name in their own advisory. A moderator standing between you and that adds no truth to it. Only delay. Claims are instant; disputes are the exception we review, not the rule.

The brief

Get the data, not the noise.

Occasional briefs built from real researcher reviews: which programs are worth your time, what the numbers say, and the pieces we publish. No spam.