Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
tesco
24
In Scope
3
Out of Scope
In-Scope Assets (24)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| *.itesco.cz/* | WILDCARD | No | ||
| *.itesco.sk/* | WILDCARD | No | ||
| *.ourtesco.com/* | WILDCARD | No | ||
| *.tesco-europe.com/* | WILDCARD | No | ||
| *.tesco.com/* | WILDCARD | No | ||
| *.tesco.hu/* | WILDCARD | No | ||
| *.tesco.ie/* | WILDCARD | No | ||
| *.tesco.org/* | WILDCARD | No | ||
| *.tesco.sk/* | WILDCARD | No | ||
| *.tescocloud.com/* | WILDCARD | No | ||
| *.tescoplc.com/* | WILDCARD | No | ||
| 389581236 | IOS | No | - | |
| 857834425 | IOS | No | - | |
| API Assets | OTHER | No | - | |
| Cloud Assets | OTHER | No | - | |
| Domain, Subdomain & Zone Takeovers | OTHER | No | - | |
| Exposed Sensitive Documents | OTHER | No | - | |
| Leaked & Default Credentials | OTHER | No | - | |
| Medium, High and Critical Severity Issue on Out-Of-Scope Assets | OTHER | No | - | |
| Third-Party Managed Assets | OTHER | No | - | |
| com.tesco.grocery.view | ANDROID | No | ||
| https://www.booker.co.uk/* | WILDCARD | No | ||
| https://www.onestop.co.uk/* | WILDCARD | No | ||
| https://www.tescomobile.com/* | WILDCARD | No |
Out-of-Scope Assets (3)
| Asset | Category | Bounty | |
|---|---|---|---|
| Dunnhumby (Non-Critical) | OTHER | No | |
| Tesco Bank | OTHER | No | |
| com.tescobank.mobile | ANDROID | No |