TSRC 的愿景

肩负腾讯公司安全漏洞、黑客入侵的发现和处理工作
这是个没有硝烟的战场,我们与两万多名安全专家并肩而行,捍卫全球亿万用户的信息、财产安全;
一直以来,我们怀揣感恩之心,努力构建开放的TSRC交流平台,回馈安全社区;
未来,我们将继续携手安全行业精英,探索互联网安全新方向,建设互联网生态安全,共铸"互联网+"新时代。

TSRC Vision

我们的贡献

ID Company Product Date Type VID Details
Wukong, TencentapacheApache Hive Standalone Metastore2025-10-27SQL InjectionCVE-2025-62728CVEID
kikayli/NVIDIA Isaac Sim Framework2025-10-13RCECVE-2025-23356CVEID
Wukong, TencentnvidiaNVIDIA Megatron-LM2025-09-01Code InjectionCVE-2025-23348CVEID
kikayli/NVIDIA Nemo2025-08-29RCECVE-2025-23312CVEID
Wukong, TencentLLaMA-FactoryLLaMA-Factory2025-06-26RCECVE-2025-53002CVEID
Wukong, Tencentlangchainlangchain2025-06-02XXECVE-2025-6984CVEID
kikayli/vllm2025-05-20RCECVE-2025-47277CVEID
kikayli/vite2025-04-02Path TraversalCVE-2025-31486CVEID
niubl/Ruby2022-04-12Double freeCVE-2022-28738Ruby Security
niubl/Ruby2022-04-12Buffer overrunCVE-2022-28739Ruby Security
niubl/Redmine2021-04-26Arbitrary file readCVE-2021-31863CVEID
niubl/Node.js2021-01-04HTTP Request SmugglingCVE-2020-8287Node.js Security
ClarkheinspurBMC2020-12-04Authentication BypassCVE-2020-26122Inspur Advisor
Nicky/EV Charger2020-10-24Free Charging/GeekPwn 2020
niubl/ruby2020-09-29HTTP Request SmugglingCVE-2020-25613Ruby Security
XbalienSemtechbasicstation2020-06-18Use-After-FreeCVE-2020-4060CVEID
XbalienSemtechLoRaMac-Node2020-05-26Buffer OverflowCVE-2020-11068CVEID
Wenxiang QianSQLite/GoogleChrome2019-12-11Out-of-bounds WriteCVE-2019-13734Google Security
Wenxiang QianSQLite/GoogleChrome2019-12-11Protection BypassCVE-2019-13750Google Security
Wenxiang QianSQLite/GoogleChrome2019-12-11Uninited Data ReadCVE-2019-13751Google Security
Wenxiang QianSQLite/GoogleChrome2019-12-11Out-of-bounds ReadCVE-2019-13752Google Security
Wenxiang QianSQLite/GoogleChrome2019-12-11Out-of-bounds ReadCVE-2019-13753Google Security
XbalienGoogleChrome2019-11-13Use-after-freeCVE-2019-13723Google Security
XbalienGoogleChrome2019-11-13Out-of-bounds accessCVE-2019-13724Google Security
Xiling GongQualcommAndroid2019-08-01Remote Code ExecutionCVE-2019-10539Qualcomm Security
Xiling GongQualcommAndroid2019-08-01Buffer OverflowCVE-2019-10540Qualcomm Security
Xiling GongGoogleAndroid2019-08-01Elevation of PrivilegeCVE-2019-10538Google Security
XbalienGoogleChrome2019-03-19Use-after-freeCVE-2019-5863Google Security
Wenxiang QianGoogleChrome2019-03-07Out of Bounds ReadCVE-2019-5835Google Security
Wenxiang Qiancurllibcurl2019-02-06Out-of-bounds ReadCVE-2018-16890Curl security
Wenxiang Qiancurllibcurl2019-02-06Stack Buffer OverflowCVE-2019-3822Curl security
Wenxiang QianSQLite/GoogleSQLite/Chromium2018-11-01Buffer Overflow/Mem LeakCVE-2018-20346Google Security
Wenxiang QianSQLite/GoogleSQLite/Chromium2018-11-01Buffer Overflow/Mem LeakCVE-2018-20505Google Security
Wenxiang QianSQLiteSQLite2018-11-01Remote DoSCVE-2018-20506SQLite Security
NickyMicrosoftCortana2018-07-15Android App RCE-Microsoft Security
Wenxiang Qian/libcivetweb2018-06-22Out-of-BoundsCVE-2018-12684CVE ORG
Wenxiang Qian/libcivetweb2018-06-22Information LeakCVE-2018-12685CVE ORG
Wenxiang Qian/libcivetweb2018-06-22Remote Code ExecutionCVE-2018-12686CVE ORG
