Skip to content
Noroxi

Evan

6 credited records · 6 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • openEQUELLA < 2026.1.0 Authenticated RCE via Java Deserialization in HTTP Invoker

    HighCVSS 8.7No exploitEPSS 1%

    apereo foundation · openequellaSep 22, 2026

  • openEQUELLA < 2026.1.0 Authenticated Stored SSTI via FreemarkerPortletRenderer

    HighCVSS 8.6No exploitEPSS 1%

    openequella · openequellaSep 20, 2026

  • Ad Inserter <= 2.8.16 - Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameter

    MediumCVSS 5.3No exploitEPSS 0%

    spacetime · ad inserter – ad manager & adsense adsSep 16, 2026

  • Horde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Part Name

    MediumCVSS 5.1No exploitEPSS 0%

    horde · impAug 24, 2026

  • Horde IMP < 7.0.1 Path Traversal via Compose.php img src

    HighCVSS 7.1No exploitEPSS 1%

    horde · impJul 1, 2026

  • Tenda G300-F Command Injection via formSetWanDiag

    HighCVSS 8.6Proof of conceptEPSS 3%

    tenda · g300-f firmwareFeb 7, 2026