Anonymous
Trend Micro Zero Day Initiative
160 записей с упоминанием · 7 за 12 месяцев · 1 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
20Наблюдать | CVE-2024-27123Эксплойта нет | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent.qnap systems inc. · qcalagent · CWE-79 | Средняя5,2 | — | 0,1 % | 18 сент. 2026 г. |
32Наблюдать | CVE-2026-49297Эксплойта нет | Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)apache · apache-airflow-providers-google · CWE-22 | Высокая8,1 | — | 1,0 % | 6 июл. 2026 г. |
36Наблюдать | CVE-2026-42252Эксплойта нет | Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user patternapache · airflow · CWE-1336 | Критическая9,1 | — | 0,6 % | 1 июн. 2026 г. |
32Наблюдать | CVE-2026-45361Эксплойта нет | Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)apache · apache-airflow-providers-google · CWE-322 | Высокая8,1 | — | 0,8 % | 25 мая 2026 г. |
35Наблюдать | CVE-2025-15024Эксплойта нет | RCE in Yordam Informatics' Library Automation Systemyordam information technology consulting, training and electronic systems industry and trade inc. · library automation system · CWE-94 | Высокая8,8 | — | 0,2 % | 14 мая 2026 г. |
35Наблюдать | CVE-2025-15023Эксплойта нет | Improper Access Control in Yordam Informatics' Library Automation Systemyordam information technology consulting, training and electronic systems industry and trade inc. · library automation system · CWE-863 | Высокая8,8 | — | 0,2 % | 14 мая 2026 г. |
36Наблюдать | CVE-2026-41446Эксплойта нет | WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpointssnap one, llc · wattbox 800 · CWE-798 | Критическая9,2 | — | 0,8 % | 28 апр. 2026 г. |
28Наблюдать | CVE-2025-29887Эксплойта нет | A command injection vulnerability has been reported to affect QuRouter 2.5.1.qnap · qurouter · CWE-77 | Высокая7,1 | — | 0,8 % | 29 авг. 2025 г. |
39Наблюдать | CVE-2025-49223Proof of concept | billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to executenaver · billboard.js · CWE-1321 | Критическая9,8 | — | 0,8 % | 3 июн. 2025 г. |
31Наблюдать | CVE-2025-0065Эксплойта нет | Improper Neutralization of Argument Delimiters in TeamViewer Clientsteamviewer · remote full client · CWE-88 | Высокая7,8 | — | 0,6 % | 28 янв. 2025 г. |
4Наблюдать | CVE-2024-38642Эксплойта нет | An improper certificate validation vulnerability has been reported to affect QuMagie.qnap · qumagie · CWE-295 | Низкая1,0 | — | 0,1 % | 6 сент. 2024 г. |
26Наблюдать | CVE-2024-21904Эксплойта нет | A path traversal vulnerability has been reported to affect several QNAP operating system versions.qnap · qts · CWE-22 | Средняя6,5 | — | 0,4 % | 6 сент. 2024 г. |
39Наблюдать | CVE-2023-3703Эксплойта нет | Proscend Advice ICR Series routers fw version 1.76proscend · m357-5g firmware · CWE-1392 | Критическая9,8 | — | 0,6 % | 3 сент. 2023 г. |
99Срочно | CVE-2023-27350Готовый эксплойт | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Критическая9,8 | KEV | 100,0 % | 20 апр. 2023 г. |
31Наблюдать | CVE-2022-43649Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.2.12465.foxit · pdf editor · CWE-416 | Высокая7,8 | — | 1,1 % | 29 мар. 2023 г. |
27Наблюдать | CVE-2022-43633Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Средняя6,8 | — | 1,1 % | 29 мар. 2023 г. |
27Наблюдать | CVE-2022-43632Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Средняя6,8 | — | 1,1 % | 29 мар. 2023 г. |
27Наблюдать | CVE-2022-43631Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Средняя6,8 | — | 1,1 % | 29 мар. 2023 г. |
35Наблюдать | CVE-2022-43630Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-121 | Высокая8,8 | — | 1,0 % | 29 мар. 2023 г. |
27Наблюдать | CVE-2022-43629Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Средняя6,8 | — | 1,1 % | 29 мар. 2023 г. |
27Наблюдать | CVE-2022-43628Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Средняя6,8 | — | 0,9 % | 29 мар. 2023 г. |
27Наблюдать | CVE-2022-43627Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Средняя6,8 | — | 1,1 % | 29 мар. 2023 г. |
27Наблюдать | CVE-2022-43626Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Средняя6,8 | — | 1,1 % | 29 мар. 2023 г. |
27Наблюдать | CVE-2022-43625Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-121 | Средняя6,8 | — | 1,1 % | 29 мар. 2023 г. |
27Наблюдать | CVE-2022-43624Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.dlink · dir-1935 firmware · CWE-78 | Средняя6,8 | — | 1,1 % | 29 мар. 2023 г. |
- CVE-2024-2712320Наблюдать
A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent.