Nicky & XbalienXiaoMiMI AI Speaker2018-06-08Remote Command Execute-XiaoMi Security
riuskskGoogleTensorFlow2018-06-01Out-of-bounds ReadCVE-2018-7574Google Security
riuskskGoogleTensorFlow2018-06-01Null Pointer DereferenceCVE-2018-7576Google Security
Bo ZhangGoogleTensorFlow2018-06-01Out-of-bounds ReadCVE-2018-8825Google Security
Bo ZhangGoogleTensorFlow2018-06-01Out-of-bounds ReadCVE-2018-7575Google Security
Bo ZhangGoogleTensorFlow2018-06-01memcpy-param-overlapCVE-2018-7577Google Security
Bo ZhangGoogleTensorFlow2018-06-01heap buffer overflowCVE-2018-10055Google Security
Bo ZhangGoogleAndroid2018-05-25Out-of-BoundsCVE-2017-15853Android Security
Peter PiQualcommAndroid2018-05-11Elevation of PrivilegeCVE-2018-3571Qualcomm Security
Peter PiQualcommAndroid2018-05-11Elevation of PrivilegeCVE-2018-3572Qualcomm Security
Xiling GongGoogleAndroid2018-05-01Remote Code ExecutionCVE-2018-5912Android Security
Xiling GongGoogleAndroid2018-05-01Remote Code ExecutionCVE-2018-2256Android Security
Peter PiQualcommAndroid2018-04-25Elevation of PrivilegeCVE-2018-3563Qualcomm Security
Zhiyang ZengAppleiMessage2018-04-24UI spoofingCVE-2018-4187Apple Security
saiyTOPThinkThinkPHP2018-04-10SQL Injection-
Peter PiGoogleAndroid2018-04-05Information LeakCVE-2018-9421Android Security
Peter PiGoogleAndroid2018-04-05Information LeakCVE-2018-9420Android Security
Peter PiGoogleAndroid2018-04-05Information LeakCVE-2018-9345Android Security
Peter PiGoogleAndroid2018-04-05Information LeakCVE-2018-9346Android Security
Zhiyang ZengAppleSafari2018-03-29UI spoofingCVE-2018-4134Apple Security
Peter PiQualcommAndroid2018-03-29Elevation of PrivilegeCVE-2017-15829Qualcomm Security
Peter PiQualcommAndroid2018-03-29Elevation of PrivilegeCVE-2017-15820Qualcomm Security
Peter PiQualcommAndroid2018-03-29Elevation of PrivilegeCVE-2017-14886Qualcomm Security
Peter PiGoogleAndroid2018-03-06Elevation of PrivilegeCVE-2017-13269Android Security
ZhangBoGoogleAndroid2018-03-06Elevation of PrivilegeCVE-2017-18069Android Security
Xiling GongGoogleAndroid2018-02-05Elevation of PrivilegeCVE-2017-15852Android Security
ZhangBoGoogleAndroid2018-02-05Elevation of PrivilegeCVE-2015-9016Android Security
Peter PiQualcommAndroid2018-01-26Elevation of PrivilegeCVE-2017-14873Qualcomm Security
WolfuGoogleAndroid2018-01-05Elevation of PrivilegeCVE-2017-13219Android Security
WolfuGoogleAndroid2018-01-05Elevation of PrivilegeCVE-2017-13207Android Security
Peter PiQualcommAndroid2017-12-14Elevation of PrivilegeCVE-2017-11031Qualcomm Security
riuskskAdobeAcrobat Pro DC2017-11-15Memory CorruptionCVE-2017-11293Adobe Security
riuskskAdobeAcrobat Pro DC2017-11-15Memory CorruptionCVE-2017-16408Adobe Security
riuskskAdobeAcrobat Pro DC2017-11-15Memory CorruptionCVE-2017-16409Adobe Security
riuskskAdobeAcrobat Pro DC2017-11-15Memory CorruptionCVE-2017-16410Adobe Security
riuskskAdobeAcrobat Pro DC2017-11-15Memory CorruptionCVE-2017-16411Adobe Security
riuskskAdobeAcrobat Pro DC2017-11-15Memory CorruptionCVE-2017-16399Adobe Security
riuskskAdobeAcrobat Pro DC2017-11-15Memory CorruptionCVE-2017-16395Adobe Security
riuskskAdobeAcrobat Pro DC2017-11-15Memory CorruptionCVE-2017-16394Adobe Security
