Anonymous
Trend Micro Zero Day Initiative
160 kredili kayıt · son 12 ayda 7 · 1 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
20İzleyin | CVE-2024-27123İstismar yok | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent.qnap systems inc. · qcalagent · CWE-79 | Orta5,2 | — | %0,1 | 18 Eyl 2026 |
32İzleyin | CVE-2026-49297İstismar yok | Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)apache · apache-airflow-providers-google · CWE-22 | Yüksek8,1 | — | %1,0 | 6 Tem 2026 |
36İzleyin | CVE-2026-42252İstismar yok | Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user patternapache · airflow · CWE-1336 | Kritik9,1 | — | %0,6 | 1 Haz 2026 |
32İzleyin | CVE-2026-45361İstismar yok | Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)apache · apache-airflow-providers-google · CWE-322 | Yüksek8,1 | — | %0,8 | 25 May 2026 |
35İzleyin | CVE-2025-15024İstismar yok | RCE in Yordam Informatics' Library Automation Systemyordam information technology consulting, training and electronic systems industry and trade inc. · library automation system · CWE-94 | Yüksek8,8 | — | %0,2 | 14 May 2026 |
35İzleyin | CVE-2025-15023İstismar yok | Improper Access Control in Yordam Informatics' Library Automation Systemyordam information technology consulting, training and electronic systems industry and trade inc. · library automation system · CWE-863 | Yüksek8,8 | — | %0,2 | 14 May 2026 |
36İzleyin | CVE-2026-41446İstismar yok | WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpointssnap one, llc · wattbox 800 · CWE-798 | Kritik9,2 | — | %0,8 | 28 Nis 2026 |
28İzleyin | CVE-2025-29887İstismar yok | A command injection vulnerability has been reported to affect QuRouter 2.5.1.qnap · qurouter · CWE-77 | Yüksek7,1 | — | %0,8 | 29 Ağu 2025 |
39İzleyin | CVE-2025-49223Kavram kanıtı | billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to executenaver · billboard.js · CWE-1321 | Kritik9,8 | — | %0,8 | 3 Haz 2025 |
31İzleyin | CVE-2025-0065İstismar yok | Improper Neutralization of Argument Delimiters in TeamViewer Clientsteamviewer · remote full client · CWE-88 | Yüksek7,8 | — | %0,6 | 28 Oca 2025 |
4İzleyin | CVE-2024-38642İstismar yok | An improper certificate validation vulnerability has been reported to affect QuMagie.qnap · qumagie · CWE-295 | Düşük1,0 | — | %0,1 | 6 Eyl 2024 |
26İzleyin | CVE-2024-21904İstismar yok | A path traversal vulnerability has been reported to affect several QNAP operating system versions.qnap · qts · CWE-22 | Orta6,5 | — | %0,4 | 6 Eyl 2024 |
39İzleyin | CVE-2023-3703İstismar yok | Proscend Advice ICR Series routers fw version 1.76proscend · m357-5g firmware · CWE-1392 | Kritik9,8 | — | %0,6 | 3 Eyl 2023 |
99Hemen | CVE-2023-27350Silahlaştırılmış | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Kritik9,8 | KEV | %100,0 | 20 Nis 2023 |
31İzleyin | CVE-2022-43649İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.2.12465.foxit · pdf editor · CWE-416 | Yüksek7,8 | — | %1,1 | 29 Mar 2023 |
27İzleyin | CVE-2022-43633İstismar yok | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Orta6,8 | — | %1,1 | 29 Mar 2023 |
27İzleyin | CVE-2022-43632İstismar yok | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Orta6,8 | — | %1,1 | 29 Mar 2023 |
27İzleyin | CVE-2022-43631İstismar yok | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Orta6,8 | — | %1,1 | 29 Mar 2023 |
35İzleyin | CVE-2022-43630İstismar yok | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-121 | Yüksek8,8 | — | %1,0 | 29 Mar 2023 |
27İzleyin | CVE-2022-43629İstismar yok | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Orta6,8 | — | %1,1 | 29 Mar 2023 |
27İzleyin | CVE-2022-43628İstismar yok | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Orta6,8 | — | %0,9 | 29 Mar 2023 |
27İzleyin | CVE-2022-43627İstismar yok | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Orta6,8 | — | %1,1 | 29 Mar 2023 |
27İzleyin | CVE-2022-43626İstismar yok | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Orta6,8 | — | %1,1 | 29 Mar 2023 |
27İzleyin | CVE-2022-43625İstismar yok | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-121 | Orta6,8 | — | %1,1 | 29 Mar 2023 |
27İzleyin | CVE-2022-43624İstismar yok | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Orta6,8 | — | %1,1 | 29 Mar 2023 |
- CVE-2024-2712320İzleyin
A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent.
