Packt

Working with CVEs for Ethical Hacking & Bug Bounties

Labor Day starts with $70+ in savings on Coursera Plus. Save 40% for 3 months.

Packt

Working with CVEs for Ethical Hacking & Bug Bounties

Ask Coursera

Gain insight into a topic and learn the fundamentals.
Intermediate level

Recommended experience

1 week to complete
at 10 hours a week
Flexible schedule
Learn at your own pace
Gain insight into a topic and learn the fundamentals.
Intermediate level

Recommended experience

1 week to complete
at 10 hours a week
Flexible schedule
Learn at your own pace

What you'll learn

  • Understand CVE terminology and how vulnerabilities are cataloged

  • Gain proficiency in using Shodan, Burp Suite, and other key tools

  • Conduct live vulnerability hunts across multiple platforms

Details to know

Shareable certificate

Add to your LinkedIn profile

Recently updated!

August 2026

Assessments

22 assignments

Taught in English

See how employees at top companies are mastering in-demand skills

 logos of Petrobras, TATA, Danone, Capgemini, P&G and L'Oreal

There are 23 modules in this course

This module introduces learners to the course structure and essential policies, ensuring they understand the rules and expectations before diving into the content.

What's included

1 video

This module provides an overview of CVEs, including their definition, naming conventions, and practical applications in cybersecurity. Learners will gain a foundational understanding of how vulnerabilities are identified and cataloged, as well as how to use CVE resources effectively.

What's included

2 videos1 assignment

This module provides an in-depth exploration of the Bugcrowd Vulnerability Rating Taxonomy (VRT), the CIA Triad, and CVSS scoring. Learners will gain the skills to assess and prioritize vulnerabilities effectively in real-world bug bounty scenarios. The content also covers the limitations of VRT and how to address them strategically.

What's included

12 videos1 assignment

This module provides an in-depth exploration of Shodan, covering its graphical interface, report generation capabilities, and methods for analyzing images and exploits. Learners will gain practical skills in using Shodan for vulnerability research and security assessments.

What's included

5 videos1 assignment

This module covers the use of Censys for subdomain enumeration, including manual and automated techniques, API key management, and result filtering. Learners will gain practical skills for reconnaissance and security research in bug bounty and penetration testing scenarios.

What's included

2 videos1 assignment

This module explores the practical application of Google Dorks for identifying website vulnerabilities, creating original search queries, and contributing to security research. Learners will gain hands-on skills in using search operators and understanding the role of Google Dorks in ethical hacking.

What's included

2 videos1 assignment

This module explores the use of Crt.sh for certificate transparency, covering techniques to detect SSL/TLS issues, identify wildcard certificates, and automate monitoring processes. Learners will gain hands-on skills in reviewing certificate logs and applying command-line tools for security analysis.

What's included

3 videos1 assignment

This module explores how vulnerability severity is assessed on the HackerOne platform, focusing on the criteria used to categorize issues and the role of program owners in the process. Learners will gain an understanding of the practical implications of severity classification in bug bounty programs.

What's included

1 video1 assignment

This module provides hands-on guidance on configuring Burp Suite Proxy for web traffic analysis and interception, essential for penetration testing. Learners will gain foundational knowledge of proxy functionality, interception techniques, and browser configuration for secure testing environments.

What's included

1 video1 assignment

This module focuses on identifying and analyzing security vulnerabilities in Microweber systems through live hunting and reviewing key concepts related to database disclosure exploits. Learners will gain hands-on experience in detecting and understanding potential security risks.

What's included

1 video1 assignment

This module explores techniques for identifying and mitigating vulnerabilities in Jira, including sensitive data exposure, user enumeration, and CVE exploitation. Learners will gain hands-on experience with live hunting methods and automation strategies to detect and address security risks.

What's included

3 videos1 assignment

This module explores how to identify and analyze SAP vulnerabilities, including authentication bypass and code execution flaws. Learners will gain hands-on experience with live hunting techniques and compare real-world CVEs. The content emphasizes understanding exploitation methods and their security implications.

What's included

3 videos1 assignment

This module explores the process of identifying and understanding CVE-2028512, a reflected cross-site scripting vulnerability in Icewarp webmail. It covers techniques for live hunting and responsible disclosure practices, equipping learners with skills to assess and respond to real-world security threats.

What's included

1 video1 assignment

This module provides an in-depth look at identifying and analyzing BigIP CVEs through practical techniques like live hunting and automation. Learners will gain skills in detecting security flaws, understanding mitigation strategies, and applying best practices for bug bounty reporting.

What's included

2 videos1 assignment

This module explores how to identify and analyze Cisco vulnerabilities related to file read and deletion exploits. Learners will gain hands-on experience with live hunting techniques and understand the impact of these vulnerabilities on system security. It also covers detection methods and automation strategies to mitigate risks.

What's included

2 videos1 assignment

This module teaches learners how to use visual reconnaissance techniques with screenshots to detect vulnerabilities in web applications. It covers the importance of visual analysis in security assessments and provides practical insights into optimizing the process for bug bounty and security research.

What's included

1 video1 assignment

This module provides an in-depth overview of various bug bounty platforms, including their roadmaps, participation processes, and reporting procedures. Learners will gain insights into how to begin their journey in bug bounty programs and understand the key requirements for successful participation.

What's included

7 videos1 assignment

This module provides an in-depth look at public vulnerability reporting platforms, focusing on how to access, monitor, and learn from real-world security issues. Learners will gain practical skills in using tools like HackerOne and Bugcrowd to understand vulnerability disclosure and researcher collaboration.

What's included

2 videos1 assignment

This module guides learners through setting up a free VPS environment specifically tailored for bug bounty activities. It covers essential steps for configuring and optimizing a reliable VPS, as well as secure methods for transmitting data and deploying automated cloud infrastructure.

What's included

3 videos1 assignment

This module teaches learners how to set up and configure alerts and notifications for their bug bounty VPS. It covers the use of real-time tools, webhooks, and Slack integration to monitor new vulnerabilities efficiently. Learners will gain practical skills to streamline their bug bounty automation workflows.

What's included

1 video1 assignment

This module explores how to investigate and assess Kubernetes vulnerabilities, with a focus on real-world examples like the Apple Hall of Fame vulnerability. Learners will gain skills in identifying, analyzing, and mitigating security risks associated with containerized environments.

What's included

1 video1 assignment

This module focuses on identifying and analyzing Citrix vulnerabilities, specifically path traversal issues. Learners will gain hands-on experience in detecting and understanding the exploits associated with these security flaws. The content emphasizes practical skills in live hunting and assessing the impact of such vulnerabilities.

What's included

1 video1 assignment

This module explores how to detect and investigate Apache-related remote code execution (RCE) vulnerabilities. Learners will gain hands-on experience in analyzing real-world security threats and understanding the implications of such vulnerabilities. The content focuses on practical techniques for live threat hunting in Apache environments.

What's included

1 video1 assignment

Instructor

Packt - Course Instructors
Packt
2,145 Courses655,267 learners

Offered by

Packt

Why people choose Coursera for their career

Felipe M.

Learner since 2018
"To be able to take courses at my own pace and rhythm has been an amazing experience. I can learn whenever it fits my schedule and mood."

Jennifer J.

Learner since 2020
"I directly applied the concepts and skills I learned from my courses to an exciting new project at work."

Larry W.

Learner since 2021
"When I need courses on topics that my university doesn't offer, Coursera is one of the best places to go."

Chaitanya A.

"Learning isn't just about being better at your job: it's so much more than that. Coursera allows me to learn without limits."

Frequently asked questions