riuskskAdobeAdobe Digital Editions2017-11-15Memory CorruptionCVE-2017-11301Adobe Security
Bo ZhangGoogleAndroid2017-11-07Elevation of PrivilegeCVE-2017-11600Android Security
Peter PiGoogleAndroid2017-11-07Elevation of PrivilegeCVE-2017-11091Android Security
Xiling GongGoogleAndroid2017-11-07Elevation of PrivilegeCVE-2017-9690Android Security
WolfuGoogleAndroid2017-11-07Elevation of PrivilegeCVE-2017-0863Android Security
WolfuGoogleAndroid2017-11-07Elevation of PrivilegeCVE-2017-11073Android Security
WolfuGoogleAndroid2017-11-07Elevation of PrivilegeCVE-2017-11093Android Security
Zhiyang ZengAppleSafari2017-11-01URL SpoofingCVE-2017-13790Apple Security
Peter PiGoogleAndroid2017-10-03Elevation of PrivilegeCVE-2017-11046Android Security
WolfuGoogleAndroid2017-10-03Elevation of PrivilegeCVE-2017-11050Android Security
WolfuGoogleAndroid2017-10-03Elevation of PrivilegeCVE-2017-11051Android Security
WolfuGoogleAndroid2017-10-03Elevation of PrivilegeCVE-2017-11067Android Security
riuskskAppleXcode2017-09-20Memory CorruptionCVE-2017-7076Apple Security
riuskskAppleXcode2017-09-20Memory CorruptionCVE-2017-7134Apple Security
riuskskAppleXcode2017-09-20Memory CorruptionCVE-2017-7135Apple Security
riuskskAppleXcode2017-09-20Memory CorruptionCVE-2017-7136Apple Security
riuskskAppleXcode2017-09-20Memory CorruptionCVE-2017-7137Apple Security
Bo ZhangRed HatLinux kernel2017-09-07Denial of ServiceCVE-2017-12153Redhat Security
riuskskAdobeAcrobat Reader2017-08-09Memory CorruptionCVE-2017-3016Adobe Security
riuskskAdobeAdobe Digital Editions2017-08-09Memory CorruptionCVE-2017-11280Adobe Security
riuskskApplemacOS2017-07-20Out-of-BoundsCVE-2017-7015Apple Security
riuskskApplemacOS2017-07-20Out-of-BoundsCVE-2017-7016Apple Security
riuskskApplemacOS2017-07-20Stack OverflowCVE-2017-7033Apple Security
Zhiyang ZengAppleSafari2017-07-20Memory CorruptionCVE-2017-7019Apple Security
Xiling GongGoogleAndroid2017-07-06Information DisclosureCVE-2017-0708Android Security
XbalienGoogleAndroid2017-07-06Elevation of privilegeCVE-2017-0704Android Security
XbalienGoogleAndroid2017-07-06Information DisclosureCVE-2017-0669Android Security
Xiling GongGoogleChrome2017-06-16Out-of-BoundsCVE-2017-5088Chrome Security
riuskskAdobeAdobe Digital Editions2017-06-14Out-of-BoundsCVE-2017-3093Adobe Security
riuskskAdobeAdobe Digital Editions2017-06-14Stack OverflowCVE-2017-3094Adobe Security
riuskskAdobeAdobe Digital Editions2017-06-14Stack OverflowCVE-2017-3095Adobe Security
riuskskAdobeAdobe Digital Editions2017-06-14Memory CorruptionCVE-2017-3096Adobe Security
Zhiyang ZengGoogleChrome2017-06-05Logical VulnerabilityCVE-2017-5085Chrome Security
Xiling GongGoogleAndroid2017-06-05Elevation of privilegeCVE-2017-8236Android Security
Zhiyang Zeng & Yuyang ZhouAppleSafari2017-05-16URL SpoofingCVE-2017-2500Apple Security
Zhiyang ZengAppleSafari2017-05-16URL SpoofingCVE-2017-2511Apple Security
Xiling GongGoogleAndroid2017-05-05Elevation of privilegeCVE-2017-0597Android Security
riuskskAdobeAcrobat Reader2017-04-12Out-of-BoundsCVE-2017-3040Adobe Security
