// the archive in numbers

Insights

Every figure below is computed live from the 11,358 disclosure records in the archive. Bounty totals reflect only what each platform publishes; competitive-audit platforms rarely attach a figure.

11,358
disclosures
$3.58M
bounty tracked
1,660
reference a CVE
765
programs
4,791
researchers
14
years covered
98 disclosures reference a CVE now in CISA’s Known Exploited Vulnerabilities catalogue — weaknesses confirmed exploited in the wild. Browse them →218 disclosures reference a CVE that EPSS scores at a 50%+ chance of exploitation in the next 30 days (FIRST.org). Rank by likelihood →

Over time

Disclosures per year
1,402689'13'15'17'19'21'23'25'26
Show the numbers
YearDisclosuresBounty
20138$2,250
2014388$33,145
2015485$108,555
2016999$362,670
20171,402$197,117
2018829$238,420
2019992$392,504
20201,086$318,235
20211,082$466,750
2022972$593,557
2023850$355,409
2024847$227,224
2025727$218,944
2026689$67,912
Bounties awarded per year
$593,557$67,912'13'15'17'19'21'23'25'26

Severity, platform & class

By severity
Critical
819
High
1,588
Medium
3,073
Low
2,016
Informational
293
None
3,040
Unrated
529
By platform
HackerOne
10,042 · $3,545,857
Bugcrowd
807 · $7,400
Code4rena
410
Immunefi
92 · $21,435
Intigriti
6 · $8,000
YesWeHack
1
Most common vulnerability classes
Cross-Site Scripting (XSS)
1,798
Authentication / Account Takeover
1,740
Information Disclosure
1,420
Broken Access Control / Privesc
1,081
Business Logic / Secure Design
914
Denial of Service
720
Memory Safety (native)
684
Remote Code / Command Execution
661
Cross-Site Request Forgery (CSRF)
458
Smart Contract / Web3
434
Cryptography / TLS
359
IDOR / Broken Object-Level Auth
322
Show the numbers
ClassDisclosures
Cross-Site Scripting (XSS)1,798
Authentication / Account Takeover1,740
Information Disclosure1,420
Broken Access Control / Privesc1,081
Business Logic / Secure Design914
Denial of Service720
Memory Safety (native)684
Remote Code / Command Execution661
Cross-Site Request Forgery (CSRF)458
Smart Contract / Web3434
Cryptography / TLS359
IDOR / Broken Object-Level Auth322

Researchers & programs

Top researchers by bounty earned
vakzz
$289,520 · 25 reports
saltyyolk
$96,500 · 8 reports
orange
$80,060 · 22 reports
haxta4ok00
$77,800 · 30 reports
h72
$63,500 · 7 reports
hhj4ck
$61,500 · 22 reports
joaxcar
$59,330 · 13 reports
haquaman
$57,400 · 28 reports
ooooooo_q
$52,503 · 47 reports
dkasak
$52,000 · 7 reports
Show the numbers
ResearcherBountyReports
vakzz$289,52025 reports
saltyyolk$96,5008 reports
orange$80,06022 reports
haxta4ok00$77,80030 reports
h72$63,5007 reports
hhj4ck$61,50022 reports
joaxcar$59,33013 reports
haquaman$57,40028 reports
ooooooo_q$52,50347 reports
dkasak$52,0007 reports
Most-disclosed programs
Internet Bug Bounty
789 · $591,448
U.S. Dept Of Defense
634 · $10,000
HackerOne
546 · $339,500
National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
502
Nextcloud
474 · $36,350
Shopify
437 · $286,852
curl
340
GitLab
238 · $623,840
X / xAI
234 · $86,809
Node.js third-party modules
190 · $250
Show the numbers
ProgramDisclosuresBounty
Internet Bug Bounty789$591,448
U.S. Dept Of Defense634$10,000
HackerOne546$339,500
National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program502
Nextcloud474$36,350
Shopify437$286,852
curl340
GitLab238$623,840
X / xAI234$86,809
Node.js third-party modules190$250

Exploitation risk

EPSS — probability of exploitation
90–100%
120
50–90%
98
10–50%
196
under 10%
1,235
Show the numbers
EPSS bandDisclosures
90–100%120
50–90%98
10–50%196
under 10%1,235
Known-exploited (KEV) findings per year
201'14'16'19'21'23'25'26

Bounty economy

Bounty size distribution
$10k+
80
$5k–10k
100
$1k–5k
653
$500–1k
627
$100–500
614
under $100
104
Bounty paid by severity
Critical
$938,048
High
$1.21M
Medium
$685,183
Low
$207,271
None
$510,322
Unrated
$36,835
Largest single bounties
Github access token exposure
$50,000 · HackerOne
Account Takeover via Password Reset without user interactions
$35,000 · HackerOne
Remote Command Execution via Github import
$33,510 · HackerOne
RCE via the DecompressedArchiveSizeValidator and Project BulkImports (behind feature flag)
$33,510 · HackerOne
Arbitrary file read via the bulk imports UploadsPipeline
$29,000 · HackerOne
Exposed Kubernetes API - RCE/Exposed Creds
$25,000 · HackerOne
SQL Injection in report_xml.php through countryFilter[] parameter
$25,000 · HackerOne
The /reports/:id.json endpoint discloses potentially sensitive user attributes when reporter summary is present
$25,000 · HackerOne

What recurs, what resonates

Most-referenced CVEs
CVE-2018-6389
11
CVE-2018-0296
11
CVE-2020-3452
9
CVE-2022-27774
8
CVE-2021-44228
7
CVE-2022-27782
7
CVE-2019-11510
7
CVE-2019-11539
6
CVE-2020-3187
5
CVE-2022-30115
5
Most-voted disclosures
Takeover an account that doesn't have a Shopify ID and more
2,983 · HackerOne
Email Confirmation Bypass in myshop.myshopify.com that Leads to Full Privilege Escalation to Any Shop Owner by Taking Advantage of the Shopify SSO
1,909 · HackerOne
Account takeover via leaked session cookie
1,622 · HackerOne
Github access token exposure
1,514 · HackerOne
Arbitrary file read via the UploadsRewriter when moving and issue
1,496 · HackerOne
Token leak in security challenge flow allows retrieving victim's PayPal email and plain text password
1,403 · HackerOne
RCE on Steam Client via buffer overflow in Server Info
1,287 · HackerOne
Potential pre-auth RCE on Twitter VPN
1,235 · HackerOne

Counts include every indexed disclosure; a report can carry more than one vulnerability class, so class figures sum to more than the total. Explore any slice in the archive or via the API.

Insights — Open Security Research Archive