vulns.co
/
GKData.io MCP

Bugcrowd · 2 min read

Tennessee Valley Authority (TVA) Vulnerability Disclosure Program

Vulnerability Disclosure

Open current program Scope capture

What this record establishes

Scope capture

Published asset rows were captured. The full policy and eligibility were not individually reviewed.

Official directory card labeled Vulnerability Disclosure. No monetary reward displayed. Program policy and submission status not reviewed.

Published asset scope

Snapshot captured 2026-10-03. Scope status: Captured.

In scope · 24 published rows
AssetTypeGroup / eligibility
*.tva.govwebsiteIn Scope Targets
*.tva.comwebsiteIn Scope Targets
*.mytva.comwebsiteIn Scope Targets
*.energyright.comwebsiteIn Scope Targets
*.tva-energyright.comwebsiteIn Scope Targets
*.tvaenergyrightsolutions.comwebsiteIn Scope Targets
tvaloans.comwebsiteIn Scope Targets
tvasites.comwebsiteIn Scope Targets
green.mytva.comwebsiteIn Scope Targets
tvavirtual.comwebsiteIn Scope Targets
tvadeposits.comwebsiteIn Scope Targets
mytva.comwebsiteIn Scope Targets
tvars.comwebsiteIn Scope Targets
tvastem.comwebsiteIn Scope Targets
tvarenewables.comwebsiteIn Scope Targets
tvawcm.comwebsiteIn Scope Targets
tvawcma.comwebsiteIn Scope Targets
myenergyrightadvisor.comwebsiteIn Scope Targets
energyright.efficientchoice.comwebsiteIn Scope Targets
tva.dynamics365portals.uswebsiteIn Scope Targets
tvasd.dynamics365portals.uswebsiteIn Scope Targets
mytvara.orgwebsiteIn Scope Targets
tvamonitoring.comwebsiteIn Scope Targets
tvasites.giswebtechguru.comwebsiteIn Scope Targets
Out of scope · 0 published rows
AssetTypeGroup / eligibility
No rows captured. This does not establish that the program has no assets or restrictions.

Capture limits

  • Only the published asset table was captured; program rules and submission eligibility still require individual review.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03
  2. Published scope source Primary source · reviewed 2026-10-03

Appears in Discovery, Bugcrowd. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software