riuskskAdobeAcrobat Reader2017-04-12Memory CorruptionCVE-2017-3039Adobe Security
kimyokAdobeAcrobat Reader2017-04-12Memory CorruptionCVE-2017-3017Adobe Security
kimyokAdobeAcrobat Reader2017-04-12Memory CorruptionCVE-2017-3018Adobe Security
kimyokAdobeAcrobat Reader2017-04-12Memory CorruptionCVE-2017-3024Adobe Security
kimyokAdobeAcrobat Reader2017-04-12Memory CorruptionCVE-2017-3025Adobe Security
kimyokAdobeAcrobat Reader2017-04-12Memory CorruptionCVE-2017-3065Adobe Security
Zhiyang Zeng/MyBB2017-04-04XSSCVE-2017-8103CVE ORG
Zhiyang Zeng/MyBB2017-04-04Directory TraversalCVE-2017-8104CVE ORG
riuskskApplemacOS/iOS2017-03-28Heap OverflowCVE-2017-2379Apple Security
riuskskApplemacOS/iOS2017-03-28Denial of ServiceCVE-2017-2417Apple Security
riuskskApplemacOS/iOS2017-03-28Out-of-BoundsCVE-2017-2487Apple Security
riuskskApplemacOS/iOS2017-03-28Memory CorruptionCVE-2017-2406Apple Security
riuskskApplemacOS/iOS2017-03-28Memory CorruptionCVE-2017-2407Apple Security
kimyokApplemacOS2017-03-28Memory CorruptionCVE-2017-2431Apple Security
kimyokApplemacOS2017-03-28Double FreeCVE-2017-2435Apple Security
Yuyang ZhouAppleSafari2017-03-28URL SpoofingCVE-2017-2376Apple Security
深夜饮酒AppleSafari2017-03-28HTTP Authentication SpoofingCVE-2017-2389Apple Security
NickyHuaweiEMUI2017-03-23Bluetooth Unlock BypassingCVE-2017-2728Security Advisories
zhaohuanApplemfi.apple.com2017-03-07Server Configuration-Apple Security
zhaohuanAppledeveloper.apple.com2017-03-07Server Configuration-Apple Security
zhaohuanAppleara.apple.com2017-03-07Server Configuration-Apple Security
riuskskFoxitFoxit Reader2017-03-02Memory CorruptionCVE-2017-5989Security Bulletins
NickyHuaweiEMUI2017-02-23Remote Code ExecutionCVE-2017-2699Security Advisories
riuskskAdobeAcrobat Reader2017-02-16Heap OverflowCVE-2017-2959Adobe Security
Peter PiQualcommAndroid2017-02-16Elevation of PrivilegeCVE-2018-11047Qualcomm Security
Peter PiQualcommAndroid2017-02-16Elevation of PrivilegeCVE-2018-15826Qualcomm Security
NickyLineCorpLine2017-01-13Cross Site Script/HallofFame
XbalienGoogleAndroid2017-01-04Elevation of PrivilegeCVE-2017-0395Android Security
riusksk/libarchive2016-12-29Use After FreeCVE-2016-10080CVE ORG
NeargleFlaskFlask2016-12-24Cross Site ScriptCVE-2016-10516 Flask Security
kimyok/libwebp2016-12-16Memory CorruptionCVE-2016-9969CVE ORG
riuskskApplemacOS/iOS2016-12-14Out-of-BoundsCVE-2016-7595Apple Security
riuskskApplemacOS/iOS2016-12-14Out-of-BoundsCVE-2016-4691Apple Security
riuskskApplemacOS2016-12-14Memory CorruptionCVE-2016-7618Apple Security
riuskskApplemacOS2016-12-14Memory CorruptionCVE-2016-7622Apple Security
riusksk/giflib2016-12-13Out-of-BoundsCVE-2016-9944CVE ORG
riusksk/OpenJPEG2016-12-07Memory CorruptionCVE-2016-9890CVE ORG
XbalienGoogleAndroid2016-12-06Elevation of PrivilegeCVE-2016-6771Android Security
riusksk/libxml22016-12-05Out-of-BoundsCVE-2016-9833CVE ORG
kimyokGooglepdfium2016-12-04Out-of-BoundsCVE-2016-9805CVE ORG
riusksk/OpenJPEG2016-12-01Memory CorruptionCVE-2016-9753CVE ORG
kimyokGoogleVRCore2016-11-30Auth Bypass/Google VRP
kimyokGooglesyncadapters2016-11-19Auth BypassCVE-2019-9281Google VRP
Nicky/ExponentCMS2016-11-11SQL InjectionCVE-2016-9272Github Issue
