https://www.openbugbounty.org/bugbounty-list/
The complete list of bug bounty and security vulnerability disclosure programs launched and operated by open bug bounty community.
Resources — Disclosure Email, Website security page, Number of reports fixed.
https://www.bugcrowd.com/bug-bounty-list/
The most comprehensive, up-to-date crowdsourced list of bug bounty and security vulnerability disclosure programs from across the web curated by the hacker community.
Filters — Program Name, Bug Bounty eligible, Swag, Hall of Fame, Submission URL, Safe harbor.
https://github.com/projectdiscovery/public-bugbounty-programs
The JSON file includes the public bug bounty programs listed on chaos.projectdiscovery.io.
{ "name":"HackerOne", "url":"https://hackerone.com/security", "bounty": true, "swag": true, "domains":[ "hackerone.com", "hackerone.net", "hacker101.com", "hackerone-ext-content.com" ] }
https://raw.githubusercontent.com/disclose/diodb/master/program-list.json
A true, community-powered, vendor-agnostic directory of all known VDP and BBPs, contact details, policy location, preferred languages, and the status of Safe harbor, Availability rewards, hall of fame, swag, and Disclosure policy.
https://github.com/cablej/hack-your-government
Vulnerability disclosure policies and bug bounty programs are becoming standard across industry and government. Beginning with the U.S. Department of Defense, several government agencies worldwide have implemented vulnerability disclosure programs.
This is a list of government agencies that have bug bounty programs or vulnerability disclosure policies.
Note: This list is not an invitation to hack any of the listed organizations. Ensure that you comply with all listed terms of an organization’s vulnerability disclosure policy.
Includes details about — Organization, Type, Rewards, Link, Notes.
https://github.com/sushiwushi/bug-bounty-dorks
List of Google Dorks to search for companies that have a responsible disclosure program or bug bounty program which are not affiliated with known bug bounty platforms such as HackerOne or BugCrowd.
Also Published here