Teaching Bug Bounty Leaderboard
This leaderboard tracks maintainer-confirmed vulnerabilities reported by students across my teaching activities. The goal is simple: encourage students to move beyond toy examples, engage with real systems, and learn how high-quality security work creates real fixes in the world.
I strongly encourage students to do real-world hacking responsibly instead of staying only with toy examples. If your work leads to a real maintainer-confirmed vulnerability, it will be rewarded through course credit, public recognition on this page, or both, depending on the course.
Quick links: GitHub reporting | Report writing | OpenSSF guide | CERT CVD guide
All-time leaderboard
| Student / Team | Approach | Term | Confirmed Bugs | Bug Gallery |
|---|---|---|---|---|
| Quoc Bui | frieren (AI4Sec Project) | Spring26 | 3 | - |
- The Approach column can describe a manual audit, a semi-automated workflow, or a custom auditor that a team built.
- The Bug Gallery column points to a collection page for the real bugs that a student or team has found, when such a page is available.
- Submissions are added after maintainer confirmation and whatever reporting workflow is used in the relevant course.