askyshangGoogleAndroid2016-11-01Denial of serviceCVE-2016-6713Android Security
riuskskAppleMac OS X2016-09-21Memory CorruptionCVE-2016-4779HT207170
riuskskAppleXcode2016-09-14Memory CorruptionCVE-2016-4705HT207140
Yuyang Zhou GoogleChrome2016-08-21Scheme bypassCVE-2016-5193Google Security
Yuyang Zhou MozillaFirefox2016-08-04same-origin policy bypassCVE-2016-5291 Mozilla Security
深夜饮酒GoogleChrome2016-07-21Content-Security-Policy bypassCVE-2016-5135Chrome Security
Xiling GongGoogleAndroid2016-07-07Elevation of privilegeCVE-2016-3745Android Security
Xiling GongGoogleAndroid2016-06-06Information DisclosureCVE-2016-2499Android Security
NickyLenovoShareIt2016-05-19UXSSCVE-2016-4783LEN-6421
NickyLenovoShareIt2016-05-19Intent Scheme URL attackCVE-2016-4782LEN-6421
riusksk/libgd2016-05-01Double FreeCVE-2016-4413libgd bug 208
Nicky/dotCMS2016-04-12SQL InjectionCVE-2016-2355dotCMS SI-35
riusksk/libav2016-03-18Memory CorruptionCVE-2016-3184libav bug 930
riuskskYahooWebMail2016-03-18XSS/Hackerone
riusksk/libav2016-03-11Memory CorruptionCVE-2016-3062libav bug 929
riuskskAdobeFlash Player2016-03-11Memory CorruptionCVE-2016-0992APSB16-08
Do9gy/Cacti2016-03-07SQL InjectionCVE-2016-3172Cacti 0002667
zhaohuan/JiveSoftware2016-02-03Directory TraversalCVE-2016-2534EDB-ID 39405
riusksk/libtiff2015-12-28Heap OverflowCVE-2015-8668Redhat Bug 129425
Do9gy/phpMyAdmin2015-12-25Info LeakCVE-2015-8669PMASA-2015-6
riusksk && monsterLakalaLakala POS2015-10-24Access Control Weakness/GeekPwn2015
riuskskSuningifPay2015-10-24Remote Code Execution/GeekPwn2015
zhuliangiBoxPayiBoxPay POS2015-10-24Access Control Weakness/GeekPwn2015
nickyChangDiChangdi Smart Oven2015-10-24Authentication Bypass/GeekPwn2015
GmxpDJIPhantom Drone2015-10-24Authentication Bypass/GeekPwn2015
GmxpAppleXcodeGhost2015-09-12Backdoor/TSRC Blog
monsterYeahkaYeahka POS2014-12-23Access Control Weakness/GeekPwn2014
riuskskKonkeKonke Smart Plug2014-10-24Authentication Bypass/GeekPwn2014
monsterBaiduiermu Camera2014-10-24Authentication Bypass/GeekPwn2014
GmxpScienerSciener Smart Door Lock2014-10-24Info Leak & Authentication Bypass/GeekPwn2014
zhaohuanEbayWebSite2014-06-10Remote Code Execution/Ebay
zhaohuanYahooWebSite2014-04-01Remote Code Execution/Hackerone
zhaohuanEvernoteWebSite2014-04-01Remote Code Execution/Evernote
dragonltxAppleQuickTime Player2014-02-25Heap OverflowCVE-2014-1249HT202932
riuskskAlibabaWebSite2014-01-11Multiple Dom XSS/ASRC
riuskskNetEaseWebSite2013-07-17Multiple Remote Code Execution/NSRC
riuskskBaiduWebSite2013-07-17Multiple Remote Code Execution/BSRC
riuskskBaiduWebSite2013-07-03Multiple SQL Injection/BSRC
riuskskMicrosoftDirectShow2013-02-12Heap OverflowCVE-2013-0077MS13-011
zhaohuanPayPalWebSite2013-02-11Multiple XSS/Paypal
riuskskNetEaseWebSite2013-01-17Multiple Dom XSS/NSRC
xti9er && chouqiu/phpMyAdmin && SourceForge2012-09-25BackdoorCVE-2012-5159PMASA-2012-5 SourceForge blog
zhaohuanMicrosoftWebSite2012-01-01SQL Injection && XSS/Microsoft
lake2AdobeFlash Player2011-01-01Cross-domain Policy BypassCVE-2011-2458APSB11-28
lake2AdobeFlash Player2009-07-30Heap OverflowCVE-2009-1862APSB09-10