Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Coursera

Working with CVEs for Ethical Hacking & Bug Bounties

Packt via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course teaches how to analyze and exploit CVEs, set up environments for penetration testing, and use Bug Bounty platforms for reporting vulnerabilities. It covers key tools like Burp Suite, Shodan, and Google Dorks for efficient hunting. Aimed at ethical hackers and security enthusiasts, this course offers practical, real-world knowledge. This course offers a deep dive into CVEs (Common Vulnerabilities and Exposures), starting with an introduction to their role in cybersecurity. You'll learn about CVE nomenclature, how to identify, and categorize vulnerabilities. The course explores tools like Bugcrowd and Shodan, helping you efficiently hunt for vulnerabilities across platforms such as Jira, SAP, and Cisco. You'll gain hands-on experience identifying different vulnerability types and learn how to report them accurately on bug bounty platforms. Throughout the course, you'll master advanced techniques like subdomain enumeration, certificate transparency, and visual recon. Practical labs will allow you to hunt for CVEs in real-world platforms such as Microweber, Cisco, and Apache, reinforcing your learning. The course is designed for ethical hackers, penetration testers, and bug bounty hunters, requiring basic knowledge of cybersecurity principles but no prior experience. By the end of the course, you will be well-equipped to conduct vulnerability hunts on major platforms, identify critical flaws, and effectively report your findings to bug bounty programs. This course provides the tools and techniques needed to advance your skills in the bug bounty space. This course is perfect for ethical hackers, penetration testers, and bug bounty hunters looking to enhance their CVE analysis and vulnerability hunting skills. It’s suitable for those with a basic understanding of cybersecurity principles, whether you’re a beginner or an intermediate practitioner. The course employs a hands-on, lab-driven approach. You’ll gain practical experience by setting up penetration testing environments and performing live vulnerability hunting. Each module builds on the last, ensuring you progress from foundational concepts to advanced techniques seamlessly. This course is based on Working with CVEs for Ethical Hacking & Bug Bounties (2026), by Hacktify Technologies Pvt. Ltd.. This video is licensed and distributed by Packt. All rights reserved. Packt is one of the world's most prolific publishers of cutting-edge technical content. For over two decades we've made it our mission to curate and publish the knowledge of only the very best technical experts. We focus on real-world courses that help our customers get the job done, with coverage that extends across a wide range of established and cutting-edge technical topics. If you're an individual or an organisation that embraces learning by doing, Packt is the perfect fit for you.

