| Bug Title | Download | CVE | Vendor/Software | Date Released |
| Cross Context Scripting (XCS) - about:history - Remote Code Execution | html | TBA | Maxthon | Dec 2012 |
| Cross Context Scripting (XCS) - RSS - Remote Code Execution | html | TBA | Maxthon | Dec 2012 |
| Privileged API Available On i.maxthon.com
| html | TBA | Maxthon | Dec 2012 |
| Cross Context Scripting (XCS) - Bookmark Toolbar and Bookmark Sidebar | html | TBA | Maxthon | Dec 2012 |
| Incorrect Executable File Handling and Same Origin Policy Implementation
| html | TBA | Maxthon | Dec 2012 |
| Same of Origin Policy Bypass - browser:home
| html | TBA | Avant Browser | Dec 2012 |
| Cross Context Scripting - browser:home - Most Visited And History Tabs | html | TBA | Avant Browser | Dec 2012 |
| Avant Browser - Stored Cross Site Scripting - Feed Reader (browser://localhost/lst?*) | html | TBA | Avant Browser | Dec 2012 |
| CSRF | html | 2012-0550 | Oracle GlassFish Server | Apr 2012 |
| Multiple Cross Site Scripting | html | 2012-0551 | Oracle GlassFish Server | Apr 2012 |
| Use After Free | html | 2011-4152 | Opera | Oct 2011 |
| DOM Cross Site Scripting | html . pdf | 2011-2133 | Adobe RoboHelp 9 | Aug 2011 |
| ParanoidFragmentSink allows javascript: URLs in chrome documents | pdf (section 2.8) | 2010-1585 | Mozilla Firefox / Thunderbird | Mar 2011 |
| Session Fixation | html . pdf | 2010-4437 | Oracle WebLogic Server | Mar 2011 |
| Multiple Cross Site Scripting Vulnerabilities | html . pdf | 2010-2406 | Oracle eBusiness Application | Oct 2010 |
| HTTP Response Splitting | html . pdf | 2010-3514 | Oracle Sun Java System Web Server | Oct 2010 |
| SOP Bypass | html . pdf | 2010-3573 | Oracle JRE java.net.URLConnection | Oct 2010 |
| XML Entity and XML Injections | html . pdf | 2009-3960 | Multiple Adobe Products | Feb 2010 |
| Chrome Privilege Code Execution | html . pdf | | Update Scanner | Aug 2009 |
| Chrome Privilege Code Execution | html . pdf | | Coolpreviews | Aug 2009 |
| Stored Cross Site Scripting | html . pdf | 2008-4725 | Opera | Oct 2008 |
| Stored Cross Site Scripting | html . pdf | | Google Analytics | Oct 2008 |
| Local File Disclosure | html . pdf | 2008-2045 | SugarCRM | Apr 2008 |
| Reflected Cross Site Scripting | html | | DotNetNuke | Aug 2006 |