СредняяCVSS 5,2Эксплойта нетEPSS 0 %qnap systems inc. · qcalagent18 сент. 2026 г.
- CVE-2026-4929732Наблюдать
Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %apache · apache-airflow-providers-google6 июл. 2026 г.
- CVE-2026-4225236Наблюдать
Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %apache · airflow1 июн. 2026 г.
- CVE-2026-4536132Наблюдать
Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %apache · apache-airflow-providers-google25 мая 2026 г.
- CVE-2025-1502435Наблюдать
RCE in Yordam Informatics' Library Automation System
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %yordam information technology consulting, training and electronic systems industry and trade inc. · library automation system14 мая 2026 г.
- CVE-2025-1502335Наблюдать
Improper Access Control in Yordam Informatics' Library Automation System
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %yordam information technology consulting, training and electronic systems industry and trade inc. · library automation system14 мая 2026 г.
- CVE-2026-4144636Наблюдать
WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %snap one, llc · wattbox 80028 апр. 2026 г.
- CVE-2025-2988728Наблюдать
A command injection vulnerability has been reported to affect QuRouter 2.5.1.
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %qnap · qurouter29 авг. 2025 г.
- CVE-2025-4922339Наблюдать
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute
КритическаяCVSS 9,8Proof of conceptEPSS 1 %naver · billboard.js3 июн. 2025 г.
- CVE-2025-006531Наблюдать
Improper Neutralization of Argument Delimiters in TeamViewer Clients
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %teamviewer · remote full client28 янв. 2025 г.
- CVE-2024-386424Наблюдать
An improper certificate validation vulnerability has been reported to affect QuMagie.
НизкаяCVSS 1,0Эксплойта нетEPSS 0 %qnap · qumagie6 сент. 2024 г.
- CVE-2024-2190426Наблюдать
A path traversal vulnerability has been reported to affect several QNAP operating system versions.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %qnap · qts6 сент. 2024 г.
- CVE-2023-370339Наблюдать
Proscend Advice ICR Series routers fw version 1.76
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %proscend · m357-5g firmware3 сент. 2023 г.
- CVE-2023-2735099Срочно
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %papercut · papercut mf20 апр. 2023 г.
- CVE-2022-4364931Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.2.12465.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %foxit · pdf editor29 мар. 2023 г.
- CVE-2022-4363327Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %dlink · dir-1935 firmware29 мар. 2023 г.
- CVE-2022-4363227Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %dlink · dir-1935 firmware29 мар. 2023 г.
- CVE-2022-4363127Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %dlink · dir-1935 firmware29 мар. 2023 г.
- CVE-2022-4363035Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dlink · dir-1935 firmware29 мар. 2023 г.
- CVE-2022-4362927Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %dlink · dir-1935 firmware29 мар. 2023 г.
- CVE-2022-4362827Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %dlink · dir-1935 firmware29 мар. 2023 г.
- CVE-2022-4362727Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %dlink · dir-1935 firmware29 мар. 2023 г.
- CVE-2022-4362627Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %dlink · dir-1935 firmware29 мар. 2023 г.
- CVE-2022-4362527Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %dlink · dir-1935 firmware29 мар. 2023 г.
- CVE-2022-4362427Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %dlink · dir-1935 firmware29 мар. 2023 г.