Syllabus

  • Introduction
    • This module introduces learners to the course structure and essential policies, ensuring they understand the rules and expectations before diving into the content.
  • All about CVE's
    • This module provides an overview of CVEs, including their definition, naming conventions, and practical applications in cybersecurity. Learners will gain a foundational understanding of how vulnerabilities are identified and cataloged, as well as how to use CVE resources effectively.
  • Bugcrowd VRT
    • This module provides an in-depth exploration of the Bugcrowd Vulnerability Rating Taxonomy (VRT), the CIA Triad, and CVSS scoring. Learners will gain the skills to assess and prioritize vulnerabilities effectively in real-world bug bounty scenarios. The content also covers the limitations of VRT and how to address them strategically.
  • Shodan
    • This module provides an in-depth exploration of Shodan, covering its graphical interface, report generation capabilities, and methods for analyzing images and exploits. Learners will gain practical skills in using Shodan for vulnerability research and security assessments.
  • Censys
    • This module covers the use of Censys for subdomain enumeration, including manual and automated techniques, API key management, and result filtering. Learners will gain practical skills for reconnaissance and security research in bug bounty and penetration testing scenarios.
  • Google Dork
    • This module explores the practical application of Google Dorks for identifying website vulnerabilities, creating original search queries, and contributing to security research. Learners will gain hands-on skills in using search operators and understanding the role of Google Dorks in ethical hacking.
  • Certificate Transparency
    • This module explores the use of Crt.sh for certificate transparency, covering techniques to detect SSL/TLS issues, identify wildcard certificates, and automate monitoring processes. Learners will gain hands-on skills in reviewing certificate logs and applying command-line tools for security analysis.
  • Hackerone Severity
    • This module explores how vulnerability severity is assessed on the HackerOne platform, focusing on the criteria used to categorize issues and the role of program owners in the process. Learners will gain an understanding of the practical implications of severity classification in bug bounty programs.
  • Setting up Environment
    • This module provides hands-on guidance on configuring Burp Suite Proxy for web traffic analysis and interception, essential for penetration testing. Learners will gain foundational knowledge of proxy functionality, interception techniques, and browser configuration for secure testing environments.
  • Microweber CVE's
    • This module focuses on identifying and analyzing security vulnerabilities in Microweber systems through live hunting and reviewing key concepts related to database disclosure exploits. Learners will gain hands-on experience in detecting and understanding potential security risks.
  • Jira CVE's
    • This module explores techniques for identifying and mitigating vulnerabilities in Jira, including sensitive data exposure, user enumeration, and CVE exploitation. Learners will gain hands-on experience with live hunting methods and automation strategies to detect and address security risks.
  • SAP CVE
    • This module explores how to identify and analyze SAP vulnerabilities, including authentication bypass and code execution flaws. Learners will gain hands-on experience with live hunting techniques and compare real-world CVEs. The content emphasizes understanding exploitation methods and their security implications.
  • Icewarp CVE
    • This module explores the process of identifying and understanding CVE-2028512, a reflected cross-site scripting vulnerability in Icewarp webmail. It covers techniques for live hunting and responsible disclosure practices, equipping learners with skills to assess and respond to real-world security threats.
  • BigIP CVE
    • This module provides an in-depth look at identifying and analyzing BigIP CVEs through practical techniques like live hunting and automation. Learners will gain skills in detecting security flaws, understanding mitigation strategies, and applying best practices for bug bounty reporting.
  • Cisco CVE's
    • This module explores how to identify and analyze Cisco vulnerabilities related to file read and deletion exploits. Learners will gain hands-on experience with live hunting techniques and understand the impact of these vulnerabilities on system security. It also covers detection methods and automation strategies to mitigate risks.
  • Visual Recon
    • This module teaches learners how to use visual reconnaissance techniques with screenshots to detect vulnerabilities in web applications. It covers the importance of visual analysis in security assessments and provides practical insights into optimizing the process for bug bounty and security research.
  • How to start with Bug Bounty Platforms and Reporting
    • This module provides an in-depth overview of various bug bounty platforms, including their roadmaps, participation processes, and reporting procedures. Learners will gain insights into how to begin their journey in bug bounty programs and understand the key requirements for successful participation.
  • Awesome Resources
    • This module provides an in-depth look at public vulnerability reporting platforms, focusing on how to access, monitor, and learn from real-world security issues. Learners will gain practical skills in using tools like HackerOne and Bugcrowd to understand vulnerability disclosure and researcher collaboration.
  • Bug Bounty Free VPS
    • This module guides learners through setting up a free VPS environment specifically tailored for bug bounty activities. It covers essential steps for configuring and optimizing a reliable VPS, as well as secure methods for transmitting data and deploying automated cloud infrastructure.
  • Bug Bounty VPS Alerts & Notifications
    • This module teaches learners how to set up and configure alerts and notifications for their bug bounty VPS. It covers the use of real-time tools, webhooks, and Slack integration to monitor new vulnerabilities efficiently. Learners will gain practical skills to streamline their bug bounty automation workflows.
  • Kubernetes CVE
    • This module explores how to investigate and assess Kubernetes vulnerabilities, with a focus on real-world examples like the Apple Hall of Fame vulnerability. Learners will gain skills in identifying, analyzing, and mitigating security risks associated with containerized environments.
  • Citrix CVE
    • This module focuses on identifying and analyzing Citrix vulnerabilities, specifically path traversal issues. Learners will gain hands-on experience in detecting and understanding the exploits associated with these security flaws. The content emphasizes practical skills in live hunting and assessing the impact of such vulnerabilities.
  • Apache CVE
    • This module explores how to detect and investigate Apache-related remote code execution (RCE) vulnerabilities. Learners will gain hands-on experience in analyzing real-world security threats and understanding the implications of such vulnerabilities. The content focuses on practical techniques for live threat hunting in Apache environments.

Taught by

Packt - Course Instructors

Reviews

Start your review of Working with CVEs for Ethical Hacking & Bug Bounties

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.