Skip to content
Noroxi

Anonymous

Trend Micro Zero Day Initiative

160 credited records · 7 in the last 12 months · 1 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent.

    MediumCVSS 5.2No exploitEPSS 0%

    qnap systems inc. · qcalagentSep 18, 2026

  • Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)

    HighCVSS 8.1No exploitEPSS 1%

    apache · apache-airflow-providers-googleJul 6, 2026

  • Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern

    CriticalCVSS 9.1No exploitEPSS 1%

    apache · airflowJun 1, 2026

  • Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)

    HighCVSS 8.1No exploitEPSS 1%

    apache · apache-airflow-providers-googleMay 25, 2026

  • RCE in Yordam Informatics' Library Automation System

    HighCVSS 8.8No exploitEPSS 0%

    yordam information technology consulting, training and electronic systems industry and trade inc. · library automation systemMay 14, 2026

  • Improper Access Control in Yordam Informatics' Library Automation System

    HighCVSS 8.8No exploitEPSS 0%

    yordam information technology consulting, training and electronic systems industry and trade inc. · library automation systemMay 14, 2026

  • WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints

    CriticalCVSS 9.2No exploitEPSS 1%

    snap one, llc · wattbox 800Apr 28, 2026

  • A command injection vulnerability has been reported to affect QuRouter 2.5.1.

    HighCVSS 7.1No exploitEPSS 1%

    qnap · qurouterAug 29, 2025

  • billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    naver · billboard.jsJun 3, 2025

  • CVE-2025-0065
    31Monitor

    Improper Neutralization of Argument Delimiters in TeamViewer Clients

    HighCVSS 7.8No exploitEPSS 1%

    teamviewer · remote full clientJan 28, 2025

  • An improper certificate validation vulnerability has been reported to affect QuMagie.

    LowCVSS 1.0No exploitEPSS 0%

    qnap · qumagieSep 6, 2024

  • A path traversal vulnerability has been reported to affect several QNAP operating system versions.

    MediumCVSS 6.5No exploitEPSS 0%

    qnap · qtsSep 6, 2024

  • CVE-2023-3703
    39Monitor

    Proscend Advice ICR Series routers fw version 1.76

    CriticalCVSS 9.8No exploitEPSS 1%

    proscend · m357-5g firmwareSep 3, 2023

  • This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    papercut · papercut mfApr 20, 2023

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.2.12465.

    HighCVSS 7.8No exploitEPSS 1%

    foxit · pdf editorMar 29, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.

    MediumCVSS 6.8No exploitEPSS 1%

    dlink · dir-1935 firmwareMar 29, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.

    MediumCVSS 6.8No exploitEPSS 1%

    dlink · dir-1935 firmwareMar 29, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.

    MediumCVSS 6.8No exploitEPSS 1%

    dlink · dir-1935 firmwareMar 29, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.

    HighCVSS 8.8No exploitEPSS 1%

    dlink · dir-1935 firmwareMar 29, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.

    MediumCVSS 6.8No exploitEPSS 1%

    dlink · dir-1935 firmwareMar 29, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.

    MediumCVSS 6.8No exploitEPSS 1%

    dlink · dir-1935 firmwareMar 29, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.

    MediumCVSS 6.8No exploitEPSS 1%

    dlink · dir-1935 firmwareMar 29, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.

    MediumCVSS 6.8No exploitEPSS 1%

    dlink · dir-1935 firmwareMar 29, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.

    MediumCVSS 6.8No exploitEPSS 1%

    dlink · dir-1935 firmwareMar 29, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.

    MediumCVSS 6.8No exploitEPSS 1%

    dlink · dir-1935 firmwareMar 29, 2023