Anonymous
Trend Micro Zero Day Initiative
160 credited records · 7 in the last 12 months · 1 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
20Monitor | CVE-2024-27123No exploit | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent.qnap systems inc. · qcalagent · CWE-79 | Medium5.2 | — | 0.1% | Sep 18, 2026 |
32Monitor | CVE-2026-49297No exploit | Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)apache · apache-airflow-providers-google · CWE-22 | High8.1 | — | 1.0% | Jul 6, 2026 |
36Monitor | CVE-2026-42252No exploit | Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user patternapache · airflow · CWE-1336 | Critical9.1 | — | 0.6% | Jun 1, 2026 |
32Monitor | CVE-2026-45361No exploit | Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)apache · apache-airflow-providers-google · CWE-322 | High8.1 | — | 0.8% | May 25, 2026 |
35Monitor | CVE-2025-15024No exploit | RCE in Yordam Informatics' Library Automation Systemyordam information technology consulting, training and electronic systems industry and trade inc. · library automation system · CWE-94 | High8.8 | — | 0.2% | May 14, 2026 |
35Monitor | CVE-2025-15023No exploit | Improper Access Control in Yordam Informatics' Library Automation Systemyordam information technology consulting, training and electronic systems industry and trade inc. · library automation system · CWE-863 | High8.8 | — | 0.2% | May 14, 2026 |
36Monitor | CVE-2026-41446No exploit | WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpointssnap one, llc · wattbox 800 · CWE-798 | Critical9.2 | — | 0.8% | Apr 28, 2026 |
28Monitor | CVE-2025-29887No exploit | A command injection vulnerability has been reported to affect QuRouter 2.5.1.qnap · qurouter · CWE-77 | High7.1 | — | 0.8% | Aug 29, 2025 |
39Monitor | CVE-2025-49223Proof of concept | billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to executenaver · billboard.js · CWE-1321 | Critical9.8 | — | 0.8% | Jun 3, 2025 |
31Monitor | CVE-2025-0065No exploit | Improper Neutralization of Argument Delimiters in TeamViewer Clientsteamviewer · remote full client · CWE-88 | High7.8 | — | 0.6% | Jan 28, 2025 |
4Monitor | CVE-2024-38642No exploit | An improper certificate validation vulnerability has been reported to affect QuMagie.qnap · qumagie · CWE-295 | Low1.0 | — | 0.1% | Sep 6, 2024 |
26Monitor | CVE-2024-21904No exploit | A path traversal vulnerability has been reported to affect several QNAP operating system versions.qnap · qts · CWE-22 | Medium6.5 | — | 0.4% | Sep 6, 2024 |
39Monitor | CVE-2023-3703No exploit | Proscend Advice ICR Series routers fw version 1.76proscend · m357-5g firmware · CWE-1392 | Critical9.8 | — | 0.6% | Sep 3, 2023 |
99Now | CVE-2023-27350Weaponized | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Critical9.8 | KEV | 100.0% | Apr 20, 2023 |
31Monitor | CVE-2022-43649No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.2.12465.foxit · pdf editor · CWE-416 | High7.8 | — | 1.1% | Mar 29, 2023 |
27Monitor | CVE-2022-43633No exploit | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Medium6.8 | — | 1.1% | Mar 29, 2023 |
27Monitor | CVE-2022-43632No exploit | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Medium6.8 | — | 1.1% | Mar 29, 2023 |
27Monitor | CVE-2022-43631No exploit | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Medium6.8 | — | 1.1% | Mar 29, 2023 |
35Monitor | CVE-2022-43630No exploit | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-121 | High8.8 | — | 1.0% | Mar 29, 2023 |
27Monitor | CVE-2022-43629No exploit | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Medium6.8 | — | 1.1% | Mar 29, 2023 |
27Monitor | CVE-2022-43628No exploit | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Medium6.8 | — | 0.9% | Mar 29, 2023 |
27Monitor | CVE-2022-43627No exploit | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Medium6.8 | — | 1.1% | Mar 29, 2023 |
27Monitor | CVE-2022-43626No exploit | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Medium6.8 | — | 1.1% | Mar 29, 2023 |
27Monitor | CVE-2022-43625No exploit | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-121 | Medium6.8 | — | 1.1% | Mar 29, 2023 |
27Monitor | CVE-2022-43624No exploit | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Medium6.8 | — | 1.1% | Mar 29, 2023 |
- CVE-2024-2712320Monitor
A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent.
