//... Security Research - Fenryx Skip to main content

Security Research

Responsible vulnerability disclosure and security research.

All vulnerabilities were responsibly disclosed to affected vendors. Organization names are anonymized.

25+
Vulnerabilities Reported
3
Critical Severity
1
CVE Assigned
24
HITCON ZeroDay

Disclosure Timeline

2025
4 disclosures
CVE-2025-13468 Medium
PHP Object Injection
Vendor Anonymized
HITCON ZeroDay High
Unauthorized Access
Vendor Anonymized
HITCON ZeroDay Low
Reflected XSS
Vendor Anonymized
HITCON ZeroDay Medium
SQL Injection
Vendor Anonymized
2024
15 disclosures
HITCON ZeroDay Low
Broken Access Control
Vendor Anonymized
HITCON ZeroDay Medium
SQL Injection
Vendor Anonymized
HITCON ZeroDay Low
Information Disclosure
Vendor Anonymized
HITCON ZeroDay High
Broken Access Control
Vendor Anonymized
HITCON ZeroDay Medium
Broken Access Control
Vendor Anonymized
HITCON ZeroDay Critical
Remote Code Execution
Vendor Anonymized
HITCON ZeroDay Low
Information Disclosure
Vendor Anonymized
HITCON ZeroDay Medium
SQL Injection
Vendor Anonymized
HITCON ZeroDay Low
Security Misconfiguration
Vendor Anonymized
HITCON ZeroDay Low
Broken Access Control
Vendor Anonymized
HITCON ZeroDay Critical
SQL Injection to RCE
Vendor Anonymized
HITCON ZeroDay Critical
Remote Code Execution
Vendor Anonymized
HITCON ZeroDay High
Security Misconfiguration
Vendor Anonymized
HITCON ZeroDay Medium
Local File Inclusion
Vendor Anonymized
HITCON ZeroDay Low
Information Disclosure
Vendor Anonymized
2023
4 disclosures
HITCON ZeroDay Low
Information Disclosure
Vendor Anonymized
HITCON ZeroDay High
SQL Injection
Vendor Anonymized
HITCON ZeroDay High
Arbitrary File Upload
Vendor Anonymized
HITCON ZeroDay Medium
Information Disclosure
Vendor Anonymized
2022
1 disclosures
HITCON ZeroDay High
Arbitrary File Upload
Vendor Anonymized
2021
1 disclosures
HITCON ZeroDay Low
Security Vulnerability
Vendor Anonymized

Responsible Disclosure

All vulnerabilities listed above were reported through official channels, including vendor security teams and Taiwan's HITCON ZeroDay vulnerability disclosure platform.

We follow responsible disclosure practices:

  • Report vulnerabilities directly to affected vendors
  • Allow reasonable time for patches before public disclosure
  • Provide detailed technical reports with remediation guidance
  • Respect vendor coordination timelines

Organization names are anonymized to protect vendors and their customers.

Need Security Assessment?

Let our experienced team identify vulnerabilities in your systems before attackers do.

Request Assessment