Submission Criteria

We are looking for the following criteria when determining to purchase submitted advisories:

  • THE VULNERABILITY MUST EXIST IN THE LATEST AVAILABLE VERSION OF THE AFFECTED PRODUCT
  • THE VULNERABILITY MUST EXIST IN PRODUCTS WITH WIDESPREAD DEPLOYMENT

Preference will be given to:

  • REMOTE CODE EXECUTION
  • SOFTWARE AFFECTING ENTERPRISES
  • SERVER-SIDE
  • OS (DESKTOP OR MOBILE)
  • BROWSERS
  • SCADA/IIoT
  • SANDBOX ESCAPES
  • VM ESCAPES
  • SECURITY PRODUCTS

We do not commonly offer on bug reports involving: cross-site scripting (XSS), DLL planting, live websites, ActiveX, most consumer-only products, including gaming software (widely used security products and some IoT may be exceptions), beta-/pre-release software, and anything already publicly posted or otherwise known.

If you have any questions or comments regarding our interest level in a particular advisory feel free to contact us directly or submit via our portal for review.