MediumCVSS 5.2No exploitEPSS 0%qnap systems inc. · qcalagentSep 18, 2026
- CVE-2026-4929732Monitor
Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)
HighCVSS 8.1No exploitEPSS 1%apache · apache-airflow-providers-googleJul 6, 2026
- CVE-2026-4225236Monitor
Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern
CriticalCVSS 9.1No exploitEPSS 1%apache · airflowJun 1, 2026
- CVE-2026-4536132Monitor
Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
HighCVSS 8.1No exploitEPSS 1%apache · apache-airflow-providers-googleMay 25, 2026
- CVE-2025-1502435Monitor
RCE in Yordam Informatics' Library Automation System
HighCVSS 8.8No exploitEPSS 0%yordam information technology consulting, training and electronic systems industry and trade inc. · library automation systemMay 14, 2026
- CVE-2025-1502335Monitor
Improper Access Control in Yordam Informatics' Library Automation System
HighCVSS 8.8No exploitEPSS 0%yordam information technology consulting, training and electronic systems industry and trade inc. · library automation systemMay 14, 2026
- CVE-2026-4144636Monitor
WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints
CriticalCVSS 9.2No exploitEPSS 1%snap one, llc · wattbox 800Apr 28, 2026
- CVE-2025-2988728Monitor
A command injection vulnerability has been reported to affect QuRouter 2.5.1.
HighCVSS 7.1No exploitEPSS 1%qnap · qurouterAug 29, 2025
- CVE-2025-4922339Monitor
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute
CriticalCVSS 9.8Proof of conceptEPSS 1%naver · billboard.jsJun 3, 2025
- CVE-2025-006531Monitor
Improper Neutralization of Argument Delimiters in TeamViewer Clients
HighCVSS 7.8No exploitEPSS 1%teamviewer · remote full clientJan 28, 2025
- CVE-2024-386424Monitor
An improper certificate validation vulnerability has been reported to affect QuMagie.
LowCVSS 1.0No exploitEPSS 0%qnap · qumagieSep 6, 2024
- CVE-2024-2190426Monitor
A path traversal vulnerability has been reported to affect several QNAP operating system versions.
MediumCVSS 6.5No exploitEPSS 0%qnap · qtsSep 6, 2024
- CVE-2023-370339Monitor
Proscend Advice ICR Series routers fw version 1.76
CriticalCVSS 9.8No exploitEPSS 1%proscend · m357-5g firmwareSep 3, 2023
- CVE-2023-2735099Now
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%papercut · papercut mfApr 20, 2023
- CVE-2022-4364931Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.2.12465.
HighCVSS 7.8No exploitEPSS 1%foxit · pdf editorMar 29, 2023
- CVE-2022-4363327Monitor
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
MediumCVSS 6.8No exploitEPSS 1%dlink · dir-1935 firmwareMar 29, 2023
- CVE-2022-4363227Monitor
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
MediumCVSS 6.8No exploitEPSS 1%dlink · dir-1935 firmwareMar 29, 2023
- CVE-2022-4363127Monitor
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
MediumCVSS 6.8No exploitEPSS 1%dlink · dir-1935 firmwareMar 29, 2023
- CVE-2022-4363035Monitor
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
HighCVSS 8.8No exploitEPSS 1%dlink · dir-1935 firmwareMar 29, 2023
- CVE-2022-4362927Monitor
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
MediumCVSS 6.8No exploitEPSS 1%dlink · dir-1935 firmwareMar 29, 2023
- CVE-2022-4362827Monitor
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
MediumCVSS 6.8No exploitEPSS 1%dlink · dir-1935 firmwareMar 29, 2023
- CVE-2022-4362727Monitor
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
MediumCVSS 6.8No exploitEPSS 1%dlink · dir-1935 firmwareMar 29, 2023
- CVE-2022-4362627Monitor
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
MediumCVSS 6.8No exploitEPSS 1%dlink · dir-1935 firmwareMar 29, 2023
- CVE-2022-4362527Monitor
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
MediumCVSS 6.8No exploitEPSS 1%dlink · dir-1935 firmwareMar 29, 2023
- CVE-2022-4362427Monitor
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
MediumCVSS 6.8No exploitEPSS 1%dlink · dir-1935 firmwareMar 29, 2023