OrtaCVSS 5,2İstismar yokEPSS %0qnap systems inc. · qcalagent18 Eyl 2026
- CVE-2026-4929732İzleyin
Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)
YüksekCVSS 8,1İstismar yokEPSS %1apache · apache-airflow-providers-google6 Tem 2026
- CVE-2026-4225236İzleyin
Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern
KritikCVSS 9,1İstismar yokEPSS %1apache · airflow1 Haz 2026
- CVE-2026-4536132İzleyin
Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
YüksekCVSS 8,1İstismar yokEPSS %1apache · apache-airflow-providers-google25 May 2026
- CVE-2025-1502435İzleyin
RCE in Yordam Informatics' Library Automation System
YüksekCVSS 8,8İstismar yokEPSS %0yordam information technology consulting, training and electronic systems industry and trade inc. · library automation system14 May 2026
- CVE-2025-1502335İzleyin
Improper Access Control in Yordam Informatics' Library Automation System
YüksekCVSS 8,8İstismar yokEPSS %0yordam information technology consulting, training and electronic systems industry and trade inc. · library automation system14 May 2026
- CVE-2026-4144636İzleyin
WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints
KritikCVSS 9,2İstismar yokEPSS %1snap one, llc · wattbox 80028 Nis 2026
- CVE-2025-2988728İzleyin
A command injection vulnerability has been reported to affect QuRouter 2.5.1.
YüksekCVSS 7,1İstismar yokEPSS %1qnap · qurouter29 Ağu 2025
- CVE-2025-4922339İzleyin
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute
KritikCVSS 9,8Kavram kanıtıEPSS %1naver · billboard.js3 Haz 2025
- CVE-2025-006531İzleyin
Improper Neutralization of Argument Delimiters in TeamViewer Clients
YüksekCVSS 7,8İstismar yokEPSS %1teamviewer · remote full client28 Oca 2025
- CVE-2024-386424İzleyin
An improper certificate validation vulnerability has been reported to affect QuMagie.
DüşükCVSS 1,0İstismar yokEPSS %0qnap · qumagie6 Eyl 2024
- CVE-2024-2190426İzleyin
A path traversal vulnerability has been reported to affect several QNAP operating system versions.
OrtaCVSS 6,5İstismar yokEPSS %0qnap · qts6 Eyl 2024
- CVE-2023-370339İzleyin
Proscend Advice ICR Series routers fw version 1.76
KritikCVSS 9,8İstismar yokEPSS %1proscend · m357-5g firmware3 Eyl 2023
- CVE-2023-2735099Hemen
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100papercut · papercut mf20 Nis 2023
- CVE-2022-4364931İzleyin
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.2.12465.
YüksekCVSS 7,8İstismar yokEPSS %1foxit · pdf editor29 Mar 2023
- CVE-2022-4363327İzleyin
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
OrtaCVSS 6,8İstismar yokEPSS %1dlink · dir-1935 firmware29 Mar 2023
- CVE-2022-4363227İzleyin
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
OrtaCVSS 6,8İstismar yokEPSS %1dlink · dir-1935 firmware29 Mar 2023
- CVE-2022-4363127İzleyin
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
OrtaCVSS 6,8İstismar yokEPSS %1dlink · dir-1935 firmware29 Mar 2023
- CVE-2022-4363035İzleyin
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
YüksekCVSS 8,8İstismar yokEPSS %1dlink · dir-1935 firmware29 Mar 2023
- CVE-2022-4362927İzleyin
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
OrtaCVSS 6,8İstismar yokEPSS %1dlink · dir-1935 firmware29 Mar 2023
- CVE-2022-4362827İzleyin
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
OrtaCVSS 6,8İstismar yokEPSS %1dlink · dir-1935 firmware29 Mar 2023
- CVE-2022-4362727İzleyin
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
OrtaCVSS 6,8İstismar yokEPSS %1dlink · dir-1935 firmware29 Mar 2023
- CVE-2022-4362627İzleyin
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
OrtaCVSS 6,8İstismar yokEPSS %1dlink · dir-1935 firmware29 Mar 2023
- CVE-2022-4362527İzleyin
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
OrtaCVSS 6,8İstismar yokEPSS %1dlink · dir-1935 firmware29 Mar 2023
- CVE-2022-4362427İzleyin
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
OrtaCVSS 6,8İstismar yokEPSS %1dlink · dir-1935 firmware29 Mar 2023