Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

tesco

HackerOneView on HackerOne
RawAI Enhanced
24
In Scope
3
Out of Scope

In-Scope Assets (24)

AssetCategoryBountyQuick Links
*.itesco.cz/*WILDCARDNo
*.itesco.sk/*WILDCARDNo
*.ourtesco.com/*WILDCARDNo
*.tesco-europe.com/*WILDCARDNo
*.tesco.com/*WILDCARDNo
*.tesco.hu/*WILDCARDNo
*.tesco.ie/*WILDCARDNo
*.tesco.org/*WILDCARDNo
*.tesco.sk/*WILDCARDNo
*.tescocloud.com/*WILDCARDNo
*.tescoplc.com/*WILDCARDNo
389581236IOSNo-
857834425IOSNo-
API AssetsOTHERNo-
Cloud AssetsOTHERNo-
Domain, Subdomain & Zone TakeoversOTHERNo-
Exposed Sensitive DocumentsOTHERNo-
Leaked & Default CredentialsOTHERNo-
Medium, High and Critical Severity Issue on Out-Of-Scope AssetsOTHERNo-
Third-Party Managed AssetsOTHERNo-
com.tesco.grocery.viewANDROIDNo
https://www.booker.co.uk/*WILDCARDNo
https://www.onestop.co.uk/*WILDCARDNo
https://www.tescomobile.com/*WILDCARDNo
Out-of-Scope Assets (3)
AssetCategoryBounty
Dunnhumby (Non-Critical)OTHERNo
Tesco BankOTHERNo
com.tescobank.mobileANDROIDNo