Submission Criteria
We are looking for the following criteria when determining to purchase submitted advisories:
- THE VULNERABILITY MUST EXIST IN THE LATEST AVAILABLE VERSION OF THE AFFECTED PRODUCT
- THE VULNERABILITY MUST EXIST IN PRODUCTS WITH WIDESPREAD DEPLOYMENT
Preference will be given to:
- REMOTE CODE EXECUTION
- SOFTWARE AFFECTING ENTERPRISES
- SERVER-SIDE
- OS (DESKTOP OR MOBILE)
- BROWSERS
- SCADA/IIoT
- SANDBOX ESCAPES
- VM ESCAPES
- SECURITY PRODUCTS
We do not commonly offer on bug reports involving: cross-site scripting (XSS), DLL planting, live websites, ActiveX, most consumer-only products, including gaming software (widely used security products and some IoT may be exceptions), beta-/pre-release software, and anything already publicly posted or otherwise known.
If you have any questions or comments regarding our interest level in a particular advisory feel free to contact us directly or submit via our portal for review.